Received: by 2002:ac0:a582:0:0:0:0:0 with SMTP id m2-v6csp3930027imm; Mon, 8 Oct 2018 11:52:09 -0700 (PDT) X-Google-Smtp-Source: ACcGV60dkLAGMz7/6HhVZ+5u5NsQKm2NpZaalPHWUVkSAbV3/DB+CVj0Iiq4v6A0TpWXAHPrhbV4 X-Received: by 2002:a62:f553:: with SMTP id n80-v6mr26207526pfh.59.1539024729009; Mon, 08 Oct 2018 11:52:09 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1539024728; cv=none; d=google.com; s=arc-20160816; b=QiprV2DeTmntpNQiE2l3ZbS187lIWZTWcz2aDpR8je9Z9lOLO+uzHp8GSkuaDUzAQr jc9LsDjpgWECLu/x4chgLMoF5fWBS/kxRiGUzwgLT5F5RyADGBn+M2HL0AlwH9lR78gm yvJlW/VMXln9ySIoT3fwdVfWKk/SYiXemK96GGQ4YDI1DL6ULm0aqnPU1kPnlrN8eg4U UIs4FzbclgaEPbZdxjqS606NelKQBrQurdxdPia6oir0tEAvG6PRMbiGaKqCzJNAUgHw xGE2WljwTFBTc9cUVi1GtfT7fjN+CCd4rssmQooSj/AoRrg1lul73i4VVBDYQ7ibFe2j El7A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=1s7Z0DNTBhID/1/8YDd4aVCkjJ/OAFxxCTL1q+PPd3Q=; b=Eg2I1RQki3yhmW3l3ELhopc/nHq2B0xyClcHktf/lACJ1bD6etQ7DzUXXS4d+jlEsp 4SeE4D28ykZRimPutbF+byD12FcUHSvWcAd2PgGHT57MMgtVkK9dEGY1dVeBO3dAlXl4 b9W7kRIApiCdwXsYnhTNFKlvqm1f4knGRGXZAT7ceBUitO71dFGW6Sj7FzectWLejqNj YyX9Va1Z7ZGRzUj4KMYY2JffLOFL4GDzoUneUtUKtKOSrVxJQtYH0C1XaeH5wFTAETp4 ug8KOF1WqITit1ebdrAwb031trviDvgmvjFDQzcKtRs2Faxe/mxnpIhSKJC34H2/U9Rm 9OXg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=e2sPEmYm; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id z11-v6si18015127pgf.66.2018.10.08.11.51.54; Mon, 08 Oct 2018 11:52:08 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=e2sPEmYm; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1732397AbeJICE5 (ORCPT + 99 others); Mon, 8 Oct 2018 22:04:57 -0400 Received: from mail.kernel.org ([198.145.29.99]:54890 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1731723AbeJICEz (ORCPT ); Mon, 8 Oct 2018 22:04:55 -0400 Received: from localhost (ip-213-127-77-176.ip.prioritytelecom.net [213.127.77.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id DECBD20645; Mon, 8 Oct 2018 18:51:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1539024707; bh=ZTfzFRpNN1iOtUZYnmx+BfWblMCsth++/s4jTA3Uf5w=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=e2sPEmYmeVaKif4PO6r4mycD3pFMGThyk+4iyCZNoYNferMwEDkzM151Sy0X7Wx9l XGcXmapaHXP32zECu81FrYc3amX2gYbtKzAK5TSbQ3r3dMG5qYFtCuAxK3GqmZfX/T GiGPnvqxdMzQZo7pFHyHe0kFPMZCeS6ERhb6yuJk= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Michal vorner Vaner , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 4.18 128/168] netfilter: nfnetlink_queue: Solve the NFQUEUE/conntrack clash for NF_REPEAT Date: Mon, 8 Oct 2018 20:31:48 +0200 Message-Id: <20181008175624.912361214@linuxfoundation.org> X-Mailer: git-send-email 2.19.0 In-Reply-To: <20181008175620.043587728@linuxfoundation.org> References: <20181008175620.043587728@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Michal 'vorner' Vaner [ Upstream commit ad18d7bf68a3da860ebb62a59c449804a6d237b4 ] NF_REPEAT places the packet at the beginning of the iptables chain instead of accepting or rejecting it right away. The packet however will reach the end of the chain and continue to the end of iptables eventually, so it needs the same handling as NF_ACCEPT and NF_DROP. Fixes: 368982cd7d1b ("netfilter: nfnetlink_queue: resolve clash for unconfirmed conntracks") Signed-off-by: Michal 'vorner' Vaner Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- net/netfilter/nfnetlink_queue.c | 1 + 1 file changed, 1 insertion(+) --- a/net/netfilter/nfnetlink_queue.c +++ b/net/netfilter/nfnetlink_queue.c @@ -233,6 +233,7 @@ static void nfqnl_reinject(struct nf_que int err; if (verdict == NF_ACCEPT || + verdict == NF_REPEAT || verdict == NF_STOP) { rcu_read_lock(); ct_hook = rcu_dereference(nf_ct_hook);