]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: conntrack: make max chain length random
authorFlorian Westphal <fw@strlen.de>
Wed, 8 Sep 2021 12:28:35 +0000 (14:28 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 21 Sep 2021 01:46:55 +0000 (03:46 +0200)
commite62fa7b5eb99b22026409e9f59358d6a2f280588
treeedca5cd570b3f5dc88766ea80db2e14d78c45f47
parent75cace0ed7181f40d3c07c9d0907c8d4cc5f7514
netfilter: conntrack: make max chain length random

Similar to commit 834b57837c7e
("ipv4: make exception cache less predictible"):

Use a random drop length to make it harder to detect when entries were
hashed to same bucket list.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_conntrack_core.c