]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: nf_conntrack: Reduce conntrack count in nf_conntrack_free()
authorEric Dumazet <dada1@cosmosbay.com>
Tue, 24 Mar 2009 13:26:50 +0000 (14:26 +0100)
committerPatrick McHardy <kaber@trash.net>
Tue, 24 Mar 2009 13:26:50 +0000 (14:26 +0100)
commit08a32e93ed2a08d70c3d414c048fd80131732048
treea86c8e51811eafbedee01347b1a5c4e76d748b81
parentb348ee912041a788f9a1360121323f602ab7a0a8
netfilter: nf_conntrack: Reduce conntrack count in nf_conntrack_free()

We use RCU to defer freeing of conntrack structures. In DOS situation, RCU might
accumulate about 10.000 elements per CPU in its internal queues. To get accurate
conntrack counts (at the expense of slightly more RAM used), we might consider
conntrack counter not taking into account "about to be freed elements, waiting
in RCU queues". We thus decrement it in nf_conntrack_free(), not in the RCU
callback.

Signed-off-by: Eric Dumazet <dada1@cosmosbay.com>
Tested-by: Joakim Tjernlund <Joakim.Tjernlund@transmode.se>
Signed-off-by: Patrick McHardy <kaber@trash.net>
net/netfilter/nf_conntrack_core.c