From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Florian Westphal <fw@strlen.de>
Cc: netfilter-devel@vger.kernel.org
Subject: Re: [PATCH v2 nf-next 0/7] netfilter: nf_tables: avoid PROVE_RCU_LIST splats
Date: Fri, 1 Nov 2024 08:31:47 +0100 [thread overview]
Message-ID: <ZySD48GBsbxTqUnh@calendula> (raw)
In-Reply-To: <20241031233742.GA8050@breakpoint.cc>
Hi Florian,
On Fri, Nov 01, 2024 at 12:37:42AM +0100, Florian Westphal wrote:
> Pablo Neira Ayuso <pablo@netfilter.org> wrote:
> > On Fri, Nov 01, 2024 at 12:02:14AM +0100, Florian Westphal wrote:
> > > Pablo Neira Ayuso <pablo@netfilter.org> wrote:
> > > > # nft -f test.nft
> > > > test.nft:3:32-45: Error: Could not process rule: Operation not supported
> > > > udp dport 4789 vxlan ip saddr 1.2.3.4
> > > > ^^^^^^^^^^^^^^
> > > >g
> > > > Reverting "netfilter: nf_tables: must hold rcu read lock while iterating expression type list"
> > > > makes it work for me again.
> > > >g
> > > > Are you compiling nf_tables built-in there? I make as a module, the
> > > > type->owner is THIS_MODULE which refers to nf_tables.ko?
> > >g
> > > Indeed, this doesn't work.
> > >g
> > > But I cannot remove this test, this code looks broken to me in case
> > > inner type is its own module.
> > >g
> > > No idea yet how to fix this.
> >g
> > I'm missing why this check is required by now.
> >g
> > Only meta and payload provide inner_ops and they are always built-in.
> >g
> > I understand this is an issue if more expressions are supported in the
> > future.
>g
> Can you mangle the patch to remove the type->owner test and amend
> the comment to say that this restriction exists (inner_ops != NULL ->
> builtin?)
>g
> Else this might work:
>g
> + if (!type->inner_ops || type->owner != THIS_MODULE) {
>g
> ... but that would also need a comment, I think :-/
IUC, your concern is future extensibility.
To support for extensions other than meta and payload, this code will
need to be updated anyway, because __nft_expr_type_get() is used and
that cannot autoload modules:
type = __nft_expr_type_get(ctx->family, tb[NFTA_EXPR_NAME]);
if (!type)g
return -ENOENT;
if (!type->inner_ops)
return -EOPNOTSUPP;
I think removing it by now is just fine.
If you prefer the defensive approach, the an explicit check for meta
and payload ops is perfectly fine, but I don't think that is needed.
There is another issue that is spotted by smack which needs to be
addressed in this series anyway, this needs a v3.
Thanks Florian.
prev parent reply other threads:[~2024-11-01 7:31 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-10-30 9:40 [PATCH v2 nf-next 0/7] netfilter: nf_tables: avoid PROVE_RCU_LIST splats Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 1/7] netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 2/7] netfilter: nf_tables: avoid false-positive lockdep splats with sets Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 3/7] netfilter: nf_tables: avoid false-positive lockdep splats with flowtables Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 4/7] netfilter: nf_tables: avoid false-positive lockdep splats in set walker Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 5/7] netfilter: nf_tables: avoid false-positive lockdep splats with basechain hook Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 6/7] netfilter: nf_tables: must hold rcu read lock while iterating expression type list Florian Westphal
2024-10-30 9:40 ` [PATCH v2 nf-next 7/7] netfilter: nf_tables: must hold rcu read lock while iterating object " Florian Westphal
2024-11-01 7:07 ` Dan Carpenter
2024-10-30 10:40 ` [PATCH v2 nf-next 0/7] netfilter: nf_tables: avoid PROVE_RCU_LIST splats Pablo Neira Ayuso
2024-10-31 21:48 ` Pablo Neira Ayuso
2024-10-31 21:56 ` Florian Westphal
2024-10-31 21:59 ` Pablo Neira Ayuso
2024-10-31 22:42 ` Pablo Neira Ayuso
2024-10-31 23:02 ` Florian Westphal
2024-10-31 23:22 ` Florian Westphal
2024-10-31 23:28 ` Pablo Neira Ayuso
2024-10-31 23:25 ` Pablo Neira Ayuso
2024-10-31 23:37 ` Florian Westphal
2024-11-01 7:31 ` Pablo Neira Ayuso [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZySD48GBsbxTqUnh@calendula \
--to=pablo@netfilter.org \
--cc=fw@strlen.de \
--cc=g@calendula \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.