diff options
author | 2020-09-25 11:56:02 +0300 | |
---|---|---|
committer | 2020-10-04 21:08:25 +0200 | |
commit | 9446ab34ace256e5e470c5aa221d46e544ad895e (patch) | |
tree | d713cfca44e780cd30cc0929ae16acc67acf572d /tools/perf/scripts/python/export-to-postgresql.py | |
parent | netfilter: nf_tables_offload: Remove unused macro FLOW_SETUP_BLOCK (diff) | |
download | linux-dev-9446ab34ace256e5e470c5aa221d46e544ad895e.tar.xz linux-dev-9446ab34ace256e5e470c5aa221d46e544ad895e.zip |
netfilter: ipset: enable memory accounting for ipset allocations
Currently netadmin inside non-trusted container can quickly allocate
whole node's memory via request of huge ipset hashtable.
Other ipset-related memory allocations should be restricted too.
v2: fixed typo ALLOC -> ACCOUNT
Signed-off-by: Vasily Averin <vvs@virtuozzo.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'tools/perf/scripts/python/export-to-postgresql.py')
0 files changed, 0 insertions, 0 deletions