[PATCH nf-next v3 0/6] net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload
From: Lorenzo Bianconi <hidden>
Date: 2026-09-17 08:29:38
Also in:
netfilter-devel
Introduce some preliminary changes needed to support flowtable offload for IPv4 over IPv6 and SIT traffic. --- Changes in v3: - Rely on nf_inet_addr instead of using two pointers for the same address. - Add specific IPPROTO_IPV6 and IPPROTO_IPIP cases in nf_flow_tunnel_ip6ip6_push() and nf_flow_tunnel_ip_push(). - Rebase on top of nf-next main branch - Link to v2: https://lore.kernel.org/r/20260907-nf-flowtable-sw-accel-ip6ip-sit-preliminary-v2-0-7c6ac1750725@oss.qualcomm.com (local) Changes in v2: - Fix dir configuration in nf_flow_offload_check_mtu() to compute tunnel MTU overhead. - Link to v1: https://lore.kernel.org/r/20260901-nf-flowtable-sw-accel-ip6ip-sit-preliminary-v1-0-72e49be8c31f@oss.qualcomm.com (local) --- Lorenzo Bianconi (6): net: netfilter: nf_flow_table: recognize IPv4/IPv6 in tunnel proto matching net: netfilter: nf_flow_table: set inner protocol when popping tunnel header net: netfilter: nf_flow_table: populate tunnel tuple regardless of inner protocol net: netfilter: add encap_proto to flow_offload_tunnel net: netfilter: nf_flow_table: refactor MTU check for tunnel offload net: netfilter: nf_flow_table: unify tunnel push for IPv4 and IPv6 include/linux/netdevice.h | 1 + include/net/netfilter/nf_flow_table.h | 1 + net/ipv4/ipip.c | 1 + net/ipv6/ip6_tunnel.c | 1 + net/netfilter/nf_flow_table_ip.c | 215 +++++++++++++++++++++------------- net/netfilter/nf_flow_table_path.c | 2 + 6 files changed, 141 insertions(+), 80 deletions(-) --- base-commit: 87b80c2f6b05cad9f0ff9136709c62a0f59923e3 change-id: 20260901-nf-flowtable-sw-accel-ip6ip-sit-preliminary-5635fae03f3e Best regards, -- Lorenzo Bianconi [off-list ref]