Re: [PATCH nf] net: netfilter: report NLM_F_DUMP_FILTERED when all is filtered out
Florian Westphal <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network,gmane.linux.kernel,gmane.linux.kernel.stable |
|---|---|
| Message-ID | <[email protected]> |
Ilya Maximets <[email protected]> wrote: > NLM_F_DUMP_FILTERED is only set on data elements in the conntrack dump. > But when everything is filtered out it is confusing for the user space, > since the flag is not reported anymore and it looks like the table was > empty, which may or may not be the case. > > 'answer_flags' were introduced precisely for this use case, and the > conntrack dump should set the flag in there in case the filtering was > applied. > > This is important, for example, to be able to tell if the filters are > supported or not by the kernel without modifying the kernel state. > > With the proper reporting of NLM_F_DUMP_FILTERED on NLMSG_DONE, an > application in user space can just try and dump with an arbitrary > filter without worrying that there could be no matching entry. The > reported flag will signal that the filtering was applied and therefore > supported. > > Fixes: cb8aa9a3affb ("netfilter: ctnetlink: add kernel side filtering for dump") > Cc: [email protected] > Signed-off-by: Ilya Maximets <[email protected]> Reviewed-by: Florian Westphal <[email protected]> FWIW this also passes libnetfilter_conntrack and conntrack userspace tests.