[Bug 1584] nft large sets load high memory requirements

bugzilla-daemon at netfilter.org bugzilla-daemon at netfilter.org
Mon Nov 18 13:53:49 CET 2024


https://bugzilla.netfilter.org/show_bug.cgi?id=1584

--- Comment #9 from Pablo Neira Ayuso <pablo at netfilter.org> ---
more improvements in userspace:

20f1c60ac8c8 src: collapse set element commands from parser
193faa5475a5 json: collapse set element commands from parser

depending on ruleset pattern.

Kernel patches also got merge to reduce memory consumption:

commit 0e1ea651c9717ddcd8e0648d8468477a31867b0a
Author: Pablo Neira Ayuso <pablo at netfilter.org>
Date:   Mon Oct 16 14:29:27 2023 +0200

    netfilter: nf_tables: shrink memory consumption of set elements

available since Linux kernel 6.8

more recently, Florian Westphal reduced kernel memory consumption for element
ever further, that will be available in the upcoming kernel 6.13

-- 
You are receiving this mail because:
You are watching all bug changes.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.netfilter.org/pipermail/netfilter-buglog/attachments/20241118/d35d3c1c/attachment.html>


More information about the netfilter-buglog mailing list