Linux Netfilter development
 help / color / mirror / Atom feed
From: Patrick McHardy <kaber@trash.net>
To: Pablo Neira Ayuso <pablo@netfilter.org>
Cc: Netfilter Development Mailinglist <netfilter-devel@vger.kernel.org>
Subject: Re: [PATCH 4/7] Helper modules load on-demand support for ctnetlink
Date: Thu, 31 Jul 2008 10:46:08 +0200	[thread overview]
Message-ID: <48917BD0.9050105@trash.net> (raw)
In-Reply-To: <48917974.3090304@netfilter.org>

Pablo Neira Ayuso wrote:
> Patrick McHardy wrote:
>> Pablo Neira Ayuso wrote:
>>> Sorry, it's wrong. Please, take this.
>>> @@ -1672,9 +1660,24 @@ ctnetlink_create_expect(struct nlattr *c
>>>      help = nfct_help(ct);
>>>  
>>>      if (!help || !help->helper) {
>>> -        /* such conntrack hasn't got any helper, abort */
>>> +#ifdef CONFIG_KMOD
>>> +        char *name;
>>> +
>>>          err = -EINVAL;
>>> +        if (!cda[CTA_EXPECT_HELP_NAME])
>>> +            goto out;
>>> +
>>> +        err = -ENOTSUPP;
>>> +        name = nla_data(cda[CTA_EXPECT_HELP_NAME]);
>>> +        if (request_module("nfct-helper-%s", name) < 0)
>>> +            goto out;
>>> +
>>> +        if (nf_ct_set_helper(ct, GFP_KERNEL) < 0)
>>> +            goto out;
>> This strikes me as quite inconsistent. First, we only perform
>> autoloading for expectation creation, but not for conntracks.
> 
> The module autoloading for conntracks is tricky, it's easy to add for
> the creation case, but I don't see a sane way to do this in the update
> case because of the spin lock that we hold most of the time.
> 
> The only idea that comes to my mind is to do the module load-on-demand
> in a very early stage - just after the tuple parsing in the
> new_conntrack function - but then we'll have to do another look up for
> the helper inside the change_helper function - that would make two
> invocations of find_byname() to assign the helper.
> 
> Moreover, someone may remove the module in the middle just after the
> module loading but, well, we have lost the race in the case.

I'd do something similar to qdiscs etc:

- lookup helper
- if not found: request_module, take lock again, repeat lookup, return 
EAGAIN if found now
- in the nfnetlink command handler: if ret == EAGAIN replay message

grep for "replay" in net/ for a few examples of this. This also
handles the race BTW.

>> Second, this implicit helper assignment is also a bit unusual,
>> why don't we simply insist that the conntrack has a helper
>> assigned through the ctnetlink conntrack interface?
> 
> If I understood well, then we simply assign the helper to the conntrack
> and the expectation part of ctnetlink should rely on the existing
> assigned helper, right?

Yes, I think thats cleaner.

> 
> Please, have a look at the patch attached.

Looks fine.


  reply	other threads:[~2008-07-31  8:46 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-07-30 11:03 [PATCH 4/7] Helper modules load on-demand support for ctnetlink Pablo Neira Ayuso
2008-07-30 11:10 ` Patrick McHardy
2008-07-30 11:29   ` Pablo Neira Ayuso
2008-07-30 11:33     ` Pablo Neira Ayuso
2008-07-30 13:35       ` Patrick McHardy
2008-07-31  8:36         ` Pablo Neira Ayuso
2008-07-31  8:46           ` Patrick McHardy [this message]
2008-07-31  9:44             ` Pablo Neira Ayuso
2008-07-31 17:51               ` Pablo Neira Ayuso
2008-07-31 21:27                 ` Pablo Neira Ayuso

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=48917BD0.9050105@trash.net \
    --to=kaber@trash.net \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=pablo@netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox