[PATCH nf v2 0/2] netfilter: preserve bridge egress VLAN tags

From: Andrea Parri

Date: Sun Oct 04 2026 - 17:24:56 EST


Conntrack-reassembled packets forwarded by a VLAN-aware bridge must
retain the VLAN state selected for their egress port when br_netfilter
refragments them.

The first patch saves the VLAN metadata for IPv6 as well as IPv4. The
second clears stale ingress tags on reused fragments when the egress
packet is untagged.

Both patches were tested under virtme-ng on a VLAN-aware bridge with
br_netfilter and nftables conntrack. With the series applied, all
fragments have the expected tag. The test is available on request.

Changes in v2:
- Add a second fix to clear stale ingress VLAN tags from reused
frag_list skbs on untagged egress.
- Document the reproduced symptoms and the separate IPv4 and IPv6
origins, narrow the first fix's claim to newly built fragments,
reword the helper comment, and make the helper take a const skb.

v1: https://lore.kernel.org/all/20260928161830.351199-1-parri.andrea@xxxxxxxxx/

Andrea Parri (2):
netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets
netfilter: br_netfilter: clear stale VLAN tag on refragmented packets

net/bridge/br_netfilter_hooks.c | 51 +++++++++++++++++----------------
1 file changed, 26 insertions(+), 25 deletions(-)

--
2.53.0