OpenVZ Forum


Home » Mailing lists » Devel » [PATCH 2.6.21-rc6] [netfilter] early_drop imrovement
Re: [NETFILTER] early_drop() imrovement (v4) [message #14931 is a reply to message #14588] Tue, 03 July 2007 06:39 Go to previous messageGo to previous message
Martin Josefsson is currently offline  Martin Josefsson
Messages: 1
Registered: July 2007
Junior Member
On Tue, 3 Jul 2007, Rusty Russell wrote:

> This looks good. The randomness in the hash means we no longer need the
> "hit the same hash bucket" heuristic to avoid hashbombing.
>
> I still wonder if we should batch up the drops a little while we're
> doing all this work? Should reduce stress under serious flood load.

Yes we should really do that, going searching for something to evict
for each new connection attempt is really painful and in this
overload situation we need all the cpu we can get.

/Martin
 
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: [PATCH 1/2] signal checkpoint: define /proc/pid/sig/
Next Topic: [PATCH] .gitignore update
Goto Forum:
  


Current Time: Fri Aug 01 07:09:20 GMT 2025

Total time taken to generate the page: 0.84757 seconds