Thread (15 messages) 15 messages, 3 authors, 3d ago

[PATCH net-next 00/11] Netfilter updates for net-next

WARM3d

From: Pablo Neira Ayuso <pablo@netfilter.org>
Date: 2026-09-27 22:34:42
Also in: netfilter-devel

Revision v1 of 125 in this series.

Revisions (125)
  1. v1 [diff vs current]
  2. v1 [diff vs current]
  3. v1 [diff vs current]
  4. v1 [diff vs current]
  5. v1 [diff vs current]
  6. v1 [diff vs current]
  7. v1 [diff vs current]
  8. v1 [diff vs current]
  9. v1 [diff vs current]
  10. v1 [diff vs current]
  11. v1 [diff vs current]
  12. v1 [diff vs current]
  13. v1 [diff vs current]
  14. v1 [diff vs current]
  15. v1 [diff vs current]
  16. v1 [diff vs current]
  17. v1 [diff vs current]
  18. v1 [diff vs current]
  19. v1 [diff vs current]
  20. v1 [diff vs current]
  21. v1 [diff vs current]
  22. v1 [diff vs current]
  23. v1 [diff vs current]
  24. v1 [diff vs current]
  25. v1 [diff vs current]
  26. v1 [diff vs current]
  27. v1 [diff vs current]
  28. v1 [diff vs current]
  29. v1 [diff vs current]
  30. v1 [diff vs current]
  31. v1 [diff vs current]
  32. v1 [diff vs current]
  33. v1 [diff vs current]
  34. v1 [diff vs current]
  35. v1 [diff vs current]
  36. v1 [diff vs current]
  37. v1 [diff vs current]
  38. v1 [diff vs current]
  39. v1 [diff vs current]
  40. v1 [diff vs current]
  41. v1 [diff vs current]
  42. v1 [diff vs current]
  43. v1 [diff vs current]
  44. v1 [diff vs current]
  45. v1 [diff vs current]
  46. v1 [diff vs current]
  47. v1 [diff vs current]
  48. v1 [diff vs current]
  49. v1 [diff vs current]
  50. v1 [diff vs current]
  51. v1 [diff vs current]
  52. v1 [diff vs current]
  53. v1 [diff vs current]
  54. v1 [diff vs current]
  55. v1 [diff vs current]
  56. v2 [diff vs current]
  57. v1 [diff vs current]
  58. v1 [diff vs current]
  59. v1 [diff vs current]
  60. v1 [diff vs current]
  61. v1 [diff vs current]
  62. v1 [diff vs current]
  63. v1 [diff vs current]
  64. v1 [diff vs current]
  65. v1 [diff vs current]
  66. v1 [diff vs current]
  67. v1 [diff vs current]
  68. v1 [diff vs current]
  69. v1 [diff vs current]
  70. v1 [diff vs current]
  71. v1 [diff vs current]
  72. v1 [diff vs current]
  73. v1 [diff vs current]
  74. v1 [diff vs current]
  75. v1 [diff vs current]
  76. v1 [diff vs current]
  77. v1 [diff vs current]
  78. v1 [diff vs current]
  79. v1 [diff vs current]
  80. v1 [diff vs current]
  81. v1 [diff vs current]
  82. v1 [diff vs current]
  83. v1 [diff vs current]
  84. v1 [diff vs current]
  85. v1 [diff vs current]
  86. v1 [diff vs current]
  87. v1 [diff vs current]
  88. v1 [diff vs current]
  89. v1 [diff vs current]
  90. v1 [diff vs current]
  91. v1 [diff vs current]
  92. v1 [diff vs current]
  93. v1 [diff vs current]
  94. v1 [diff vs current]
  95. v1 [diff vs current]
  96. v1 [diff vs current]
  97. v1 [diff vs current]
  98. v1 [diff vs current]
  99. v1 [diff vs current]
  100. v1 [diff vs current]
  101. v1 [diff vs current]
  102. v2 [diff vs current]
  103. v1 [diff vs current]
  104. v1 [diff vs current]
  105. v1 [diff vs current]
  106. v1 [diff vs current]
  107. v1 [diff vs current]
  108. v1 [diff vs current]
  109. v1 [diff vs current]
  110. v1 [diff vs current]
  111. v2 [diff vs current]
  112. v1 [diff vs current]
  113. v1 [diff vs current]
  114. v2 [diff vs current]
  115. v3 [diff vs current]
  116. v1 [diff vs current]
  117. v1 [diff vs current]
  118. v2 [diff vs current]
  119. v1 [diff vs current]
  120. v1 [diff vs current]
  121. v2 [diff vs current]
  122. v3 [diff vs current]
  123. v1 [diff vs current]
  124. v1 [diff vs current]
  125. v1 current
Hi,

The following patchset contains Netfilter updates for net-next. The
fixes included in this batch are deemed to handle correctness issues
present in the Netfilter tree:

1) TCP sequence tracking is not reset inconditionally by synproxy when
   recycling an entry, sashiko reports the zero offset case skips it.
   Add a new function to inconditionally reset TCP sequence tracking.
   From Fernando F. Mancera.

