From: Patrick McHardy <kaber@trash.net>
To: Massimiliano Hofer <max@nucleus.it>
Cc: Netfilter Development Mailinglist <netfilter-devel@lists.netfilter.org>
Subject: Re: priv_data patch
Date: Mon, 14 Aug 2006 17:14:06 +0200 [thread overview]
Message-ID: <44E0933E.5060905@trash.net> (raw)
In-Reply-To: <200608141702.50753.max@nucleus.it>
Massimiliano Hofer wrote:
> On Monday 14 August 2006 4:37 pm, you wrote:
>
>>Hmm .. recent does a table lookup during runtime and the table could be
>>cached. That would improve things a bit, but in my opinion not enough
>>to justify this patch. Same for hashlimit. What data would condition
>>store exactly?
>
>
> I need a pointer to per condition data, so that multiple rules with the same
> name refer to the same flag.
> I can break userspace compatibility and store a pointer in the userspace
> structure. I just thought this could be useful to everyone (and let me
> maintain userspace compatibility along the way).
That looks like the only valid type of usage. Which means your initial
implementation, which just provided space for a pointer to the
individual instances, might have been the better way. I need to think
about this some more and look at the modules that could make use of
this again.
>>Its actually quite clear what is needed. We want a userspace interface
>>built on netlink, that acts on individual rules, not entire rulesets.
>>There are a few more ideas, like handling negation centrally, allowing
>>userspace to specify whether a target is terminal or not, allow multiple
>>non-terminal targets in a row, etc, but nothing really fundamental.
>
>
> I thought the current way of doing things was specifically designed to
> minimize softirq locking (especially with arbitarily long chains and
> arbitrary initialization code). We could switch to RCU lists, though...
Yes, it should be possible to do lockless ruleset evaluation (at least
on the ruleset level, some modules will still need locking).
prev parent reply other threads:[~2006-08-14 15:14 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-08-14 13:34 priv_data patch Patrick McHardy
2006-08-14 14:25 ` Joakim Axelsson
2006-08-14 14:31 ` Patrick McHardy
2006-08-14 15:20 ` Joakim Axelsson
2006-08-14 15:28 ` Patrick McHardy
2006-08-14 16:04 ` Joakim Axelsson
2006-08-14 16:13 ` Patrick McHardy
2006-08-14 16:55 ` Joakim Axelsson
2006-08-14 16:59 ` Patrick McHardy
2006-08-15 8:27 ` Amin Azez
2006-08-15 8:40 ` Joakim Axelsson
2006-08-14 15:31 ` Patrick McHardy
2006-08-14 15:40 ` Joakim Axelsson
2006-08-14 15:46 ` Patrick McHardy
2006-08-14 15:56 ` Joakim Axelsson
2006-08-14 16:01 ` Patrick McHardy
2006-08-14 16:13 ` Joakim Axelsson
2006-08-14 16:26 ` Patrick McHardy
2006-08-14 16:40 ` Joakim Axelsson
2006-08-14 16:50 ` Patrick McHardy
2006-08-14 17:11 ` Joakim Axelsson
2006-08-14 17:48 ` Patrick McHardy
2006-08-14 17:59 ` Joakim Axelsson
2006-08-14 15:53 ` Massimiliano Hofer
2006-08-14 14:40 ` Massimiliano Hofer
2006-08-14 14:48 ` Patrick McHardy
2006-08-14 14:58 ` Joakim Axelsson
2006-08-14 15:05 ` Patrick McHardy
2006-08-14 16:19 ` Massimiliano Hofer
2006-08-14 16:32 ` Joakim Axelsson
[not found] ` <200608141557.35918.max@nucleus.it>
[not found] ` <44E08AC7.2050204@trash.net>
[not found] ` <200608141702.50753.max@nucleus.it>
2006-08-14 15:14 ` Patrick McHardy [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=44E0933E.5060905@trash.net \
--to=kaber@trash.net \
--cc=max@nucleus.it \
--cc=netfilter-devel@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.