[PATCH] netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation

Shaojie Sun <[email protected]>
Newsgroups gmane.comp.security.firewalls.netfilter.devel
Message-ID <[email protected]>
The documentation for nf_conntrack_expect_max incorrectly states that the
default value is nf_conntrack_buckets / 256. However, the code in
nf_conntrack_expect_init() shows:

    nf_ct_expect_hsize = nf_conntrack_htable_size / 256;
    nf_ct_expect_max = nf_ct_expect_hsize * 4;

This means the default value is actually nf_conntrack_buckets / 64
(i.e. 4 times the hash table size, which defaults to
nf_conntrack_buckets / 256).

Fix the documentation to reflect the correct default value and add
explanation of the calculation.

Signed-off-by: Shaojie Sun <[email protected]>
---
 Documentation/networking/nf_conntrack-sysctl.rst | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/Documentation/networking/nf_conntrack-sysctl.rst b/Documentation/networking/nf_conntrack-sysctl.rst
index 35f889259fcd..77521253fe22 100644
--- a/Documentation/networking/nf_conntrack-sysctl.rst
+++ b/Documentation/networking/nf_conntrack-sysctl.rst
@@ -44,7 +44,8 @@ nf_conntrack_events - BOOLEAN
 
 nf_conntrack_expect_max - INTEGER
 	Maximum size of expectation table.  Default value is
-	nf_conntrack_buckets / 256. Minimum is 1.
+	nf_conntrack_buckets / 64 (i.e. 4 times the hash table size,
+	which defaults to nf_conntrack_buckets / 256). Minimum is 1.
 
 nf_conntrack_frag6_high_thresh - INTEGER
 	default 262144
-- 
2.50.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.