From: Florian Westphal <fw@strlen.de>
To: <netfilter-devel@vger.kernel.org>
Cc: Jozsef Kadlecsik <kadlec@netfilter.org>, Florian Westphal <fw@strlen.de>
Subject: [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable
Date: Fri, 4 Sep 2026 20:53:08 +0200 [thread overview]
Message-ID: <20260904185321.30313-1-fw@strlen.de> (raw)
v4: add rhashtable_flush_and_free() helper to rhashtable, then
use it in patch 4.
Sending the entire thing at once as this is now deferred to -next anyway
due to need for new rhashtable function.
It would be possible to stop after 're-add forceadd' and push
the rest in a different merge request in case this is too much for
one nf-next -> net-next batch.
1) Add rhashtable_flush_and_free helper to rhashtable.
2) Add rhashtable boilerplate stubs to ipset. Implement initialization and
destruction of the rhashtable.
3) Add rhltable boilerplate stubs to netfilter ipset.
4) Replace ipset internal hash tables with rhashtable. Enforce an explicit
chain length limit via RHL_MAX_CHAINLEN. Maintain backward compatibility
for old configuration options.
5) Restore forceadd support in ipset by re-implementing removed eviction
logic. Add a helper to locate random key slots for potential element
replacement.
6) Include dynamic memory allocation for CIDR storage in userspace reports.
7) Remove obsolete data_next stubs in netfilter ipset. Retain only the
necessary stubs for specific backend netmask expansion.
8) Remove last region lock usage in ipset. Move locking responsibility to
kadt, uadt, and flush callbacks. Keep IPSET_TEST bitmap types lockless.
9) Remove multi-flag from netfilter ipset. Eliminate legacy logic used for
skipping identical entries and sizing hash buckets.
From Jozsef Kadlecsik.
10) Remove ipset resize functionality. Also from Jozsef.
11) Remove trivial kvfree wrapper in netfilter ipset.
12) Replace rcu_read_lock_bh() with plain rcu_read_lock.
13) Improve ipset lockdep coverage by removing always-true arguments to
rcu_dereference_protected(). Add assertions to verify mutex holding in
specific callpaths.
Florian Westphal (11):
rhashtable: add rhashtable_flush_and_free helper
netfilter: ipset: add rhashtable boilerplate stubs
netfilter: ipset: add rhltable boilerplate stubs
netfilter: ipset: replace internal hash table with rhashtable
netfilter: ipset: re-add forceadd support
netfilter: ipset: also report mem size for cidr storage to userspace
netfilter: ipset: remove obsolete data_next stubs
netfilter: ipset: remove last region lock usage
netfilter: ipset: remove trivial kvfree wrapper
netfilter: ipset: use plain rcu_read_lock
netfilter: ipset: improve lockdep coverage
Jozsef Kadlecsik (2):
netfilter: ipset: remove multi-flag
netfilter: ipset: remove resize completely
include/linux/netfilter/ipset/ip_set.h | 22 +-
include/linux/rhashtable.h | 19 +
lib/rhashtable.c | 127 ++
net/netfilter/ipset/ip_set_bitmap_gen.h | 10 +-
net/netfilter/ipset/ip_set_bitmap_ip.c | 16 +-
net/netfilter/ipset/ip_set_bitmap_ipmac.c | 15 +-
net/netfilter/ipset/ip_set_bitmap_port.c | 16 +-
net/netfilter/ipset/ip_set_core.c | 77 +-
net/netfilter/ipset/ip_set_hash_gen.h | 1618 +++++++-----------
net/netfilter/ipset/ip_set_hash_ip.c | 11 +-
net/netfilter/ipset/ip_set_hash_ipmac.c | 19 +-
net/netfilter/ipset/ip_set_hash_ipmark.c | 12 +-
net/netfilter/ipset/ip_set_hash_ipport.c | 13 +-
net/netfilter/ipset/ip_set_hash_ipportip.c | 13 +-
net/netfilter/ipset/ip_set_hash_ipportnet.c | 13 +-
net/netfilter/ipset/ip_set_hash_mac.c | 9 +-
net/netfilter/ipset/ip_set_hash_net.c | 12 +-
net/netfilter/ipset/ip_set_hash_netiface.c | 38 +-
net/netfilter/ipset/ip_set_hash_netnet.c | 20 +-
net/netfilter/ipset/ip_set_hash_netport.c | 13 +-
net/netfilter/ipset/ip_set_hash_netportnet.c | 21 +-
net/netfilter/ipset/ip_set_list_set.c | 27 +-
22 files changed, 932 insertions(+), 1209 deletions(-)
--
2.55.0
next reply other threads:[~2026-09-04 18:53 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 18:53 Florian Westphal [this message]
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29 ` Florian Westphal
2026-09-08 5:12 ` Herbert Xu
2026-09-08 5:30 ` Florian Westphal
2026-09-08 9:04 ` Herbert Xu
2026-09-08 9:56 ` Florian Westphal
2026-09-08 12:39 ` Herbert Xu
2026-09-08 13:25 ` Florian Westphal
2026-09-09 3:49 ` Herbert Xu
2026-09-09 4:17 ` Herbert Xu
2026-09-09 14:45 ` Florian Westphal
2026-09-10 9:11 ` Herbert Xu
2026-09-10 10:41 ` Florian Westphal
2026-09-11 11:56 ` Herbert Xu
2026-09-11 12:54 ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904185321.30313-1-fw@strlen.de \
--to=fw@strlen.de \
--cc=kadlec@netfilter.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.