[PATCH 1/2 nf-next] netfilter: seqadj: do not take ct lock if seqadj is NULL
Fernando Fernandez Mancera <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <[email protected]> |
This is a small optimization, only take ct lock if seqadj is present. In the unlikely case seqadj isn't present we can return immediately. This is consistent with the behavior of other functions that checks seqadj. Signed-off-by: Fernando Fernandez Mancera <[email protected]> --- net/netfilter/nf_conntrack_seqadj.c | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/net/netfilter/nf_conntrack_seqadj.c b/net/netfilter/nf_conntrack_seqadj.c index 220216a4edc5..d75e8dafb189 100644 --- a/net/netfilter/nf_conntrack_seqadj.c +++ b/net/netfilter/nf_conntrack_seqadj.c @@ -10,20 +10,19 @@ int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo, s32 off) { + struct nf_conn_seqadj *seqadj = nfct_seqadj(ct); enum ip_conntrack_dir dir = CTINFO2DIR(ctinfo); - struct nf_conn_seqadj *seqadj; struct nf_ct_seqadj *this_way; if (off == 0) return 0; - spin_lock_bh(&ct->lock); - seqadj = nfct_seqadj(ct); - if (!seqadj) { - spin_unlock_bh(&ct->lock); + if (unlikely(!seqadj)) return 0; - } + set_bit(IPS_SEQ_ADJUST_BIT, &ct->status); + + spin_lock_bh(&ct->lock); this_way = &seqadj->seq[dir]; this_way->offset_before = off; this_way->offset_after = off; -- 2.55.0