Skip to content

Commit

Permalink
netfilter: nf_tables: skip synchronize_rcu if transaction log is empty
Browse files Browse the repository at this point in the history
After processing the transaction log, the remaining entries of the log
need to be released.

However, in some cases no entries remain, e.g. because the transaction
did not remove anything.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
  • Loading branch information
Florian Westphal authored and Pablo Neira Ayuso committed Apr 26, 2018
1 parent dceb48d commit 2f99aa3
Showing 1 changed file with 17 additions and 8 deletions.
25 changes: 17 additions & 8 deletions net/netfilter/nf_tables_api.c
Original file line number Diff line number Diff line change
Expand Up @@ -5761,7 +5761,7 @@ static void nft_chain_commit_update(struct nft_trans *trans)
}
}

static void nf_tables_commit_release(struct nft_trans *trans)
static void nft_commit_release(struct nft_trans *trans)
{
switch (trans->msg_type) {
case NFT_MSG_DELTABLE:
Expand Down Expand Up @@ -5790,6 +5790,21 @@ static void nf_tables_commit_release(struct nft_trans *trans)
kfree(trans);
}

static void nf_tables_commit_release(struct net *net)
{
struct nft_trans *trans, *next;

if (list_empty(&net->nft.commit_list))
return;

synchronize_rcu();

list_for_each_entry_safe(trans, next, &net->nft.commit_list, list) {
list_del(&trans->list);
nft_commit_release(trans);
}
}

static int nf_tables_commit(struct net *net, struct sk_buff *skb)
{
struct nft_trans *trans, *next;
Expand Down Expand Up @@ -5920,13 +5935,7 @@ static int nf_tables_commit(struct net *net, struct sk_buff *skb)
}
}

synchronize_rcu();

list_for_each_entry_safe(trans, next, &net->nft.commit_list, list) {
list_del(&trans->list);
nf_tables_commit_release(trans);
}

nf_tables_commit_release(net);
nf_tables_gen_notify(net, skb, NFT_MSG_NEWGEN);

return 0;
Expand Down

0 comments on commit 2f99aa3

Please sign in to comment.