[PATCH nf 0/5] netfilter: ipset: rhashtable conversion

Florian Westphal <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <[email protected]>
This series contains the initial rhashtable conversion. I elided
several followup commits that remove dead code, e.g. the region locking
or the resize callback, this will be sent later as a followup.

1) Add rhashtable boilerplate stubs to netfilter ipset. Implement rhashtable
initialization and destruction.

2) Add rhltable boilerplate stubs to Netfilter IPSet. Prepare switching from
rhashtable for sets sharing hash keys.

3) Replace ipset internal hash tables with rhashtables. Introduce
RHL_MAX_CHAINLEN to explicitly bound chain length. Keep automatic
rhashtable shrinking disabled to prevent errors during set dumping.

4) Restore SET_WITH_FORCEADD eviction logic in ipset. Add
mtype_remove_random() helper to identify key slots for eviction.

5) Report CIDR storage memory size to userspace, including dynamic allocation.

Florian Westphal (5):
  netfilter: ipset: add rhashtable boilerplate stubs
  netfilter: ipset: add rhltable boilerplate stubs
  netfilter: ipset: replace internal hash table with rhashtable
  netfilter: ipset: re-add forceadd support
  netfilter: ipset: also report mem size for cidr storage to userspace

 net/netfilter/ipset/ip_set_hash_gen.h      | 1618 ++++++++------------
 net/netfilter/ipset/ip_set_hash_netiface.c |   24 +-
 2 files changed, 672 insertions(+), 970 deletions(-)

-- 
2.54.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.