From: Florian Westphal <fw@strlen.de>
To: <netfilter-devel@vger.kernel.org>
Cc: Jozsef Kadlecsik <kadlec@netfilter.org>, Florian Westphal <fw@strlen.de>
Subject: [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock
Date: Fri, 4 Sep 2026 20:53:20 +0200 [thread overview]
Message-ID: <20260904185321.30313-13-fw@strlen.de> (raw)
In-Reply-To: <20260904185321.30313-1-fw@strlen.de>
No need to disable/reenable softirqs.
Assisted-by: Claude:claude-sonnet-4-6
Signed-off-by: Florian Westphal <fw@strlen.de>
---
net/netfilter/ipset/ip_set_core.c | 4 ++--
net/netfilter/ipset/ip_set_hash_gen.h | 19 ++++++++-----------
net/netfilter/ipset/ip_set_hash_netnet.c | 8 ++++----
net/netfilter/ipset/ip_set_hash_netportnet.c | 8 ++++----
4 files changed, 18 insertions(+), 21 deletions(-)
diff --git a/net/netfilter/ipset/ip_set_core.c b/net/netfilter/ipset/ip_set_core.c
index 632e30c7f35d..856e53271b38 100644
--- a/net/netfilter/ipset/ip_set_core.c
+++ b/net/netfilter/ipset/ip_set_core.c
@@ -1868,9 +1868,9 @@ static int ip_set_utest(struct sk_buff *skb, const struct nfnl_info *info,
set->type->adt_policy, NULL))
return -IPSET_ERR_PROTOCOL;
- rcu_read_lock_bh();
+ rcu_read_lock();
ret = set->variant->uadt(set, tb, IPSET_TEST, &lineno, 0, 0);
- rcu_read_unlock_bh();
+ rcu_read_unlock();
/* Userspace can't trigger element to be re-added */
if (ret == -EAGAIN)
ret = 1;
diff --git a/net/netfilter/ipset/ip_set_hash_gen.h b/net/netfilter/ipset/ip_set_hash_gen.h
index 225f30e5b749..cf48b7c50ca1 100644
--- a/net/netfilter/ipset/ip_set_hash_gen.h
+++ b/net/netfilter/ipset/ip_set_hash_gen.h
@@ -17,9 +17,6 @@
#define ipset_dereference_nfnl(p) \
rcu_dereference_protected(p, \
lockdep_nfnl_is_held(NFNL_SUBSYS_IPSET))
-#define ipset_dereference_bh_nfnl(p) \
- rcu_dereference_bh_check(p, \
- lockdep_nfnl_is_held(NFNL_SUBSYS_IPSET))
/* Kept for backward compatibility */
#define AHASH_INIT_SIZE 2
@@ -729,7 +726,7 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
int i;
#endif
- rcu_read_lock_bh();
+ rcu_read_lock();
#ifdef IP_SET_HASH_WITH_MULTI
{
struct rhlist_head *tmp, *list;
@@ -906,7 +903,7 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
ret = flag_exist ? 0 : -IPSET_ERR_EXIST;
out_rcu_unlock:
- rcu_read_unlock_bh();
+ rcu_read_unlock();
return ret;
}
@@ -920,7 +917,7 @@ mtype_del(struct ip_set *set, void *value, const struct ip_set_ext *ext,
struct mtype_rht_elem *e;
int ret = -IPSET_ERR_EXIST;
- rcu_read_lock_bh();
+ rcu_read_lock();
#ifdef IP_SET_HASH_WITH_MULTI
{
struct rhlist_head *tmp, *list;
@@ -954,7 +951,7 @@ mtype_del(struct ip_set *set, void *value, const struct ip_set_ext *ext,
ip_set_ext_destroy(set, &e->elem);
kfree_rcu(e, rcu);
out_unlock:
- rcu_read_unlock_bh();
+ rcu_read_unlock();
return ret ? -IPSET_ERR_EXIST : 0;
}
@@ -994,10 +991,10 @@ mtype_test_cidrs(struct ip_set *set, struct mtype_elem *d,
pr_debug("test by nets\n");
retry:
multi = 0;
- nets0 = ipset_dereference_bh_nfnl(h->rnets[0]);
+ nets0 = rcu_dereference(h->rnets[0]);
seq0 = read_seqcount_begin(&nets0->seq);
#if IPSET_NET_COUNT == 2
- nets1 = ipset_dereference_bh_nfnl(h->rnets[1]);
+ nets1 = rcu_dereference(h->rnets[1]);
seq1 = read_seqcount_begin(&nets1->seq);
#endif
for (j = 0; j < nets0->len && !multi; j++) {
@@ -1076,7 +1073,7 @@ mtype_test(struct ip_set *set, void *value, const struct ip_set_ext *ext,
int i;
#endif
- rcu_read_lock_bh();
+ rcu_read_lock();
#ifdef IP_SET_HASH_WITH_NETS
