From: Florian Westphal <fw@strlen.de>
To: <netfilter-devel@vger.kernel.org>
Cc: Jozsef Kadlecsik <kadlec@netfilter.org>, Florian Westphal <fw@strlen.de>
Subject: [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag
Date: Fri, 4 Sep 2026 20:53:17 +0200 [thread overview]
Message-ID: <20260904185321.30313-10-fw@strlen.de> (raw)
In-Reply-To: <20260904185321.30313-1-fw@strlen.de>
From: Jozsef Kadlecsik <kadlec@netfilter.org>
This is a leftover from the old hash table that needed this to know both
when to skip already-matched identical ip/mask pairs and to know the
number of same-key elements to size the hash buckets.
Signed-off-by: Jozsef Kadlecsik <kadlec@netfilter.org>
Signed-off-by: Florian Westphal <fw@strlen.de>
---
net/netfilter/ipset/ip_set_hash_gen.h | 22 +++++++-------------
net/netfilter/ipset/ip_set_hash_ip.c | 6 ++----
net/netfilter/ipset/ip_set_hash_ipmac.c | 6 ++----
net/netfilter/ipset/ip_set_hash_ipmark.c | 6 ++----
net/netfilter/ipset/ip_set_hash_ipport.c | 6 ++----
net/netfilter/ipset/ip_set_hash_ipportip.c | 6 ++----
net/netfilter/ipset/ip_set_hash_ipportnet.c | 6 ++----
net/netfilter/ipset/ip_set_hash_mac.c | 3 +--
net/netfilter/ipset/ip_set_hash_net.c | 6 ++----
net/netfilter/ipset/ip_set_hash_netiface.c | 8 ++-----
net/netfilter/ipset/ip_set_hash_netnet.c | 6 ++----
net/netfilter/ipset/ip_set_hash_netport.c | 6 ++----
net/netfilter/ipset/ip_set_hash_netportnet.c | 6 ++----
13 files changed, 30 insertions(+), 63 deletions(-)
diff --git a/net/netfilter/ipset/ip_set_hash_gen.h b/net/netfilter/ipset/ip_set_hash_gen.h
index b6614ddb9e78..973adb854082 100644
--- a/net/netfilter/ipset/ip_set_hash_gen.h
+++ b/net/netfilter/ipset/ip_set_hash_gen.h
@@ -278,10 +278,7 @@ static int mtype_rht_cmpfn(struct rhashtable_compare_arg *arg, const void *obj)
#ifdef IP_SET_HASH_WITH_MULTI
return !mtype_key_equal(&e->elem, (const struct mtype_elem *)arg->key);
#else
- u32 multi = 0;
-
- return !mtype_data_equal(&e->elem,
- (const struct mtype_elem *)arg->key, &multi);
+ return !mtype_data_equal(&e->elem, (const struct mtype_elem *)arg->key);
#endif
}
@@ -737,7 +734,6 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
{
struct rhlist_head *tmp, *list;
unsigned int seen = 0;
- u32 multi = 0;
list = rhltable_lookup(&h->rhlt, d, mtype_rht_params);
if (!list)
@@ -749,8 +745,7 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
ipset_hash_elem_destroy_free(set, old);
continue;
}
-
- if (mtype_data_equal(&old->elem, d, &multi))
+ if (mtype_data_equal(&old->elem, d))
goto insert;
++seen;
}
@@ -841,10 +836,9 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
if (list) {
const struct mtype_rht_elem *dup;
struct rhlist_head *tmp;
- u32 multi = 0;
rhl_for_each_entry_rcu(dup, tmp, list, node) {
- if (dup == e || !mtype_data_equal(&dup->elem, d, &multi))
+ if (dup == e || !mtype_data_equal(&dup->elem, d))
continue;
/* check for duplicate key insertion: unlikely,
@@ -930,13 +924,12 @@ mtype_del(struct ip_set *set, void *value, const struct ip_set_ext *ext,
#ifdef IP_SET_HASH_WITH_MULTI
{
struct rhlist_head *tmp, *list;
- u32 multi = 0;
list = rhltable_lookup(&h->rhlt, d, mtype_rht_params);
if (!list)
goto out_unlock;
rhl_for_each_entry_rcu(e, tmp, list, node) {
- if (!mtype_data_equal(&e->elem, d, &multi))
+ if (!mtype_data_equal(&e->elem, d))
continue;
if (SET_ELEM_EXPIRED(set, &e->elem))
goto out_unlock;
@@ -995,8 +988,8 @@ mtype_test_cidrs(struct ip_set *set, struct mtype_elem *d,
#else
int ret, j;
#endif
+ bool multi = false;
unsigned int seq0;
- u32 multi;
pr_debug("test by nets\n");
retry:
@@ -1035,7 +1028,7 @@ mtype_test_cidrs(struct ip_set *set, struct mtype_elem *d,
rhl_for_each_entry_rcu(e, tmp, list, node) {
if (!SET_ELEM_EXPIRED(set, &e->elem))
multi = true;
- if (!mtype_data_equal(&e->elem, d, &multi))
+ if (!mtype_data_equal(&e->elem, d))
continue;
ret = mtype_data_match(&e->elem, ext, mext, set, flags);
if (ret)
@@ -1100,14 +1093,13 @@ mtype_test(struct ip_set *set, void *value, const struct ip_set_ext *ext,
#ifdef IP_SET_HASH_WITH_MULTI
{
struct rhlist_head *tmp, *list;
- u32 multi = 0;
list = rhltable_lookup(&h->rhlt, d, mtype_rht_params);
if (!list)
goto out;
rhl_for_each_entry_rcu(e, tmp, list, node) {
- if (!mtype_data_equal(&e->elem, d, &multi))
+ if (!mtype_data_equal(&e->elem, d))
continue;
ret = mtype_data_match(&e->elem, ext, mext, set, flags);
if (ret)
diff --git a/net/netfilter/ipset/ip_set_hash_ip.c b/net/netfilter/ipset/ip_set_hash_ip.c
index 9b82ec5d4037..44aac980b0b2 100644
--- a/net/netfilter/ipset/ip_set_hash_ip.c
+++ b/net/netfilter/ipset/ip_set_hash_ip.c
@@ -49,8 +49,7 @@ struct hash_ip4_elem {
static bool
hash_ip4_data_equal(const struct hash_ip4_elem *e1,
- const struct hash_ip4_elem *e2,
- u32 *multi)
+ const struct hash_ip4_elem *e2)
{
return e1->ip == e2->ip;
}
@@ -181,8 +180,7 @@ struct hash_ip6_elem {
static bool
hash_ip6_data_equal(const struct hash_ip6_elem *ip1,
- const struct hash_ip6_elem *ip2,
- u32 *multi)
+ const struct hash_ip6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6);
}
diff --git a/net/netfilter/ipset/ip_set_hash_ipmac.c b/net/netfilter/ipset/ip_set_hash_ipmac.c
index dced4c5f3ca3..88f4931aadeb 100644
--- a/net/netfilter/ipset/ip_set_hash_ipmac.c
+++ b/net/netfilter/ipset/ip_set_hash_ipmac.c
@@ -50,8 +50,7 @@ struct hash_ipmac4_elem {
static bool
hash_ipmac4_data_equal(const struct hash_ipmac4_elem *e1,
- const struct hash_ipmac4_elem *e2,
- u32 *multi)
+ const struct hash_ipmac4_elem *e2)
{
return e1->ip == e2->ip && ether_addr_equal(e1->ether, e2->ether);
}
@@ -150,8 +149,7 @@ struct hash_ipmac6_elem {
static bool
hash_ipmac6_data_equal(const struct hash_ipmac6_elem *e1,
