Re: [PATCH v5 6/8] netfilter: Remove the now superfluous sentinel elements from ctl_table array

Joel Granados <[email protected]>
Newsgroups org.kernel.vger.linux-x25,dev.linux.lists.bridge,dev.linux.lists.mptcp,org.kernel.vger.dccp,org.kernel.vger.linux-hams,org.kernel.vger.linux-kernel,org.kernel.vger.linux-nfs,org.kernel.vger.linux-rdma,org.kernel.vger.linux-s390,org.kernel.vger.linux-sctp,org.kernel.vger.linux-wpan,org.kernel.vger.lvs-devel,org.kernel.vger.netdev,org.kernel.vger.netfilter-devel
Message-ID <[email protected]>
On Fri, Apr 26, 2024 at 03:09:45PM +0300, Julian Anastasov wrote:
> 
> 	Hello,
> 
> On Fri, 26 Apr 2024, Joel Granados via B4 Relay wrote:
> 
> > From: Joel Granados <[email protected]>
> > 
> > This commit comes at the tail end of a greater effort to remove the
> > empty elements at the end of the ctl_table arrays (sentinels) which will
> > reduce the overall build time size of the kernel and run time memory
> > bloat by ~64 bytes per sentinel (further information Link :
> > https://lore.kernel.org/all/ZO5Yx5JFogGi%[email protected]/)
> > 
> > * Remove sentinel elements from ctl_table structs
> > * Remove instances where an array element is zeroed out to make it look
> >   like a sentinel. This is not longer needed and is safe after commit
> >   c899710fe7f9 ("networking: Update to register_net_sysctl_sz") added
> >   the array size to the ctl_table registration
> > * Remove the need for having __NF_SYSCTL_CT_LAST_SYSCTL as the
> >   sysctl array size is now in NF_SYSCTL_CT_LAST_SYSCTL
> > * Remove extra element in ctl_table arrays declarations
> > 
> > Acked-by: Kees Cook <[email protected]> # loadpin & yama
> > Signed-off-by: Joel Granados <[email protected]>
> > ---
> >  net/bridge/br_netfilter_hooks.c         | 1 -
> >  net/ipv6/netfilter/nf_conntrack_reasm.c | 1 -
> >  net/netfilter/ipvs/ip_vs_ctl.c          | 5 +----
> >  net/netfilter/ipvs/ip_vs_lblc.c         | 5 +----
> >  net/netfilter/ipvs/ip_vs_lblcr.c        | 5 +----
> >  net/netfilter/nf_conntrack_standalone.c | 6 +-----
> >  net/netfilter/nf_log.c                  | 3 +--
> >  7 files changed, 5 insertions(+), 21 deletions(-)
> 
> ...
> 
> > diff --git a/net/netfilter/ipvs/ip_vs_ctl.c b/net/netfilter/ipvs/ip_vs_ctl.c
> > index 143a341bbc0a..50b5dbe40eb8 100644
> > --- a/net/netfilter/ipvs/ip_vs_ctl.c
> > +++ b/net/netfilter/ipvs/ip_vs_ctl.c
> 
> ...
> 
> > @@ -4286,10 +4285,8 @@ static int __net_init ip_vs_control_net_init_sysctl(struct netns_ipvs *ipvs)
> >  			return -ENOMEM;
> >  
> >  		/* Don't export sysctls to unprivileged users */
> > -		if (net->user_ns != &init_user_ns) {
> > -			tbl[0].procname = NULL;
> > +		if (net->user_ns != &init_user_ns)
> >  			ctl_table_size = 0;
> > -		}
> >  	} else
> >  		tbl = vs_vars;
> >  	/* Initialize sysctl defaults */
> 
> 	We are in process of changing this code (not in trees yet):
> 
> https://marc.info/?t=171345219600002&r=1&w=2
> 
> 	As I'm not sure which patch will win, the end result should
> be this single if-block/hunk to be removed.
Thx for the heads up. I have made a note of it in case this set ends up
being after yours.


> 
> Regards
> 
> --
> Julian Anastasov <[email protected]>
> 

-- 

Joel Granados
signature.asc (application/pgp-signature, 659 B)
-----BEGIN PGP SIGNATURE-----

iQGzBAABCgAdFiEErkcJVyXmMSXOyyeQupfNUreWQU8FAmYvaToACgkQupfNUreW
QU+SSwv+L+03hxc8J2P/i5B1B0mUQVpmedwuNIg1F6QSEgnsIAQzagQUlBPPFYhC
9+gNBsEpUMPb2PVXyRXpd3QQm0XPgv43A38qO27lQYg1VPpf+zpzosrvz0lJaoo/
BesbgCri6d6bPmpgGfq4BuYWksB0jvU/Ci63m7Qz5wKcG5hM0G7jEHggHJkz8BWP
8i4SO8Fwb0pbbd7Hwqb1hUJd1uk+coHhyknMfIwmVFPPTN9C1COJFgFE9YiCT9zq
9L1d/uWcu0n9sB7MzW93vrPrMYZ1xeIvWrYwXI05Wr3FnTYXGhSpnZcMUN7rHorj
EQv06C97YKmL3HiTPcIxtxGxjG1v3U+RZZ49wxo56yiNPT/kECnkTFT+7GxJ+/4d
HkB8WMPpqP6PRbPNLJdm94ynbyi8N6+4fgscCSLRuAeiyVqNGXmvLsY3NZWJmpGl
UBeeGwtDSjq9oVM5y9hiKeBbljcUbPpBiHZIuZ0qvm/P02md5XTdbdRJEYjMpxjq
LcjGNoOh
=+2c9
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.