]> git.baikalelectronics.ru Git - kernel.git/commit
netfilter: conntrack: make max chain length random
authorFlorian Westphal <fw@strlen.de>
Wed, 8 Sep 2021 12:28:35 +0000 (14:28 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 21 Sep 2021 01:46:55 +0000 (03:46 +0200)
commit9a14c45335222bb34ed68ed39e4e9b29eec8eaa8
treeedca5cd570b3f5dc88766ea80db2e14d78c45f47
parent53b1cba2d153310fa9e794ff6695a437894aad7a
netfilter: conntrack: make max chain length random

Similar to commit 66a61928e42a
("ipv4: make exception cache less predictible"):

Use a random drop length to make it harder to detect when entries were
hashed to same bucket list.

Signed-off-by: Florian Westphal <fw@strlen.de>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nf_conntrack_core.c