[PATCH 4/4] first conntrack ID must be 1 not 2

Jozsef Kadlecsik kadlec at blackhole.kfki.hu
Fri Feb 17 09:18:33 CET 2006


On Thu, 16 Feb 2006, Patrick McHardy wrote:

> Jozsef Kadlecsik wrote:
> > On Thu, 16 Feb 2006, Patrick McHardy wrote:
> >
> >>>(jiffies, tuples) would be unique even in that case.
> >>
> >>Thats true. But what is the advantage over using the counter?
>
> Actually it would still not be unique if connections live
> shorter than a jiffy and are resurrected.

I can imagine such a situation only when the conntrack table is full and
we are forced to drop unassured connections - when we are in trouble
anyway.

> > Some clever solution should only be found to spread the expectations
> > over multiple, separatedly locked buckets...
>
> I've talked to Harald about this and as a start we can start by
> allowing masks only for the source part of the tuple. That
> means we can hash by destinations.

That's actually fine! Now I should complete that hashtrie/hashtable
testing I have been planning...

Best regards,
Jozsef
-
E-mail  : kadlec at blackhole.kfki.hu, kadlec at sunserv.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary



More information about the netfilter-devel mailing list