summaryrefslogtreecommitdiff
path: root/net/sysctl_net.c
diff options
context:
space:
mode:
authorFlorian Westphal <fw@strlen.de>2024-04-23 15:44:28 +0200
committerPablo Neira Ayuso <pablo@netfilter.org>2024-05-06 16:29:21 +0200
commit119c790a271de02dadb36ba0c1fc31a7d5d4c62b (patch)
tree643eaf20c4a4e673e5e42978506ae73e0fc20512 /net/sysctl_net.c
parentf9a6e7fb521cb6e1ff1a654a2a7f9331611f8140 (diff)
netfilter: conntrack: remove flowtable early-drop test
Not sure why this special case exists. Early drop logic (which kicks in when conntrack table is full) should be independent of flowtable offload and only consider assured bit (i.e., two-way traffic was seen). flowtable entries hold a reference to the conntrack entry (struct nf_conn) that has been offloaded. The conntrack use count is not decremented until after the entry is free'd. This change therefore will not result in exceeding the conntrack table limit. It does allow early-drop of tcp flows even when they've been offloaded, but only if they have been offloaded before syn-ack was received or after at least one peer has sent a fin. Currently 'fin' packet reception already stops offloading, so this should not impact offloading either. Cc: Vlad Buslov <vladbu@nvidia.com> Signed-off-by: Florian Westphal <fw@strlen.de> Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/sysctl_net.c')
0 files changed, 0 insertions, 0 deletions