[lvc-project] [PATCH 6.1.y 2/2] netfilter: nft_set_pipapo: remove dirty flag
Denis Zubov
d.zubov at tssltd.ru
Tue Sep 22 15:18:10 MSK 2026
From: Florian Westphal <fw at strlen.de>
commit 532aec7e878b527fcee8877350ab5c5341789626 upstream.
After previous change:
->clone exists: ->dirty is always true
->clone == NULL ->dirty is always false
So remove this flag.
Signed-off-by: Florian Westphal <fw at strlen.de>
Reviewed-by: Stefano Brivio <sbrivio at redhat.com>
Signed-off-by: Pablo Neira Ayuso <pablo at netfilter.org>
Needed in 6.1.y: since 16f3595c0441 (backport of 9df95785d3d8) the
dirty flag early return in nft_pipapo_commit() can strand a gc batch
on priv->gc_head between pipapo_gc_scan() and pipapo_gc_queue(),
which triggers the WARN_ON_ONCE() in nft_pipapo_destroy(). Context
adjusted for the deferred gc list.
Fixes: 16f3595c0441 ("netfilter: nft_set_pipapo: split gc into unlink and reclaim phase")
Signed-off-by: Denis Zubov <d.zubov at tssltd.ru>
---
net/netfilter/nft_set_pipapo.c | 25 -------------------------
net/netfilter/nft_set_pipapo.h | 2 --
2 files changed, 27 deletions(-)
diff --git a/net/netfilter/nft_set_pipapo.c b/net/netfilter/nft_set_pipapo.c
index 9add83917f17..cee8d6afc91e 100644
--- a/net/netfilter/nft_set_pipapo.c
+++ b/net/netfilter/nft_set_pipapo.c
@@ -1273,7 +1273,6 @@ static int nft_pipapo_insert(const struct net *net, const struct nft_set *set,
const u8 *start = (const u8 *)elem->key.val.data, *end;
struct nft_pipapo_elem *e = elem->priv, *dup;
struct nft_pipapo_match *m = pipapo_maybe_clone(set);
- struct nft_pipapo *priv = nft_set_priv(set);
u8 genmask = nft_genmask_next(net);
u64 tstamp = nft_net_tstamp(net);
struct nft_pipapo_field *f;
@@ -1337,8 +1336,6 @@ static int nft_pipapo_insert(const struct net *net, const struct nft_set *set,
}
/* Insert */
- priv->dirty = true;
-
bsize_max = m->bsize_max;
nft_pipapo_for_each_field(f, i, m) {
@@ -1735,8 +1732,6 @@ static void pipapo_gc_scan(struct nft_set *set, struct nft_pipapo_match *m)
* NFT_SET_ELEM_DEAD_BIT.
*/
if (__nft_set_elem_expired(&e->ext, tstamp)) {
- priv->dirty = true;
-
if (!nft_trans_gc_space(gc)) {
gc = nft_trans_gc_alloc(set, 0, GFP_KERNEL);
if (!gc)
@@ -1850,13 +1845,9 @@ static void nft_pipapo_commit(struct nft_set *set)
if (time_after_eq(jiffies, priv->last_gc + nft_set_gc_interval(set)))
pipapo_gc_scan(set, priv->clone);
- if (!priv->dirty)
- return;
-
old = rcu_replace_pointer(priv->match, priv->clone,
nft_pipapo_transaction_mutex_held(set));
priv->clone = NULL;
- priv->dirty = false;
if (old)
call_rcu(&old->rcu, pipapo_reclaim_match);
@@ -1868,12 +1859,8 @@ static void nft_pipapo_abort(const struct nft_set *set)
{
struct nft_pipapo *priv = nft_set_priv(set);
- if (!priv->dirty)
- return;
-
if (!priv->clone)
return;
- priv->dirty = false;
pipapo_free_match(priv->clone);
priv->clone = NULL;
}
@@ -2128,7 +2115,6 @@ static void nft_pipapo_remove(const struct net *net, const struct nft_set *set,
match_end += NFT_PIPAPO_GROUPS_PADDED_SIZE(f);
if (last && f->mt[rulemap[i].to].e == e) {
- priv->dirty = true;
pipapo_drop(m, rulemap);
return;
}
@@ -2319,22 +2305,11 @@ static int nft_pipapo_init(const struct nft_set *set,
f->mt = NULL;
}
- /* Create an initial clone of matching data for next insertion */
- priv->clone = pipapo_clone(m);
- if (!priv->clone) {
- err = -ENOMEM;
- goto out_free;
- }
-
- priv->dirty = false;
-
INIT_LIST_HEAD(&priv->gc_head);
rcu_assign_pointer(priv->match, m);
return 0;
-out_free:
- free_percpu(m->scratch);
out_scratch:
kfree(m);
diff --git a/net/netfilter/nft_set_pipapo.h b/net/netfilter/nft_set_pipapo.h
index 949f4cd709b2..1116112bceb0 100644
--- a/net/netfilter/nft_set_pipapo.h
+++ b/net/netfilter/nft_set_pipapo.h
@@ -171,7 +171,6 @@ struct nft_pipapo_match {
* @match: Currently in-use matching data
* @clone: Copy where pending insertions and deletions are kept
* @width: Total bytes to be matched for one packet, including padding
- * @dirty: Working copy has pending insertions or deletions
* @last_gc: Timestamp of last garbage collection run, jiffies
* @gc_head: list of nft_trans_gc to queue up for mem reclaim
*/
@@ -179,7 +178,6 @@ struct nft_pipapo {
struct nft_pipapo_match __rcu *match;
struct nft_pipapo_match *clone;
int width;
- bool dirty;
unsigned long last_gc;
struct list_head gc_head;
};
--
2.53.0
More information about the lvc-project
mailing list