[<prev] [next>] [day] [month] [year] [list]
Message-Id: <20251219115351.5662-1-Hamaguchi.Yuto@da.MitsubishiElectric.co.jp>
Date: Fri, 19 Dec 2025 20:53:51 +0900
From: Yuto Hamaguchi <Hamaguchi.Yuto@...MitsubishiElectric.co.jp>
To: pablo@...filter.org,
kadlec@...filter.org,
netfilter-devel@...r.kernel.org
Cc: coreteam@...filter.org,
netdev@...r.kernel.org,
Hamaguchi.Yuto@...MitsubishiElectric.co.jp
Subject: [PATCH nf] netfilter: nf_conntrack: Add allow_clash to generic protocol handler
The upstream commit, 71d8c47fc653711c41bc3282e5b0e605b3727956
("netfilter: conntrack: introduce clash resolution on insertion race"),
sets allow_clash=true in the UDP/UDPLITE protocol handler
but does not set it in the generic protocol handler.
As a result, packets composed of connectionless protocols at each layer,
such as UDP over IP-in-IP, still drop packets due to conflicts during conntrack insertion.
To resolve this, this patch sets allow_clash in the nf_conntrack_l4proto_generic.
Signed-off-by: Yuto Hamaguchi <Hamaguchi.Yuto@...MitsubishiElectric.co.jp>
---
net/netfilter/nf_conntrack_proto_generic.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/netfilter/nf_conntrack_proto_generic.c b/net/netfilter/nf_conntrack_proto_generic.c
index e831637bc8ca..cb260eb3d012 100644
--- a/net/netfilter/nf_conntrack_proto_generic.c
+++ b/net/netfilter/nf_conntrack_proto_generic.c
@@ -67,6 +67,7 @@ void nf_conntrack_generic_init_net(struct net *net)
const struct nf_conntrack_l4proto nf_conntrack_l4proto_generic =
{
.l4proto = 255,
+ .allow_clash = true,
#ifdef CONFIG_NF_CONNTRACK_TIMEOUT
.ctnl_timeout = {
.nlattr_to_obj = generic_timeout_nlattr_to_obj,
--
2.36.1
Powered by blists - more mailing lists