Linux Netfilter development
 help / color / mirror / Atom feed
From: Florian Westphal <fw@strlen.de>
To: Herbert Xu <herbert@gondor.apana.org.au>
Cc: netfilter-devel@vger.kernel.org, kadlec@netfilter.org,
	linux-crypto@vger.kernel.org
Subject: Re: [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper
Date: Tue, 8 Sep 2026 07:30:10 +0200	[thread overview]
Message-ID: <ap-dYotn2QqdTVqf@strlen.de> (raw)
In-Reply-To: <ap-ZOyOS6j_K5gmZ@gondor.apana.org.au>

Herbert Xu <herbert@gondor.apana.org.au> wrote:
> Florian Westphal <fw@strlen.de> wrote:
> > Will be used by upcoming ipset rhashtable conversion.
> > 
> > "walk rht with unlink+free" triggers LLM reject pattern:
> > "possible softirq CPU stall".
> > 
> > "walk rht with unlink+free + cond_resched" triggers
> > "possibly skipped elements".
> > 
> > Add a helper to detach current hash backend storage from the
> > rhashtable, then iterate and flush all contained elements.
> > 
> > Cc: herbert@gondor.apana.org.au
> > Cc: linux-crypto@vger.kernel.org
> > Link: https://sashiko.dev/#/patchset/20260828152256.8759-1-fw%40strlen.de
> > Assisted-by: Claude:claude-sonnet-5
> > Signed-off-by: Florian Westphal <fw@strlen.de>
> > ---
> > Herbert: If you prefer to take this via the crypto tree, please
> > let me know.
> > Otherwise, an explicit Ack would be appreciated, so this can
> > be handled via nf-next.  Thanks.
> > 
> > net/ipv6/ila/ could be converted to use this helper too.
> > 
> > include/linux/rhashtable.h |  19 ++++++
> > lib/rhashtable.c           | 127 +++++++++++++++++++++++++++++++++++++
> > 2 files changed, 146 insertions(+)
> 
> Sorry I wasn't paying attention.
> 
> So is the problem that there is no way to remove all elements for
> a given key in an rhltable?

No.  The problem is that I am too dumb to remove them without having
an LLM tell me to go fuck myself.

> If that is what's needed then we should just add it for rhltable
> since normal rhashtable's do not contain duplicate objects for a
> given key.

I don't understand this response.  This isn't about rhashtable vs.
rhltable.  This is about my incompetence to flush an rhashtable or
rhashtable.  Simple version:

        rhashtable_walk_enter();
        rhashtable_walk_start();

        while ((he = rhashtable_walk_next())) {
                if (IS_ERR(he)) {
                        if (PTR_ERR(he) != -EAGAIN) { ..  break; }
                        continue;
                }

		rhashtable_remove_fast()
		/* free */
        }

        rhashtable_walk_stop();
        rhashtable_walk_exit();

... tells that this causes softirq lockup for huge tables.

Adding a lock-break after N elements via
if (flushed > 64) {
	rhashtable_walk_stop();
	cond_resched();
	rhashtable_walk_start();
}

... tells that this will skip some elements.


... Full restart on atomic_read(->nelems) > 0 post loop
seems wrong to me too.

So, to get out of this I tried to add a 'flush all elements' helper to
the core that just replaces backend storage.

Does adding such a helper make sense or not?  Thats the only question
here.  If yes, I'll make a v2. If no, I will go back to V1.  Unless you
have a better idea.

  reply	other threads:[~2026-09-08  5:30 UTC|newest]

Thread overview: 28+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-04 18:53 [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29   ` Florian Westphal
2026-09-08  5:12   ` Herbert Xu
2026-09-08  5:30     ` Florian Westphal [this message]
2026-09-08  9:04       ` Herbert Xu
2026-09-08  9:56         ` Florian Westphal
2026-09-08 12:39           ` Herbert Xu
2026-09-08 13:25             ` Florian Westphal
2026-09-09  3:49               ` Herbert Xu
2026-09-09  4:17   ` Herbert Xu
2026-09-09 14:45     ` Florian Westphal
2026-09-10  9:11       ` Herbert Xu
2026-09-10 10:41         ` Florian Westphal
2026-09-11 11:56           ` Herbert Xu
2026-09-11 12:54             ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ap-dYotn2QqdTVqf@strlen.de \
    --to=fw@strlen.de \
    --cc=herbert@gondor.apana.org.au \
    --cc=kadlec@netfilter.org \
    --cc=linux-crypto@vger.kernel.org \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox