Thread (63 messages) 63 messages, 4 authors, 2010-02-04

Re: [PATCH] netfilter: per netns nf_conntrack_cachep

From: Patrick McHardy <hidden>
Date: 2010-02-04 13:04:32
Also in: lkml, netfilter-devel

Alexey Dobriyan wrote:
On Thu, Feb 4, 2010 at 2:30 PM, Patrick McHardy [off-list ref] wrote:
quoted
Alexey Dobriyan wrote:
quoted
On Thu, Feb 4, 2010 at 2:25 PM, Patrick McHardy [off-list ref] wrote:
quoted
Jon Masters wrote:
quoted
On Wed, 2010-02-03 at 21:09 +0200, Alexey Dobriyan wrote:
quoted
On Wed, Feb 03, 2010 at 01:38:09PM -0500, Jon Masters wrote:
quoted
*). Per namespace cacheing allocation (the cachep bits). We know it's
still possible for weirdness to happen in the SLAB cache here.
Tiny race, needs reproducer.
Maybe. I think it's worth fixing anyway.
Absolutely, I'll also apply Eric's patch with the %p fix for the
slab name.
This would show kernel pointers in userspace ;-)
So, net->id is required.
I don't see the problem. But yes, it would be nicer to have an ID.
This is done (or rather, not done) to not show attackers
where data structures are.
That's news to me, my /proc is full of kernel space pointers,
including data.

In any case, we need a fix for this suitable for 2.6.33. If
you don't like using the pointer, please send a patch to add
an id to the network namespaces.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help