Linux Netfilter development
 help / color / mirror / Atom feed
* [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation
@ 2026-10-02 12:49 Phil Sutter
  2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Phil Sutter @ 2026-10-02 12:49 UTC (permalink / raw)
  To: netfilter-devel; +Cc: Balazs Gulacsi

Special casing for SNAT/DNAT conntrack states was broken with inverted
matches:

- Wrong bit in invert_flags checked (typo?)
- Missing space after operator (cosmetics!)

Reported-by: Balazs Gulacsi <m2gulbal@gmail.com>
Closes: https://bugzilla.netfilter.org/show_bug.cgi?id=1826
Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 extensions/libxt_conntrack.c      | 2 +-
 extensions/libxt_conntrack.txlate | 6 ++++++
 2 files changed, 7 insertions(+), 1 deletion(-)

diff --git a/extensions/libxt_conntrack.c b/extensions/libxt_conntrack.c
index 04940154eb314..2b41213edb0e4 100644
--- a/extensions/libxt_conntrack.c
+++ b/extensions/libxt_conntrack.c
@@ -1230,7 +1230,7 @@ static int _conntrack3_mt_xlate(struct xt_xlate *xl,
 		if ((sinfo->state_mask & XT_CONNTRACK_STATE_SNAT) ||
 		    (sinfo->state_mask & XT_CONNTRACK_STATE_DNAT)) {
 			xt_xlate_add(xl, "%sct status %s%s", space,
-				     sinfo->invert_flags & XT_CONNTRACK_STATUS ? "!=" : "",
+				     sinfo->invert_flags & XT_CONNTRACK_STATE ? "!= " : "",
 				     sinfo->state_mask & XT_CONNTRACK_STATE_SNAT ? "snat" : "dnat");
 			space = " ";
 		} else {
diff --git a/extensions/libxt_conntrack.txlate b/extensions/libxt_conntrack.txlate
index 0f44a957878e8..79b34df9e3586 100644
--- a/extensions/libxt_conntrack.txlate
+++ b/extensions/libxt_conntrack.txlate
@@ -55,6 +55,12 @@ nft 'add rule ip filter INPUT ct direction original ct original protocol 6 ct st
 iptables-translate -t filter -A INPUT -m conntrack --ctstate SNAT -j ACCEPT
 nft 'add rule ip filter INPUT ct status snat counter accept'
 
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate SNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != snat counter accept'
+
 iptables-translate -t filter -A INPUT -m conntrack --ctstate DNAT -j ACCEPT
 nft 'add rule ip filter INPUT ct status dnat counter accept'
 
+iptables-translate -t filter -A INPUT -m conntrack ! --ctstate DNAT -j ACCEPT
+nft 'add rule ip filter INPUT ct status != dnat counter accept'
+
-- 
2.54.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-08 13:28 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-02 12:49 [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation Phil Sutter
2026-10-02 12:49 ` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command Phil Sutter
2026-10-08 13:28 ` [iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation Phil Sutter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox