From: Florian Westphal <fw@strlen.de>
To: <netfilter-devel@vger.kernel.org>
Cc: Jozsef Kadlecsik <kadlec@netfilter.org>, Florian Westphal <fw@strlen.de>
Subject: [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support
Date: Fri, 4 Sep 2026 20:53:13 +0200 [thread overview]
Message-ID: <20260904185321.30313-6-fw@strlen.de> (raw)
In-Reply-To: <20260904185321.30313-1-fw@strlen.de>
The rhashtable conversion removed the SET_WITH_FORCEADD eviction logic.
Add mtype_remove_random() helper to lookup a random key slot.
If there is an element, try to evict it and allow add of the new element
just like before the rhashtable conversion.
Assisted-by: Claude:claude-opus-4-6
Signed-off-by: Florian Westphal <fw@strlen.de>
---
net/netfilter/ipset/ip_set_hash_gen.h | 76 +++++++++++++++++++++++++--
1 file changed, 71 insertions(+), 5 deletions(-)
diff --git a/net/netfilter/ipset/ip_set_hash_gen.h b/net/netfilter/ipset/ip_set_hash_gen.h
index 7cc2b515e71c..ad190b2f8632 100644
--- a/net/netfilter/ipset/ip_set_hash_gen.h
+++ b/net/netfilter/ipset/ip_set_hash_gen.h
@@ -154,6 +154,9 @@ static const union nf_inet_addr zeromask = {};
#undef mtype_kadt
#undef mtype_uadt
+#undef mtype_remove_random
+#undef mtype_remove_key
+#undef mtype_remove_cmpfn
#undef mtype_add
#undef mtype_do_set_exts
#undef mtype_del
@@ -205,6 +208,9 @@ static const union nf_inet_addr zeromask = {};
#define mtype_kadt IPSET_TOKEN(MTYPE, _kadt)
#define mtype_uadt IPSET_TOKEN(MTYPE, _uadt)
+#define mtype_remove_random IPSET_TOKEN(MTYPE, _remove_random)
+#define mtype_remove_key IPSET_TOKEN(MTYPE, _remove_key)
+#define mtype_remove_cmpfn IPSET_TOKEN(MTYPE, _remove_cmpfn)
#define mtype_add IPSET_TOKEN(MTYPE, _add)
#define mtype_del IPSET_TOKEN(MTYPE, _del)
#define mtype_test_cidrs IPSET_TOKEN(MTYPE, _test_cidrs)
@@ -637,6 +643,64 @@ mtype_rht_size(struct ip_set *set, u32 *elements, size_t *ext_size)
(offsetof(struct mtype_rht_elem, elem) + set->dsize);
}
+static u32 mtype_remove_key(const void *data, u32 len, u32 seed)
+{
+ return get_random_u32();
+}
+
+static int mtype_remove_cmpfn(struct rhashtable_compare_arg *arg, const void *obj)
+{
+ return 0; /* always match */
+}
+
+/**
+ * mtype_remove_random() - Remove a random element from the set (forceadd)
+ * @set: Pointer to the ip_set
+ * @h: Pointer to the htype
+ *
+ * When sets created with forceadd option become full the next addition
+ * to the set may succeed and evict a random entry from the set.
+ * Best-effort: no linear scan; 'return false' is fine.
+ *
+ * Return: true if an element was evicted, false otherwise.
+ */
+static bool
+mtype_remove_random(struct ip_set *set)
+{
+ static const struct rhashtable_params ip_set_hash_rnd_params = {
+ .head_offset = offsetof(struct mtype_rht_elem, node),
+ .key_offset = offsetof(struct mtype_rht_elem, elem),
+ .hashfn = mtype_remove_key,
+ .obj_hashfn = mtype_rht_obj_hashfn,
+ .obj_cmpfn = mtype_remove_cmpfn,
+ .key_len = sizeof(u32),
+ };
+ struct mtype_rht_elem *e = NULL;
+ struct htype *h = set->data;
+ bool removed = false;
+ static const u32 k;
+
+#ifdef IP_SET_HASH_WITH_MULTI
+ {
+ struct rhlist_head *list = rhltable_lookup(&h->rhlt, &k,
+ ip_set_hash_rnd_params);
+ if (!list)
+ return false;
+
+ e = container_of(list, typeof(*e), node);
+ }
+#else
+ e = rhashtable_lookup(&h->ht, &k, ip_set_hash_rnd_params);
+#endif
+ if (e && !ipset_hash_remove(h, e))
+ removed = true;
+
+ if (removed)
+ ipset_hash_elem_destroy_free(set, e);
+
+ return removed;
+}
+
/* Add an element to a hash and update the internal counters when succeeded,
* otherwise report the proper error code.
*/
@@ -706,11 +770,13 @@ mtype_add(struct ip_set *set, void *value, const struct ip_set_ext *ext,
}
if (!old && ipset_hash_nelems(h) >= h->maxelem) {
- if (net_ratelimit())
- pr_warn("Set %s is full, maxelem %u reached\n",
- set->name, h->maxelem);
- ret = -IPSET_ERR_HASH_FULL;
- goto out_rcu_unlock;
+ if (!SET_WITH_FORCEADD(set) || !mtype_remove_random(set)) {
+ if (net_ratelimit())
+ pr_warn("Set %s is full, maxelem %u reached\n",
+ set->name, h->maxelem);
+ ret = -IPSET_ERR_HASH_FULL;
+ goto out_rcu_unlock;
+ }
}
e = kzalloc(offsetof(struct mtype_rht_elem, elem) + set->dsize,
--
2.55.0
next prev parent reply other threads:[~2026-09-04 18:53 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 18:53 [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29 ` Florian Westphal
2026-09-08 5:12 ` Herbert Xu
2026-09-08 5:30 ` Florian Westphal
2026-09-08 9:04 ` Herbert Xu
2026-09-08 9:56 ` Florian Westphal
2026-09-08 12:39 ` Herbert Xu
2026-09-08 13:25 ` Florian Westphal
2026-09-09 3:49 ` Herbert Xu
2026-09-09 4:17 ` Herbert Xu
2026-09-09 14:45 ` Florian Westphal
2026-09-10 9:11 ` Herbert Xu
2026-09-10 10:41 ` Florian Westphal
2026-09-11 11:56 ` Herbert Xu
2026-09-11 12:54 ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` Florian Westphal [this message]
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904185321.30313-6-fw@strlen.de \
--to=fw@strlen.de \
--cc=kadlec@netfilter.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.