netlink: specs: fix the conntrack filter type

The CTA_FILTER doesn't contain nested tuple attributes, instead it
contains bit masks that specify which tuple attributes to filter on.
The values for filtering are taken from the top-level CTA_TUPLE_ORIG
and CTA_TUPLE_REPLY, which are also missing in the attribute list
for the dump request.

The bits themselves somehow are not in the public headers, so not
defining them in the spec either for now.  Once they are public in
uAPI, they can be added here with enum-as-flags.

Fixes: 23fc9311a5 ("netlink: specs: add conntrack dump and stats dump support")
Cc: stable@vger.kernel.org
Signed-off-by: Ilya Maximets <i.maximets@ovn.org>
Reviewed-by: Asbjørn Sloth Tønnesen <ast@fiberby.net>
Link: https://patch.msgid.link/20260826220444.4054714-2-i.maximets@ovn.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
Ilya Maximets 2026-08-27 00:01:11 +02:00 committed by Jakub Kicinski
parent 7fcc2fe39f
commit 2a004bfb62

View File

@ -360,6 +360,17 @@ attribute-sets:
name: tsoff
type: u32
byte-order: big-endian
-
name: filter-attrs
attributes:
-
name: orig-flags
type: u32
doc: bitmask of tuple fields to filter on, original direction
-
name: reply-flags
type: u32
doc: bitmask of tuple fields to filter on, reply direction
-
name: conntrack-attrs
attributes:
@ -466,7 +477,7 @@ attribute-sets:
-
name: filter
type: nest
nested-attributes: tuple-attrs
nested-attributes: filter-attrs
-
name: status-mask
type: u32
@ -591,6 +602,8 @@ operations:
request:
value: 0x101
attributes:
- tuple-orig
- tuple-reply
- mark
- filter
- status