Re: Slow "nft list counters"

Pablo Neira Ayuso <[email protected]> Mon, 6 Oct 2025 22:52:41 +0200
Newsgroups gmane.comp.security.firewalls.netfilter.general
Message-ID <aOQsGUZTYvZkDcFx@calendula>
On Mon, Oct 06, 2025 at 12:39:56PM +0200, Stephan Ferlin-Reiter wrote:
> Hi,
> 
> On a host I have many network interfaces with associated nftables
> rules and named counters. I’d like to get the state of the counters
> and thought about running “nft -j list counters”. That seems to take
> many seconds, however. As an alternative I wrote a small program that
> talks netlink and sends a dump request with NFT_MSG_GETOBJ for the
> tables I care about. That takes just milliseconds.
> 
> Now I’m wondering whether I’m missing something in my program - I do
> seem to get what I care about. I’m also curious as to why the
> operation with the nft tool takes so long. Is it maybe looking at all
> the rules, which are complex in my case?

What userspace nftables version are you using?

I remember to have speed up this recently:

commit 969ce17b66f8084626610202f11d607911e049e6
Author: Pablo Neira Ayuso <[email protected]>
Date:   Mon Aug 26 00:41:37 2024 +0200

    cache: add filtering support for objects
    
    Currently, full ruleset flag is set on to fetch objects.

otherwise, provide simple script to reproduce.

Thanks.