All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 00/33] Netfilter/IPVS updates for net-next
@ 2019-01-28 23:57 Pablo Neira Ayuso
  2019-01-28 23:57 ` [PATCH 01/33] netfilter: nf_tables: prepare nft_object for lookups via hashtable Pablo Neira Ayuso
                   ` (33 more replies)
  0 siblings, 34 replies; 37+ messages in thread
From: Pablo Neira Ayuso @ 2019-01-28 23:57 UTC (permalink / raw)
  To: netfilter-devel; +Cc: davem, netdev

Hi David,

The following patchset contains Netfilter/IPVS updates for your net-next tree:

1) Introduce a hashtable to speed up object lookups, from Florian Westphal.

2) Make direct calls to built-in extension, also from Florian.

3) Call helper before confirming the conntrack as it used to be originally,
   from Florian.

4) Call request_module() to autoload br_netfilter when physdev is used
   to relax the dependency, also from Florian.

5) Allow to insert rules at a given position ID that is internal to the
   batch, from Phil Sutter.

6) Several patches to replace conntrack indirections by direct calls,
   and to reduce modularization, from Florian. This also includes
   several follow up patches to deal with minor fallout from this
   rework.

7) Use RCU from conntrack gre helper, from Florian.

8) GRE conntrack module becomes built-in into nf_conntrack, from Florian.

9) Replace nf_ct_invert_tuplepr() by calls to nf_ct_invert_tuple(),
   from Florian.

10) Unify sysctl handling at the core of nf_conntrack, from Florian.

11) Provide modparam to register conntrack hooks.

12) Allow to match on the interface kind string, from wenxu.

13) Remove several exported symbols, not required anymore now after
    a bit of de-modulatization work has been done, from Florian.

14) Remove built-in map support in the hash extension, this can be
    done with the existing userspace infrastructure, from laura.

15) Remove indirection to calculate checksums in IPVS, from Matteo Croce.

16) Use call wrappers for indirection in IPVS, also from Matteo.

17) Remove superfluous __percpu parameter in nft_counter, patch from
    Luc Van Oostenryck.

You can pull these changes from:

  git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-next.git

Thanks!

----------------------------------------------------------------

The following changes since commit 435f3f267780321a1aff41bdade257722328ead5:

  Merge branch 'tcp_openreq_child' (2019-01-17 22:19:05 -0800)

are available in the git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-next.git HEAD

for you to fetch changes up to 83f529281d7aa42b10c2c5cb64fcbd2c7cab4409:

  netfilter: ipv4: remove useless export_symbol (2019-01-28 11:32:58 +0100)

----------------------------------------------------------------
Cong Wang (1):
      netfilter: conntrack: fix error path in nf_conntrack_pernet_init()

Florian Westphal (25):
      netfilter: nf_tables: prepare nft_object for lookups via hashtable
      netfilter: nf_tables: handle nft_object lookups via rhltable
      netfilter: nf_tables: add direct calls for all builtin expressions
      netfilter: conntrack: remove helper hook again
      netfilter: physdev: relax br_netfilter dependency
      netfilter: conntrack: handle builtin l4proto packet functions via direct calls
      netfilter: conntrack: handle icmp pkt_to_tuple helper via direct calls
      netfilter: conntrack: gre: convert rwlock to rcu
      netfilter: conntrack: gre: switch module to be built-in
      netfilter: conntrack: remove net_id
      netfilter: conntrack: remove pkt_to_tuple callback
      netfilter: conntrack: remove invert_tuple callback
      netfilter: conntrack: remove module owner field
      netfilter: conntrack: remove remaining l4proto indirect packet calls
      netfilter: conntrack: remove pernet l4 proto register interface
      netfilter: conntrack: avoid unneeded nf_conntrack_l4proto lookups
      netfilter: conntrack: unify sysctl handling
      netfilter: conntrack: remove sysctl registration helpers
      netfilter: conntrack: remove l4proto init and get_net callbacks
      netfilter: conntrack: remove l4proto destroy hook
      netfilter: conntrack: remove nf_ct_l4proto_find_get
      netfilter: nat: un-export nf_nat_used_tuple
      netfilter: conntrack: fix IPV6=n builds
      netfilter: conntrack: fix bogus port values for other l4 protocols
      netfilter: ipv4: remove useless export_symbol

