* [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation
@ 2026-10-02 12:49 Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
To: netfilter-devel; +Cc: Balazs Gulacsi
Special casing for SNAT/DNAT conntrack states was broken with inverted
matches:
- Wrong bit in invert_flags checked (typo?)
- Missing space after operator (cosmetics!)
Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1826
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
extensions/libxt_conntrack.c | 2 +-
extensions/libxt_conntrack.txlate | 6 ++++++
2 files changed, 7 insertions(+), 1 deletion(-)
diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index 04940154eb314..2b41213edb0e4 100644
--- a/extensions/libxt_conntrack.c
+++ b/extensions/libxt_conntrack.c
@@ -1230,7 +1230,7 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl,
if ((sinfo->state_mask & XT_CONNTRACK_STATE_SNAT) ||
(sinfo->state_mask & XT_CONNTRACK_STATE_DNAT)) {
xt_xlate_add(xl, "%sct status %s%s", space,
- sinfo->invert_flags & XT_CONNTRACK_STATUS ? "!=" : "",
+ sinfo->invert_flags & XT_CONNTRACK_STATE ? "!= " : "",
sinfo->state_mask & XT_CONNTRACK_STATE_SNAT ? "snat" : "dnat");
space = " ";
} else {
diff --git a/extensions/libxt_conntrack.txlate b/extensions/libxt_conntrack.txlate
index 0f44a957878e8..79b34df9e3586 100644
--- a/extensions/libxt_conntrack.txlate
+++ b/extensions/libxt_conntrack.txlate
@@ -55,6 +55,12 @@ nft 'add rule ip filter INPUT ct direction original ct original protocol 6 ct st
iptables-translate -t filter -A INPUT -m conntrack --ctstate SNAT -j ACCEPT
nft 'add rule ip filter INPUT ct status snat counter accept'
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate SNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != snat counter accept'
+
iptables-translate -t filter -A INPUT -m conntrack --ctstate DNAT -j ACCEPT
nft 'add rule ip filter INPUT ct status dnat counter accept'
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat counter accept'
+
--
2.54.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
@ 2026-10-02 12:49 ` Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
To: netfilter-devel; +Cc: Balazs Gulacsi
Balazs writes:
> iptables-translate ignores the RELATED,ESTABLISHED states, when DNAT
> is also present:
> # iptables-translate -A SOMECHAIN -m conntrack \
> --ctstate RELATED,ESTABLISHED,DNAT -j DROP
> nft 'add rule ip filter SOMECHAIN ct status dnat counter drop'
> # iptables-translate -A SOMECHAIN -m conntrack \
> --ctstate RELATED,ESTABLISHED -j DROP
> nft 'add rule ip filter SOMECHAIN ct state related,established counter drop'
Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1827
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
extensions/libxt_conntrack.c | 4 +++-
extensions/libxt_conntrack.txlate | 14 ++++++++++++++
2 files changed, 17 insertions(+), 1 deletion(-)
diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index 2b41213edb0e4..4ac4fba00c9c5 100644
--- a/extensions/libxt_conntrack.c
+++ b/extensions/libxt_conntrack.c
@@ -1233,7 +1233,9 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl,
sinfo->invert_flags & XT_CONNTRACK_STATE ? "!= " : "",
sinfo->state_mask & XT_CONNTRACK_STATE_SNAT ? "snat" : "dnat");
space = " ";
- } else {
+ }
+ if (sinfo->state_mask & ~(XT_CONNTRACK_STATE_SNAT |
+ XT_CONNTRACK_STATE_DNAT)) {
xt_xlate_add(xl, "%sct state ", space);
state_xlate_print(xl, sinfo->state_mask,
sinfo->invert_flags & XT_CONNTRACK_STATE);
diff --git a/extensions/libxt_conntrack.txlate b/extensions/libxt_conntrack.txlate
index 79b34df9e3586..e7255e2a516fd 100644
--- a/extensions/libxt_conntrack.txlate
+++ b/extensions/libxt_conntrack.txlate
@@ -64,3 +64,17 @@ nft 'add rule ip filter INPUT ct status dnat counter accept'
iptables-translate -t filter -A INPUT -m conntrack ! --ctstate DNAT -j ACCEPT
nft 'add rule ip filter INPUT ct status != dnat counter accept'
+iptables-translate -t filter -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status dnat ct state related,established counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack --ctstate ESTABLISHED,DNAT --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status dnat ct state established ct status confirmed counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established ct status confirmed counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT ! --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established ct status ! confirmed counter accept'
--
2.54.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
@ 2026-10-02 12:49 ` Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
To: netfilter-devel; +Cc: Evgeniy Gorbanyov
From: Evgeniy Gorbanyov <esgor@altlinux.org>
iptables-restore returns early on -6, and ip6tables-restore on -4, so
a rule for the other family is ignored. A command already parsed on
that line is still executed. replace_entry() then dereferences NULL
address pointers because post_parse() never ran.
Clear the command before returning so the line is dropped.
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1864
Signed-off-by: Evgeniy Gorbanyov <esgor@altlinux.org>
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
.../0019-family-flag-after-command_0 | 29 +++++++++++++++++++
iptables/xshared.c | 8 +++--
2 files changed, 35 insertions(+), 2 deletions(-)
create mode 100755 iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
diff --git a/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0 b/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
new file mode 100755
index 0000000000000..4e1bed1e984fe
--- /dev/null
+++ b/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
@@ -0,0 +1,29 @@
+#!/bin/bash
+
+# -4/-6 during restore skips the whole line. If the flag appears after a
+# command has already been parsed, that command must be discarded.
+# Otherwise iptables-restore executes it without post_parse() and crashes
+# on NULL address pointers in replace_entry.
+
+set -e
+
+$XT_MULTI iptables-restore <<EOF
+*filter
+-A FORWARD -m comment --comment keep -j ACCEPT
+-R FORWARD 1 -6 -m comment --comment gone -j DROP
+-F FORWARD -6
+COMMIT
+EOF
+
+EXPECT='-A FORWARD -m comment --comment keep -j ACCEPT'
+diff -u -Z <(echo -e "$EXPECT") <($XT_MULTI iptables -S | grep -v '^-P')
+
+$XT_MULTI ip6tables-restore <<EOF
+*filter
+-A FORWARD -m comment --comment keep -j ACCEPT
+-R FORWARD 1 -4 -m comment --comment gone -j DROP
+-F FORWARD -4
+COMMIT
+EOF
+
+diff -u -Z <(echo -e "$EXPECT") <($XT_MULTI ip6tables -S | grep -v '^-P')
diff --git a/iptables/xshared.c b/iptables/xshared.c
index 263dcc32e5eb1..bb3da97be9fd3 100644
--- a/iptables/xshared.c
+++ b/iptables/xshared.c
@@ -1903,8 +1903,10 @@ void do_parse(int argc, char *argv[],
if (args->family == AF_INET)
break;
- if (p->restore && args->family == AF_INET6)
+ if (p->restore && args->family == AF_INET6) {
+ p->command = CMD_NONE;
return;
+ }
exit_tryhelp(2, p->line);
@@ -1912,8 +1914,10 @@ void do_parse(int argc, char *argv[],
if (args->family == AF_INET6)
break;
- if (p->restore && args->family == AF_INET)
+ if (p->restore && args->family == AF_INET) {
+ p->command = CMD_NONE;
return;
+ }
exit_tryhelp(2, p->line);
--
2.54.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
@ 2026-10-08 13:28 ` Phil Sutter
2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-08 13:28 UTC (permalink / raw)
To: netfilter-devel; +Cc: Balazs Gulacsi
On Fri, Oct 02, 2026 at 02:49:14PM +0200, Phil Sutter wrote:
> Special casing for SNAT/DNAT conntrack states was broken with inverted
> matches:
>
> - Wrong bit in invert_flags checked (typo?)
> - Missing space after operator (cosmetics!)
>
> Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
> Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1826
> Signed-off-by: Phil Sutter <phil@nwl.cc>
Series applied.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-08 13:28 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox