Message ID | 20220312220315.64531-1-pablo@netfilter.org (mailing list archive) |
---|---|
State | Accepted |
Delegated to: | Netdev Maintainers |
Headers | show |
On Sat, 12 Mar 2022 23:03:12 +0100 Pablo Neira Ayuso wrote: > 1) Revert port remap to mitigate shadowing service ports, this is causing > problems in existing setups and this mitigation can be achieved with > explicit ruleset, eg. > > ... tcp sport < 16386 tcp dport >= 32768 masquerade random > > This patches provided a built-in policy similar to the one described above. > > 2) Disable register tracking infrastructure in nf_tables. Florian reported > two issues: > > - Existing expressions with no implemented .reduce interface > that causes data-store on register should cancel the tracking. > - Register clobbering might be possible storing data on registers that > are larger than 32-bits. > > This might lead to generating incorrect ruleset bytecode. These two > issues are scheduled to be addressed in the next release cycle. Minor nit for the future - it'd still be useful to have Fixes tags even for reverts or current release fixes so that lowly backporters (myself included) do not have to dig into history to double confirm patches are not needed in the production kernels we maintain. Thanks!
Jakub Kicinski <kuba@kernel.org> wrote: > Minor nit for the future - it'd still be useful to have Fixes tags even > for reverts or current release fixes so that lowly backporters (myself > included) do not have to dig into history to double confirm patches > are not needed in the production kernels we maintain. Thanks! Understood, will do so next time. For the record, the tags would have been: Fixes: 878aed8db324 ("netfilter: nat: force port remap to prevent shadowing well-known ports") Fixes: 4a6fbdd801e8 ("netfilter: conntrack: tag conntracks picked up in local out hook") Fixes: 12e4ecfa244b ("netfilter: nf_tables: add register tracking infrastructure") ... all were merged v5.17-rc1 onwards.
On Tue, 15 Mar 2022 00:07:19 +0100 Florian Westphal wrote: > Jakub Kicinski <kuba@kernel.org> wrote: > > Minor nit for the future - it'd still be useful to have Fixes tags even > > for reverts or current release fixes so that lowly backporters (myself > > included) do not have to dig into history to double confirm patches > > are not needed in the production kernels we maintain. Thanks! > > Understood, will do so next time. > > For the record, the tags would have been: > > Fixes: 878aed8db324 ("netfilter: nat: force port remap to prevent shadowing well-known ports") > Fixes: 4a6fbdd801e8 ("netfilter: conntrack: tag conntracks picked up in local out hook") > Fixes: 12e4ecfa244b ("netfilter: nf_tables: add register tracking infrastructure") > > ... all were merged v5.17-rc1 onwards. Thanks!