- const struct hash_ipmac6_elem *e2,
- u32 *multi)
+ const struct hash_ipmac6_elem *e2)
{
return ipv6_addr_equal(&e1->ip.in6, &e2->ip.in6) &&
ether_addr_equal(e1->ether, e2->ether);
diff --git a/net/netfilter/ipset/ip_set_hash_ipmark.c b/net/netfilter/ipset/ip_set_hash_ipmark.c
index 6196b0112cf9..88c8239ea3b8 100644
--- a/net/netfilter/ipset/ip_set_hash_ipmark.c
+++ b/net/netfilter/ipset/ip_set_hash_ipmark.c
@@ -45,8 +45,7 @@ struct hash_ipmark4_elem {
static bool
hash_ipmark4_data_equal(const struct hash_ipmark4_elem *ip1,
- const struct hash_ipmark4_elem *ip2,
- u32 *multi)
+ const struct hash_ipmark4_elem *ip2)
{
return ip1->ip == ip2->ip &&
ip1->mark == ip2->mark;
@@ -181,8 +180,7 @@ struct hash_ipmark6_elem {
static bool
hash_ipmark6_data_equal(const struct hash_ipmark6_elem *ip1,
- const struct hash_ipmark6_elem *ip2,
- u32 *multi)
+ const struct hash_ipmark6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6) &&
ip1->mark == ip2->mark;
diff --git a/net/netfilter/ipset/ip_set_hash_ipport.c b/net/netfilter/ipset/ip_set_hash_ipport.c
index 7842ff4ad74f..f2f41700d59e 100644
--- a/net/netfilter/ipset/ip_set_hash_ipport.c
+++ b/net/netfilter/ipset/ip_set_hash_ipport.c
@@ -53,8 +53,7 @@ struct hash_ipport4_elem {
static bool
hash_ipport4_data_equal(const struct hash_ipport4_elem *ip1,
- const struct hash_ipport4_elem *ip2,
- u32 *multi)
+ const struct hash_ipport4_elem *ip2)
{
return ip1->ip == ip2->ip &&
ip1->port == ip2->port &&
@@ -223,8 +222,7 @@ struct hash_ipport6_elem {
static bool
hash_ipport6_data_equal(const struct hash_ipport6_elem *ip1,
- const struct hash_ipport6_elem *ip2,
- u32 *multi)
+ const struct hash_ipport6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6) &&
ip1->port == ip2->port &&
diff --git a/net/netfilter/ipset/ip_set_hash_ipportip.c b/net/netfilter/ipset/ip_set_hash_ipportip.c
index b1b24358c810..7e82bcd9aa42 100644
--- a/net/netfilter/ipset/ip_set_hash_ipportip.c
+++ b/net/netfilter/ipset/ip_set_hash_ipportip.c
@@ -49,8 +49,7 @@ struct hash_ipportip4_elem {
static bool
hash_ipportip4_data_equal(const struct hash_ipportip4_elem *ip1,
- const struct hash_ipportip4_elem *ip2,
- u32 *multi)
+ const struct hash_ipportip4_elem *ip2)
{
return ip1->ip == ip2->ip &&
ip1->ip2 == ip2->ip2 &&
@@ -220,8 +219,7 @@ struct hash_ipportip6_elem {
static bool
hash_ipportip6_data_equal(const struct hash_ipportip6_elem *ip1,
- const struct hash_ipportip6_elem *ip2,
- u32 *multi)
+ const struct hash_ipportip6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6) &&
ipv6_addr_equal(&ip1->ip2.in6, &ip2->ip2.in6) &&
diff --git a/net/netfilter/ipset/ip_set_hash_ipportnet.c b/net/netfilter/ipset/ip_set_hash_ipportnet.c
index 58a47a0f89f0..01950dbff27d 100644
--- a/net/netfilter/ipset/ip_set_hash_ipportnet.c
+++ b/net/netfilter/ipset/ip_set_hash_ipportnet.c
@@ -62,8 +62,7 @@ struct hash_ipportnet4_elem {
static bool
hash_ipportnet4_data_equal(const struct hash_ipportnet4_elem *ip1,
- const struct hash_ipportnet4_elem *ip2,
- u32 *multi)
+ const struct hash_ipportnet4_elem *ip2)
{
return ip1->ip == ip2->ip &&
ip1->ip2 == ip2->ip2 &&
@@ -320,8 +319,7 @@ struct hash_ipportnet6_elem {
static bool
hash_ipportnet6_data_equal(const struct hash_ipportnet6_elem *ip1,
- const struct hash_ipportnet6_elem *ip2,
- u32 *multi)
+ const struct hash_ipportnet6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6) &&
ipv6_addr_equal(&ip1->ip2.in6, &ip2->ip2.in6) &&
diff --git a/net/netfilter/ipset/ip_set_hash_mac.c b/net/netfilter/ipset/ip_set_hash_mac.c
index 4c195db349f7..0e7b30faddee 100644
--- a/net/netfilter/ipset/ip_set_hash_mac.c
+++ b/net/netfilter/ipset/ip_set_hash_mac.c
@@ -40,8 +40,7 @@ struct hash_mac4_elem {
static bool
hash_mac4_data_equal(const struct hash_mac4_elem *e1,
- const struct hash_mac4_elem *e2,
- u32 *multi)
+ const struct hash_mac4_elem *e2)
{
return ether_addr_equal(e1->ether, e2->ether);
}
diff --git a/net/netfilter/ipset/ip_set_hash_net.c b/net/netfilter/ipset/ip_set_hash_net.c
index 157660674f1d..431f0ae56054 100644
--- a/net/netfilter/ipset/ip_set_hash_net.c
+++ b/net/netfilter/ipset/ip_set_hash_net.c
@@ -50,8 +50,7 @@ struct hash_net4_elem {
static bool
hash_net4_data_equal(const struct hash_net4_elem *ip1,
- const struct hash_net4_elem *ip2,
- u32 *multi)
+ const struct hash_net4_elem *ip2)
{
return ip1->ip == ip2->ip &&
ip1->cidr == ip2->cidr;
@@ -221,8 +220,7 @@ struct hash_net6_elem {
static bool
hash_net6_data_equal(const struct hash_net6_elem *ip1,
- const struct hash_net6_elem *ip2,
- u32 *multi)
+ const struct hash_net6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6) &&
ip1->cidr == ip2->cidr;
diff --git a/net/netfilter/ipset/ip_set_hash_netiface.c b/net/netfilter/ipset/ip_set_hash_netiface.c
index 82b00337cfef..0869a62ef200 100644
--- a/net/netfilter/ipset/ip_set_hash_netiface.c
+++ b/net/netfilter/ipset/ip_set_hash_netiface.c
@@ -74,11 +74,9 @@ hash_netiface4_key_equal(const struct hash_netiface4_elem *ip1,
static bool
hash_netiface4_data_equal(const struct hash_netiface4_elem *ip1,
- const struct hash_netiface4_elem *ip2,
- u32 *multi)
+ const struct hash_netiface4_elem *ip2)
{
return hash_netiface4_key_equal(ip1, ip2) &&
- (++*multi) &&
(ip1->wildcard ?
strncmp(ip1->iface, ip2->iface, strlen(ip1->iface)) == 0 :
strcmp(ip1->iface, ip2->iface) == 0);
@@ -314,11 +312,9 @@ hash_netiface6_key_equal(const struct hash_netiface6_elem *ip1,
static bool
hash_netiface6_data_equal(const struct hash_netiface6_elem *ip1,
- const struct hash_netiface6_elem *ip2,
- u32 *multi)
+ const struct hash_netiface6_elem *ip2)
{
return hash_netiface6_key_equal(ip1, ip2) &&
- (++*multi) &&
(ip1->wildcard ?
strncmp(ip1->iface, ip2->iface, strlen(ip1->iface)) == 0 :
strcmp(ip1->iface, ip2->iface) == 0);
diff --git a/net/netfilter/ipset/ip_set_hash_netnet.c b/net/netfilter/ipset/ip_set_hash_netnet.c
index 4e77e40ebc2c..a6bd24e3b1ac 100644
--- a/net/netfilter/ipset/ip_set_hash_netnet.c
+++ b/net/netfilter/ipset/ip_set_hash_netnet.c
@@ -58,8 +58,7 @@ struct hash_netnet4_elem {
static bool
hash_netnet4_data_equal(const struct hash_netnet4_elem *ip1,
- const struct hash_netnet4_elem *ip2,
- u32 *multi)
+ const struct hash_netnet4_elem *ip2)
{
return ip1->ipcmp == ip2->ipcmp &&
ip1->ccmp == ip2->ccmp;
@@ -295,8 +294,7 @@ struct hash_netnet6_elem {
static bool
hash_netnet6_data_equal(const struct hash_netnet6_elem *ip1,
- const struct hash_netnet6_elem *ip2,
- u32 *multi)
+ const struct hash_netnet6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip[0].in6, &ip2->ip[0].in6) &&
ipv6_addr_equal(&ip1->ip[1].in6, &ip2->ip[1].in6) &&
diff --git a/net/netfilter/ipset/ip_set_hash_netport.c b/net/netfilter/ipset/ip_set_hash_netport.c
index dfe8f995abbe..a301aff67c6d 100644
--- a/net/netfilter/ipset/ip_set_hash_netport.c
+++ b/net/netfilter/ipset/ip_set_hash_netport.c
@@ -60,8 +60,7 @@ struct hash_netport4_elem {
static bool
hash_netport4_data_equal(const struct hash_netport4_elem *ip1,
- const struct hash_netport4_elem *ip2,
- u32 *multi)
+ const struct hash_netport4_elem *ip2)
{
return ip1->ip == ip2->ip &&
ip1->port == ip2->port &&
@@ -277,8 +276,7 @@ struct hash_netport6_elem {
static bool
hash_netport6_data_equal(const struct hash_netport6_elem *ip1,
- const struct hash_netport6_elem *ip2,
- u32 *multi)
+ const struct hash_netport6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip.in6, &ip2->ip.in6) &&
ip1->port == ip2->port &&
diff --git a/net/netfilter/ipset/ip_set_hash_netportnet.c b/net/netfilter/ipset/ip_set_hash_netportnet.c
index 0dc79d37beac..8575a2c5e215 100644
--- a/net/netfilter/ipset/ip_set_hash_netportnet.c
+++ b/net/netfilter/ipset/ip_set_hash_netportnet.c
@@ -59,8 +59,7 @@ struct hash_netportnet4_elem {
static bool
hash_netportnet4_data_equal(const struct hash_netportnet4_elem *ip1,
- const struct hash_netportnet4_elem *ip2,
- u32 *multi)
+ const struct hash_netportnet4_elem *ip2)
{
return ip1->ipcmp == ip2->ipcmp &&
ip1->ccmp == ip2->ccmp &&
@@ -352,8 +351,7 @@ struct hash_netportnet6_elem {
static bool
hash_netportnet6_data_equal(const struct hash_netportnet6_elem *ip1,
- const struct hash_netportnet6_elem *ip2,
- u32 *multi)
+ const struct hash_netportnet6_elem *ip2)
{
return ipv6_addr_equal(&ip1->ip[0].in6, &ip2->ip[0].in6) &&
ipv6_addr_equal(&ip1->ip[1].in6, &ip2->ip[1].in6) &&
--
2.55.0
next prev parent reply other threads:[~2026-09-04 18:54 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 18:53 [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29 ` Florian Westphal
2026-09-08 5:12 ` Herbert Xu
2026-09-08 5:30 ` Florian Westphal
2026-09-08 9:04 ` Herbert Xu
2026-09-08 9:56 ` Florian Westphal
2026-09-08 12:39 ` Herbert Xu
2026-09-08 13:25 ` Florian Westphal
2026-09-09 3:49 ` Herbert Xu
2026-09-09 4:17 ` Herbert Xu
2026-09-09 14:45 ` Florian Westphal
2026-09-10 9:11 ` Herbert Xu
2026-09-10 10:41 ` Florian Westphal
2026-09-11 11:56 ` Herbert Xu
2026-09-11 12:54 ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` Florian Westphal [this message]
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904185321.30313-10-fw@strlen.de \
--to=fw@strlen.de \
--cc=kadlec@netfilter.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.