Quoting Gao feng (gaofeng@xxxxxxxxxxxxxx): > Currently the sysctl of netfilter proto is not isolated, so when > changing proto's sysctl in container will cause the host's sysctl > be changed too. it's not expected. > > This patch set adds the namespace support for netfilter protos. Thanks for doing this, Gao, sounds good. (The set has gotten better scrutiny than I could give it, so I'll wait until at least the next submission to attempt a review) -serge -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html