Laura Garcia Liebana (1):
      Revert "netfilter: nft_hash: add map lookups for hashing operations"

Luc Van Oostenryck (1):
      netfilter: nft_counter: remove wrong __percpu of nft_counter_resest()'s arg

Matteo Croce (2):
      ipvs: avoid indirect calls when calculating checksums
      ipvs: use indirect call wrappers

Pablo Neira Ayuso (1):
      netfilter: nf_conntrack: provide modparam to always register conntrack hooks

Phil Sutter (1):
      netfilter: nf_tables: Support RULE_ID reference in new rule

wenxu (1):
      netfilter: nft_meta: Add NFT_META_I/OIFKIND meta type

 include/linux/netfilter/nf_conntrack_proto_gre.h |  17 +-
 include/linux/netfilter_ipv4.h                   |   6 -
 include/net/ip_vs.h                              |   3 -
 include/net/netfilter/br_netfilter.h             |   1 -
 include/net/netfilter/ipv4/nf_conntrack_ipv4.h   |   3 +
 include/net/netfilter/nf_conntrack.h             |   2 -
 include/net/netfilter/nf_conntrack_core.h        |   5 +-
 include/net/netfilter/nf_conntrack_l4proto.h     | 122 +++---
 include/net/netfilter/nf_nat.h                   |   4 -
 include/net/netfilter/nf_tables.h                |  26 +-
 include/net/netfilter/nf_tables_core.h           |  16 +
 include/net/netns/conntrack.h                    |  30 +-
 include/uapi/linux/netfilter/nf_tables.h         |  10 +-
 net/bridge/br_netfilter_hooks.c                  |   5 -
 net/ipv4/netfilter.c                             |  18 -
 net/ipv4/netfilter/nf_nat_l3proto_ipv4.c         |   2 +-
 net/ipv6/netfilter/nf_nat_l3proto_ipv6.c         |   2 +-
 net/netfilter/Kconfig                            |   2 +-
 net/netfilter/Makefile                           |   3 +-
 net/netfilter/ipvs/ip_vs_core.c                  |  49 ++-
 net/netfilter/ipvs/ip_vs_proto_ah_esp.c          |   2 -
 net/netfilter/ipvs/ip_vs_proto_sctp.c            |   8 +-
 net/netfilter/ipvs/ip_vs_proto_tcp.c             |  15 +-
 net/netfilter/ipvs/ip_vs_proto_udp.c             |  15 +-
 net/netfilter/nf_conntrack_core.c                | 210 +++++----
 net/netfilter/nf_conntrack_expect.c              |   2 +-
 net/netfilter/nf_conntrack_netlink.c             |  14 +-
 net/netfilter/nf_conntrack_pptp.c                |   2 +-
 net/netfilter/nf_conntrack_proto.c               | 514 ++++-------------------
 net/netfilter/nf_conntrack_proto_dccp.c          | 134 +-----
 net/netfilter/nf_conntrack_proto_generic.c       |  85 +---
 net/netfilter/nf_conntrack_proto_gre.c           | 196 ++-------
 net/netfilter/nf_conntrack_proto_icmp.c          |  67 +--
 net/netfilter/nf_conntrack_proto_icmpv6.c        |  69 +--
 net/netfilter/nf_conntrack_proto_sctp.c          | 128 +-----
 net/netfilter/nf_conntrack_proto_tcp.c           | 160 +------
 net/netfilter/nf_conntrack_proto_udp.c           |  80 +---
 net/netfilter/nf_conntrack_standalone.c          | 427 ++++++++++++++++++-
 net/netfilter/nf_flow_table_core.c               |   2 +-
 net/netfilter/nf_nat_core.c                      |  15 +-
 net/netfilter/nf_tables_api.c                    | 137 +++++-
 net/netfilter/nf_tables_core.c                   |  25 +-
 net/netfilter/nfnetlink_cttimeout.c              |  19 +-
 net/netfilter/nft_bitwise.c                      |   5 +-
 net/netfilter/nft_byteorder.c                    |   6 +-
 net/netfilter/nft_cmp.c                          |   6 +-
 net/netfilter/nft_counter.c                      |   2 +-
 net/netfilter/nft_ct.c                           |   4 +-
 net/netfilter/nft_dynset.c                       |   5 +-
 net/netfilter/nft_hash.c                         | 121 ------
 net/netfilter/nft_immediate.c                    |   6 +-
 net/netfilter/nft_meta.c                         |  12 +
 net/netfilter/nft_objref.c                       |   5 +-
 net/netfilter/nft_payload.c                      |   6 +-
 net/netfilter/nft_quota.c                        |   2 +-
 net/netfilter/nft_range.c                        |   5 +-
 net/netfilter/nft_rt.c                           |   6 +-
 net/netfilter/utils.c                            |  19 +
 net/netfilter/xt_CT.c                            |   2 +-
 net/netfilter/xt_physdev.c                       |   9 +-
 net/openvswitch/conntrack.c                      |   2 +-
 61 files changed, 1178 insertions(+), 1697 deletions(-)

