netfilter: nft_set_hash: GC reaps elements with conncount for dynamic sets only
conncount has its own GC handler which determines when to reap stale elements, this is convenient for dynamic sets. However, this also reaps non-dynamic sets with static configurations coming from control plane. Always run connlimit gc handler but honor feedback to reap element if this set is dynamic. Fixes: 290180e2 ("netfilter: nf_tables: add connlimit support") Signed-off-by:Pablo Neira Ayuso <pablo@netfilter.org>
Loading