Re: [PATCH net-next 1/9] netfilter: conncount: normalize tuple and zone on successful ct lookup

[email protected] Wed, 05 Aug 2026 23:50:32 +0000
Newsgroups gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network
Message-ID <178597383266.567483.8728487954347201602.git-patchwork-notify@kernel.org>
Hello:

This series was applied to netdev/net-next.git (main)
by Pablo Neira Ayuso <[email protected]>:

On Fri, 31 Jul 2026 17:33:54 +0200 you wrote:
> From: Fernando Fernandez Mancera <[email protected]>
> 
> When get_ct_or_tuple_from_skb() falls back to looking for a connection
> via nf_conntrack_find_get(), a successful lookup sets ct but leaves
> tuple and zone unupdated.
> 
> If the packet belongs to a reply flow, tuple will remain in the reply
> direction. As conncount relies on the original direction tuple to count
> the connections consistenly, passing an unnormalized reply tuple could
> lead to problems.
> 
> [...]

Here is the summary with links:
  - [net-next,1/9] netfilter: conncount: normalize tuple and zone on successful ct lookup
    https://git.kernel.org/netdev/net-next/c/e53932f0e5de
  - [net-next,2/9] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
    https://git.kernel.org/netdev/net-next/c/f19fd12143db
  - [net-next,3/9] netfilter: flowtable: consolidate flowtable device check
    https://git.kernel.org/netdev/net-next/c/df1705f289ba
  - [net-next,4/9] net: dsa: stop at the user device in .fill_forward_path
    https://git.kernel.org/netdev/net-next/c/5be6e044bea6
  - [net-next,5/9] net: do not advance stack index from dev_fwd_path()
    https://git.kernel.org/netdev/net-next/c/5deda60c56ee
  - [net-next,6/9] net: pass dst via net_device_path in dev_fill_forward_path()
    https://git.kernel.org/netdev/net-next/c/0ad8404e7766
  - [net-next,7/9] netfilter: flowtable: release tunnel route on error when building forward path
    https://git.kernel.org/netdev/net-next/c/806273fcaffb
  - [net-next,8/9] netfilter: nf_tables: call skb_valid_dst() before skb_dst()
    https://git.kernel.org/netdev/net-next/c/689db98e535b
  - [net-next,9/9] netfilter: conntrack: tcp: use UNACK timeout for non-closing RST packets
    https://git.kernel.org/netdev/net-next/c/bf80e6802273

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html