commit | 3e86638e9a0be8bcf7db007909d8307b8b9f8e3b | [log] [tgz] |
---|---|---|
author | Florian Westphal <fw@strlen.de> | Mon May 02 18:40:14 2016 +0200 |
committer | Pablo Neira Ayuso <pablo@netfilter.org> | Thu May 05 16:39:48 2016 +0200 |
tree | 75d479d79da94ed566823e26e0731494e15de259 | |
parent | 56d52d4892d0e478a005b99ed10d0a7f488ea8c1 [diff] |
netfilter: conntrack: consider ct netns in early_drop logic When iterating, skip conntrack entries living in a different netns. We could ignore netns and kill some other non-assured one, but it has two problems: - a netns can kill non-assured conntracks in other namespace - we would start to 'over-subscribe' the affected/overlimit netns. Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>