Conntrack-reassembled packets forwarded by a VLAN-aware bridge must
retain the VLAN state selected for their egress port when br_netfilter
refragments them.

The first patch saves the VLAN metadata for IPv6 as well as IPv4. The
second clears stale ingress tags on reused fragments when the egress
packet is untagged.

Both patches were tested under virtme-ng on a VLAN-aware bridge with
br_netfilter and nftables conntrack. With the series applied, all
fragments have the expected tag. The test is available on request.

Changes in v2:
  - Add a second fix to clear stale ingress VLAN tags from reused
    frag_list skbs on untagged egress.
  - Document the reproduced symptoms and the separate IPv4 and IPv6
    origins, narrow the first fix's claim to newly built fragments,
    reword the helper comment, and make the helper take a const skb.

v1: https://lore.kernel.org/all/[email protected]/

Andrea Parri (2):
  netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets
  netfilter: br_netfilter: clear stale VLAN tag on refragmented packets

 net/bridge/br_netfilter_hooks.c | 51 +++++++++++++++++----------------
 1 file changed, 26 insertions(+), 25 deletions(-)

-- 
2.53.0


Reply via email to