netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH nf-next 0/3] netfilter: remove per-netns conntrack tables, part 2
@ 2016-05-05 22:51 Florian Westphal
  2016-05-05 22:51 ` [PATCH nf-next 1/3] netfilter: conntrack: check netns when walking expect hash Florian Westphal
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Florian Westphal @ 2016-05-05 22:51 UTC (permalink / raw)
  To: netfilter-devel

This series removes the per-namespace duplication of the expectation table.
We use one table for all namespaces, using net_hash_mix(net) as additional
hash seed so entries are spread evenly even if addresses overlap.

The max limit was already global, even before this patch.
couting is still done per namespace.


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2016-05-08 22:19 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-05-05 22:51 [PATCH nf-next 0/3] netfilter: remove per-netns conntrack tables, part 2 Florian Westphal
2016-05-05 22:51 ` [PATCH nf-next 1/3] netfilter: conntrack: check netns when walking expect hash Florian Westphal
2016-05-05 22:51 ` [PATCH nf-next 2/3] netfilter: conntrack: make netns address part of " Florian Westphal
2016-05-05 22:51 ` [PATCH nf-next 3/3] netfilter: conntrack: use a single expectation table for all namespaces Florian Westphal
2016-05-08 22:19 ` [PATCH nf-next 0/3] netfilter: remove per-netns conntrack tables, part 2 Pablo Neira Ayuso

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).