Eric Dumazet wrote: > IPS_CONFIRMED_BIT is set under nf_conntrack_lock (in __nf_conntrack_confirm()), > we probably want to add a synchronisation under ct->lock as well, > or __nf_ct_refresh_acct() could set ct->timeout.expires to extra_jiffies, > while a different cpu could confirm the conntrack. Before the conntrack is confirmed, it is exclusively handled by a single CPU. I agree that we need to make sure the IPS_CONFIRMED_BIT is visible before we add the conntrack to the hash table since the lookup is lockless, but simply moving the set_bit before the hash insertion should be fine I think.