Vasily Averin 33758c8914 memcg: enable accounting for nft objects
nftables replaces iptables, but it lacks memcg accounting.

This patch account most of the memory allocation associated with nft
and should protect the host from misusing nft inside a memcg restricted
container.

Signed-off-by: Vasily Averin <vvs@openvz.org>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
2022-03-28 10:11:23 +02:00
..
2022-03-07 09:48:55 +01:00
2022-01-22 08:33:37 +02:00
2021-11-23 20:16:22 -08:00
2022-01-06 12:33:35 +00:00
2022-02-15 14:54:40 +00:00
2022-02-10 15:29:39 +00:00
2022-03-18 13:30:52 +00:00
2022-02-28 15:39:53 +01:00
2021-07-29 15:06:49 +01:00