Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [iptables PATCH] tests: shell: Test for false-positive rule check
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables 2/2] ebtables-nft: add broute table emulation
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables v2] build: use pkg-config for libpcap
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables 2/2] ebtables-nft: add broute table emulation
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: [PATCH iptables 2/2] ebtables-nft: add broute table emulation
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [PATCH nft 2/4] evaluate: bogus missing transport protocol
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/4] revisit NAT redirect support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/4] optimize: assert nat type on nat statement helper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 4/4] optimize: support for redirect and masquerade
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/4] netlink_delinearize: do not reset protocol context for nat protocol expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] ip6tables: Fix checking existence of rule
- From: Phil Sutter <phil@xxxxxx>
- Re: [External] Re: [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: Fei Cheng <chenwei.0515@xxxxxxxxxxxxx>
- Re: [External] Re: [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: Edward Cree <ecree.xilinx@xxxxxxxxx>
- [PATCH iptables 1/2] include: update nf_tables uapi header
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH iptables 2/2] ebtables-nft: add broute table emulation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [External] Re: [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: Fei Cheng <chenwei.0515@xxxxxxxxxxxxx>
- [PATCH iptables] ip6tables: Fix checking existence of rule
- From: Markus Boehme <markubo@xxxxxxxxxx>
- [PATCH nf] netfilter: br_netfilter: fix recent physdev match breakage
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: Edward Cree <ecree.xilinx@xxxxxxxxx>
- Re: [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH v5] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <sven.auhagen@xxxxxxxxxxxx>
- Re: [PATCH v5] netfilter: nf_flow_table: count offloaded flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5] netfilter: nf_flow_table: count offloaded flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5] netfilter: nf_flow_table: count offloaded flows
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH iptables v2] build: use pkg-config for libpcap
- From: Alyssa Ross <hi@xxxxxxxxx>
- Re: [PATCH iptables] build: use pkg-config for libpcap
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH iptables] build: use pkg-config for libpcap
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [syzbot] WARNING: proc registration bug in clusterip_tg_check (3)
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- Re: [PATCH iptables] build: use pkg-config for libpcap
- From: Alyssa Ross <hi@xxxxxxxxx>
- Re: [PATCH iptables] build: use pkg-config for libpcap
- From: Alyssa Ross <hi@xxxxxxxxx>
- Re: [PATCH iptables] build: use pkg-config for libpcap
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH iptables] build: use pkg-config for libpcap
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on
- From: Fei Cheng <chenwei.0515@xxxxxxxxxxxxx>
- [PATCH iptables] build: use pkg-config for libpcap
- From: Alyssa Ross <hi@xxxxxxxxx>
- Re: [GIT PULL] netfilter updates for net-next 2023-03-30
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [GIT PULL] netfilter updates for net-next 2023-03-30
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 0/4] netfilter updates for net-next
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH net-next 4/4] netfilter: ctnetlink: Support offloaded conntrack entry deletion
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 3/4] netfilter: Correct documentation errors in nf_tables.h
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 2/4] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 1/4] netfilter: nfnetlink_log: remove rcu_bh usage
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 0/4] netfilter updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC PATCH v2] nft: autocomplete for libreadline
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- RE: [RFC PATCH] nft: autocomplete for libreadline
- From: Jan Engelhardt <jengelh@xxxxxxx>
- RE: [RFC PATCH] nft: autocomplete for libreadline
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [RFC PATCH] nft: autocomplete for libreadline
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [RFC PATCH] nft: autocomplete for libreadline
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [nft PATCH] xt: Fix translation error path
- From: Phil Sutter <phil@xxxxxx>
- RE: iptables patch
- From: Kevin Peeters <kevin.peeters@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: Correct documentation errors in nf_tables.h
- From: Matthieu De Beule <matthieu.debeule@xxxxxxxxx>
- Re: iptables patch
- From: Phil Sutter <phil@xxxxxx>
- RE: iptables patch
- From: Kevin Peeters <kevin.peeters@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nfnetlink_log: remove rcu_bh usage
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: iptables patch
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nftables] exthdr: add boolean DCCP option matching
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] xt: Fix translation error path
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft,v3 07/12] evaluate: honor statement length in bitwise evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft,v3 05/12] evaluate: set up integer type to shift expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: iptables patch
- From: Kevin Peeters <kevin.peeters@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH v5] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Eric Sage <eric_sage@xxxxxxxxx>
- Re: [lvc-project] [PATCH] netfilter: nfnetlink: NULL-check skb->dev in __build_packet_message()
- From: "Igor A. Artemiev" <Igor.A.Artemiev@xxxxxxx>
- [PATCH nft] intervals: use expression location when translating to intervals
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] exthdr: add boolean DCCP option matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [lvc-project] [PATCH] netfilter: nfnetlink: NULL-check skb->dev in __build_packet_message()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [lvc-project] [PATCH] netfilter: nfnetlink: NULL-check skb->dev in __build_packet_message()
- From: Igor Artemiev <Igor.A.Artemiev@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH v4] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Eric Sage <eric_sage@xxxxxxxxx>
- Re: [PATCH v3] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v3 0/4] Support for shifted port-ranges in NAT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Stanislav Fomichev <sdf@xxxxxxxxxx>
