Commit 9d74da11 authored by Pablo Neira Ayuso's avatar Pablo Neira Ayuso
Browse files

netfilter: nft_set_hash: GC reaps elements with conncount for dynamic sets only



conncount has its own GC handler which determines when to reap stale
elements, this is convenient for dynamic sets. However, this also reaps
non-dynamic sets with static configurations coming from control plane.
Always run connlimit gc handler but honor feedback to reap element if
this set is dynamic.

Fixes: 290180e2 ("netfilter: nf_tables: add connlimit support")
Signed-off-by: default avatarPablo Neira Ayuso <pablo@netfilter.org>
parent ed3ba9b6
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please to comment