From: Ido Schimmel <idosch@nvidia.com>
To: Kuniyuki Iwashima <kuniyu@google.com>
Cc: Andrew Lunn <andrew+netdev@lunn.ch>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
David Ahern <dsahern@kernel.org>, Simon Horman <horms@kernel.org>,
Kuniyuki Iwashima <kuni1840@gmail.com>,
netdev@vger.kernel.org
Subject: Re: [PATCH v3 net-next 00/15] neighbour: Namespacify arp_tbl and nd_tbl.
Date: Tue, 11 Aug 2026 19:54:53 +0300 [thread overview]
Message-ID: <20260811165453.GA3163487@shredder> (raw)
In-Reply-To: <20260811022448.116235-1-kuniyu@google.com>
On Tue, Aug 11, 2026 at 02:23:34AM +0000, Kuniyuki Iwashima wrote:
> The neighbour subsystem is almost ready to drop RTNL.
>
> However, the control paths are serialised by the global
> per-table lock.
>
> This series converts arp_tbl and nd_tbl to per-netns table.
>
> Patch 1 deflakes test_neigh.sh.
>
> Patch 2 ~ 3 are misc cleanup.
>
> Patch 4 ~ 7 store arp_tbl/nd_tbl to net->neigh_tables[] and
> remove the global neigh_tables[].
>
> Patch 8 ~ 9 replace the direct access to arp_tbl/nd_tbl to
> net->neigh_tables[] using new helpers.
>
> Patch 10 ~ 12 finally replace the global table with per-netns
> table.
>
> Patch 13 ~ 14 clean up unnecessary net_eq().
>
> Patch 15 updates test_neigh.sh.
The change is good, but the cover letter should explicitly state that
this patchset introduces a behavior change with a regression potential
(as evident by patch 15).
I'm aware of at least one deployment that will most likely regress
without some changes in user space before upgrading the kernel. In this
deployment, the host has several namespaces representing different
routers with hundreds/thousands neighbours in each namespace.
Currently, they set the GC thresholds in the initial namespace so that
they are high enough for all the namespaces combined. With this
patchset, the GC thresholds in the initial namespace will no longer
affect the other namespaces and the routers will fail because the
default thresholds (128/512/1024) are too low.
I can ask them to keep doing what they are doing, but also set the
per-namespace GC thresholds. It will fail on current kernels (harmless),
but work on future ones. Similarly for the base reachable time which
currently they set in the initial namespace to the maximum among all
namespaces.
Another thing worth a discussion is the policy regarding the initial
values in each namespace. With this patchset, new namespaces all get the
same default values instead of inheriting from the initial namespace:
# sysctl net.ipv4.neigh.default.gc_thresh1
net.ipv4.neigh.default.gc_thresh1 = 128
# sysctl -wq net.ipv4.neigh.default.gc_thresh1=129
# ip netns add ns1
# ip netns exec ns1 sysctl net.ipv4.neigh.default.gc_thresh1
net.ipv4.neigh.default.gc_thresh1 = 128
Assuming that today people configure the initial namespace before
creating namespaces, changing the policy to inherit from the initial
namespace will probably result in fewer regression reports. There is a
knob that controls this policy for other settings (see
devconf_inherit_init_net).
next prev parent reply other threads:[~2026-08-11 16:55 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 2:23 [PATCH v3 net-next 00/15] neighbour: Namespacify arp_tbl and nd_tbl Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 01/15] selftest: net: Deflake Periodic GC test in test_neigh.sh Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 02/15] neighbour: Remove __neigh_for_each_release() Kuniyuki Iwashima
2026-08-11 14:27 ` David Ahern
2026-08-11 2:23 ` [PATCH v3 net-next 03/15] neighbour: Remove lock dance for neigh_update_{gc,managed}_list() Kuniyuki Iwashima
2026-08-11 14:34 ` David Ahern
2026-08-11 2:23 ` [PATCH v3 net-next 04/15] neighbour: Remove unnecessary EXPORT_SYMBOL() Kuniyuki Iwashima
2026-08-11 14:28 ` David Ahern
2026-08-11 2:23 ` [PATCH v3 net-next 05/15] neighbour: Remove __rcu from neigh_tables[] Kuniyuki Iwashima
2026-08-11 14:42 ` David Ahern
2026-08-11 2:23 ` [PATCH v3 net-next 06/15] neighbour: Store arp_tbl and nd_tbl in net->neigh_tables[] Kuniyuki Iwashima
2026-08-11 15:19 ` David Ahern
2026-08-11 16:06 ` Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 07/15] neighbour: Remove neigh_tables[] Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 08/15] ipv4: Replace &arp_tbl with arp_table(net) Kuniyuki Iwashima
2026-08-11 12:31 ` Nikolay Aleksandrov
2026-08-11 15:42 ` David Ahern
2026-08-11 16:10 ` Kuniyuki Iwashima
2026-08-11 16:25 ` David Ahern
2026-08-11 16:32 ` Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 09/15] ipv6: Replace &nd_tbl with nd_table(net) Kuniyuki Iwashima
2026-08-11 13:07 ` Nikolay Aleksandrov
2026-08-11 2:23 ` [PATCH v3 net-next 10/15] neighbour: Clean up neigh_table_init() and neigh_table_clear() Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 11/15] neighbour: Convert neigh_table.entries to refcount_t Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 12/15] neighbour: Namespacify neigh_tables Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 13/15] neighbour: Don't store net in struct pneigh_entry Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 14/15] neighbour: Remove unnecessary net_eq() Kuniyuki Iwashima
2026-08-11 2:23 ` [PATCH v3 net-next 15/15] selftest: net: Specify netns for ip ntable in test_neigh.sh Kuniyuki Iwashima
2026-08-11 16:54 ` Ido Schimmel [this message]
2026-08-11 18:39 ` [PATCH v3 net-next 00/15] neighbour: Namespacify arp_tbl and nd_tbl Kuniyuki Iwashima
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811165453.GA3163487@shredder \
--to=idosch@nvidia.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kuni1840@gmail.com \
--cc=kuniyu@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox