Re: [PATCH v3 1/1] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid

From: Lance Yang
Date: Mon Jul 28 2025 - 21:53:01 EST




On 2025/7/29 08:55, Pablo Neira Ayuso wrote:
On Mon, Jul 28, 2025 at 06:25:14PM +0800, Lance Yang wrote:
From: Lance Yang <lance.yang@xxxxxxxxx>

When no logger is registered, nf_conntrack_log_invalid fails to log invalid
packets, leaving users unaware of actual invalid traffic. Improve this by
loading nf_log_syslog, similar to how 'iptables -I FORWARD 1 -m conntrack
--ctstate INVALID -j LOG' triggers it.

JFYI: I ended up taking v2 into nf-next, let me know if there is any
issue with your previous version, thanks.

Thanks for picking up v2 and merging it into nf-next!

No issues at all from my side. v3 only contains minor cleanups with
no functional changes, so v2 is fine and good to go ;)

Thanks,
Lance