Thread (23 messages) flat view 23 messages, 6 authors, 2015-01-12

Re: [PATCH 2/3] x_tables: Use also dev->ifalias for interface matching

From: Eric Dumazet <hidden>
Date: 2015-01-12 16:46:16
Also in: lkml, netfilter-devel

On Mon, 2015-01-12 at 17:32 +0100, Jan Engelhardt wrote:
On Monday 2015-01-12 17:04, Eric Dumazet wrote:
quoted
iptables should have used ifindex [for interface matching],
it[']s sad we allowed the substring match in first place.
How would you solve interface name wildcards with ifindices?
(They come in handy if you have something like lots of tun+/veth+
interfaces from openvpn/lxc.)

This is what I said : "it[']s sad we allowed the substring match in
first place."

This obviously referred to wildcards, in the in/out interface match for
every _single_ rule, consuming 64 bytes of memory per rule and per cpu !
Which is absolutely crazy in term of memory usage.

Matching tun+ or whatever could easily be done by a match (-m ...),
because you can factorize this quite easily (called once for a group of
rules)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help