On Thursday 2008-08-21 18:04, adobriyan@xxxxxxxxx wrote: >Make untracked conntrack per-netns. Why? It does not store any useful information per se, it is merely used to add a third type of ct, iow: (a) ct==NULL (b) ct!=NULL (c) ct==&untracked mmap(2)'s return value for example has something similar: (a) mmap(...)==NULL (b) mmap(...)==MMAP_FAILED (c) otherwise The untracked ct is a singleton, and should stay one, unless there are further reasons not to do so. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html