From: Jim Westfall <hidden> Date: 2018-01-14 20:18:59
This used to be the previous behavior in older kernels but became broken in
a263b3093641f (ipv4: Make neigh lookups directly in output packet path)
and then later removed because it was broken in 0bb4087cbec0 (ipv4: Fix neigh
lookup keying over loopback/point-to-point devices)
Not having this results in there being an arp entry for every remote ip
address that the device talks to. Given a fairly active device it can
cause the arp table to become huge and/or having to add/purge large number
of entires to keep within table size thresholds.
$ ip -4 neigh show nud noarp | grep tun | wc -l
55850
$ lnstat -k arp_cache:entries,arp_cache:allocs,arp_cache:destroys -c 10
arp_cach|arp_cach|arp_cach|
entries| allocs|destroys|
81493|620166816|620126069|
101867| 10186| 0|
113854| 5993| 0|
118773| 2459| 0|
27937| 18579| 63998|
39256| 5659| 0|
56231| 8487| 0|
65602| 4685| 0|
79697| 7047| 0|
90733| 5517| 0|
v2:
- fixes coding style issues
Jim Westfall (2):
net: Allow neigh contructor functions ability to modify the
primary_key
ipv4: Make neigh lookup keys for loopback/point-to-point devices be
INADDR_ANY
include/net/arp.h | 3 +++
net/core/neighbour.c | 4 ++--
net/ipv4/arp.c | 7 ++++++-
3 files changed, 11 insertions(+), 3 deletions(-)
--
2.15.1
From: Jim Westfall <hidden> Date: 2018-01-14 20:19:00
Use n->primary_key instead of pkey to account for the possibility that a neigh
constructor function may have modified the primary_key value.
Signed-off-by: Jim Westfall <redacted>
---
net/core/neighbour.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
From: Jim Westfall <hidden> Date: 2018-01-14 20:19:01
Map all lookup neigh keys to INADDR_ANY for loopback/point-to-point devices
to avoid making an entry for every remote ip the device needs to talk to.
This used the be the old behavior but became broken in a263b3093641f
(ipv4: Make neigh lookups directly in output packet path) and later removed
in 0bb4087cbec0 (ipv4: Fix neigh lookup keying over loopback/point-to-point
devices) because it was broken.
Signed-off-by: Jim Westfall <redacted>
---
include/net/arp.h | 3 +++
net/ipv4/arp.c | 7 ++++++-
2 files changed, 9 insertions(+), 1 deletion(-)
From: David Miller <davem@davemloft.net> Date: 2018-01-15 19:54:08
From: Jim Westfall <redacted>
Date: Sun, 14 Jan 2018 04:18:49 -0800
This used to be the previous behavior in older kernels but became broken in
a263b3093641f (ipv4: Make neigh lookups directly in output packet path)
and then later removed because it was broken in 0bb4087cbec0 (ipv4: Fix neigh
lookup keying over loopback/point-to-point devices)
Not having this results in there being an arp entry for every remote ip
address that the device talks to. Given a fairly active device it can
cause the arp table to become huge and/or having to add/purge large number
of entires to keep within table size thresholds.
...
v2:
- fixes coding style issues
Series applied and queued up for -stable, thank you.
From: Jim Westfall <hidden> Date: 2018-01-15 21:42:39
David Miller [off-list ref] wrote [01.15.18]:
From: Jim Westfall <redacted>
Date: Sun, 14 Jan 2018 04:18:49 -0800
quoted
This used to be the previous behavior in older kernels but became broken in
a263b3093641f (ipv4: Make neigh lookups directly in output packet path)
and then later removed because it was broken in 0bb4087cbec0 (ipv4: Fix neigh
lookup keying over loopback/point-to-point devices)
Not having this results in there being an arp entry for every remote ip
address that the device talks to. Given a fairly active device it can
cause the arp table to become huge and/or having to add/purge large number
of entires to keep within table size thresholds.
...
quoted
v2:
- fixes coding style issues
Series applied and queued up for -stable, thank you.
Thanks for applying these. We see the same type of behavior with ipv6
over point-to-point interfaces and I would like to fix these as well by
mapping all the ndisc_cache entries to in6addr_any. However my knowledge
of ndisc is limited and I'm unclear if its safe to assume ndisc, like
arp, would never exist on the point-to-point interface.
Thanks
jim
From: David Miller <davem@davemloft.net> Date: 2018-01-15 21:59:58
From: Jim Westfall <redacted>
Date: Mon, 15 Jan 2018 13:42:38 -0800
David Miller [off-list ref] wrote [01.15.18]:
quoted
From: Jim Westfall <redacted>
Date: Sun, 14 Jan 2018 04:18:49 -0800
quoted
This used to be the previous behavior in older kernels but became broken in
a263b3093641f (ipv4: Make neigh lookups directly in output packet path)
and then later removed because it was broken in 0bb4087cbec0 (ipv4: Fix neigh
lookup keying over loopback/point-to-point devices)
Not having this results in there being an arp entry for every remote ip
address that the device talks to. Given a fairly active device it can
cause the arp table to become huge and/or having to add/purge large number
of entires to keep within table size thresholds.
...
quoted
v2:
- fixes coding style issues
Series applied and queued up for -stable, thank you.
Thanks for applying these. We see the same type of behavior with ipv6
over point-to-point interfaces and I would like to fix these as well by
mapping all the ndisc_cache entries to in6addr_any. However my knowledge
of ndisc is limited and I'm unclear if its safe to assume ndisc, like
arp, would never exist on the point-to-point interface.
Ok, hopefully some ipv6 experts can chime in.
Thank you.