Hello,
This series contains initial netfilter skb drop_reason support, from
myself.
First few patches fix up a few spots to make sure we won't trip
when followup patches embed error numbers in the upper bits
(we already do this in some places).
Then, nftables and bridge netfilter get converted to call kfree_skb_reason
directly to let tooling pinpoint exact location of packet drops,
rather than the existing NF_DROP catchall in nf_hook_slow().
I would like to eventually convert all netfilter modules, but as some
callers cannot deal with NF_STOLEN (notably act_ct), more preparation
work is needed for this.
Last patch gets rid of an ugly 'de-const' cast in nftables.
The following changes since commit a0a86022474304e012aad5d41943fdd31a036284:
Merge branch 'devlink-deadlock' (2023-10-18 09:23:02 +0100)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git tags/nf-next-23-10-18
for you to fetch changes up to 256001672153af5786c6ca148114693d7d76d836:
netfilter: nf_tables: de-constify set commit ops function argument (2023-10-18 10:26:43 +0200)
----------------------------------------------------------------
netfilter next pull request 2023-10-18
----------------------------------------------------------------
Florian Westphal (7):
netfilter: xt_mangle: only check verdict part of return value
netfilter: nf_tables: mask out non-verdict bits when checking return value
netfilter: conntrack: convert nf_conntrack_update to netfilter verdicts
netfilter: nf_nat: mask out non-verdict bits when checking return value
netfilter: make nftables drops visible in net dropmonitor
netfilter: bridge: convert br_netfilter to NF_DROP_REASON
netfilter: nf_tables: de-constify set commit ops function argument
include/linux/netfilter.h | 10 +++++++
include/net/netfilter/nf_tables.h | 2 +-
net/bridge/br_netfilter_hooks.c | 26 ++++++++--------
net/bridge/br_netfilter_ipv6.c | 6 ++--
net/ipv4/netfilter/iptable_mangle.c | 9 +++---
net/ipv6/netfilter/ip6table_mangle.c | 9 +++---
net/netfilter/core.c | 6 ++--
net/netfilter/nf_conntrack_core.c | 58 ++++++++++++++++++++----------------
net/netfilter/nf_nat_proto.c | 5 ++--
net/netfilter/nf_tables_core.c | 8 +++--
net/netfilter/nf_tables_trace.c | 8 +++--
net/netfilter/nfnetlink_queue.c | 15 ++++++----
net/netfilter/nft_set_pipapo.c | 7 ++---
13 files changed, 100 insertions(+), 69 deletions(-)