From nobody Mon Sep 28 06:35:37 2026 Received: from mail-ed2-f7.google.com (mail-ed2-f7.google.com [74.125.228.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D0D5948550F for ; Tue, 25 Aug 2026 15:27:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.228.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787671654; cv=none; b=o+foOIrWHZY+G+vVdFbrgWavuE8iXvS1tcRRgHVuIACsYLDzQA5r/nEgGXczPc2I9551FTSH5c3UrLg5GLCWFOAv6ceUGtbXgY0+0odM6pM/faiKAwU3yaF70Li2RGtoOjsPN220OVzrfapArMUzS5PkdDFP3TR88T2S4PZFhYw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787671654; c=relaxed/simple; bh=uQVz+K1/tiwkasTG+w79z8H2afc5AsmIftpAEk5RMkY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=uR5Bhfx3fS5VeI8jbrIUUdKptzQK1KFRWL8A8m5ngSI88pX6ee0HeeuaQnacGRAC0IoCZHrdnqe6bM3R3/tc2d1F9oXOmPC3cSjMiFY6AxcIMOObqy3VlsKI6K5n2OlgtrhbV9HdFLw8iyvYegA5m4m05V9NBlO6ERkFqBpjVmE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=74.125.228.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ovn.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-ed2-f7.google.com with SMTP id 4fb4d7f45d1cf-6a3e9930062so3206633a12.0 for ; Tue, 25 Aug 2026 08:27:32 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787671651; x=1788276451; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+5k9HBpOvCsTp3v94rUbWHBbfWVbyD8PJy/u/PILaBw=; b=Go6RA2dAF8nZe6+hzDnF43JpGB+UkfNECK+esLXy6JQ8l/pd87ky33ddcfpHVfWcRe inOXsi5SlHFsLlUzzPbk79t4dms8MOk+h/a6ed7t524ffXyfDdKY54JEV3QLaQXDJQco SHRzjKnOJ3ohkZHWcauYVeJ26aNER7c9X5FEOTAfE6BPYR4HzR77TQji+9Z+E4zPBZpw s3TYnR2uorgSjMqMkuPjm1WFcjRkLxnxETPFrEFwa+43GXjSeli31k9mPHty9v8+Etql yGBKwsiObVMOv7TL6cLYLu3TJSX6z209+9LBH98VAff2d++xX2iFNkxmwM/bEGbtPJMS UlFw== X-Forwarded-Encrypted: i=1; AHgh+RoOgaP2NoxyX7z7T8R9QwXu5A+NIjFlAvCJXu+jEZyZM7Uo+WXerCJ+SZWgWvXCl8djNFIp6PRIymZuQWM=@vger.kernel.org X-Gm-Message-State: AFuF++l8Y33FooMNI9wr6fdcCRfEWMy4IyGoF1m0eTIq9kjTsnOru4bM XaRa8U/SOMR5v9Q53WxjTxWQRdTZYyTzqjegvk0h9uzyueFeCfogPA4c X-Gm-Gg: AR+sD10iKDorKtEINRoSg0AI3PWe671nOPpOrVRWG5uDp4rIKeFE2t0znK+YQmrUblh NNvvtRvxX5i6TC9TsvEWXWMTqHiXjkJ22hHU3g3VlH5Z8VaLoH3YB6cX1foZoV0O/orF44Od0Qc N8DIZDSaSGTR8VosYPBDnl05Jhp8WBUtCUUXGX+dVhFVgTFJbVlZgktf4xAOdLckanFmJ5OfIIz c377izI8j3dHTeCqMkoZOgDkrrDMD95vW2LFvdjwCEDFQV7LMfSuzfRsQVrQnmEi0LLkLicFnqq fAbaszFPxMyOoz81pOvcNJlkfsJFpmzyJ40tPc5E1nIVdOKqSPPmsvLLaBOR597llw5ug7No1mS kche1un9Xgs/xnZ8JtJ+giXWIuf0wiRjUkqyFLye5LSDR88yMbM0Ud5NNHWlLl3JpbEJX0r+Jcc W19GiiRch8aKnQaVCW6OVhymqQVNmPyHAVFiu5So1TEsp0bbRzH3rk2BWTm+3qJFQ9j1OchNDBa W3/sHbIwOlLljEttQjnslpy0TWN1/k= X-Received: by 2002:a17:906:f591:b0:c24:6045:2a94 with SMTP id a640c23a62f3a-c24e5c8ad60mr1019878166b.4.1787671650465; Tue, 25 Aug 2026 08:27:30 -0700 (PDT) Received: from im-t490s.redhat.com (89-24-33-32.nat.epc.tmcz.cz. [89.24.33.32]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c250a9ef996sm1808866b.62.2026.08.25.08.27.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 25 Aug 2026 08:27:29 -0700 (PDT) From: Ilya Maximets To: netfilter-devel@vger.kernel.org Cc: Pablo Neira Ayuso , Florian Westphal , Phil Sutter , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Romain Bellan , Florent Fourcot , coreteam@netfilter.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Ilya Maximets , stable@vger.kernel.org Subject: [PATCH nf] net: netfilter: report NLM_F_DUMP_FILTERED when all is filtered out Date: Tue, 25 Aug 2026 17:27:24 +0200 Message-ID: <20260825152725.3678225-1-i.maximets@ovn.org> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" NLM_F_DUMP_FILTERED is only set on data elements in the conntrack dump. But when everything is filtered out it is confusing for the user space, since the flag is not reported anymore and it looks like the table was empty, which may or may not be the case. 'answer_flags' were introduced precisely for this use case, and the conntrack dump should set the flag in there in case the filtering was applied. This is important, for example, to be able to tell if the filters are supported or not by the kernel without modifying the kernel state. With the proper reporting of NLM_F_DUMP_FILTERED on NLMSG_DONE, an application in user space can just try and dump with an arbitrary filter without worrying that there could be no matching entry. The reported flag will signal that the filtering was applied and therefore supported. Fixes: cb8aa9a3affb ("netfilter: ctnetlink: add kernel side filtering for d= ump") Cc: stable@vger.kernel.org Signed-off-by: Ilya Maximets Reviewed-by: Florian Westphal --- net/netfilter/nf_conntrack_netlink.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/netfilter/nf_conntrack_netlink.c b/net/netfilter/nf_conntr= ack_netlink.c index 9b4e29557ec3..579ada063b1b 100644 --- a/net/netfilter/nf_conntrack_netlink.c +++ b/net/netfilter/nf_conntrack_netlink.c @@ -1077,6 +1077,8 @@ static int ctnetlink_start(struct netlink_callback *c= b) } =20 cb->data =3D filter; + if (filter) + cb->answer_flags =3D NLM_F_DUMP_FILTERED; return 0; } =20 --=20 2.55.0