Re: [PATCH nf] netfilter: nf_tables: map basechain priority to hardware priority

2019-07-30 Thread Jakub Kicinski
On Tue, 30 Jul 2019 12:54:17 +0200, Pablo Neira Ayuso wrote: > This patch maps basechain netfilter priorities from -8192 to 8191 to > hardware priority 0xC000 + 1. tcf_auto_prio() uses 0xC000 if the user > specifies no priority, then it subtract 1 for each new tcf_proto object. > This patch uses th

Re: [PATCH nf] netfilter: nf_tables: map basechain priority to hardware priority

2019-07-30 Thread Marcelo Ricardo Leitner
On Tue, Jul 30, 2019 at 12:54:17PM +0200, Pablo Neira Ayuso wrote: > This patch maps basechain netfilter priorities from -8192 to 8191 to > hardware priority 0xC000 + 1. tcf_auto_prio() uses 0xC000 if the user > specifies no priority, then it subtract 1 for each new tcf_proto object. > This patch u

Re: [PATCH nf] netfilter: nf_tables: map basechain priority to hardware priority

2019-07-30 Thread Pablo Neira Ayuso
On Tue, Jul 30, 2019 at 01:18:00PM +0200, Pablo Neira Ayuso wrote: > On Tue, Jul 30, 2019 at 12:54:17PM +0200, Pablo Neira Ayuso wrote: > [...] > > @@ -180,6 +181,29 @@ static int nft_setup_cb_call(struct nft_base_chain > > *basechain, > > return 0; > > } > > > > +/* Available priorities fo

Re: [PATCH nf] netfilter: nf_tables: map basechain priority to hardware priority

2019-07-30 Thread Pablo Neira Ayuso
On Tue, Jul 30, 2019 at 12:54:17PM +0200, Pablo Neira Ayuso wrote: [...] > @@ -180,6 +181,29 @@ static int nft_setup_cb_call(struct nft_base_chain > *basechain, > return 0; > } > > +/* Available priorities for hardware offload range: -8192..8191 */ > +#define NFT_BASECHAIN_OFFLOAD_PRIO_MA

[PATCH nf] netfilter: nf_tables: map basechain priority to hardware priority

2019-07-30 Thread Pablo Neira Ayuso
This patch maps basechain netfilter priorities from -8192 to 8191 to hardware priority 0xC000 + 1. tcf_auto_prio() uses 0xC000 if the user specifies no priority, then it subtract 1 for each new tcf_proto object. This patch uses the hardware priority range from 0xC000 to 0x for netfilter. Signe