Linux Netfilter development
 help / color / mirror / Atom feed
From: Phil Sutter <phil@nwl.cc>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: netfilter-devel@vger.kernel.org, Florian Westphal <fw@strlen.de>,
	Eric Garver <e@erig.me>
Subject: [nf-next PATCH v3 06/16] netfilter: nf_tables: Tolerate chains with no remaining hooks
Date: Thu, 12 Sep 2024 14:21:38 +0200	[thread overview]
Message-ID: <20240912122148.12159-7-phil@nwl.cc> (raw)
In-Reply-To: <20240912122148.12159-1-phil@nwl.cc>

Do not drop a netdev-family chain if the last interface it is registered
for vanishes. Users dumping and storing the ruleset upon shutdown for
restore upon next boot may otherwise lose the chain and all contained
rules. They will still lose the list of devices, a later patch will fix
that. For now, this aligns the event handler's behaviour with that for
flowtables.
The controversal situation at netns exit should be no problem here:
event handler will unregister the hooks, core nftables cleanup code will
drop the chain itself.

Signed-off-by: Phil Sutter <phil@nwl.cc>
---
 include/net/netfilter/nf_tables.h |  2 --
 net/netfilter/nf_tables_api.c     | 21 ---------------------
 net/netfilter/nft_chain_filter.c  | 29 +++++++----------------------
 3 files changed, 7 insertions(+), 45 deletions(-)

diff --git a/include/net/netfilter/nf_tables.h b/include/net/netfilter/nf_tables.h
index efd6b55b4914..16daffcee0e1 100644
--- a/include/net/netfilter/nf_tables.h
+++ b/include/net/netfilter/nf_tables.h
@@ -1228,8 +1228,6 @@ static inline bool nft_is_base_chain(const struct nft_chain *chain)
 	return chain->flags & NFT_CHAIN_BASE;
 }
 
-int __nft_release_basechain(struct nft_ctx *ctx);
-
 unsigned int nft_do_chain(struct nft_pktinfo *pkt, void *priv);
 
 static inline bool nft_use_inc(u32 *use)
diff --git a/net/netfilter/nf_tables_api.c b/net/netfilter/nf_tables_api.c
index 457696f55003..46d4e9056bf1 100644
--- a/net/netfilter/nf_tables_api.c
+++ b/net/netfilter/nf_tables_api.c
@@ -11386,27 +11386,6 @@ int nft_data_dump(struct sk_buff *skb, int attr, const struct nft_data *data,
 }
 EXPORT_SYMBOL_GPL(nft_data_dump);
 
-int __nft_release_basechain(struct nft_ctx *ctx)
-{
-	struct nft_rule *rule, *nr;
-
-	if (WARN_ON(!nft_is_base_chain(ctx->chain)))
-		return 0;
-
-	nf_tables_unregister_hook(ctx->net, ctx->chain->table, ctx->chain);
-	list_for_each_entry_safe(rule, nr, &ctx->chain->rules, list) {
-		list_del(&rule->list);
-		nft_use_dec(&ctx->chain->use);
-		nf_tables_rule_release(ctx, rule);
-	}
-	nft_chain_del(ctx->chain);
-	nft_use_dec(&ctx->table->use);
-	nf_tables_chain_destroy(ctx->chain);
-
-	return 0;
-}
-EXPORT_SYMBOL_GPL(__nft_release_basechain);
-
 static void __nft_release_hook(struct net *net, struct nft_table *table)
 {
 	struct nft_flowtable *flowtable;
diff --git a/net/netfilter/nft_chain_filter.c b/net/netfilter/nft_chain_filter.c
index 7010541fcca6..543f258b7c6b 100644
--- a/net/netfilter/nft_chain_filter.c
+++ b/net/netfilter/nft_chain_filter.c
@@ -322,34 +322,19 @@ static void nft_netdev_event(unsigned long event, struct net_device *dev,
 			     struct nft_ctx *ctx)
 {
 	struct nft_base_chain *basechain = nft_base_chain(ctx->chain);
-	struct nft_hook *hook, *found = NULL;
-	int n = 0;
+	struct nft_hook *hook;
 
 	list_for_each_entry(hook, &basechain->hook_list, list) {
-		if (hook->ops.dev == dev)
-			found = hook;
-
-		n++;
-	}
-	if (!found)
-		return;
+		if (hook->ops.dev != dev)
+			continue;
 
