+1
−1
+22
−22
Loading
nftables replaces iptables, but it lacks memcg accounting. This patch account most of the memory allocation associated with nft and should protect the host from misusing nft inside a memcg restricted container. Signed-off-by:Vasily Averin <vvs@openvz.org> Signed-off-by:
Pablo Neira Ayuso <pablo@netfilter.org>