Re: [PATCH nf-next 1/4] netfilter: flowtable: consolidate net_device field in nft_forward_info struct
Lorenzo Bianconi <[email protected]> Sat, 25 Jul 2026 12:20:20 +0200
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <amSN5P0T6PB_ji6C@lore-desk> |
> info->indev and info->outdev refer to the same device, a single > info->dev field is sufficient. > > While at it, remove unused router parameter from the flowtable path > discovery function. > > Signed-off-by: Pablo Neira Ayuso <[email protected]> Acked-by: Lorenzo Bianconi <[email protected]> > --- > net/netfilter/nf_flow_table_path.c | 20 ++++++++------------ > 1 file changed, 8 insertions(+), 12 deletions(-) > > diff --git a/net/netfilter/nf_flow_table_path.c b/net/netfilter/nf_flow_table_path.c > index 98c03b487f52..261bb44d08eb 100644 > --- a/net/netfilter/nf_flow_table_path.c > +++ b/net/netfilter/nf_flow_table_path.c > @@ -42,8 +42,7 @@ static bool nft_is_valid_ether_device(const struct net_device *dev) > return true; > } > > -static int nft_dev_fill_forward_path(const struct nf_flow_route *route, > - const struct dst_entry *dst_cache, > +static int nft_dev_fill_forward_path(const struct dst_entry *dst_cache, > const struct nf_conn *ct, > enum ip_conntrack_dir dir, u8 *ha, > struct net_device_path_stack *stack) > @@ -76,8 +75,7 @@ static int nft_dev_fill_forward_path(const struct nf_flow_route *route, > } > > struct nft_forward_info { > - const struct net_device *indev; > - const struct net_device *outdev; > + const struct net_device *dev; > struct id { > __u16 id; > __be16 proto; > @@ -109,7 +107,7 @@ static int nft_dev_path_info(const struct net_device_path_stack *stack, > case DEV_PATH_VLAN: > case DEV_PATH_PPPOE: > case DEV_PATH_TUN: > - info->indev = path->dev; > + info->dev = path->dev; > if (is_zero_ether_addr(info->h_source)) > memcpy(info->h_source, path->dev->dev_addr, ETH_ALEN); > > @@ -179,10 +177,9 @@ static int nft_dev_path_info(const struct net_device_path_stack *stack, > return -1; > } > } > - info->outdev = info->indev; > > if (nf_flowtable_hw_offload(flowtable) && > - nft_is_valid_ether_device(info->indev)) > + nft_is_valid_ether_device(info->dev)) > info->xmit_type = FLOW_OFFLOAD_XMIT_DIRECT; > > return 0; > @@ -255,17 +252,16 @@ static int nft_dev_forward_path(const struct nft_pktinfo *pkt, > unsigned char ha[ETH_ALEN]; > int i; > > - if (nft_dev_fill_forward_path(route, dst, ct, dir, ha, &stack) < 0 || > + if (nft_dev_fill_forward_path(dst, ct, dir, ha, &stack) < 0 || > nft_dev_path_info(&stack, &info, ha, &ft->data) < 0) > return -ENOENT; > > - if (!nft_flowtable_find_dev(info.indev, ft)) > + if (!nft_flowtable_find_dev(info.dev, ft)) > return -ENOENT; > > - if (info.outdev) > - route->tuple[dir].out.ifindex = info.outdev->ifindex; > + route->tuple[!dir].in.ifindex = info.dev->ifindex; > + route->tuple[dir].out.ifindex = info.dev->ifindex; > > - route->tuple[!dir].in.ifindex = info.indev->ifindex; > for (i = 0; i < info.num_encaps; i++) { > route->tuple[!dir].in.encap[i].id = info.encap[i].id; > route->tuple[!dir].in.encap[i].proto = info.encap[i].proto; > -- > 2.47.3 >
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQTquNwa3Txd3rGGn7Y6cBh0uS2trAUCamSN5AAKCRA6cBh0uS2t rIuvAQC56LiDtKAIkWQhJZKCSmBOz08RDUaqzcUird9IL4fAmAD+MO6ve2Kcvv40 GTxamTWG05uI4WevbjfWZzHnJbnxNAY= =BVM0 -----END PGP SIGNATURE-----