Created attachment 1584954 [details] Patch that is upstream On current Kernels (5.0.20+ and 5.1.6+) there is a bug in the nf_conntrack_netlink module that prevents userspace tools from deleting singular conntrack entries from the conntrack table. I have sent a patch upstream and it was accepted for inclusion here: https://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf.git/commit/?id=e7600865db32b69deb0109b8254244dca592adcf Would it be possible to pick this up downstream until we see a release of a kernel with this patch included? Totally fine if not if it's too much effort. Thanks!
Hi Felix, I've picked it up for the v5.1.16 build in Fedora.
FEDORA-2019-d969cc2703 has been submitted as an update to Fedora 30. https://bodhi.fedoraproject.org/updates/FEDORA-2019-d969cc2703
kernel-5.1.16-300.fc30, kernel-headers-5.1.16-300.fc30 has been pushed to the Fedora 30 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-d969cc2703
kernel-5.1.16-200.fc29, kernel-headers-5.1.16-200.fc29 has been pushed to the Fedora 29 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-a6d06090f0
kernel-5.1.16-300.fc30, kernel-headers-5.1.16-300.fc30 has been pushed to the Fedora 30 stable repository. If problems still persist, please make note of it in this bug report.
kernel-5.1.16-200.fc29, kernel-headers-5.1.16-200.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.
Bug reappeared in kernel-5.2.2-200.fc30.x86_64 which is used for the current Test Day. It seems patch was not carried over. Meanwhile I got notice that the patch was picked up for inclusion in stable. So it should be showing up in the releases after the next one.
Fixed in 5.1.20 and 5.2.3