Thread (7 messages) flat view 7 messages, 3 authors, 2021-05-13

RE: netfilter: iptables-restore: setsockopt(3, SOL_IP, IPT_SO_SET_REPLACE, "security...", ...) return -EAGAIN

From: Dexuan Cui <decui@microsoft.com>
Date: 2021-05-13 06:02:12
Also in: lkml, netfilter-devel

From: Dexuan Cui
Sent: Wednesday, May 12, 2021 9:19 PM
...
I think the latest mainline kernel should also have the same race.
It looks like this by-design race exists since day one?
I indeed reproduced the issue with the latest stable tree (v5.12.3) as well.
quoted
BTW, iptables does have a retry mechanism for getsockopt():
2f93205b375e ("Retry ruleset dump when kernel returns EAGAIN.")
(https://git.netfilter.org/iptables/commit/libiptc?id=2f93205b375e&context=10
quoted
&ignorews=0&dt=0)

But it looks like this is enough? 
I missed a "not". IMO 2f93205b375e is not enough.

Thanks,
-- Dexuan
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help