On Mon, Jan 24, 2022 at 05:37:32AM +0000, kai zhang wrote: > Below configuration, mangle,filter and security tables have no rule: Yes, but there are loaded in your iptables-legacy environment. In iptables-nft this will not happen. > # iptables -t raw -I PREROUTING 1 -p tcp --dport 22 -j TRACE > # sysctl net.netfilter.nf_log.2=nf_log_ipv4 > > There are 5 logs for incoming ssh packet: > > kernel: [ 7018.727278] TRACE: raw:PREROUTING:policy:2 IN=enp9s0 ... > kernel: [ 7018.727304] TRACE: mangle:PREROUTING:policy:1 IN=enp9s0 ... > kernel: [ 7018.727327] TRACE: mangle:INPUT:policy:1 IN=enp9s0 ... > kernel: [ 7018.727343] TRACE: filter:INPUT:policy:1 IN=enp9s0 ... > kernel: [ 7018.727359] TRACE: security:INPUT:policy:1 IN=enp9s0 ... tracing was not designed to display every registered table/chain even if it has not rules. > Signed-off-by: kai zhang <zhangkaiheb@xxxxxxx> > --- > net/ipv4/netfilter/ip_tables.c | 4 +++- > net/ipv6/netfilter/ip6_tables.c | 4 +++- > 2 files changed, 6 insertions(+), 2 deletions(-) > > diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c > index 2ed7c58b4..5f0e6096e 100644 > --- a/net/ipv4/netfilter/ip_tables.c > +++ b/net/ipv4/netfilter/ip_tables.c > @@ -304,9 +304,11 @@ ipt_do_table(void *priv, > > #if IS_ENABLED(CONFIG_NETFILTER_XT_TARGET_TRACE) > /* The packet is traced: log it */ > - if (unlikely(skb->nf_trace)) > + if (unlikely(skb->nf_trace)) { > trace_packet(state->net, skb, hook, state->in, > state->out, table->name, private, e); > + nf_reset_trace(skb); > + } > #endif > /* Standard target? */ > if (!t->u.kernel.target->target) { > diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c > index 2d816277f..ae842a835 100644 > --- a/net/ipv6/netfilter/ip6_tables.c > +++ b/net/ipv6/netfilter/ip6_tables.c > @@ -327,9 +327,11 @@ ip6t_do_table(void *priv, struct sk_buff *skb, > > #if IS_ENABLED(CONFIG_NETFILTER_XT_TARGET_TRACE) > /* The packet is traced: log it */ > - if (unlikely(skb->nf_trace)) > + if (unlikely(skb->nf_trace)) { > trace_packet(state->net, skb, hook, state->in, > state->out, table->name, private, e); > + nf_reset_trace(skb); > + } > #endif > /* Standard target? */ > if (!t->u.kernel.target->target) { > -- > 2.30.2 >