Re: [PATCH nf-next] netfilter: flowtable: tear down flow entries with stale dst from GC

Pablo Neira Ayuso <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <alCjFNcjbTZpibjv@chamomile>
On Fri, Jul 10, 2026 at 09:36:10AM +0200, Pablo Neira Ayuso wrote:
> In case of route updates, tear down flow entries with stale dst to give
> them a chance to obtain a fresh route.
> 
> This is specifically useful for hardware offloaded entries, where the
> flowtable software dataplane sees no packet, where the existing check
> for stale dst entries does not help.

Scratch this, I posted the wrong patch. Sending a v2.

> Signed-off-by: Pablo Neira Ayuso <[email protected]>
> ---
>  net/netfilter/nf_flow_table_core.c | 10 ++++++++++
>  1 file changed, 10 insertions(+)
> 
> diff --git a/net/netfilter/nf_flow_table_core.c b/net/netfilter/nf_flow_table_core.c
> index 99c5b9d671a0..61ab27de79fa 100644
> --- a/net/netfilter/nf_flow_table_core.c
> +++ b/net/netfilter/nf_flow_table_core.c
> @@ -561,6 +561,14 @@ static void nf_flow_table_extend_ct_timeout(struct nf_conn *ct)
>  	nf_ct_put(ct);
>  }
>  
> +static bool nf_flow_check_dst(struct flow_offload *flow,
> +			      enum flow_offload_tuple_dir dir)
> +{
> +	struct flow_offload_tuple *tuple = &flow->tuplehash[dir].tuple;
> +
> +	return tuple->dst_cache && dst_check(tuple->dst_cache, tuple->dst_cookie);
> +}
> +
>  static void nf_flow_offload_gc_step(struct nf_flowtable *flow_table,
>  				    struct flow_offload *flow, void *data)
>  {
> @@ -568,6 +576,8 @@ static void nf_flow_offload_gc_step(struct nf_flowtable *flow_table,
>  
>  	if (nf_flow_has_expired(flow) ||
>  	    nf_ct_is_dying(flow->ct) ||
> +	    nf_flow_check_dst(flow, FLOW_OFFLOAD_DIR_ORIGINAL) ||
> +	    nf_flow_check_dst(flow, FLOW_OFFLOAD_DIR_REPLY) ||
>  	    nf_flow_custom_gc(flow_table, flow)) {
>  		flow_offload_teardown(flow);
>  		teardown = true;
> -- 
> 2.47.3
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.