Re: [PATCH net] netlink: specs: fix the conntrack filter type

Asbjørn Sloth Tønnesen <[email protected]>
Newsgroups gmane.linux.kernel.stable,gmane.linux.kernel,gmane.comp.security.firewalls.netfilter.devel,gmane.linux.network
Message-ID <[email protected]>
On 8/25/26 3:58 PM, Ilya Maximets wrote:
> The CTA_FILTER doesn't contain nested tuple attributes, instead it
> contains bit masks that specify which tuple attributes to filter on.
> The values for filtering are taken from the top-level CTA_TUPLE_ORIG
> and CTA_TUPLE_REPLY.

As identified by Sashiko-NIPA[1], then CTA_TUPLE_ORIG and CTA_TUPLE_REPLY
are both absent from the GET DUMP request attribute list.

However this doesn't prevent ynl CLI from sending the attributes:

$ sudo ./tools/net/ynl/pyynl/cli.py --family conntrack --dump get --json \
   '{"nfgen-family": 2, "filter": {"orig-flags": 1}}'
Netlink error: Invalid argument

$ sudo ./tools/net/ynl/pyynl/cli.py --family conntrack --dump get --json \
'{"nfgen-family": 2, "filter": {"orig-flags": 1}, "tuple-orig": {"tuple-ip": {"ip-v4-src": "192.255.0.255", "ip-v4-dst": 
"192.255.255.0"}}}'
[]

Otherwise, LGTM.

[1] https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260825155832.3685714-1-i.maximets%40ovn.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.