diff options
| author | Fernando Fernandez Mancera <fmancera@suse.de> | 2026-05-26 23:58:31 +0200 |
|---|---|---|
| committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2026-06-01 13:43:53 +0200 |
| commit | 2fcba19caaeb2a33017459d3430f057967bb91b6 (patch) | |
| tree | fd1dec24cb0abc3f3655c7bcd788e27e5a841f39 /tools/perf/scripts/python/bin | |
| parent | 36d29ceec32c8206a12dc2810cf65fd394e45baa (diff) | |
netfilter: synproxy: add mutex to guard hook reference counting
As the synproxy infrastructure register netfilter hooks on-demand when a
user adds the first iptables target or nftables expression, if done
concurrently they can race each other.
Introduce a mutex to serialize the refcount control blocks access from
both frontends. While a per namespace mutex might be more efficient, it
is not needed for target/expression like SYNPROXY.
Fixes: ad49d86e07a4 ("netfilter: nf_tables: Add synproxy support")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'tools/perf/scripts/python/bin')
0 files changed, 0 insertions, 0 deletions