2) Update documentation to reflect that the default maximum number of
   expectations (nf_conntrack_expect_max) is nf_conntrack_buckets / 64.
   From Shaojie Sun.

3) Remove useless break; after return in nft_osf, from Linkui Xiao.

4) Fix typos in comments in the netfilter tree, from Hemanth Selam.

5) Remove a few conntrack error stats duplicated updates,
   from Phil Sutter.

6) Do not bump invalid and drop conntrack error stats when packet is
   dropped, this is another duplicate. also From Phil.

7) Set on netns pointer before registering the flowtable, this is
   a requirement by the next patch, not fixing an existing issue.
   From Qingfang Deng.

8) Remove unnecessary workqueue work flush for all of the existing
   netns when device is gone. Also from Qingfang Deng.

9) Rework-fix nfnetlink_hook to correctly deal with large netlink
   dumps. Use sequence numbers to detect interference with hook
   updates while netlink dump is ongoing. From Phil Sutter.

10) Fix ctnetlink dump filtering by the IPv6 address, this has
    only work correctly for IPv4 this far, from Piotr Kubik.

11) ctnetlink filtering by zone is supported, but the ctnetlink
    dump filtering infrastructure was never updated to include a
    flag from userspace, update it to fill this gap.
    From Ilya Maximets.

Please, pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28

Thanks.

----------------------------------------------------------------

The following changes since commit 014d795c73837ea2339a4ea8e8f82c6e959b845d:

  idpf: fix kernel-doc parameter descriptions (2026-09-25 18:26:50 -0700)

are available in the Git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git nf-next-26-09-28

for you to fetch changes up to 46da6029bf468ce3c426cb8b4abf96976ed9d4c8:

  netfilter: conntrack: make filtering by zone discoverable (2026-09-27 23:39:21 +0200)

----------------------------------------------------------------
netfilter pull request 26-09-28

----------------------------------------------------------------
Fernando Fernandez Mancera (1):
      netfilter: synproxy: fix reset of ct seqadj when reopening a connection

Hemanth Selam (1):
      netfilter: fix several typos in comments

Ilya Maximets (1):
      netfilter: conntrack: make filtering by zone discoverable

Linkui Xiao (1):
      netfilter: osf: remove unreachable break in nf_osf_ttl()

Phil Sutter (3):
      netfilter: conntrack: Untangle insert_failed counter from others
      netfilter: conntrack: Untangle drop and invalid counters
      netfilter: nfnetlink: Fix for interrupted hook dumps

Piotr Kubik (1):
      netfilter: ctnetlink: fix inverted IPv6 address match in dump filter

Qingfang Deng (2):
      net/sched: act_ct: set net pointer before publishing flowtable
      netfilter: flowtable: check namespace before iterating flows

Shaojie Sun (1):
      netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation

 Documentation/netlink/specs/conntrack.yaml         |   6 +
 Documentation/networking/nf_conntrack-sysctl.rst   |   2 +-
 include/net/netfilter/nf_conntrack_seqadj.h        |   1 +
 include/net/netns/netfilter.h                      |   2 +
 include/uapi/linux/netfilter/nfnetlink_conntrack.h |   1 +
 net/ipv4/netfilter/arp_tables.c                    |   2 +-
 net/netfilter/core.c                               |  18 ++-
 net/netfilter/ipset/ip_set_core.c                  |   2 +-
 net/netfilter/ipvs/ip_vs_sync.c                    |   2 +-
 net/netfilter/nf_conntrack_core.c                  |   5 +-
 net/netfilter/nf_conntrack_netlink.c               |  19 ++-
 net/netfilter/nf_conntrack_seqadj.c                |  17 +++
 net/netfilter/nf_flow_table_core.c                 |  17 +--
 net/netfilter/nf_nat_core.c                        |  11 ++
 net/netfilter/nf_synproxy_core.c                   |   4 +-
 net/netfilter/nfnetlink_hook.c                     |  74 ++++++-----
 net/netfilter/nfnetlink_osf.c                      |   1 -
 net/sched/act_ct.c                                 |   2 +-
 .../selftests/net/netfilter/conntrack_dump_flush.c | 145 ++++++++++++++-------
 .../net/netfilter/conntrack_icmp_related.sh        |   2 +-
 20 files changed, 229 insertions(+), 104 deletions(-)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help