Commit 28faa979 authored by David S. Miller's avatar David S. Miller

ipsec: Make xfrm_larval_drop default to 1.

The previous default behavior is definitely the least user
friendly.  Hanging there forever just because the keying
daemon is wedged or the refreshing of the policy can't move
forward is anti-social to say the least.
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent ded67c0e
...@@ -34,7 +34,7 @@ ...@@ -34,7 +34,7 @@
#include "xfrm_hash.h" #include "xfrm_hash.h"
int sysctl_xfrm_larval_drop __read_mostly; int sysctl_xfrm_larval_drop __read_mostly = 1;
#ifdef CONFIG_XFRM_STATISTICS #ifdef CONFIG_XFRM_STATISTICS
DEFINE_SNMP_STAT(struct linux_xfrm_mib, xfrm_statistics) __read_mostly; DEFINE_SNMP_STAT(struct linux_xfrm_mib, xfrm_statistics) __read_mostly;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment