From mboxrd@z Thu Jan 1 00:00:00 1970 From: Sarah Newman Subject: Re: [PATCH] net: bridge: add max_fdb_count Date: Wed, 15 Nov 2017 11:43:34 -0800 Message-ID: References: <1510774027-2468-1-git-send-email-srn@prgmr.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit To: netdev@vger.kernel.org Return-path: Received: from mail.prgmr.com ([71.19.149.6]:49066 "EHLO mail.prgmr.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753083AbdKOTnf (ORCPT ); Wed, 15 Nov 2017 14:43:35 -0500 Received: from [192.168.2.33] (c-174-62-74-142.hsd1.ca.comcast.net [174.62.74.142]) (Authenticated sender: srn) by mail.prgmr.com (Postfix) with ESMTPSA id AA08928C045 for ; Wed, 15 Nov 2017 14:43:34 -0500 (EST) In-Reply-To: <1510774027-2468-1-git-send-email-srn@prgmr.com> Content-Language: en-US Sender: netdev-owner@vger.kernel.org List-ID: On 11/15/2017 11:27 AM, Sarah Newman wrote: > Current memory and CPU usage for managing bridge fdb entries is unbounded. > Add a parameter max_fdb_count, controlled from sysfs, which places an upper > limit on the number of entries. Defaults to 1024. > > When max_fdb_count is met or exceeded, whether traffic is sent out a > given port should depend on its flooding behavior. > > This may instead be mitigated by filtering mac address entries in the > PREROUTING chain of the ebtables nat table, but this is only practical > when mac addresses are known in advance. > > Signed-off-by: Sarah Newman I would love to improve this patch, but have limited time to devote to this... What I would try first would be to maintain a data structure roughly ordered based on both number of times an address was observed as well as age and evict the least used, oldest entry when max_fdb_count was reached. --Sarah