| From 6e8b352ecd5db8e3460c7af2aa8d49fdbc0d3ea3 Mon Sep 17 00:00:00 2001 |
| From: Florian Westphal <fw@strlen.de> |
| Date: Tue, 7 Jan 2020 12:25:10 +0100 |
| Subject: [PATCH] netfilter: hashlimit: do not use indirect calls during gc |
| |
| commit 28b3a4270c0fc064557e409111f2a678e64b6fa7 upstream. |
| |
| no need, just use a simple boolean to indicate we want to reap all |
| entries. |
| |
| Signed-off-by: Florian Westphal <fw@strlen.de> |
| Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/net/netfilter/xt_hashlimit.c b/net/netfilter/xt_hashlimit.c |
| index 3cf399838294..cd121e28d163 100644 |
| --- a/net/netfilter/xt_hashlimit.c |
| +++ b/net/netfilter/xt_hashlimit.c |
| @@ -353,21 +353,7 @@ static int htable_create(struct net *net, struct hashlimit_cfg3 *cfg, |
| return 0; |
| } |
| |
| -static bool select_all(const struct xt_hashlimit_htable *ht, |
| - const struct dsthash_ent *he) |
| -{ |
| - return true; |
| -} |
| - |
| -static bool select_gc(const struct xt_hashlimit_htable *ht, |
| - const struct dsthash_ent *he) |
| -{ |
| - return time_after_eq(jiffies, he->expires); |
| -} |
| - |
| -static void htable_selective_cleanup(struct xt_hashlimit_htable *ht, |
| - bool (*select)(const struct xt_hashlimit_htable *ht, |
| - const struct dsthash_ent *he)) |
| +static void htable_selective_cleanup(struct xt_hashlimit_htable *ht, bool select_all) |
| { |
| unsigned int i; |
| |
| @@ -377,7 +363,7 @@ static void htable_selective_cleanup(struct xt_hashlimit_htable *ht, |
| |
| spin_lock_bh(&ht->lock); |
| hlist_for_each_entry_safe(dh, n, &ht->hash[i], node) { |
| - if ((*select)(ht, dh)) |
| + if (time_after_eq(jiffies, dh->expires) || select_all) |
| dsthash_free(ht, dh); |
| } |
| spin_unlock_bh(&ht->lock); |
| @@ -391,7 +377,7 @@ static void htable_gc(struct work_struct *work) |
| |
| ht = container_of(work, struct xt_hashlimit_htable, gc_work.work); |
| |
| - htable_selective_cleanup(ht, select_gc); |
| + htable_selective_cleanup(ht, false); |
| |
| queue_delayed_work(system_power_efficient_wq, |
| &ht->gc_work, msecs_to_jiffies(ht->cfg.gc_interval)); |
| @@ -415,7 +401,7 @@ static void htable_destroy(struct xt_hashlimit_htable *hinfo) |
| { |
| cancel_delayed_work_sync(&hinfo->gc_work); |
| htable_remove_proc_entry(hinfo); |
| - htable_selective_cleanup(hinfo, select_all); |
| + htable_selective_cleanup(hinfo, true); |
| kfree(hinfo->name); |
| vfree(hinfo); |
| } |
| -- |
| 2.7.4 |
| |