^ permalink raw reply	[flat|nested] 37+ messages in thread

end of thread, other threads:[~2019-01-29  8:09 UTC | newest]

Thread overview: 37+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-01-28 23:57 [PATCH 00/33] Netfilter/IPVS updates for net-next Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 01/33] netfilter: nf_tables: prepare nft_object for lookups via hashtable Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 02/33] netfilter: nf_tables: handle nft_object lookups via rhltable Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 03/33] netfilter: nf_tables: add direct calls for all builtin expressions Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 04/33] netfilter: conntrack: remove helper hook again Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 05/33] netfilter: physdev: relax br_netfilter dependency Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 06/33] netfilter: nf_tables: Support RULE_ID reference in new rule Pablo Neira Ayuso
2019-01-29  5:24   ` Cong Wang
2019-01-29  8:09     ` Florian Westphal
2019-01-28 23:57 ` [PATCH 07/33] netfilter: conntrack: handle builtin l4proto packet functions via direct calls Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 08/33] netfilter: conntrack: handle icmp pkt_to_tuple helper " Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 09/33] netfilter: conntrack: gre: convert rwlock to rcu Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 10/33] netfilter: conntrack: gre: switch module to be built-in Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 11/33] netfilter: conntrack: remove net_id Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 12/33] netfilter: conntrack: remove pkt_to_tuple callback Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 13/33] netfilter: conntrack: remove invert_tuple callback Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 14/33] netfilter: conntrack: remove module owner field Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 15/33] netfilter: conntrack: remove remaining l4proto indirect packet calls Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 16/33] netfilter: conntrack: remove pernet l4 proto register interface Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 17/33] netfilter: conntrack: avoid unneeded nf_conntrack_l4proto lookups Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 18/33] netfilter: conntrack: unify sysctl handling Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 19/33] netfilter: conntrack: remove sysctl registration helpers Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 20/33] netfilter: conntrack: remove l4proto init and get_net callbacks Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 21/33] netfilter: conntrack: remove l4proto destroy hook Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 22/33] netfilter: conntrack: remove nf_ct_l4proto_find_get Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 23/33] netfilter: nf_conntrack: provide modparam to always register conntrack hooks Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 24/33] netfilter: nft_meta: Add NFT_META_I/OIFKIND meta type Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 25/33] netfilter: nat: un-export nf_nat_used_tuple Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 26/33] Revert "netfilter: nft_hash: add map lookups for hashing operations" Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 27/33] netfilter: conntrack: fix IPV6=n builds Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 28/33] netfilter: conntrack: fix bogus port values for other l4 protocols Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 29/33] ipvs: avoid indirect calls when calculating checksums Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 30/33] ipvs: use indirect call wrappers Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 31/33] netfilter: nft_counter: remove wrong __percpu of nft_counter_resest()'s arg Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 32/33] netfilter: conntrack: fix error path in nf_conntrack_pernet_init() Pablo Neira Ayuso
2019-01-28 23:57 ` [PATCH 33/33] netfilter: ipv4: remove useless export_symbol Pablo Neira Ayuso
2019-01-29  1:38 ` [PATCH 00/33] Netfilter/IPVS updates for net-next David Miller

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.