From: Patrick McHardy <kaber@trash.net>
To: Joakim Axelsson <gozem@gozem.se>
Cc: Massimiliano Hofer <max@nucleus.it>,
Netfilter Development Mailinglist
<netfilter-devel@lists.netfilter.org>
Subject: Re: priv_data patch
Date: Mon, 14 Aug 2006 17:46:59 +0200 [thread overview]
Message-ID: <44E09AF3.2080406@trash.net> (raw)
In-Reply-To: <20060814154005.GW7194@kriss.csbnet.se>
Joakim Axelsson wrote:
> 2006-08-14 17:31:18+0200, Patrick McHardy <kaber@trash.net> ->
>
>>Joakim Axelsson wrote:
>>
>>>Alot of my patches can use it. Not having todo an ugly solution trying to
>>>sneak away from being reseted when another rule is altered. I sure would
>>>like to have it added. Simpyl do not change for example -m limit into using
>>>it if it breaks the "feature" of reseting its state then altering another
>>>unrelated rule.
>>
>>I forgot to reply to this. You seem to misunderstand, limit doesn't
>>reset its state today. It will when moving private data out of the
>>structures shared with userspace. Same for all other users of this,
>>they will "forget" their state on each ruleset change.
>
>
> Okie, now I get it. This seams to have changed from 2.4 then.
No, this behaviour has been there since the beginning.
> As altering
> one unrelated rule will trigger the checkentry for _all_ rules. The code i
> posted was a (somewhat ugly) workaround for this, and yes relying on
> userspace not altering a kernel-space pointer for us. However, the case is
> the same for xt_limit with r->master = r; (and quota). Alter master in
> userspace after the limit rule has been initiated and you will get some
> really nasty result.
Thats not true, the master pointer is reinitialized on every change by
the checkentry function (which, as you note, is called on all rules for
every change). The simple reason why it keeps its current state is
because it is dumped to userspace and echoed back. If you move it out of
the structure shared with userspace, this can not happen anymore.
next prev parent reply other threads:[~2006-08-14 15:46 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-08-14 13:34 priv_data patch Patrick McHardy
2006-08-14 14:25 ` Joakim Axelsson
2006-08-14 14:31 ` Patrick McHardy
2006-08-14 15:20 ` Joakim Axelsson
2006-08-14 15:28 ` Patrick McHardy
2006-08-14 16:04 ` Joakim Axelsson
2006-08-14 16:13 ` Patrick McHardy
2006-08-14 16:55 ` Joakim Axelsson
2006-08-14 16:59 ` Patrick McHardy
2006-08-15 8:27 ` Amin Azez
2006-08-15 8:40 ` Joakim Axelsson
2006-08-14 15:31 ` Patrick McHardy
2006-08-14 15:40 ` Joakim Axelsson
2006-08-14 15:46 ` Patrick McHardy [this message]
2006-08-14 15:56 ` Joakim Axelsson
2006-08-14 16:01 ` Patrick McHardy
2006-08-14 16:13 ` Joakim Axelsson
2006-08-14 16:26 ` Patrick McHardy
2006-08-14 16:40 ` Joakim Axelsson
2006-08-14 16:50 ` Patrick McHardy
2006-08-14 17:11 ` Joakim Axelsson
2006-08-14 17:48 ` Patrick McHardy
2006-08-14 17:59 ` Joakim Axelsson
2006-08-14 15:53 ` Massimiliano Hofer
2006-08-14 14:40 ` Massimiliano Hofer
2006-08-14 14:48 ` Patrick McHardy
2006-08-14 14:58 ` Joakim Axelsson
2006-08-14 15:05 ` Patrick McHardy
2006-08-14 16:19 ` Massimiliano Hofer
2006-08-14 16:32 ` Joakim Axelsson
[not found] ` <200608141557.35918.max@nucleus.it>
[not found] ` <44E08AC7.2050204@trash.net>
[not found] ` <200608141702.50753.max@nucleus.it>
2006-08-14 15:14 ` Patrick McHardy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=44E09AF3.2080406@trash.net \
--to=kaber@trash.net \
--cc=gozem@gozem.se \
--cc=max@nucleus.it \
--cc=netfilter-devel@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.