[PATCH nf v2 0/2] netfilter: preserve bridge egress VLAN tags
From: Andrea Parri
Date: Sun Oct 04 2026 - 17:24:56 EST
Conntrack-reassembled packets forwarded by a VLAN-aware bridge must
retain the VLAN state selected for their egress port when br_netfilter
refragments them.
The first patch saves the VLAN metadata for IPv6 as well as IPv4. The
second clears stale ingress tags on reused fragments when the egress
packet is untagged.
Both patches were tested under virtme-ng on a VLAN-aware bridge with
br_netfilter and nftables conntrack. With the series applied, all
fragments have the expected tag. The test is available on request.
Changes in v2:
- Add a second fix to clear stale ingress VLAN tags from reused
frag_list skbs on untagged egress.
- Document the reproduced symptoms and the separate IPv4 and IPv6
origins, narrow the first fix's claim to newly built fragments,
reword the helper comment, and make the helper take a const skb.
v1: https://lore.kernel.org/all/20260928161830.351199-1-parri.andrea@xxxxxxxxx/
Andrea Parri (2):
netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets
netfilter: br_netfilter: clear stale VLAN tag on refragmented packets
net/bridge/br_netfilter_hooks.c | 51 +++++++++++++++++----------------
1 file changed, 26 insertions(+), 25 deletions(-)
--
2.53.0