netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
authorLance Yang <lance.yang@linux.dev>
Mon, 26 May 2025 08:59:02 +0000 (16:59 +0800)
committerPablo Neira Ayuso <pablo@netfilter.org>
Fri, 25 Jul 2025 16:35:41 +0000 (18:35 +0200)
commite89a68046687fe9913ce3bfad82f7ccbb65687e0
tree523ba2a1ee568c6184aa737ed1158f4fbe1c0c23
parentaa5840167780a315f8a050b77f41acb852465e2d
netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid

When no logger is registered, nf_conntrack_log_invalid fails to log invalid
packets, leaving users unaware of actual invalid traffic. Improve this by
loading nf_log_syslog, similar to how 'iptables -I FORWARD 1 -m conntrack
--ctstate INVALID -j LOG' triggers it.

Suggested-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Zi Li <zi.li@linux.dev>
Signed-off-by: Lance Yang <lance.yang@linux.dev>
Acked-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/net/netfilter/nf_log.h
net/netfilter/nf_conntrack_standalone.c
net/netfilter/nf_log.c