From: Andrea Parri <parri.andrea@gmail.com>
To: Pablo Neira Ayuso <pablo@netfilter.org>,
Florian Westphal <fw@strlen.de>,
netfilter-devel@vger.kernel.org
Cc: Andrea Parri <parri.andrea@gmail.com>, Phil Sutter <phil@nwl.cc>,
Nikolay Aleksandrov <razor@blackwall.org>,
Ido Schimmel <idosch@nvidia.com>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
Bernhard Thaler <bernhard.thaler@wvnet.at>,
coreteam@netfilter.org, bridge@lists.linux.dev,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH nf v2 0/2] netfilter: preserve bridge egress VLAN tags
Date: Sun, 4 Oct 2026 23:24:26 +0200 [thread overview]
Message-ID: <20261004212429.3648-1-parri.andrea@gmail.com> (raw)
Conntrack-reassembled packets forwarded by a VLAN-aware bridge must
retain the VLAN state selected for their egress port when br_netfilter
refragments them.
The first patch saves the VLAN metadata for IPv6 as well as IPv4. The
second clears stale ingress tags on reused fragments when the egress
packet is untagged.
Both patches were tested under virtme-ng on a VLAN-aware bridge with
br_netfilter and nftables conntrack. With the series applied, all
fragments have the expected tag. The test is available on request.
Changes in v2:
- Add a second fix to clear stale ingress VLAN tags from reused
frag_list skbs on untagged egress.
- Document the reproduced symptoms and the separate IPv4 and IPv6
origins, narrow the first fix's claim to newly built fragments,
reword the helper comment, and make the helper take a const skb.
v1: https://lore.kernel.org/all/20260928161830.351199-1-parri.andrea@gmail.com/
Andrea Parri (2):
netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets
netfilter: br_netfilter: clear stale VLAN tag on refragmented packets
net/bridge/br_netfilter_hooks.c | 51 +++++++++++++++++----------------
1 file changed, 26 insertions(+), 25 deletions(-)
--
2.53.0
next reply other threads:[~2026-10-04 21:24 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-04 21:24 Andrea Parri [this message]
2026-10-04 21:24 ` [PATCH nf v2 1/2] netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets Andrea Parri
2026-10-04 21:24 ` [PATCH nf v2 2/2] netfilter: br_netfilter: clear stale VLAN tag on refragmented packets Andrea Parri
2026-10-04 21:29 ` [PATCH nf v2 0/2] netfilter: preserve bridge egress VLAN tags netdev-bot+sinfo
2026-10-04 21:42 ` Andrea Parri
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261004212429.3648-1-parri.andrea@gmail.com \
--to=parri.andrea@gmail.com \
--cc=bernhard.thaler@wvnet.at \
--cc=bridge@lists.linux.dev \
--cc=coreteam@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
--cc=razor@blackwall.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®