Re: [PATCH net 00/13] Netfilter/IPVS fixes for net
Florian Westphal <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network |
|---|---|
| Message-ID | <[email protected]> |
Jakub Kicinski <[email protected]> wrote: > On Mon, 10 Aug 2026 21:06:08 +0200 Pablo Neira Ayuso wrote: > > The following patchset contains Netfilter/IPVS fixes for net. Still > > large batch for this late -rc cycle but at least have of these fixes in > > this batch have been cooking for several weeks before: > > Does any of the AI-detected issues seem concerning? > > https://netdev-ai.bots.linux.dev/sashiko/#/patchset/[email protected] Only commenting on those patches that I worked on or commented during review: Patch 6: [PATCH net 06/13] netfilter: nf_conntrack: defer invalid log until after unlock Its fine. This is for debugging. We could restore the removed info if anyone needs it, I even was about to suggest to original author to simply remove the invalid logging but decided against it (since you can log the packet to userspace via nfnetlink). I prefer the simpler version that doesn't snapshot data while under lock. Patch 7: [PATCH net 07/13] netfilter: nfnetlink_log: wait for rcu grace period before freeing pernet state Yes, one could have added this Fixes tag or Cc stable to the patch. Don't think this warrants a respin by itself. Patch 12: [PATCH net 12/13] netfilter: ipset: fix list type element drift bug Even if the ordering is "wrong", the patch that added it is ancient (even in RHEL7) so its long established behaviour. ipset test suite also has test for this and those tests pass, so changing kernel behaviour will need to adjust (old..) test cases as well.