From: Ali Firas <alishmery18@gmail.com>
To: pabeni@redhat.com, netdev@vger.kernel.org, idosch@nvidia.com
Cc: kuba@kernel.org, davem@davemloft.net, edumazet@google.com,
andrew+netdev@lunn.ch, horms@kernel.org, razor@blackwall.org,
roopa@nvidia.com, shuah@kernel.org,
linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH net-next v3 0/6] vxlan: vnifilter: bound a single request and account per-VNI memory
Date: Wed, 7 Oct 2026 07:54:34 +0300 [thread overview]
Message-ID: <20261007045434.499651-1-alishmery18@gmail.com> (raw)
In-Reply-To: <7913b40f-f7d2-41ec-acb2-1edc7f2b833c@redhat.com>
On 10/1/26 13:45, Paolo Abeni wrote:
> Sashiko complain WRT partial accounting of patch 5/6 looks legit.
Agreed. A VNI that carries a remote also creates an FDB entry, an rdst
and a per-CPU dst cache, none of them accounted. v4 accounts those
allocations on the vnifilter path, passing gfp down rather than flipping
the shared helper, so the learning path keeps plain GFP_ATOMIC.
> Also it would make sense to reword a bit the commit message of patch 1 and
> 2 to reflect the above.
Will do.
v4 will also bound the dump per nlmsg rather than per entry, per
Sashiko's note on patch 4: a device holding 8192 contiguous VNIs can
still dump as one message that replay refuses.
On the Fixes: tag asked for on patch 2 -- Jakub asked for net-next
without one, so I am not adding it:
https://lore.kernel.org/netdev/20260921150904.65a704eb@kernel.org/
pw-bot: cr
prev parent reply other threads:[~2026-10-07 4:55 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-27 21:52 [PATCH net-next v3 0/6] vxlan: vnifilter: bound a single request and account per-VNI memory Ali Firas
2026-09-27 21:52 ` [PATCH net-next v3 1/6] vxlan: vnifilter: validate the VXLAN_VNIFILTER_ENTRY nest Ali Firas
2026-09-30 3:52 ` netdev-bot+sashiko
2026-09-27 21:52 ` [PATCH net-next v3 2/6] vxlan: vnifilter: reject VNIs outside the 24-bit space Ali Firas
2026-09-30 3:52 ` netdev-bot+sashiko
2026-09-27 21:52 ` [PATCH net-next v3 3/6] vxlan: vnifilter: bound the number of VNIs one request may touch Ali Firas
2026-09-30 3:52 ` netdev-bot+sashiko
2026-09-27 21:52 ` [PATCH net-next v3 4/6] vxlan: vnifilter: clamp the dumped VNI range to the request limit Ali Firas
2026-09-30 3:52 ` netdev-bot+sashiko
2026-09-27 21:52 ` [PATCH net-next v3 5/6] vxlan: vnifilter: account per-VNI memory to memcg Ali Firas
2026-09-30 3:52 ` netdev-bot+sashiko
2026-09-27 21:52 ` [PATCH net-next v3 6/6] selftests: net: test the vxlan vnifilter request limit and dump replay Ali Firas
2026-09-30 3:52 ` netdev-bot+sashiko
2026-10-01 11:45 ` [PATCH net-next v3 0/6] vxlan: vnifilter: bound a single request and account per-VNI memory Paolo Abeni
2026-10-07 4:54 ` Ali Firas [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007045434.499651-1-alishmery18@gmail.com \
--to=alishmery18@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=razor@blackwall.org \
--cc=roopa@nvidia.com \
--cc=shuah@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox