Thread (34 messages) flat view 34 messages, 6 authors, 2018-08-12

Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace

From: David Ahern <hidden>
Date: 2018-07-17 17:43:22
Also in: lkml, netfilter-devel

On 7/17/18 11:40 AM, Cong Wang wrote:
On Tue, Jul 17, 2018 at 5:11 AM [off-list ref] wrote:
quoted
From: David Ahern <redacted>

Nikita Leshenko reported that neighbor entries in one namespace can
evict neighbor entries in another. The problem is that the neighbor
tables have entries across all namespaces without separate accounting
and with global limits on when to scan for entries to evict.
It is nothing new, people including me already noticed this before.

quoted
Resolve by making the neighbor tables for ipv4, ipv6 and decnet per
namespace and making the accounting and threshold limits per namespace.

The last discussion about this a long time ago concluded that neigh
table entries are controllable by remote, so after moving it to per netns,
it would be easier to DOS the host.
There are still limits on the total number of entries and with
per-namespace limits an admin has better control.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help