[PATCH v3 0/3] Namespaceify two sysctls related with route

From: cgel . zte
Date: Tue Aug 30 2022 - 05:15:21 EST


From: xu xin <xu.xin16@xxxxxxxxxx>

With the rise of cloud native, more and more container applications are
deployed. The network namespace is one of the foundations of the container.
The sysctls of error_cost and error_burst are important knobs to control
the sending frequency of ICMP_DEST_UNREACH packet for ipv4. When different
containers has requirements on the tuning of error_cost and error_burst,
for host's security, the sysctls should exist per network namespace.

Different netns has different requirements on the setting of error_cost
and error_burst, which are related with limiting the frequency of sending
ICMP_DEST_UNREACH packets. Enable them to be configured per netns.

xu xin (3):
ipv4: Namespaceify route/error_cost knob
ipv4: Namespaceify route/error_burst knob
ipv4: add documentation of two sysctls about icmp

Documentation/networking/ip-sysctl.rst | 17 ++++++++++++
include/net/netns/ipv4.h | 2 ++
net/ipv4/route.c | 36 ++++++++++++++------------
3 files changed, 39 insertions(+), 16 deletions(-)

--
2.25.1