Thread (34 messages) flat view 34 messages, 6 authors, 2018-08-12

Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace

From: Cong Wang <hidden>
Date: 2018-07-17 17:40:25
Also in: lkml, netfilter-devel

On Tue, Jul 17, 2018 at 5:11 AM [off-list ref] wrote:
From: David Ahern <redacted>

Nikita Leshenko reported that neighbor entries in one namespace can
evict neighbor entries in another. The problem is that the neighbor
tables have entries across all namespaces without separate accounting
and with global limits on when to scan for entries to evict.
It is nothing new, people including me already noticed this before.

Resolve by making the neighbor tables for ipv4, ipv6 and decnet per
namespace and making the accounting and threshold limits per namespace.

The last discussion about this a long time ago concluded that neigh
table entries are controllable by remote, so after moving it to per netns,
it would be easier to DOS the host.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help