Netfilter developers should be aware of a changeset now merged into Linus'
bk tree. A section of code in nf_hook_slow() which invalidates hardware
checksums and recalculates them on output paths has been removed and
pushed up to the Netfilter components which actually mangle packets (e.g.
What this means is that any new code, or out of tree code (e.g. POM) needs
to be reviewed to ensure that it handles hardware checksumming correctly
itself, as the netfilter core code no longer does this. (Although note
that NAT targets/helpers are covered automatically).
Briefly, what needs to be done is: before mangling a packet in a way which
might affect the TCP or UDP checksum, if the packet has hardware
checksumming enabled, call skb_checksum_help().
For more details & code examples, refer to the changeset info: