From: Florian Westphal <fw@strlen.de>
To: Herbert Xu <herbert@gondor.apana.org.au>
Cc: netfilter-devel@vger.kernel.org, kadlec@netfilter.org,
linux-crypto@vger.kernel.org
Subject: Re: [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper
Date: Tue, 8 Sep 2026 07:30:10 +0200 [thread overview]
Message-ID: <ap-dYotn2QqdTVqf@strlen.de> (raw)
In-Reply-To: <ap-ZOyOS6j_K5gmZ@gondor.apana.org.au>
Herbert Xu <herbert@gondor.apana.org.au> wrote:
> Florian Westphal <fw@strlen.de> wrote:
> > Will be used by upcoming ipset rhashtable conversion.
> >
> > "walk rht with unlink+free" triggers LLM reject pattern:
> > "possible softirq CPU stall".
> >
> > "walk rht with unlink+free + cond_resched" triggers
> > "possibly skipped elements".
> >
> > Add a helper to detach current hash backend storage from the
> > rhashtable, then iterate and flush all contained elements.
> >
> > Cc: herbert@gondor.apana.org.au
> > Cc: linux-crypto@vger.kernel.org
> > Link: https://sashiko.dev/#/patchset/20260828152256.8759-1-fw%40strlen.de
> > Assisted-by: Claude:claude-sonnet-5
> > Signed-off-by: Florian Westphal <fw@strlen.de>
> > ---
> > Herbert: If you prefer to take this via the crypto tree, please
> > let me know.
> > Otherwise, an explicit Ack would be appreciated, so this can
> > be handled via nf-next. Thanks.
> >
> > net/ipv6/ila/ could be converted to use this helper too.
> >
> > include/linux/rhashtable.h | 19 ++++++
> > lib/rhashtable.c | 127 +++++++++++++++++++++++++++++++++++++
> > 2 files changed, 146 insertions(+)
>
> Sorry I wasn't paying attention.
>
> So is the problem that there is no way to remove all elements for
> a given key in an rhltable?
No. The problem is that I am too dumb to remove them without having
an LLM tell me to go fuck myself.
> If that is what's needed then we should just add it for rhltable
> since normal rhashtable's do not contain duplicate objects for a
> given key.
I don't understand this response. This isn't about rhashtable vs.
rhltable. This is about my incompetence to flush an rhashtable or
rhashtable. Simple version:
rhashtable_walk_enter();
rhashtable_walk_start();
while ((he = rhashtable_walk_next())) {
if (IS_ERR(he)) {
if (PTR_ERR(he) != -EAGAIN) { .. break; }
continue;
}
rhashtable_remove_fast()
/* free */
}
rhashtable_walk_stop();
rhashtable_walk_exit();
... tells that this causes softirq lockup for huge tables.
Adding a lock-break after N elements via
if (flushed > 64) {
rhashtable_walk_stop();
cond_resched();
rhashtable_walk_start();
}
... tells that this will skip some elements.
... Full restart on atomic_read(->nelems) > 0 post loop
seems wrong to me too.
So, to get out of this I tried to add a 'flush all elements' helper to
the core that just replaces backend storage.
Does adding such a helper make sense or not? Thats the only question
here. If yes, I'll make a v2. If no, I will go back to V1. Unless you
have a better idea.
next prev parent reply other threads:[~2026-09-08 5:30 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-04 18:53 [PATCH nf-next v4 00/13] ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 01/13] rhashtable: add rhashtable_flush_and_free helper Florian Westphal
2026-09-04 19:29 ` Florian Westphal
2026-09-08 5:12 ` Herbert Xu
2026-09-08 5:30 ` Florian Westphal [this message]
2026-09-08 9:04 ` Herbert Xu
2026-09-08 9:56 ` Florian Westphal
2026-09-08 12:39 ` Herbert Xu
2026-09-08 13:25 ` Florian Westphal
2026-09-09 3:49 ` Herbert Xu
2026-09-09 4:17 ` Herbert Xu
2026-09-09 14:45 ` Florian Westphal
2026-09-10 9:11 ` Herbert Xu
2026-09-10 10:41 ` Florian Westphal
2026-09-11 11:56 ` Herbert Xu
2026-09-11 12:54 ` Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 02/13] netfilter: ipset: add rhashtable boilerplate stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 03/13] netfilter: ipset: add rhltable " Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 04/13] netfilter: ipset: replace internal hash table with rhashtable Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 05/13] netfilter: ipset: re-add forceadd support Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 06/13] netfilter: ipset: also report mem size for cidr storage to userspace Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 07/13] netfilter: ipset: remove obsolete data_next stubs Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 08/13] netfilter: ipset: remove last region lock usage Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 09/13] netfilter: ipset: remove multi-flag Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 10/13] netfilter: ipset: remove resize completely Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 11/13] netfilter: ipset: remove trivial kvfree wrapper Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 12/13] netfilter: ipset: use plain rcu_read_lock Florian Westphal
2026-09-04 18:53 ` [PATCH nf-next v4 13/13] netfilter: ipset: improve lockdep coverage Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ap-dYotn2QqdTVqf@strlen.de \
--to=fw@strlen.de \
--cc=herbert@gondor.apana.org.au \
--cc=kadlec@netfilter.org \
--cc=linux-crypto@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox