Le 06/06/2024 à 10:53, Florian Westphal a écrit :
Nicolas Dichtel nicolas.dichtel@6wind.com wrote:
I understand it's "sad" to keep nf_conntrack_events=1, but this change breaks the backward compatibility. A container migrated to a host with a recent kernel is broken. Usually, in the networking stack, sysctl are added to keep the legacy behavior and enable new systems to use "modern" features. There are a lot of examples :)
Weeks of work down the drain. I wonder if we can make any changes aside from bug fixes in the future.
The commit doesn't remove the optimization, it only keeps the existing behavior. Systems that require this optimization, could still turn nf_conntrack_event to 2.