From: Pablo Neira Ayuso <pablo@netfilter.org>
To: Ken-ichirou MATSUZAWA <chamaken@gmail.com>
Cc: netfilter-devel@vger.kernel.org
Subject: Re: [PATCHv2 nf-next 1/1] netfilter: nfnetlink_queue: check NFQA_CFG_F_CONNTRACK config flag
Date: Tue, 6 Oct 2015 12:07:28 +0200 [thread overview]
Message-ID: <20151006100728.GA2429@salvia> (raw)
In-Reply-To: <20151006021246.GB30037@gmail.com>
On Tue, Oct 06, 2015 at 11:12:46AM +0900, Ken-ichirou MATSUZAWA wrote:
> This patch enables to check GLUE_CT is enabled or not when
> NFQA_CFG_F_CONNTRACK config flag is received. And try to load
> nf_conntrack_netlink module, and l3proto module if family is
> specified. Then returns error either case is failed.
>
> Signed-off-by: Ken-ichirou MATSUZAWA <chamas@h4.dion.ne.jp>
> ---
> net/netfilter/nfnetlink_queue.c | 19 +++++++++++++++++++
> 1 file changed, 19 insertions(+)
>
> diff --git a/net/netfilter/nfnetlink_queue.c b/net/netfilter/nfnetlink_queue.c
> index a659e57..99c9c8c 100644
> --- a/net/netfilter/nfnetlink_queue.c
> +++ b/net/netfilter/nfnetlink_queue.c
> @@ -34,6 +34,7 @@
> #include <net/tcp_states.h>
> #include <net/netfilter/nf_queue.h>
> #include <net/netns/generic.h>
> +#include <net/netfilter/nf_conntrack.h>
>
> #include <linux/atomic.h>
>
> @@ -1225,6 +1226,24 @@ nfqnl_recv_config(struct sock *ctnl, struct sk_buff *skb,
> goto err_out_unlock;
> }
> #endif
> + if (flags & mask & NFQA_CFG_F_CONNTRACK) {
> + if (!rcu_access_pointer(nfnl_ct_hook))
> +#ifdef CONFIG_MODULES
> + if (request_module("ip_conntrack_netlink") ||
nfnl_lock is held while requesting a module, which is something that
we should avoid. Please, abort the operation and return -EAGAIN to
retry, this is the usual procedure when requesting other modules.
> + !rcu_access_pointer(nfnl_ct_hook))
> +#endif
> + {
> + ret = -EOPNOTSUPP;
> + goto err_out_unlock;
> + }
> +
> + if (nfmsg->nfgen_family &&
> + nf_ct_l3proto_try_module_get(nfmsg->nfgen_family)) {
> + ret = -EPROTONOSUPPORT;
> + goto err_out_unlock;
I think this chunk belongs to nf_conntrack_netlink, the
nf_conntrack_{ipv4,ipv6} modules gets loaded when the user tries to
create a conntrack/expectation.
