From mboxrd@z Thu Jan 1 00:00:00 1970 From: Jon Masters Subject: Re: [PATCH] netfilter: per netns nf_conntrack_cachep Date: Tue, 02 Feb 2010 13:16:38 -0500 Message-ID: <1265134598.2861.191.camel@tonnant> References: <1264813832.2793.446.camel@tonnant> <1265023437.2848.30.camel@edumazet-laptop> <1265035970.2848.50.camel@edumazet-laptop> <1265036548.2848.55.camel@edumazet-laptop> <1265108690.2861.118.camel@tonnant> <1265110504.2861.135.camel@tonnant> <1265129192.2861.141.camel@tonnant> <4B685756.8010107@trash.net> <1265130426.2861.158.camel@tonnant> Mime-Version: 1.0 Content-Type: text/plain Content-Transfer-Encoding: 7bit Cc: Patrick McHardy , Eric Dumazet , linux-kernel , netdev , netfilter-devel , "Paul E. McKenney" To: Alexey Dobriyan Return-path: In-Reply-To: Sender: netdev-owner@vger.kernel.org List-Id: netfilter-devel.vger.kernel.org On Tue, 2010-02-02 at 19:58 +0200, Alexey Dobriyan wrote: > Yes, moving to init_net-only function is fine. So moving the "setup up fake conntrack" bits to init_init_net from init_net still results in the panic, which means that the use count really is dropping to zero and we really are trying to free it when using multiple namespaces. Per ns is probably an easier way to go. Just for kicks, I'll have it error out on attempting to free to see if I can get this box to stay up for a while. Jon.