- [PATCH nf-next v3 4/4] netfilter: nft_redir: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 3/4] netfilter: nft_masq: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 2/4] netfilter: nft_nat: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 1/4] netfilter: nat: extend core support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 0/4] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 0/3] bpf: add netfilter program type
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Stanislav Fomichev <sdf@xxxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH nftables 0/8] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nftables 0/8] Support for shifted port-ranges in NAT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 1/5] netfilter: nft_redir: use `struct nf_nat_range2` throughout and deduplicate eval call-backs
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH v3] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Eric Sage <eric_sage@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Stanislav Fomichev <sdf@xxxxxxxxxx>
- Re: [PATCH nft] payload: set byteorder when completing expression
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH v2] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] payload: set byteorder when completing expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Eric Sage <eric_sage@xxxxxxxxx>
- [PATCH nft,v3 11/12] tests: shell: add test-cases for ct and packet mark payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 12/12] tests: py: extend test-cases for mark statements with bitwise expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 09/12] tests: py: add test-cases for ct and packet mark payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 04/12] evaluate: relax type-checking for integer arguments in mark statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 10/12] tests: shell: rename and move bitwise test-cases
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 07/12] evaluate: honor statement length in bitwise evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 02/12] evaluate: support shifts larger than the width of the left operand
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 08/12] netlink_delinerize: incorrect byteorder in mark statement listing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 06/12] evaluate: honor statement length in integer evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 05/12] evaluate: set up integer type to shift expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 03/12] evaluate: don't eval unary arguments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 00/12] mark statement support for non-constant expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 01/12] netlink_delinearize: correct type and byte-order of shifts
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion
- From: Simon Horman <simon.horman@xxxxxxxxxxxx>
- [PATCH v10 13/13] landlock: Document Landlock's network support
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 11/13] selftests/landlock: Add 10 new test suites dedicated to network
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 09/13] landlock: Add network rules and TCP hooks support
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 12/13] samples/landlock: Add network demo
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 10/13] selftests/landlock: Share enforce_ruleset()
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 08/13] landlock: Refactor landlock_add_rule() syscall
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 07/13] landlock: Refactor layer helpers
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 06/13] landlock: Move and rename layer helpers
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 05/13] landlock: Refactor merge/inherit_ruleset functions
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 03/13] landlock: Remove unnecessary inlining
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 04/13] landlock: Refactor landlock_find_rule/insert_rule
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 02/13] landlock: Allow filesystem layout changes for domains without such rule type
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 01/13] landlock: Make ruleset's access masks more generic
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH v10 00/13] Network support for Landlock
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 0/3] bpf: add netfilter program type
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: nfnetlink_queue: enable classid socket info retrieval
- From: eric_sage@xxxxxxxxx
- [PATCH nft,v2 7/8] tests: shell: rename and move bitwise test-cases
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 6/8] tests: py: add test-cases for ct and packet mark payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 8/8] tests: shell: add test-cases for ct and packet mark payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 5/8] evaluate: relax type-checking for integer arguments in mark statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 0/8] mark statement support for non-constant expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 1/8] netlink_delinearize: correct type and byte-order of shifts
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 2/8] evaluate: support shifts larger than the width of the left operand
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 4/8] evaluate: get length from statement instead of lhs expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 3/8] evaluate: don't eval unary arguments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 5/5] netfilter: keep conntrack reference until IPsecv6 policy checks are done
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 4/5] xtables: move icmp/icmpv6 logic to xt_tcpudp
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 3/5] netfilter: xtables: disable 32bit compat interface by default
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 2/5] netfilter: nft_masq: deduplicate eval call-backs
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 1/5] netfilter: nft_redir: use `struct nf_nat_range2` throughout and deduplicate eval call-backs
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 0/5] netfilter updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion
- From: Paul Blakey <paulb@xxxxxxxxxx>
- Re: [PATCH net-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH] net : netfilter: Keep conntrack reference until IPsecv6 policy checks are done
- From: Madhu Koriginja <madhu.koriginja@xxxxxxx>
- [PATCH net-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion
- From: Paul Blakey <paulb@xxxxxxxxxx>
- Re: [nft PATCH 1/2] Reduce signature of do_list_table()
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list
- From: Kyuwon Shim <Kyuwon.Shim@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list
- From: Kyuwon Shim <Kyuwon.Shim@xxxxxxxxxxxxxxxxxxx>
- [nft PATCH 1/2] Reduce signature of do_list_table()
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/2] Avoid a memleak with 'reset rules' command
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH v5] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <Sven.Auhagen@xxxxxxxxxxxx>
- Re: [PATCH ulogd2 v3 0/2] pcap: prevent crashes when output `FILE *` is null
