From: Oliver <oliver@8.c.9.b.0.7.4.0.1.0.0.2.ip6.arpa>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter-devel@vger.kernel.org
Subject: Re: [PATCH 1/2] netfilter: ipset: Add hash:net,net module to kernel.
Date: Fri, 20 Sep 2013 09:10:12 +0200 [thread overview]
Message-ID: <3633622.RvhfsYxaem@gentoovm> (raw)
In-Reply-To: <alpine.DEB.2.00.1309192042050.24965@blackhole.kfki.hu>
On Thursday 19 September 2013 20:58:23 Jozsef Kadlecsik wrote:
> On Thu, 19 Sep 2013, Oliver wrote:
> > On Thursday 19 September 2013 11:30:50 Jozsef Kadlecsik wrote:
> > > On Thu, 19 Sep 2013, Oliver wrote:
> > > > > On Tue, 17 Sep 2013, Oliver wrote:
> > > > <snip>
> > > >
> > > > > > @@ -461,6 +462,9 @@ mtype_expire(struct ip_set *set, struct htype
> > > > > > *h,
> > > > > > u8
> > > > > > nets_length, size_t dsize)>
> > > > > >
> > > > > > struct mtype_elem *data;
> > > > > > u32 i;
> > > > > > int j;
> > > > > >
> > > > > > +#if IPSET_NET_COUNT > 1
> > > > > > + u8 k;
> > > > > > +#endif
> > > > >
> > > > > Please get rid of all these #if .. [#else ...] #endif constructions,
> > > > > except in mtype_test_cidrs. The compiler optimizes away the for loop
> > > > > when
> > > > > IPSET_NET_COUNT == 1.
> > > >
> > > > Yep, there's a couple of other places where I don't currently see a
> > > > way
> > > > around it, but anywhere that it doesn't pose a logical problem to
> > > > existing types, I've removed it.
> > >
> > > Where do you think it's required, except in mtype_test_cidrs?
> >
> > Well actually, I've come to the realisation that it's actually required
> > pretty much everywhere that I placed it because of the simple reason
> > that in the existing hash types, data->cidr is not a u8 array, but it is
> > in hash:net,net obviously.
>
> Yes, you are quite right, I was blind.
>
> > So now either we can convert all the existing hash types so that the
> > cidr member of their struct is a single-element array, or we keep the
> > preprocessor conditions, your choice.
>
> I don't really like either of them... What about tweaking the CIDR macro,
> into something like this:
>
> #ifdef IP_SET_HASH_WITH_NETS
> #if IPSET_NET_COUNT > 1
> #define __CIDR(data, i) ((data)->cidr[i])
> #else
> #define __CIDR(data, i) ((data)->cidr)
> #endif
> #ifdef IP_SET_HASH_WITH_NETS_PACKED
> /* When cidr is packed with nomatch, cidr - 1 is stored in the entry */
> #define CIDR(data, i) (__CIDR(data, i) + 1)
> #else
> #define CIDR(data, i) __CIDR(data, i)
> #endif
> #endif
>
> What do you think?
Yeah, that works for me.
I simplified __CIDR for multiple nets to just the following:
#define __CIDR(cidr, i) (cidr[i])
So the changes to the rest of the code are pretty minimal :)
I'll patch-bomb the mailing list shortly.
Kind Regards,
Oliver.
next prev parent reply other threads:[~2013-09-20 7:10 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2013-09-17 12:26 [PATCH 0/2] Add new hash:net,net type to ipset Oliver
2013-09-17 12:26 ` [PATCH 1/2] netfilter: ipset: Add hash:net,net module to kernel Oliver
2013-09-18 17:23 ` Jozsef Kadlecsik
2013-09-19 9:13 ` Oliver
2013-09-19 9:30 ` Jozsef Kadlecsik
2013-09-19 15:00 ` Oliver
2013-09-19 18:58 ` Jozsef Kadlecsik
2013-09-20 7:10 ` Oliver [this message]
2013-09-17 12:26 ` [PATCH 2/2] ipset: Add userspace code to support hash:net,net kernel module Oliver
2013-09-18 17:26 ` Jozsef Kadlecsik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=3633622.RvhfsYxaem@gentoovm \
--to=oliver@8.c.9.b.0.7.4.0.1.0.0.2.ip6.arpa \
--cc=kadlec@blackhole.kfki.hu \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox