Re: [PATCH net-next v3 0/6] vxlan: vnifilter: bound a single request and account per-VNI memory

From: Ali Firas

Date: Wed Oct 07 2026 - 00:56:15 EST


On 10/1/26 13:45, Paolo Abeni wrote:
> Sashiko complain WRT partial accounting of patch 5/6 looks legit.

Agreed. A VNI that carries a remote also creates an FDB entry, an rdst
and a per-CPU dst cache, none of them accounted. v4 accounts those
allocations on the vnifilter path, passing gfp down rather than flipping
the shared helper, so the learning path keeps plain GFP_ATOMIC.

> Also it would make sense to reword a bit the commit message of patch 1 and
> 2 to reflect the above.

Will do.

v4 will also bound the dump per nlmsg rather than per entry, per
Sashiko's note on patch 4: a device holding 8192 contiguous VNIs can
still dump as one message that replay refuses.

On the Fixes: tag asked for on patch 2 -- Jakub asked for net-next
without one, so I am not adding it:

https://lore.kernel.org/netdev/20260921150904.65a704eb@xxxxxxxxxx/

pw-bot: cr