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 4/9] evaluate: don't eval unary arguments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 7/9] tests: py: add test-cases for ct and packet mark payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/9] netlink_delinearize: correct type and byte-order of shifts
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/9] evaluate: insert byte-order conversions for expressions between 9 and 15 bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/9] mark statement support for non-constant expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 6/9] evaluate: relax type-checking for integer arguments in mark statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/9] evaluate: support shifts larger than the width of the left operand
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 8/9] tests: shell: rename and move bitwise test-cases
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 5/9] evaluate: get length from statement instead of lhs expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 9/9] tests: shell: add test-cases for ct and packet mark payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ulogd2 v3 0/2] pcap: prevent crashes when output `FILE *` is null
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ulogd2 v3 1/2] pcap: simplify opening of output file
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH ulogd2 v3 1/2] pcap: simplify opening of output file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next] xtables: move icmp/icmpv6 logic to xt_tcpudp
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: xtables: disable 32bit compat interface by default
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ulogd2 v3 0/2] pcap: prevent crashes when output `FILE *` is null
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ulogd2 v3 1/2] pcap: simplify opening of output file
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ulogd2 v3 1/2] pcap: simplify opening of output file
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH ulogd2 v3 1/2] pcap: simplify opening of output file
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH ulogd2 v3 2/2] pcap: prevent crashes when output `FILE *` is null
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH ulogd2 v3 0/2] pcap: prevent crashes when output `FILE *` is null
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH net-next] net: netfilter: Keep conntrack reference until IPsecv6 policy checks are done
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ulogd2 v2] pcap: prevent crashes when output `FILE *` is null
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] Correct documentation errors in nf_tables.h
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 1/2] netfilter: nft_redir: use `struct nf_nat_range2` throughout and deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 2/2] netfilter: nft_masq: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 0/2] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 0/2] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: nft_masq: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nft_redir: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH ulogd2 v2] pcap: prevent crashes when output `FILE *` is null
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] meta: don't crash if meta key isn't known
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <sven.auhagen@xxxxxxxxxxxx>
- Re: [PATCH v4] netfilter: nf_flow_table: count offloaded flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ipset PATCH] tests: hash:ip,port.t: Replace VRRP by GRE protocol
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH v4] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <sven.auhagen@xxxxxxxxxxxx>
- Re: [PATCH libnftnl] expr: meta: introduce broute meta expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4] netfilter: nf_flow_table: count offloaded flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft,v3] parser_bison: simplify reset syntax
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3] parser_bison: simplify reset syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft,v2] parser_bison: simplify reset syntax
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft,v2] parser_bison: simplify reset syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: simplify reset syntax
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] parser_bison: simplify reset syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 00/12] Network support for Landlock
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] Correct documentation errors in nf_tables.h
- From: Matthieu De Beule <matthieu.debeule@xxxxxxxxx>
- [PATCH nft] Revert "evaluate: relax type-checking for integer arguments in mark statements"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] nftables 1.0.7 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v9 00/12] Network support for Landlock
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: nft_masq: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 0/3] NF NAT deduplication refactoring
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nft_redir: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next v2 0/9] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next v2 0/9] Support for shifted port-ranges in NAT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH nftables] src: fix a couple of typo's in comments
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nftables] exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nftables] exthdr: add boolean DCCP option matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables] exthdr: add boolean DCCP option matching
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: nft_nat: correct length for loading protocol registers
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [ipset PATCH] tests: hash:ip,port.t: Replace VRRP by GRE protocol
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] src: improve error reporting for unsupported chain type
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] cmd: move command functions to src/cmd.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ipset PATCH] tests: hash:ip,port.t: Replace VRRP by GRE protocol
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: improve error reporting for unsupported chain type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ipset PATCH] tests: hash:ip,port.t: Replace VRRP by GRE protocol
- From: Phil Sutter <phil@xxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Phil Sutter <phil@xxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ipset PATCH 0/4] Some testsuite improvements
- From: Phil Sutter <phil@xxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Phil Sutter <phil@xxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Phil Sutter <phil@xxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ipset PATCH 0/4] Some testsuite improvements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] xt: Fix fallback printing for extensions matching keywords
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2] Reject invalid chain priority values in user space
