]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: conntrack: remove __nf_ct_unconfirmed_destroy
authorFlorian Westphal <fw@strlen.de>
Mon, 11 Apr 2022 11:01:23 +0000 (13:01 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Fri, 13 May 2022 16:52:17 +0000 (18:52 +0200)
commit5f69fb2053979f428c7d763e4c2d2ad24e9bca50
tree8455a8b1512d2703f09e5dac3cc7ac19535a2e12
parent2b5b00c75a91c4bb04c1599dc4b9fbabfe04a93b
netfilter: conntrack: remove __nf_ct_unconfirmed_destroy

Its not needed anymore:

A. If entry is totally new, then the rcu-protected resource
must already have been removed from global visibility before call
to nf_ct_iterate_destroy.

B. If entry was allocated before, but is not yet in the hash table
   (uncofirmed case), genid gets incremented and synchronize_rcu() call
   makes sure access has completed.

C. Next attempt to peek at extension area will fail for unconfirmed
  conntracks, because ext->genid != genid.

D. Conntracks in the hash are iterated as before.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_conntrack_core.c
net/netfilter/nf_conntrack_helper.c
net/netfilter/nfnetlink_cttimeout.c