Hello, This series contains initial netfilter skb drop_reason support, from myself. First few patches fix up a few spots to make sure we won't trip when followup patches embed error numbers in the upper bits (we already do this in some places). Then, nftables and bridge netfilter get converted to call kfree_skb_reason directly to let tooling pinpoint exact location of packet drops, rather than the existing NF_DROP catchall in nf_hook_slow(). I would like to eventually convert all netfilter modules, but as some callers cannot deal with NF_STOLEN (notably act_ct), more preparation work is needed for this. Last patch gets rid of an ugly 'de-const' cast in nftables. The following changes since commit a0a86022474304e012aad5d41943fdd31a036284: Merge branch 'devlink-deadlock' (2023-10-18 09:23:02 +0100) are available in the Git repository at: https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git tags/nf-next-23-10-18 for you to fetch changes up to 256001672153af5786c6ca148114693d7d76d836: netfilter: nf_tables: de-constify set commit ops function argument (2023-10-18 10:26:43 +0200) ---------------------------------------------------------------- netfilter next pull request 2023-10-18 ---------------------------------------------------------------- Florian Westphal (7): netfilter: xt_mangle: only check verdict part of return value netfilter: nf_tables: mask out non-verdict bits when checking return value netfilter: conntrack: convert nf_conntrack_update to netfilter verdicts netfilter: nf_nat: mask out non-verdict bits when checking return value netfilter: make nftables drops visible in net dropmonitor netfilter: bridge: convert br_netfilter to NF_DROP_REASON netfilter: nf_tables: de-constify set commit ops function argument include/linux/netfilter.h | 10 +++++++ include/net/netfilter/nf_tables.h | 2 +- net/bridge/br_netfilter_hooks.c | 26 ++++++++-------- net/bridge/br_netfilter_ipv6.c | 6 ++-- net/ipv4/netfilter/iptable_mangle.c | 9 +++--- net/ipv6/netfilter/ip6table_mangle.c | 9 +++--- net/netfilter/core.c | 6 ++-- net/netfilter/nf_conntrack_core.c | 58 ++++++++++++++++++++---------------- net/netfilter/nf_nat_proto.c | 5 ++-- net/netfilter/nf_tables_core.c | 8 +++-- net/netfilter/nf_tables_trace.c | 8 +++-- net/netfilter/nfnetlink_queue.c | 15 ++++++---- net/netfilter/nft_set_pipapo.c | 7 ++--- 13 files changed, 100 insertions(+), 69 deletions(-)