[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20181003153719.ukchffiac7dr6qlt@salvia>
Date: Wed, 3 Oct 2018 17:37:19 +0200
From: Pablo Neira Ayuso <pablo@...filter.org>
To: Chenbo Feng <chenbofeng.kernel@...il.com>
Cc: netdev@...r.kernel.org, netfilter-devel@...r.kernel.org,
kernel-team@...roid.com, Lorenzo Colitti <lorenzo@...gle.com>,
maze@...gle.com, Chenbo Feng <fengc@...gle.com>
Subject: Re: [PATCH net-next] netfilter: xt_quota: fix the behavior of
xt_quota module
On Mon, Oct 01, 2018 at 06:23:08PM -0700, Chenbo Feng wrote:
> From: Chenbo Feng <fengc@...gle.com>
>
> A major flaw of the current xt_quota module is that quota in a specific
> rule gets reset every time there is a rule change in the same table. It
> makes the xt_quota module not very useful in a table in which iptables
> rules are changed at run time. This fix introduces a new counter that is
> visible to userspace as the remaining quota of the current rule. When
> userspace restores the rules in a table, it can restore the counter to
> the remaining quota instead of resetting it to the full quota.
Applied, thanks.
Powered by blists - more mailing lists