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2] Reject invalid chain priority values in user space
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH v2] Reject invalid chain priority values in user space
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 0/4] Netfilter fixes for net
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [nft PATCH] Reject invalid chain priority values in user space
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] Reject invalid chain priority values in user space
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/9] netfilter: bridge: introduce broute meta statement
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [nft PATCH] Reject invalid chain priority values in user space
- From: Phil Sutter <phil@xxxxxx>
- Re: [ANNOUNCE] libnftnl 1.2.5 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] libnftnl 1.2.5 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/4] netfilter: nft_redir: correct value of inet type `.maxattrs`
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/4] netfilter: nft_redir: correct length for loading protocol registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/4] netfilter: nft_masq: correct length for loading protocol registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/4] netfilter: nft_nat: correct length for loading protocol registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] xt: Fix fallback printing for extensions matching keywords
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] xt: Fix fallback printing for extensions matching keywords
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/4] NAT fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list
- From: Kyuwon Shim <kyuwon.shim@xxxxxxxxxxxxxxxxxxx>
- [PATCH net-next 9/9] netfilter: nat: fix indentation of function arguments
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 8/9] netfilter: conntrack: fix typo
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 7/9] selftests: add a selftest for big tcp
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 6/9] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 5/9] netfilter: move br_nf_check_hbh_len to utils
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 4/9] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 3/9] netfilter: bridge: check len before accessing more nh data
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 2/9] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 0/9] Netfilter updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 1/9] netfilter: bridge: introduce broute meta statement
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/4] NAT fixes
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCHv2 nf-next 6/6] selftests: add a selftest for big tcp
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 1/9] netfilter: conntrack: fix typo
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 7/9] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 4/9] netfilter: nft_nat: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 3/9] netfilter: nat: extend core support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 8/9] netfilter: nft_redir: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 5/9] netfilter: nft_masq: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 0/9] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 9/9] netfilter: nft_redir: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 6/9] netfilter: nft_masq: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 2/9] netfilter: nat: fix indentation of function arguments
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf 2/4] netfilter: nft_masq: correct length for loading protocol registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf 4/4] netfilter: nft_redir: correct value of inet type `.maxattrs`
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf 0/4] NAT fixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf 1/4] netfilter: nft_nat: correct length for loading protocol registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf 3/4] netfilter: nft_redir: correct length for loading protocol registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCHv2 nf-next 6/6] selftests: add a selftest for big tcp
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCHv2 nf-next 4/6] netfilter: move br_nf_check_hbh_len to utils
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCHv2 nf-next 5/6] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCHv2 nf-next 3/6] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCHv2 nf-next 2/6] netfilter: bridge: check len before accessing more nh data
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCHv2 nf-next 1/6] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCHv2 nf-next 0/6] netfilter: handle ipv6 jumbo packets properly for bridge ovs and tc
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH nf-next 5/6] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH nf-next 6/6] selftests: add a selftest for big tcp
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH nf-next 00/13] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next 12/13] netfilter: nft_redir: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next 05/13] netfilter: nft_nat: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next 4/6] netfilter: move br_nf_check_hbh_len to utils
- From: Aaron Conole <aconole@xxxxxxxxxx>
- Re: [PATCH nf-next 6/6] selftests: add a selftest for big tcp
- From: Aaron Conole <aconole@xxxxxxxxxx>
- Re: [PATCH nf-next 3/6] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len
- From: Aaron Conole <aconole@xxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: bridge: check len before accessing more nh data
- From: Aaron Conole <aconole@xxxxxxxxxx>
- Re: [PATCH nf-next 1/6] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len
- From: Aaron Conole <aconole@xxxxxxxxxx>
- Re: [PATCH nf-next 5/6] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Aaron Conole <aconole@xxxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [ipset PATCH 2/4] tests: xlate: Make test input valid
- From: Phil Sutter <phil@xxxxxx>
- [ipset PATCH 0/4] Some testsuite improvements
- From: Phil Sutter <phil@xxxxxx>
- [ipset PATCH 3/4] tests: cidr.sh: Add ipcalc fallback
- From: Phil Sutter <phil@xxxxxx>
- [ipset PATCH 1/4] tests: xlate: Test built binary by default
- From: Phil Sutter <phil@xxxxxx>
- [ipset PATCH 4/4] tests: hash:ip,port.t: 'vrrp' is printed as 'carp'
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH nf-next 00/13] Support for shifted port-ranges in NAT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 12/13] netfilter: nft_redir: deduplicate eval call-backs
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 10/13] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 05/13] netfilter: nft_nat: add support for shifted port-ranges
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 2/3] netfilter: tproxy: fix deadlock due to missing BH disable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: conntrack: adopt safer max chain length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: conntrack:
