Thread (18 messages) flat view 18 messages, 3 authors, 17d ago

Re: [PATCH net 0/4] net/sched: reset conntrack after packet munging

From: Florian Westphal <fw@strlen.de>
Date: 2026-08-20 17:37:13

Jamal Hadi Salim [off-list ref] wrote:
quoted
Yes, e.g. what if pedit inflated th->doff?
nf_conntrack_in() checked that this was fine, but now the pipeline
can re-neg on that.
True.
So my question to you then is: what about BPF, OVS, future thingy? Are
you going to fix each individually?
I see no alternative?  I mean, what are you suggesting?
We can apply the patch from Kyle, that will stop the reproducer.
But I can tell you that we'll need hundreds of followup patches
all over.

I mean, we always relied on IP stack having checked that iph->ihl is
fine, the ipv6 header is complete, etc.

And that isn't exclusive to netfilter.

My best suggestion is to remove skb->_nfct and reparse everywhere,
but I will NOT make such a patch, IMO conntrack and netfilter might
as well be axed then.  Hey, would solve a few bugs.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help