-	if (n > 1) {
 		if (!(ctx->chain->table->flags & NFT_TABLE_F_DORMANT))
-			nf_unregister_net_hook(ctx->net, &found->ops);
+			nf_unregister_net_hook(ctx->net, &hook->ops);
 
-		list_del_rcu(&found->list);
-		kfree_rcu(found, rcu);
-		return;
+		list_del_rcu(&hook->list);
+		kfree_rcu(hook, rcu);
+		break;
 	}
-
-	/* UNREGISTER events are also happening on netns exit.
-	 *
-	 * Although nf_tables core releases all tables/chains, only this event
-	 * handler provides guarantee that hook->ops.dev is still accessible,
-	 * so we cannot skip exiting net namespaces.
-	 */
-	__nft_release_basechain(ctx);
 }
 
 static int nf_tables_netdev_event(struct notifier_block *this,
-- 
2.43.0


  parent reply	other threads:[~2024-09-12 12:45 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-09-12 12:21 [nf-next PATCH v3 00/16] Dynamic hook interface binding Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 01/16] netfilter: nf_tables: Keep deleted flowtable hooks until after RCU Phil Sutter
2024-09-12 13:32   ` Florian Westphal
2024-09-12 13:48     ` Phil Sutter
2024-09-12 14:27       ` Florian Westphal
2024-09-16  0:00     ` Pablo Neira Ayuso
2024-09-16 21:42       ` Pablo Neira Ayuso
2024-09-17 21:14   ` Pablo Neira Ayuso
2024-09-12 12:21 ` [nf-next PATCH v3 02/16] netfilter: nf_tables: Flowtable hook's pf value never varies Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 03/16] netfilter: nf_tables: Store user-defined hook ifname Phil Sutter
2024-09-12 12:56   ` Florian Westphal
2024-09-12 13:26     ` Phil Sutter
2024-09-12 13:38       ` Florian Westphal
2024-09-12 12:21 ` [nf-next PATCH v3 04/16] netfilter: nf_tables: Use stored ifname in netdev hook dumps Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 05/16] netfilter: nf_tables: Compare netdev hooks based on stored name Phil Sutter
2024-09-12 12:21 ` Phil Sutter [this message]
2024-10-31 14:01   ` [nf-next PATCH v3 06/16] netfilter: nf_tables: Tolerate chains with no remaining hooks Florian Westphal
2024-10-31 14:19     ` Phil Sutter
2024-10-31 14:37       ` Florian Westphal
2024-10-31 15:16         ` Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 07/16] netfilter: nf_tables: Introduce functions freeing nft_hook objects Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 08/16] netfilter: nf_tables: Introduce nft_hook_find_ops() Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 09/16] netfilter: nf_tables: Introduce nft_register_flowtable_ops() Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 10/16] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 11/16] netfilter: nf_tables: chain: Respect NETDEV_REGISTER events Phil Sutter
2024-09-12 14:40   ` Florian Westphal
2024-09-12 15:05     ` Phil Sutter
2024-09-12 15:12       ` Florian Westphal
2024-09-12 15:41         ` Phil Sutter
2024-09-12 16:06           ` Florian Westphal
2024-09-12 16:25             ` Phil Sutter
2024-09-12 20:43               ` Florian Westphal
2024-09-13 11:42                 ` Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 12/16] netfilter: nf_tables: flowtable: " Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 13/16] netfilter: nf_tables: Handle NETDEV_CHANGENAME events Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 14/16] netfilter: nf_tables: Support wildcard netdev hook specs Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 15/16] netfilter: nf_tables: Add notications for hook changes Phil Sutter
2024-09-12 12:21 ` [nf-next PATCH v3 16/16] selftests: netfilter: Torture nftables netdev hooks Phil Sutter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240912122148.12159-7-phil@nwl.cc \
    --to=phil@nwl.cc \
    --cc=e@erig.me \
    --cc=fw@strlen.de \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pablo@netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox