From: Patrick McHardy <kaber@trash.net>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter-devel@vger.kernel.org, Pablo Neira Ayuso <pablo@netfilter.org>
Subject: Re: [PATCH 02/13] IP set core support
Date: Wed, 02 Feb 2011 07:45:26 +0100 [thread overview]
Message-ID: <4D48FD86.2040008@trash.net> (raw)
In-Reply-To: <4D48FC48.3000807@trash.net>
On 02.02.2011 07:40, Patrick McHardy wrote:
> On 01.02.2011 20:43, Jozsef Kadlecsik wrote:
>> On Tue, 1 Feb 2011, Patrick McHardy wrote:
>>
>>> I guess you're relying on that the original message is appended to a
>>> nlmsgerr message. That doesn't seem right though, if you want to return
>>> something to userspace, you should construct a new message.
>>
>> The message we are processing here carried multiple commands (each having
>> an attribute with the line number of the given command) and one failed
>> from some reason. We have to notify the userspace which command, at what
>> line failed. For this reason the multi-command messages have got an
>> attribute, which can be filled out with the line number - that happens
>> here. The attribute is already there, the message is not enlarged, just
>> the empty value is overwritten with the proper value.
>>
>> The line number reporting works this way, tested in the testsuite too.
>
> I'm still not really clear how this works since the message contents
> have been copied from userspace, so modifying the contents seems
> useless. I'll have a closer look at userspace to understand how this
> works.
>
>> If I had to construct a completely new message and sent it, that'd be more
>> or less the duplication of netlink_ack. Additionally I had to suppress
>> netlink from sending an errmsg/ack too.
>>
>> If one can't rely on the modifiable message and nlmsgerr, then the error
>> reporting in netlink is, hm, not really useful :-(
>
> I'm mainly not clear about how this works at all, will have a closer
> look at userspace :)
OK, it does what I expected initially, rely on the contents to be
appended to the nlmsgerr and decode that message in userspace.
It's somewhat creative use, but I guess there's nothing fundamentally
wrong doing this.
next prev parent reply other threads:[~2011-02-02 6:45 UTC|newest]
Thread overview: 47+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-01-31 22:52 [PATCH 00/13] ipset kernel patches v3 Jozsef Kadlecsik
2011-01-31 22:52 ` [PATCH 01/13] NFNL_SUBSYS_IPSET id and NLA_PUT_NET* macros Jozsef Kadlecsik
2011-01-31 22:52 ` [PATCH 02/13] IP set core support Jozsef Kadlecsik
2011-01-31 22:52 ` [PATCH 03/13] bitmap:ip set type support Jozsef Kadlecsik
2011-01-31 22:52 ` [PATCH 04/13] bitmap:ip,mac " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 05/13] bitmap:port set " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 06/13] hash:ip " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 07/13] hash:ip,port " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 08/13] hash:ip,port,ip " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 09/13] hash:ip,port,net " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 10/13] hash:net " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 11/13] hash:net,port " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 12/13] list:set " Jozsef Kadlecsik
2011-01-31 22:53 ` [PATCH 13/13] "set" match and "SET" target support Jozsef Kadlecsik
2011-02-01 14:56 ` Patrick McHardy
2011-02-01 14:55 ` [PATCH 12/13] list:set set type support Patrick McHardy
2011-02-01 14:54 ` [PATCH 11/13] hash:net,port " Patrick McHardy
2011-02-01 14:53 ` [PATCH 10/13] hash:net " Patrick McHardy
2011-02-01 14:52 ` [PATCH 09/13] hash:ip,port,net " Patrick McHardy
2011-02-01 14:42 ` [PATCH 08/13] hash:ip,port,ip " Patrick McHardy
2011-02-01 14:40 ` [PATCH 07/13] hash:ip,port " Patrick McHardy
2011-02-01 14:39 ` [PATCH 06/13] hash:ip " Patrick McHardy
2011-02-01 14:37 ` [PATCH 05/13] bitmap:port " Patrick McHardy
2011-02-01 14:36 ` [PATCH 04/13] bitmap:ip,mac " Patrick McHardy
2011-02-01 14:34 ` [PATCH 03/13] bitmap:ip set " Patrick McHardy
2011-02-01 14:31 ` [PATCH 02/13] IP set core support Patrick McHardy
2011-02-01 15:34 ` Patrick McHardy
2011-02-01 19:43 ` Jozsef Kadlecsik
2011-02-01 21:22 ` Jozsef Kadlecsik
2011-02-01 21:28 ` Jozsef Kadlecsik
2011-02-02 6:50 ` Patrick McHardy
2011-02-02 19:46 ` Jozsef Kadlecsik
2011-02-02 22:56 ` Patrick McHardy
2011-02-02 6:40 ` Patrick McHardy
2011-02-02 6:45 ` Patrick McHardy [this message]
2011-02-01 14:24 ` [PATCH 01/13] NFNL_SUBSYS_IPSET id and NLA_PUT_NET* macros Patrick McHardy
2011-02-01 14:18 ` [PATCH 00/13] ipset kernel patches v3 Patrick McHardy
2011-02-01 17:42 ` Patrick McHardy
-- strict thread matches above, loose matches on Subject: below --
2011-01-21 14:01 [PATCH 00/13] ipset kernel patches v2 Jozsef Kadlecsik
2011-01-21 14:01 ` [PATCH 01/13] NFNL_SUBSYS_IPSET id and NLA_PUT_NET* macros Jozsef Kadlecsik
2011-01-21 14:01 ` [PATCH 02/13] IP set core support Jozsef Kadlecsik
2011-01-21 21:39 ` Jozsef Kadlecsik
2011-01-25 14:47 ` Patrick McHardy
2011-01-25 21:23 ` Jozsef Kadlecsik
2011-01-26 11:57 ` Patrick McHardy
2011-01-26 11:57 ` Patrick McHardy
2011-01-25 15:06 ` Patrick McHardy
2011-01-25 21:28 ` Jozsef Kadlecsik
2011-01-27 8:58 ` Jozsef Kadlecsik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4D48FD86.2040008@trash.net \
--to=kaber@trash.net \
--cc=kadlec@blackhole.kfki.hu \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.