diff options
author | Vasily Averin <vasily.averin@linux.dev> | 2022-03-24 21:05:50 +0300 |
---|---|---|
committer | Pablo Neira Ayuso <pablo@netfilter.org> | 2022-03-28 11:11:23 +0300 |
commit | 33758c891479ea1c736abfee64b5225925875557 (patch) | |
tree | c7c0a388313a1894e13529f422e2265ab830fb00 /net/compat.c | |
parent | f2dd495a8d589371289981d5ed33e6873df94ecc (diff) | |
download | linux-33758c891479ea1c736abfee64b5225925875557.tar.xz |
memcg: enable accounting for nft objects
nftables replaces iptables, but it lacks memcg accounting.
This patch account most of the memory allocation associated with nft
and should protect the host from misusing nft inside a memcg restricted
container.
Signed-off-by: Vasily Averin <vvs@openvz.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
Diffstat (limited to 'net/compat.c')
0 files changed, 0 insertions, 0 deletions