Re: nftables RP filter and loopback

Pablo Neira Ayuso <[email protected]> Wed, 23 Apr 2025 22:56:38 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <aAlUBmTljaz3bD-L@calendula>
On Wed, Apr 23, 2025 at 02:06:05PM +0200, Florian Westphal wrote:
> Pablo Neira Ayuso <[email protected]> wrote:
> > Yes, I didn't notice either. Anyway, unless you can forecast any
> > issue, I'd suggest to backport the entire patch? IIRC patch is
> > relatively small and keeping it in sync with main could possibly help
> > with cherrypicking fixes.
> 
> Right, it would keep -stable "bug compatible" too.
> 
> Maybe its ok to ask to cherry-pick it as is for
> 6.14 and 6.12.

OK, let's request this cherry-pick for 6.12. Thanks

> 6.13 is EOL already, 6.12 is longterm.
> 
> This would leave 6.6 and 6.1 longterm out but from lack
> of bug reports so far I would not say its a prominent bug.
> 
> The upstream patch cherry-picks for all except 6.1.y, but
> AFAICS its just a simple context conflict.
> 
> Earlier longterm kernels aren't affected.