Re: [PATCH nf] netfilter: nf_conncount: fix zone comparison in tuple dedup

Florian Westphal <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network,gmane.linux.kernel,gmane.linux.kernel.stable
Message-ID <[email protected]>
Yizhou Zhao <[email protected]> wrote:
> The "already exists" dedup logic in __nf_conncount_add() decides
> whether a connection has already been counted and can be skipped instead
> of incrementing the connlimit count.  It compares the conntrack zone of a
> list entry with the zone of the connection being added using
> nf_ct_zone_id() and nf_ct_zone_equal(), passing conn->zone.dir or
> zone->dir as the direction argument.

Right, thats bogus.

> @@ -211,8 +220,10 @@ static int __nf_conncount_add(struct net *net,
>  			/* Not found, but might be about to be confirmed */
>  			if (PTR_ERR(found) == -EAGAIN) {
>  				if (nf_ct_tuple_equal(&conn->tuple, &tuple) &&
> -				    nf_ct_zone_id(&conn->zone, conn->zone.dir) ==
> -				    nf_ct_zone_id(zone, zone->dir))
> +				    nf_ct_zone_id(&conn->zone,
> +						  nf_conncount_zone_dir(&conn->zone)) ==
> +				    nf_ct_zone_id(zone,
> +						  nf_conncount_zone_dir(zone)))

Should this be a simpler:

                                if (nf_ct_tuple_equal(&conn->tuple, &tuple) &&
-                                   nf_ct_zone_id(&conn->zone, conn->zone.dir) ==
-                                   nf_ct_zone_id(zone, zone->dir))
+                                   nf_ct_zone_equal(&conn->zone, &zone), IP_CT_DIR_ORIGINAL)

?

The tuple is always the 'original' direction, so it would follow that
we should not care about reply zone dir.

Also see:
https://sashiko.dev/#/patchset/20260706114820.74006-1-zhaoyz24%40mails.tsinghua.edu.cn
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.