/* If we test an IP address and not a network address,
* try all possible network sizes
@@ -1114,7 +1111,7 @@ mtype_test(struct ip_set *set, void *value, const struct ip_set_ext *ext,
ret = mtype_data_match(&e->elem, ext, mext, set, flags);
#endif
out:
- rcu_read_unlock_bh();
+ rcu_read_unlock();
return ret;
}
diff --git a/net/netfilter/ipset/ip_set_hash_netnet.c b/net/netfilter/ipset/ip_set_hash_netnet.c
index a6bd24e3b1ac..6b768725e4cd 100644
--- a/net/netfilter/ipset/ip_set_hash_netnet.c
+++ b/net/netfilter/ipset/ip_set_hash_netnet.c
@@ -148,10 +148,10 @@ hash_netnet4_kadt(struct ip_set *set, const struct sk_buff *skb,
struct hash_netnet4_elem e = { };
struct ip_set_ext ext = IP_SET_INIT_KEXT(skb, opt, set);
- rcu_read_lock_bh();
+ rcu_read_lock();
e.cidr[0] = INIT_CIDR(h->rnets[0], HOST_MASK);
e.cidr[1] = INIT_CIDR(h->rnets[1], HOST_MASK);
- rcu_read_unlock_bh();
+ rcu_read_unlock();
if (adt == IPSET_TEST)
e.ccmp = (HOST_MASK << (sizeof(e.cidr[0]) * 8)) | HOST_MASK;
@@ -382,10 +382,10 @@ hash_netnet6_kadt(struct ip_set *set, const struct sk_buff *skb,
struct hash_netnet6_elem e = { };
struct ip_set_ext ext = IP_SET_INIT_KEXT(skb, opt, set);
- rcu_read_lock_bh();
+ rcu_read_lock();
e.cidr[0] = INIT_CIDR(h->rnets[0], HOST_MASK);
e.cidr[1] = INIT_CIDR(h->rnets[1], HOST_MASK);
- rcu_read_unlock_bh();
+ rcu_read_unlock();
if (adt == IPSET_TEST)
e.ccmp = (HOST_MASK << (sizeof(u8) * 8)) | HOST_MASK;
diff --git a/net/netfilter/ipset/ip_set_hash_netportnet.c b/net/netfilter/ipset/ip_set_hash_netportnet.c
index 8575a2c5e215..d1e4ce2f2afa 100644
--- a/net/netfilter/ipset/ip_set_hash_netportnet.c
+++ b/net/netfilter/ipset/ip_set_hash_netportnet.c
@@ -155,10 +155,10 @@ hash_netportnet4_kadt(struct ip_set *set, const struct sk_buff *skb,
struct hash_netportnet4_elem e = { };
struct ip_set_ext ext = IP_SET_INIT_KEXT(skb, opt, set);
- rcu_read_lock_bh();
+ rcu_read_lock();
e.cidr[0] = INIT_CIDR(h->rnets[0], HOST_MASK);
e.cidr[1] = INIT_CIDR(h->rnets[1], HOST_MASK);
- rcu_read_unlock_bh();
+ rcu_read_unlock();
if (adt == IPSET_TEST)
e.ccmp = (HOST_MASK << (sizeof(e.cidr[0]) * 8)) | HOST_MASK;
@@ -444,10 +444,10 @@ hash_netportnet6_kadt(struct ip_set *set, const struct sk_buff *skb,
struct hash_netportnet6_elem e = { };
struct ip_set_ext ext = IP_SET_INIT_KEXT(skb, opt, set);
- rcu_read_lock_bh();
+ rcu_read_lock();
e.cidr[0] = INIT_CIDR(h->rnets[0], HOST_MASK);
e.cidr[1] = INIT_CIDR(h->rnets[1], HOST_MASK);
- rcu_read_unlock_bh();
+ rcu_read_unlock();
if (adt == IPSET_TEST)
e.ccmp = (HOST_MASK << (sizeof(u8) * 8)) | HOST_MASK;
--
2.55.0
next prev parent reply other threads:[~2026-09-04 18:54 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 18:53 [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29 ` Florian Westphal
2026-09-08 5:12 ` Herbert Xu
2026-09-08 5:30 ` Florian Westphal
2026-09-08 9:04 ` Herbert Xu
2026-09-08 9:56 ` Florian Westphal
2026-09-08 12:39 ` Herbert Xu
2026-09-08 13:25 ` Florian Westphal
2026-09-09 3:49 ` Herbert Xu
2026-09-09 4:17 ` Herbert Xu
2026-09-09 14:45 ` Florian Westphal
2026-09-10 9:11 ` Herbert Xu
2026-09-10 10:41 ` Florian Westphal
2026-09-11 11:56 ` Herbert Xu
2026-09-11 12:54 ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` Florian Westphal [this message]
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904185321.30313-13-fw@strlen.de \
--to=fw@strlen.de \
--cc=kadlec@netfilter.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.