Hi, The following patchset contains Netfilter fixes for net: 1) br_netfilter drops IPv6 packets if ipv6 is disabled, from Leonardo Bras. 2) nft_socket hits BUG() due to illegal skb->sk caching, patch from Fernando Fernandez Mancera. 3) nft_fib_netdev could be called with ipv6 disabled, leading to crash in the fib lookup, also from Leonardo. 4) ctnetlink honors IPS_OFFLOAD flag, just like nf_conntrack sysctl does. 5) Properly set up flowtable entry timeout, otherwise immediate removal by garbage collector might occur. You can pull these changes from: git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git Thanks. ---------------------------------------------------------------- The following changes since commit e33b4325e60e146c2317a8b548cbd633239ff83b: net: stmmac: dwmac-sun8i: Variable "val" in function sun8i_dwmac_set_syscon() could be uninitialized (2019-09-02 11:48:15 -0700) are available in the git repository at: git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git HEAD for you to fetch changes up to 110e48725db6262f260f10727d0fb2d3d25895e4: netfilter: nf_flow_table: set default timeout after successful insertion (2019-09-03 22:55:42 +0200) ---------------------------------------------------------------- Fernando Fernandez Mancera (1): netfilter: nft_socket: fix erroneous socket assignment Leonardo Bras (2): netfilter: bridge: Drops IPv6 packets if IPv6 module is not loaded netfilter: nft_fib_netdev: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled Pablo Neira Ayuso (2): netfilter: ctnetlink: honor IPS_OFFLOAD flag netfilter: nf_flow_table: set default timeout after successful insertion net/bridge/br_netfilter_hooks.c | 4 ++++ net/netfilter/nf_conntrack_netlink.c | 7 +++++-- net/netfilter/nf_flow_table_core.c | 2 +- net/netfilter/nft_fib_netdev.c | 3 +++ net/netfilter/nft_socket.c | 6 +++--- 5 files changed, 16 insertions(+), 6 deletions(-)