Re: [PATCH v3 0/3] Namespaceify two sysctls related with route
From: Jakub Kicinski
Date: Wed Aug 31 2022 - 15:58:56 EST
On Tue, 30 Aug 2022 09:14:53 +0000 cgel.zte@xxxxxxxxx wrote:
> With the rise of cloud native, more and more container applications are
> deployed. The network namespace is one of the foundations of the container.
> The sysctls of error_cost and error_burst are important knobs to control
> the sending frequency of ICMP_DEST_UNREACH packet for ipv4. When different
> containers has requirements on the tuning of error_cost and error_burst,
> for host's security, the sysctls should exist per network namespace.
>
> Different netns has different requirements on the setting of error_cost
> and error_burst, which are related with limiting the frequency of sending
> ICMP_DEST_UNREACH packets. Enable them to be configured per netns.
One last time, if v6 doesn't need it, neither should v4.
Seems like you're just trying to check a box.
I'm dropping these patches from patchwork, please don't repost them
again, unless someone from the community voices support for merging
them.