* [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
@ 2026-10-02 12:49 ` Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
To: netfilter-devel; +Cc: Balazs Gulacsi
Balazs writes:
> iptables-translate ignores the RELATED,ESTABLISHED states, when DNAT
> is also present:
> # iptables-translate -A SOMECHAIN -m conntrack \
> --ctstate RELATED,ESTABLISHED,DNAT -j DROP
> nft 'add rule ip filter SOMECHAIN ct status dnat counter drop'
> # iptables-translate -A SOMECHAIN -m conntrack \
> --ctstate RELATED,ESTABLISHED -j DROP
> nft 'add rule ip filter SOMECHAIN ct state related,established counter drop'
Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1827
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
extensions/libxt_conntrack.c | 4 +++-
extensions/libxt_conntrack.txlate | 14 ++++++++++++++
2 files changed, 17 insertions(+), 1 deletion(-)
diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index 2b41213edb0e4..4ac4fba00c9c5 100644
--- a/extensions/libxt_conntrack.c
+++ b/extensions/libxt_conntrack.c
@@ -1233,7 +1233,9 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl,
sinfo->invert_flags & XT_CONNTRACK_STATE ? "!= " : "",
sinfo->state_mask & XT_CONNTRACK_STATE_SNAT ? "snat" : "dnat");
space = " ";
- } else {
+ }
+ if (sinfo->state_mask & ~(XT_CONNTRACK_STATE_SNAT |
+ XT_CONNTRACK_STATE_DNAT)) {
xt_xlate_add(xl, "%sct state ", space);
state_xlate_print(xl, sinfo->state_mask,
sinfo->invert_flags & XT_CONNTRACK_STATE);
diff --git a/extensions/libxt_conntrack.txlate b/extensions/libxt_conntrack.txlate
index 79b34df9e3586..e7255e2a516fd 100644
--- a/extensions/libxt_conntrack.txlate
+++ b/extensions/libxt_conntrack.txlate
@@ -64,3 +64,17 @@ nft 'add rule ip filter INPUT ct status dnat counter accept'
iptables-translate -t filter -A INPUT -m conntrack ! --ctstate DNAT -j ACCEPT
nft 'add rule ip filter INPUT ct status != dnat counter accept'
+iptables-translate -t filter -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status dnat ct state related,established counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack --ctstate ESTABLISHED,DNAT --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status dnat ct state established ct status confirmed counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established ct status confirmed counter accept'
+
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate RELATED,ESTABLISHED,DNAT ! --ctstatus CONFIRMED -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat ct state ! related,established ct status ! confirmed counter accept'
--
2.54.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
@ 2026-10-02 12:49 ` Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2 siblings, 0 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
To: netfilter-devel; +Cc: Evgeniy Gorbanyov
From: Evgeniy Gorbanyov <esgor@altlinux.org>
iptables-restore returns early on -6, and ip6tables-restore on -4, so
a rule for the other family is ignored. A command already parsed on
that line is still executed. replace_entry() then dereferences NULL
address pointers because post_parse() never ran.
Clear the command before returning so the line is dropped.
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1864
Signed-off-by: Evgeniy Gorbanyov <esgor@altlinux.org>
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
.../0019-family-flag-after-command_0 | 29 +++++++++++++++++++
iptables/xshared.c | 8 +++--
2 files changed, 35 insertions(+), 2 deletions(-)
create mode 100755 iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
diff --git a/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0 b/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
new file mode 100755
index 0000000000000..4e1bed1e984fe
--- /dev/null
+++ b/iptables/tests/shell/testcases/ipt-restore/0019-family-flag-after-command_0
@@ -0,0 +1,29 @@
+#!/bin/bash
+
+# -4/-6 during restore skips the whole line. If the flag appears after a
+# command has already been parsed, that command must be discarded.
+# Otherwise iptables-restore executes it without post_parse() and crashes
+# on NULL address pointers in replace_entry.
+
+set -e
+
+$XT_MULTI iptables-restore <<EOF
+*filter
+-A FORWARD -m comment --comment keep -j ACCEPT
+-R FORWARD 1 -6 -m comment --comment gone -j DROP
+-F FORWARD -6
+COMMIT
+EOF
+
+EXPECT='-A FORWARD -m comment --comment keep -j ACCEPT'
+diff -u -Z <(echo -e "$EXPECT") <($XT_MULTI iptables -S | grep -v '^-P')
+
+$XT_MULTI ip6tables-restore <<EOF
+*filter
+-A FORWARD -m comment --comment keep -j ACCEPT
+-R FORWARD 1 -4 -m comment --comment gone -j DROP
+-F FORWARD -4
+COMMIT
+EOF
+
+diff -u -Z <(echo -e "$EXPECT") <($XT_MULTI ip6tables -S | grep -v '^-P')
diff --git a/iptables/xshared.c b/iptables/xshared.c
index 263dcc32e5eb1..bb3da97be9fd3 100644
--- a/iptables/xshared.c
+++ b/iptables/xshared.c
@@ -1903,8 +1903,10 @@ void do_parse(int argc, char *argv[],
if (args->family == AF_INET)
break;
- if (p->restore && args->family == AF_INET6)
+ if (p->restore && args->family == AF_INET6) {
+ p->command = CMD_NONE;
return;
+ }
exit_tryhelp(2, p->line);
@@ -1912,8 +1914,10 @@ void do_parse(int argc, char *argv[],
if (args->family == AF_INET6)
break;
- if (p->restore && args->family == AF_INET)
+ if (p->restore && args->family == AF_INET) {
+ p->command = CMD_NONE;
return;
+ }
exit_tryhelp(2, p->line);
--
2.54.0
^ permalink raw reply related [flat|nested] 4+ messages in thread