Re: [PATCH nf] net: netfilter: report NLM_F_DUMP_FILTERED when all is filtered out
From: Florian Westphal
Date: Wed Aug 26 2026 - 12:50:12 EST
Ilya Maximets <i.maximets@xxxxxxx> wrote:
> NLM_F_DUMP_FILTERED is only set on data elements in the conntrack dump.
> But when everything is filtered out it is confusing for the user space,
> since the flag is not reported anymore and it looks like the table was
> empty, which may or may not be the case.
>
> 'answer_flags' were introduced precisely for this use case, and the
> conntrack dump should set the flag in there in case the filtering was
> applied.
>
> This is important, for example, to be able to tell if the filters are
> supported or not by the kernel without modifying the kernel state.
>
> With the proper reporting of NLM_F_DUMP_FILTERED on NLMSG_DONE, an
> application in user space can just try and dump with an arbitrary
> filter without worrying that there could be no matching entry. The
> reported flag will signal that the filtering was applied and therefore
> supported.
>
> Fixes: cb8aa9a3affb ("netfilter: ctnetlink: add kernel side filtering for dump")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Ilya Maximets <i.maximets@xxxxxxx>
Reviewed-by: Florian Westphal <fw@xxxxxxxxx>
FWIW this also passes libnetfilter_conntrack and conntrack userspace tests.