Vasily Averin 9446ab34ac netfilter: ipset: enable memory accounting for ipset allocations
Currently netadmin inside non-trusted container can quickly allocate
whole node's memory via request of huge ipset hashtable.
Other ipset-related memory allocations should be restricted too.

v2: fixed typo ALLOC -> ACCOUNT

Signed-off-by: Vasily Averin <vvs@virtuozzo.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
2020-10-04 21:08:25 +02:00
..
2020-09-18 14:12:43 -07:00
2020-06-23 20:27:09 -07:00
2020-09-18 14:12:43 -07:00
2020-08-27 07:55:59 -07:00
2020-09-20 19:09:11 -07:00
2020-07-13 17:20:40 -07:00