netfilter: nft_limit: convert to token-based limiting at nanosecond granularity
authorPablo Neira Ayuso <pablo@netfilter.org>
Fri, 31 Jul 2015 12:10:22 +0000 (14:10 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Fri, 7 Aug 2015 09:49:49 +0000 (11:49 +0200)
commitdba27ec1bc382014aa2ba46e96f421b5f6536dae
tree315ad68755c1dc85658effc89e56bc7235b1234e
parent09e4e42a00b99e94cfce27e63b06daca0c26e841
netfilter: nft_limit: convert to token-based limiting at nanosecond granularity

Rework the limit expression to use a token-based limiting approach that refills
the bucket gradually. The tokens are calculated at nanosecond granularity
instead jiffies to improve precision.

Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
net/netfilter/nft_limit.c