← Back to team overview

kernel-packages team mailing list archive

[Bug 1549332] Re: xfrm4_gc_thresh should default to INT_MAX


** Changed in: linux (Ubuntu)
   Importance: Undecided => Medium

** Tags added: cherry-pick

You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux in Ubuntu.

  xfrm4_gc_thresh should default to INT_MAX

Status in linux package in Ubuntu:
  In Progress

Bug description:
  The default xfrm4_gc_thresh (and xfrm6_gc_thresh) value is currently
  32k, but in systems with > 16 cpus, this will (eventually) cause
  failures when ipsec uses too many dst objects.  As xfrm doesn't
  actually manage its dst objects, the flowcache does, this parameter
  doesn't actually control xfrm dst gc, it only causes failures when
  exceeded.  Thus is should simply be set to INT_MAX.

  Upstream commit that fixes this is

To manage notifications about this bug go to: