From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Laight Subject: RE: [PATCH] net: bridge: add max_fdb_count Date: Tue, 21 Nov 2017 14:53:21 +0000 Message-ID: References: <1510774027-2468-1-git-send-email-srn@prgmr.com> Mime-Version: 1.0 Content-Type: text/plain; charset="Windows-1252" Content-Transfer-Encoding: 8BIT To: 'Sarah Newman' , "netdev@vger.kernel.org" Return-path: Received: from smtp-out6.electric.net ([192.162.217.184]:50631 "EHLO smtp-out6.electric.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751221AbdKUOxF (ORCPT ); Tue, 21 Nov 2017 09:53:05 -0500 In-Reply-To: <1510774027-2468-1-git-send-email-srn@prgmr.com> Content-Language: en-US Sender: netdev-owner@vger.kernel.org List-ID: From: Sarah Newman > Sent: 15 November 2017 19:27 > Current memory and CPU usage for managing bridge fdb entries is unbounded. > Add a parameter max_fdb_count, controlled from sysfs, which places an upper > limit on the number of entries. Defaults to 1024. > > When max_fdb_count is met or exceeded, whether traffic is sent out a > given port should depend on its flooding behavior. Does it make sense for a bridge to run in a mode where it doesn't remember (all the) MAC addresses from one of its interfaces? Rather than flood unknown addresses they are just sent to the 'everywhere else' interface. David