Re: [PATCH v4 net-next 00/15] neighbour: Namespacify arp_tbl and nd_tbl.

Nikolay Aleksandrov <[email protected]>
Newsgroups gmane.linux.network
Message-ID <[email protected]>
On 13/08/2026 11:02, Kuniyuki Iwashima wrote:
> The neighbour subsystem is almost ready to drop RTNL.
> 
> However, the control paths are serialised by the global
> per-table lock.
> 
> This series converts arp_tbl and nd_tbl to per-netns table.
> 
> With the series, /proc/sys/net/ipv{4,6}/neigh/default/ can
> be configured per netns, which was only configurable in
> init_net.
> 
> To avoid potential regression, all the settings are inherited
> from init_net by default, and this behaviour is controlled by
> a new sysctl knob, net.core.neigh_inherit_init_net:
> 
>    # sysctl net.core.neigh_inherit_init_net
>    net.core.neigh_inherit_init_net = 1
>    # sysctl net.ipv4.neigh.default.gc_thresh1
>    net.ipv4.neigh.default.gc_thresh1 = 128
>    # sysctl net.ipv4.neigh.default.gc_thresh1=129
>    net.ipv4.neigh.default.gc_thresh1 = 129
>    # unshare -n sysctl net.ipv4.neigh.default.gc_thresh1
>    net.ipv4.neigh.default.gc_thresh1 = 129
> 
> If it is turned off, all settings are reset in the new netns:
> 
>    # sysctl net.core.neigh_inherit_init_net=0
>    net.core.neigh_inherit_init_net = 0
>    # unshare -n sysctl net.ipv4.neigh.default.gc_thresh1
>    net.ipv4.neigh.default.gc_thresh1 = 128
> 
> Series overview:
> 
>    Patch 1 deflakes test_neigh.sh.
> 
>    Patch 2 ~ 3 are misc cleanup.
> 
>    Patch 4 ~ 7 store arp_tbl/nd_tbl to net->neigh_tables[] and
>    remove the global neigh_tables[].
> 
>    Patch 8 ~ 9 replace the direct access to arp_tbl/nd_tbl to
>    net->neigh_tables[] using new helpers.
> 
>    Patch 10 ~ 12 finally replace the global table with per-netns
>    table.
> 
>    Patch 13 ~ 14 clean up unnecessary net_eq().
> 
>    Patch 15 updates test_neigh.sh.
> 
> Note that some buggy drivers access nd_tbl without checking
> disable_ipv6_mod, so nd_tbl's extern definition is still left.
> 
> 
> Changes:
>    v4:
>      * Patch 12
>        * Add sysctl knob, net.core.neigh_inherit_init_net
>        * Inherit all neigh parms by default
> 
>    v3: https://lore.kernel.org/netdev/[email protected]/
>      * Add Patch 1 & 11
>      * Patch 12
>        * Remove timer_shutdown_sync() in neigh_flush_one() and
>          rely on tbl->entries (Patch 11) to free it in neigh_table_free().
>      * Patch 15
>        * Remove stale comments
> 
>    v2: https://lore.kernel.org/netdev/[email protected]/
>      * Add Patch 11 & 13
>      * Patch 7
>        * Add note about mlx5e_tc_update_neigh_used_value()
>      * Patch 9
>        * Add __maybe_unused to net in neigh_table_clear()
>      * Patch 10
>        * panic() when register_pernet_subsys(&arp_net_ops) fails
>        * Add timer_shutdown_sync() in neigh_flush_one()
>      * Patch 11
>        * Split from the next patch
>        * Remove net comparison in pneigh_dump_table()
>        * Remove net arg of pneigh_create(), pneigh_delete(), and
>          pneigh_lookup()
> 
>    v1: https://lore.kernel.org/netdev/[email protected]/
> 
> 
> Kuniyuki Iwashima (15):
>    selftest: net: Deflake Periodic GC test in test_neigh.sh.
>    neighbour: Remove __neigh_for_each_release().
>    neighbour: Remove lock dance for neigh_update_{gc,managed}_list().
>    neighbour: Remove unnecessary EXPORT_SYMBOL().
>    neighbour: Remove __rcu from neigh_tables[].
>    neighbour: Store arp_tbl and nd_tbl in net->neigh_tables[].
>    neighbour: Remove neigh_tables[].
>    ipv4: Replace &arp_tbl with arp_table(net).
>    ipv6: Replace &nd_tbl with nd_table(net).
>    neighbour: Clean up neigh_table_init() and neigh_table_clear().
>    neighbour: Convert neigh_table.entries to refcount_t.
>    neighbour: Namespacify neigh_tables.
>    neighbour: Don't store net in struct pneigh_entry.
>    neighbour: Remove unnecessary net_eq().
>    selftest: net: Specify netns for ip ntable in test_neigh.sh.
> 
>   Documentation/admin-guide/sysctl/net.rst      |  14 +
>   drivers/infiniband/ulp/ipoib/ipoib_main.c     |  27 +-
>   .../marvell/prestera/prestera_router.c        |  10 +-
>   .../mellanox/mlx5/core/en/rep/neigh.c         |  29 +-
>   .../mellanox/mlx5/core/en/tc_tun_encap.c      |  23 +-
>   .../mellanox/mlx5/core/en_accel/ipsec.c       |   6 +-
>   .../ethernet/mellanox/mlxsw/spectrum_router.c |  31 +-
>   .../ethernet/mellanox/mlxsw/spectrum_span.c   |  10 +-
>   .../netronome/nfp/flower/tunnel_conf.c        |  14 +-
>   drivers/net/ethernet/rocker/rocker_main.c     |   2 +-
>   drivers/net/ethernet/rocker/rocker_ofdpa.c    |   2 +-
>   drivers/net/ethernet/sfc/tc_counters.c        |   8 +-
>   drivers/net/ethernet/sfc/tc_encap_actions.c   |   4 +-
>   drivers/net/vrf.c                             |   2 +-
>   drivers/net/vxlan/vxlan_core.c                |  16 +-
>   include/net/arp.h                             |  10 +-
>   include/net/ndisc.h                           |  20 +-
>   include/net/neighbour.h                       |  22 +-
>   include/net/net_namespace.h                   |   4 +
>   include/net/route.h                           |   7 +-
>   net/bridge/br_arp_nd_proxy.c                  |   4 +-
>   net/core/neighbour.c                          | 400 +++++++++---------
>   net/core/sysctl_net_core.c                    |  12 +
>   net/ieee802154/6lowpan/tx.c                   |   3 +-
>   net/ipv4/arp.c                                | 131 ++++--
>   net/ipv4/devinet.c                            |  18 +-
>   net/ipv4/fib_semantics.c                      |   7 +-
>   net/ipv4/route.c                              |   2 +-
>   net/ipv6/addrconf.c                           |  17 +-
>   net/ipv6/ip6_output.c                         |   4 +-
>   net/ipv6/ndisc.c                              | 146 ++++---
>   net/ipv6/route.c                              |  18 +-
>   tools/testing/selftests/net/test_neigh.sh     |  66 +--
>   33 files changed, 620 insertions(+), 469 deletions(-)
> 

Nice work! With init_net inherit as default, for the set:
Reviewed-by: Nikolay Aleksandrov <[email protected]>

Cheers,
  Nik
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.