]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: ctnetlink: export nf_conntrack_max
authorFlorent Fourcot <florent.fourcot@wifirst.fr>
Sun, 6 May 2018 14:30:14 +0000 (16:30 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Sun, 6 May 2018 22:04:02 +0000 (00:04 +0200)
commit92d5425a2b00214e435300814db82bb2b99b46e6
tree1781bcc0453ea536af4ad4c69e5e7016d631406b
parent933691b6832b011ecffc6da603e535c927ea6bde
netfilter: ctnetlink: export nf_conntrack_max

IPCTNL_MSG_CT_GET_STATS netlink command allow to monitor current number
of conntrack entries. However, if one wants to compare it with the
maximum (and detect exhaustion), the only solution is currently to read
sysctl value.

This patch add nf_conntrack_max value in netlink message, and simplify
monitoring for application built on netlink API.

Signed-off-by: Florent Fourcot <florent.fourcot@wifirst.fr>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
include/uapi/linux/netfilter/nfnetlink_conntrack.h
net/netfilter/nf_conntrack_core.c
net/netfilter/nf_conntrack_netlink.c