Hi, The following patchset contains Netfilter fixes for net: 1) Add selftest for nft_synproxy, from Florian Westphal. 2) xt_socket destroy path incorrectly disables IPv4 defrag for IPv6 traffic (typo), from Eric Dumazet. 3) Fix exit value selftest nft_concat_range.sh, from Hangbin Liu. 4) nft_synproxy disables the IPv4 hooks if the IPv6 hooks fail to be registered. 5) disable rp_filter on router in selftest nft_fib.sh, also from Hangbin Liu. Please, pull these changes from: git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git Thanks. ---------------------------------------------------------------- The following changes since commit 7db788ad627aabff2b74d4f1a3b68516d0fee0d7: nfp: flower: fix ida_idx not being released (2022-02-08 21:06:35 -0800) are available in the Git repository at: git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf.git HEAD for you to fetch changes up to bbe4c0896d25009a7c86285d2ab024eed4374eea: selftests: netfilter: disable rp_filter on router (2022-02-11 00:01:04 +0100) ---------------------------------------------------------------- Eric Dumazet (1): netfilter: xt_socket: fix a typo in socket_mt_destroy() Florian Westphal (1): selftests: netfilter: add synproxy test Hangbin Liu (2): selftests: netfilter: fix exit value for nft_concat_range selftests: netfilter: disable rp_filter on router Pablo Neira Ayuso (2): netfilter: nft_synproxy: unregister hooks on init error path selftests: netfilter: synproxy test requires nf_conntrack net/netfilter/nft_synproxy.c | 4 +- net/netfilter/xt_socket.c | 2 +- tools/testing/selftests/netfilter/Makefile | 2 +- .../selftests/netfilter/nft_concat_range.sh | 2 +- tools/testing/selftests/netfilter/nft_fib.sh | 1 + tools/testing/selftests/netfilter/nft_synproxy.sh | 117 +++++++++++++++++++++ 6 files changed, 124 insertions(+), 4 deletions(-) create mode 100755 tools/testing/selftests/netfilter/nft_synproxy.sh