RE: netfilter: iptables-restore: setsockopt(3, SOL_IP,IPT_SO_SET_REPLACE, "security...", ...) return -EAGAIN
From: Dexuan Cui
Date: Thu May 13 2021 - 02:02:15 EST
> From: Dexuan Cui
> Sent: Wednesday, May 12, 2021 9:19 PM
> I think the latest mainline kernel should also have the same race.
> It looks like this by-design race exists since day one?
I indeed reproduced the issue with the latest stable tree (v5.12.3) as well.
> > BTW, iptables does have a retry mechanism for getsockopt():
> > 2f93205b375e ("Retry ruleset dump when kernel returns EAGAIN.")
> > &ignorews=0&dt=0)
> > But it looks like this is enough?
I missed a "not". IMO 2f93205b375e is not enough.