Otherwise we create a hard dependency between nfnetlink_queue and
nf_conntrack, which is what we're trying to avoid ;-)
> + }
> + }
> +
> spin_lock_bh(&queue->lock);
> queue->flags &= ~mask;
> queue->flags |= flags & mask;
> --
> 1.7.10.4
>
next prev parent reply other threads:[~2015-10-06 10:00 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-10-01 18:43 [PATCH 1/2 v3] netfilter: nfnetlink_queue: get rid of nfnetlink_queue_ct.c Pablo Neira Ayuso
2015-10-01 18:43 ` [PATCH 2/2 v3] netfilter: rename nfnetlink_queue_core.c to nfnetlink_queue.c Pablo Neira Ayuso
2015-10-05 2:44 ` [PATCHv2 nf-next 0/4] netfilter: nfnetlink_log attach conntrack information Ken-ichirou MATSUZAWA
2015-10-05 2:47 ` [PATCHv2 nf-next 1/4] netfilter: nfnetlink_queue: rename related to nfqueue attaching conntrack info Ken-ichirou MATSUZAWA
2015-10-05 2:48 ` [PATCHv2 nf-next 2/4] netfilter: Kconfig rename QUEUE_CT to GLUE_CT Ken-ichirou MATSUZAWA
2015-10-05 2:49 ` [PATCHv2 nf-next 3/4] netfilter: nf_conntrack_netlink: add const qualifier to nfnl_hook.get_ct Ken-ichirou MATSUZAWA
2015-10-05 2:50 ` [PATCHv2 nf-next 4/4] netfilter: nfnetlink_log: allow to attach conntrack Ken-ichirou MATSUZAWA
2015-10-05 15:23 ` Pablo Neira Ayuso
2015-10-06 2:10 ` [PATCHv2 nf-next 0/1] netfilter: nfnetlink_queue: check NFQA_CFG_F_CONNTRACK config flag Ken-ichirou MATSUZAWA
2015-10-06 2:12 ` [PATCHv2 nf-next 1/1] " Ken-ichirou MATSUZAWA
2015-10-06 10:07 ` Pablo Neira Ayuso [this message]
2015-10-07 4:20 ` Ken-ichirou MATSUZAWA
2015-10-07 4:23 ` [PATCHv3 nf-next] " Ken-ichirou MATSUZAWA
2015-10-07 4:25 ` [PATCH nf-next] netfilter: nfnetlink_log: autoload nf_conntrack_netlink module " Ken-ichirou MATSUZAWA
2015-10-12 17:13 ` Pablo Neira Ayuso
2015-10-12 20:10 ` Pablo Neira Ayuso
2015-10-16 17:05 ` Pablo Neira Ayuso
2015-11-06 0:46 ` Ken-ichirou MATSUZAWA
2015-11-06 0:49 ` [PATCH nf-next 1/3] netfilter: nfnetlink_queue: remove duplicated obsolete commands handling Ken-ichirou MATSUZAWA
2015-11-08 22:14 ` Pablo Neira Ayuso
2016-01-05 0:24 ` Ken-ichirou MATSUZAWA
2016-01-05 0:28 ` [PATCH nf-next 1/5] netfilter: nfnetlink_queue: validate dependencies to avoid breaking atomicity Ken-ichirou MATSUZAWA
2016-01-05 0:29 ` [PATCH nf-next 2/5] netfilter: nfnetlink_queue: not handle options after unbind Ken-ichirou MATSUZAWA
2016-01-05 0:31 ` [PATCH nf-next 3/5] netfilter: nfnetlink_queue: just returns error for unknown command Ken-ichirou MATSUZAWA
2016-01-05 0:32 ` [PATCH nf-next 4/5] netfilter: nfnetlink_queue: autoload nf_conntrack_netlink module NFQA_CFG_F_CONNTRACK config flag Ken-ichirou MATSUZAWA
2016-01-05 0:34 ` [PATCH nf-next 5/5] netfilter: nfnetlink_log: just returns error for unknown command Ken-ichirou MATSUZAWA
2016-01-05 11:03 ` Pablo Neira Ayuso
2015-11-06 0:56 ` [PATCH nf-next 2/3] netfilter: nfnetlink_queue: validate dependencies to avoid breaking atomicity Ken-ichirou MATSUZAWA
2015-11-06 0:58 ` [PATCH nf-next 3/3] netfilter: nfnetlink_queue: autoload nf_conntrack_netlink module NFQA_CFG_F_CONNTRACK config flag Ken-ichirou MATSUZAWA
2015-10-07 4:27 ` [PATCH nf-next] netfilter: nf_conntrack_netlink: fix nf-nat module loaded checking Ken-ichirou MATSUZAWA
2015-10-07 4:30 ` [PATCH nf-next] netfilter: nf_conntrack_netlink: fix locks around helper module loading Ken-ichirou MATSUZAWA
2015-10-05 15:33 ` [PATCHv2 nf-next 0/4] netfilter: nfnetlink_log attach conntrack information Pablo Neira Ayuso
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20151006100728.GA2429@salvia \
--to=pablo@netfilter.org \
--cc=chamaken@gmail.com \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox