Le 06/06/2024 à 10:53, Florian Westphal a écrit : > Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx> wrote: >> I understand it's "sad" to keep nf_conntrack_events=1, but this change breaks >> the backward compatibility. A container migrated to a host with a recent kernel >> is broken. >> Usually, in the networking stack, sysctl are added to keep the legacy behavior >> and enable new systems to use "modern" features. There are a lot of examples :) > > Weeks of work down the drain. I wonder if we can make any changes aside > from bug fixes in the future. The commit doesn't remove the optimization, it only keeps the existing behavior. Systems that require this optimization, could still turn nf_conntrack_event to 2.