Re: nftables RP filter and loopback

Florian Westphal <[email protected]> Wed, 23 Apr 2025 11:10:20 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <[email protected]>
Pablo Neira Ayuso <[email protected]> wrote:
> Florian, is it worth to request to include this update to -stable
> kernels? Or you prefer the manpage note as it has been suggested?

I'll send a patch to update the nft_fib selftest to cover this,
then make a backport of the change that doesn't include the the
socket optimzation.

When I changed it I did not realize that this fixes a bug; I would
have split the change in two if I had.