Re: [PATCH net-next 1/9] netfilter: conncount: normalize tuple and zone on successful ct lookup
[email protected] Wed, 05 Aug 2026 23:50:32 +0000
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network |
|---|---|
| Message-ID | <178597383266.567483.8728487954347201602.git-patchwork-notify@kernel.org> |
Hello: This series was applied to netdev/net-next.git (main) by Pablo Neira Ayuso <[email protected]>: On Fri, 31 Jul 2026 17:33:54 +0200 you wrote: > From: Fernando Fernandez Mancera <[email protected]> > > When get_ct_or_tuple_from_skb() falls back to looking for a connection > via nf_conntrack_find_get(), a successful lookup sets ct but leaves > tuple and zone unupdated. > > If the packet belongs to a reply flow, tuple will remain in the reply > direction. As conncount relies on the original direction tuple to count > the connections consistenly, passing an unnormalized reply tuple could > lead to problems. > > [...] Here is the summary with links: - [net-next,1/9] netfilter: conncount: normalize tuple and zone on successful ct lookup https://git.kernel.org/netdev/net-next/c/e53932f0e5de - [net-next,2/9] netfilter: flowtable: consolidate net_device field in nft_forward_info struct https://git.kernel.org/netdev/net-next/c/f19fd12143db - [net-next,3/9] netfilter: flowtable: consolidate flowtable device check https://git.kernel.org/netdev/net-next/c/df1705f289ba - [net-next,4/9] net: dsa: stop at the user device in .fill_forward_path https://git.kernel.org/netdev/net-next/c/5be6e044bea6 - [net-next,5/9] net: do not advance stack index from dev_fwd_path() https://git.kernel.org/netdev/net-next/c/5deda60c56ee - [net-next,6/9] net: pass dst via net_device_path in dev_fill_forward_path() https://git.kernel.org/netdev/net-next/c/0ad8404e7766 - [net-next,7/9] netfilter: flowtable: release tunnel route on error when building forward path https://git.kernel.org/netdev/net-next/c/806273fcaffb - [net-next,8/9] netfilter: nf_tables: call skb_valid_dst() before skb_dst() https://git.kernel.org/netdev/net-next/c/689db98e535b - [net-next,9/9] netfilter: conntrack: tcp: use UNACK timeout for non-closing RST packets https://git.kernel.org/netdev/net-next/c/bf80e6802273 You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html