Message ID | 2f512ef8-8bb8-c227-1cde-1be56ae4c3ec@virtuozzo.com |
---|---|
Headers | show |
Series | netfilter: exit_net checks for objects initialized in net_init hook | expand |
Vasily Averin <vvs@virtuozzo.com> wrote: > OpenVz kernel team have a long history of fighting against namespace-related bugs, > some of them could be excluded by using simple checks described below. > > One of typical errors is related to live cycle of namespaces: > usually objects created for some namespace should not live longer than namespace itself. These changes look good to me, thank you. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html
Hi Vasily, On Sun, Nov 12, 2017 at 02:32:14PM +0300, Vasily Averin wrote: > OpenVz kernel team have a long history of fighting against namespace-related bugs, > some of them could be excluded by using simple checks described below. I'm folding this series into one single patch, description looks like this: netfilter: exit_net cleanup check added Be sure that lists initialized in net_init hook was return to initial state. I understand your goal is to make it easier for review, but given this is all part of the same logic change, I just hope you don't mind I have squashed them into one single patch like I did. Thanks. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html