From: Florian Westphal <fw@strlen.de>
To: Herbert Xu <herbert@gondor.apana.org.au>
Cc: netfilter-devel@vger.kernel.org, kadlec@netfilter.org,
linux-crypto@vger.kernel.org
Subject: Re: [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper
Date: Tue, 8 Sep 2026 07:30:10 +0200 [thread overview]
Message-ID: <ap-dYotn2QqdTVqf@strlen.de> (raw)
In-Reply-To: <ap-ZOyOS6j_K5gmZ@gondor.apana.org.au>
Herbert Xu <herbert@gondor.apana.org.au> wrote:
> Florian Westphal <fw@strlen.de> wrote:
> > Will be used by upcoming ipset rhashtable conversion.
> >
> > "walk rht with unlink+free" triggers LLM reject pattern:
> > "possible softirq CPU stall".
> >
> > "walk rht with unlink+free + cond_resched" triggers
> > "possibly skipped elements".
> >
> > Add a helper to detach current hash backend storage from the
> > rhashtable, then iterate and flush all contained elements.
> >
> > Cc: herbert@gondor.apana.org.au
> > Cc: linux-crypto@vger.kernel.org
> > Link: https://sashiko.dev/#/patchset/20260828152256.8759-1-fw%40strlen.de
> > Assisted-by: Claude:claude-sonnet-5
> > Signed-off-by: Florian Westphal <fw@strlen.de>
> > ---
> > Herbert: If you prefer to take this via the crypto tree, please
> > let me know.
> > Otherwise, an explicit Ack would be appreciated, so this can
> > be handled via nf-next. Thanks.
> >
> > net/ipv6/ila/ could be converted to use this helper too.
> >
> > include/linux/rhashtable.h | 19 ++++++
> > lib/rhashtable.c | 127 +++++++++++++++++++++++++++++++++++++
> > 2 files changed, 146 insertions(+)
>
> Sorry I wasn't paying attention.
>
> So is the problem that there is no way to remove all elements for
> a given key in an rhltable?
No. The problem is that I am too dumb to remove them without having
an LLM tell me to go fuck myself.
> If that is what's needed then we should just add it for rhltable
> since normal rhashtable's do not contain duplicate objects for a
> given key.
I don't understand this response. This isn't about rhashtable vs.
rhltable. This is about my incompetence to flush an rhashtable or
rhashtable. Simple version:
rhashtable_walk_enter();
rhashtable_walk_start();
while ((he = rhashtable_walk_next())) {
if (IS_ERR(he)) {
if (PTR_ERR(he) != -EAGAIN) { .. break; }
continue;
}
rhashtable_remove_fast()
/* free */
}
rhashtable_walk_stop();
rhashtable_walk_exit();
... tells that this causes softirq lockup for huge tables.
Adding a lock-break after N elements via
if (flushed > 64) {
rhashtable_walk_stop();
cond_resched();
rhashtable_walk_start();
}
... tells that this will skip some elements.
... Full restart on atomic_read(->nelems) > 0 post loop
seems wrong to me too.
So, to get out of this I tried to add a 'flush all elements' helper to
the core that just replaces backend storage.
Does adding such a helper make sense or not? Thats the only question
here. If yes, I'll make a v2. If no, I will go back to V1. Unless you
have a better idea.
next prev parent reply other threads:[~2026-09-08 5:30 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 18:53 [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29 ` Florian Westphal
2026-09-08 5:12 ` Herbert Xu
2026-09-08 5:30 ` Florian Westphal [this message]
2026-09-08 9:04 ` Herbert Xu
2026-09-08 9:56 ` Florian Westphal
2026-09-08 12:39 ` Herbert Xu
2026-09-08 13:25 ` Florian Westphal
2026-09-09 3:49 ` Herbert Xu
2026-09-09 4:17 ` Herbert Xu
2026-09-09 14:45 ` Florian Westphal
2026-09-10 9:11 ` Herbert Xu
2026-09-10 10:41 ` Florian Westphal
2026-09-11 11:56 ` Herbert Xu
2026-09-11 12:54 ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ap-dYotn2QqdTVqf@strlen.de \
--to=fw@strlen.de \
--cc=herbert@gondor.apana.org.au \
--cc=kadlec@netfilter.org \
--cc=linux-crypto@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.