Merge tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf

Pablo Neira Ayuso says:

====================
Netfilter/IPVS fixes for net

The following batch contains Netfilter fixes for net. This batch
fixes crashes as recent feature regression, one of the due to a
dependency that has been pulled into -stable:

1) Expand existing ipset fix for bitmap sets to disallow comments
   updates from kernel-side adds, from Florian Westphal.

2) Drop flowtable reference if nf_ct_netns_get() fails, otherwise
   flowtable cannot ever be removed, from Aohan Mei.

3) nft_rbtree GC should collect end elements that contained in
   this transaction batch, new or deleted elements are never
   expired. From Weiming Shi.

4) Restrict nf_nat_bpf so it does not set unknown NF_NAT_MANIP_*
   values, from Fernando F. Mancera.

5) Flowtable GC must skip flows that are pending hardware updates,
   generalize the PENDING flag and use it to inhibit GC.

6) Restore flowtable with ieee80211 which broke due to a relatively
   recent commit, which was pulled in by -stable, causing a regression
   in 6.18 kernels.

And the following IPVS fixes:

1) Fix accounting of cache entries in IPVS LBLC for destinations,
   which eventually fills up the table and trigger recurrent
   resizing, from Julian Anastasov.

2) Limit IPVS cache growth for LBLCR and LBLC schedulers,
   from Zhiling Zou.

3) Restrict IP_VS_CONN_F_ONE_PACKET for normal connections,
   do not allow to use it with templates. Also from Julian.

4) Sanitize flags in IPVS sync messages received in the backup.
   From Julian Anastasov.

netfilter pull request 26-09-30

* tag 'nf-26-09-30' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf:
  netfilter: flowtable: restore ieee80211 forward path
  netfilter: flowtable: generalize pending status bit
  netfilter: bpf: reject invalid NAT manipulation types
  netfilter: nft_set_rbtree: skip transaction elements during GC
  ipvs: filter some flags received in the backup server
  ipvs: do not create invisible templates
  ipvs: bound LBLCR and LBLC cache growth
  ipvs: fix missing counter decrement in lblc
  netfilter: nft_flow_offload: drop flowtable reference on init error path
  netfilter: ipset: do not update comments from kernel-side adds
====================

Link: https://patch.msgid.link/20260930074142.298353-1-pablo@netfilter.org
Signed-off-by: Paolo Abeni <pabeni@redhat.com>