[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <20220830091453.286285-1-xu.xin16@zte.com.cn>
Date: Tue, 30 Aug 2022 09:14:53 +0000
From: cgel.zte@...il.com
To: davem@...emloft.net, kuba@...nel.org, yoshfuji@...ux-ipv6.org,
dsahern@...nel.org
Cc: netdev@...r.kernel.org, linux-kernel@...r.kernel.org,
xu.xin16@....com.cn
Subject: [PATCH v3 0/3] Namespaceify two sysctls related with route
From: xu xin <xu.xin16@....com.cn>
With the rise of cloud native, more and more container applications are
deployed. The network namespace is one of the foundations of the container.
The sysctls of error_cost and error_burst are important knobs to control
the sending frequency of ICMP_DEST_UNREACH packet for ipv4. When different
containers has requirements on the tuning of error_cost and error_burst,
for host's security, the sysctls should exist per network namespace.
Different netns has different requirements on the setting of error_cost
and error_burst, which are related with limiting the frequency of sending
ICMP_DEST_UNREACH packets. Enable them to be configured per netns.
xu xin (3):
ipv4: Namespaceify route/error_cost knob
ipv4: Namespaceify route/error_burst knob
ipv4: add documentation of two sysctls about icmp
Documentation/networking/ip-sysctl.rst | 17 ++++++++++++
include/net/netns/ipv4.h | 2 ++
net/ipv4/route.c | 36 ++++++++++++++------------
3 files changed, 39 insertions(+), 16 deletions(-)
--
2.25.1
Powered by blists - more mailing lists