From: Phil Sutter <phil@nwl.cc>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter-devel@vger.kernel.org, Florian Westphal <fw@strlen.de>,
Eric Garver <e@erig.me>
Subject: [nf-next PATCH v3 00/16] Dynamic hook interface binding
Date: Thu, 12 Sep 2024 14:21:32 +0200 [thread overview]
Message-ID: <20240912122148.12159-1-phil@nwl.cc> (raw)
Changes since v2:
- Practically complete rewrite with wildcard interface spec support
The first two patches of this series are fixes to existing code but
cause conflicts if not applied in order. They may go into nf tree as
well, though only the first one is a real bug and seems to be of low
impact.
The next three patches introduce external storing of the user-supplied
interface name in nft_hook structs to decouple code from values in
->ops.dev or ->ops value in general.
Patch 6 eliminates a quirk in netdev-family chain netdev event handler,
aligns behaviour with flowtables and paves the way for following
changes.
Patches 7-10 prepare for and implement nf_hook_ops lists in nft_hook
objects. This is crucial for wildcard interface specs and convenient
with dynamic netdev hook registration upon NETDEV_REGISTER events.
Patches 11-13 leverage the new infrastructure to correctly handle
NETDEV_REGISTER and NETDEV_CHANGENAME events.
Patch 14 prepares the code for non-NUL-terminated interface names passed
by user space which resemble prefixes to match on. As a side-effect,
hook allocation code becomes tolerant to non-matching interface specs.
The final two patches implement netlink notifications for netdev
add/remove events and add a kselftest.
Phil Sutter (16):
netfilter: nf_tables: Keep deleted flowtable hooks until after RCU
netfilter: nf_tables: Flowtable hook's pf value never varies
netfilter: nf_tables: Store user-defined hook ifname
netfilter: nf_tables: Use stored ifname in netdev hook dumps
netfilter: nf_tables: Compare netdev hooks based on stored name
netfilter: nf_tables: Tolerate chains with no remaining hooks
netfilter: nf_tables: Introduce functions freeing nft_hook objects
netfilter: nf_tables: Introduce nft_hook_find_ops()
netfilter: nf_tables: Introduce nft_register_flowtable_ops()
netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook
netfilter: nf_tables: chain: Respect NETDEV_REGISTER events
netfilter: nf_tables: flowtable: Respect NETDEV_REGISTER events
netfilter: nf_tables: Handle NETDEV_CHANGENAME events
netfilter: nf_tables: Support wildcard netdev hook specs
netfilter: nf_tables: Add notications for hook changes
selftests: netfilter: Torture nftables netdev hooks
include/linux/netfilter.h | 2 +
include/net/netfilter/nf_tables.h | 11 +-
include/uapi/linux/netfilter/nf_tables.h | 5 +
net/netfilter/nf_tables_api.c | 386 +++++++++++++-----
net/netfilter/nf_tables_offload.c | 51 ++-
net/netfilter/nft_chain_filter.c | 64 +--
net/netfilter/nft_flow_offload.c | 2 +-
.../testing/selftests/net/netfilter/Makefile | 1 +
.../net/netfilter/nft_interface_stress.sh | 149 +++++++
9 files changed, 508 insertions(+), 163 deletions(-)
create mode 100755 tools/testing/selftests/net/netfilter/nft_interface_stress.sh
--
2.43.0
next reply other threads:[~2024-09-12 12:22 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-12 12:21 Phil Sutter [this message]
2024-09-12 12:21 ` [nf-next PATCH v3 01/16] netfilter: nf_tables: Keep deleted flowtable hooks until after RCU Phil Sutter
2024-09-12 13:32 ` Florian Westphal
2024-09-12 13:48 ` Phil Sutter
2024-09-12 14:27 ` Florian Westphal
2024-09-16 0:00 ` Pablo Neira Ayuso
2024-09-16 21:42 ` Pablo Neira Ayuso
2024-09-17 21:14 ` Pablo Neira Ayuso
2024-09-12 12:21 ` [nf-next PATCH v3 02/16] netfilter: nf_tables: Flowtable hook's pf value never varies Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 03/16] netfilter: nf_tables: Store user-defined hook ifname Phil Sutter
2024-09-12 12:56 ` Florian Westphal
2024-09-12 13:26 ` Phil Sutter
2024-09-12 13:38 ` Florian Westphal
2024-09-12 12:21 ` [nf-next PATCH v3 04/16] netfilter: nf_tables: Use stored ifname in netdev hook dumps Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 05/16] netfilter: nf_tables: Compare netdev hooks based on stored name Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 06/16] netfilter: nf_tables: Tolerate chains with no remaining hooks Phil Sutter
2024-10-31 14:01 ` Florian Westphal
2024-10-31 14:19 ` Phil Sutter
2024-10-31 14:37 ` Florian Westphal
2024-10-31 15:16 ` Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 07/16] netfilter: nf_tables: Introduce functions freeing nft_hook objects Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 08/16] netfilter: nf_tables: Introduce nft_hook_find_ops() Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 09/16] netfilter: nf_tables: Introduce nft_register_flowtable_ops() Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 10/16] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 11/16] netfilter: nf_tables: chain: Respect NETDEV_REGISTER events Phil Sutter
2024-09-12 14:40 ` Florian Westphal
2024-09-12 15:05 ` Phil Sutter
2024-09-12 15:12 ` Florian Westphal
2024-09-12 15:41 ` Phil Sutter
2024-09-12 16:06 ` Florian Westphal
2024-09-12 16:25 ` Phil Sutter
2024-09-12 20:43 ` Florian Westphal
2024-09-13 11:42 ` Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 12/16] netfilter: nf_tables: flowtable: " Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 13/16] netfilter: nf_tables: Handle NETDEV_CHANGENAME events Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 14/16] netfilter: nf_tables: Support wildcard netdev hook specs Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 15/16] netfilter: nf_tables: Add notications for hook changes Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 16/16] selftests: netfilter: Torture nftables netdev hooks Phil Sutter
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240912122148.12159-1-phil@nwl.cc \
--to=phil@nwl.cc \
--cc=e@erig.me \
--cc=fw@strlen.de \
--cc=netfilter-devel@vger.kernel.org \
--cc=pablo@netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox