]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: connlimit: improve packet-to-closed-connection logic
authorFlorian Westphal <fw@strlen.de>
Fri, 7 Mar 2014 13:37:10 +0000 (14:37 +0100)
committerPablo Neira Ayuso <pablo@netfilter.org>
Wed, 12 Mar 2014 12:55:01 +0000 (13:55 +0100)
commit27ce093ab8b1ca77e938a718929af4fe187a87be
treea751b086f8c4e6acdb8d2e220ba76d351930ad79
parent99ca3d88b270cf871d08168b5383534c431b7797
netfilter: connlimit: improve packet-to-closed-connection logic

Instead of freeing the entry from our list and then adding
it back again in the 'packet to closing connection' case just keep the
matching entry around.  Also drop the found_ct != NULL test as
nf_ct_tuplehash_to_ctrack is just container_of().

Reviewed-by: Jesper Dangaard Brouer <brouer@redhat.com>
Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/xt_connlimit.c