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 5/6] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 4/6] netfilter: move br_nf_check_hbh_len to utils
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/6] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: bridge: check len before accessing more nh data
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/6] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: conntrack:
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [PATCH net] netfilter: conntrack:
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 12/12] landlock: Document Landlock's network support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH nf-next 5/6] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Simon Horman <simon.horman@xxxxxxxxxxxx>
- Re: [PATCH nf-next 4/6] netfilter: move br_nf_check_hbh_len to utils
- From: Simon Horman <simon.horman@xxxxxxxxxxxx>
- Re: [PATCH nf-next 3/6] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len
- From: Simon Horman <simon.horman@xxxxxxxxxxxx>
- Re: [PATCH v9 12/12] landlock: Document Landlock's network support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: bridge: check len before accessing more nh data
- From: Simon Horman <simon.horman@xxxxxxxxxxxx>
- Re: [PATCH nf-next 1/6] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len
- From: Simon Horman <simon.horman@xxxxxxxxxxxx>
- Re: [PATCH v9 12/12] landlock: Document Landlock's network support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: tproxy: fix deadlock due to missing BH disable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 06/12] landlock: Refactor _unmask_layers() and _init_layer_masks()
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 00/12] Network support for Landlock
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH nf-next 13/13] netfilter: nft_redir: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 11/13] netfilter: nft_redir: correct length for loading protocol registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 10/13] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 12/13] netfilter: nft_redir: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 05/13] netfilter: nft_nat: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 00/13] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 08/13] netfilter: nft_masq: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 01/13] netfilter: conntrack: fix typo
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 04/13] netfilter: nft_nat: correct length for loading protocol registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 09/13] netfilter: nft_redir: correct value of inet type `.maxattrs`
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 02/13] netfilter: nat: fix indentation of function arguments
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 07/13] netfilter: nft_masq: deduplicate eval call-backs
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 03/13] netfilter: nat: extend core support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 06/13] netfilter: nft_masq: correct length for loading protocol registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 3/3] redir: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 2/3] masq: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 1/3] nat: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 0/3] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 4/8] json: formatting fixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 3/8] redir: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 6/8] doc: correct NAT statement description
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 8/8] test: py: add tests for shifted nat port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 0/8] Support for shifted port-ranges in NAT
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 7/8] doc: add shifted port-ranges to nat statements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 2/8] masq: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 1/8] nat: add support for shifted port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 5/8] json: add support for shifted nat port-ranges
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [nft PATCH v4 13/32] evaluate: support shifts larger than the width of the left operand
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 6/6] selftests: add a selftest for big tcp
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf-next 5/6] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf-next 4/6] netfilter: move br_nf_check_hbh_len to utils
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf-next 2/6] netfilter: bridge: check len before accessing more nh data
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf-next 3/6] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf-next 1/6] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf-next 0/6] netfilter: handle ipv6 jumbo packets properly for bridge ovs and tc
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf] netfilter: tproxy: fix deadlock due to missing BH disable
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Major Dávid <major.david@xxxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Major Dávid <major.david@xxxxxxxxxx>
- [PATCH v2] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Ivan Delalande <colona@xxxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 3/3] bpf: minimal support for programs hooked into netfilter framework
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 3/3] bpf: minimal support for programs hooked into netfilter framework
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Stanislav Fomichev <sdf@xxxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 0/3] bpf: add netfilter program type
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: [PATCH RFC v2 bpf-next 3/3] bpf: minimal support for programs hooked into netfilter framework
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: Bug report DNAT destination not work
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH RFC v2 bpf-next 3/3] bpf: minimal support for programs hooked into netfilter framework
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH RFC v2 bpf-next 2/3] libbpf: sync header file, add nf prog section name
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH RFC v2 bpf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH RFC v2 bpf-next 0/3] bpf: add netfilter program type
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Major Dávid <major.david@xxxxxxxxxx>
- Re: CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Florian Westphal <fw@xxxxxxxxx>
- CPU soft lockup in a spin lock using tproxy and nfqueue
- From: Major Dávid <major.david@xxxxxxxxxx>
- Re: Bug report DNAT destination not work
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: [PATCH] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Bug report DNAT destination not work
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: [PATCH] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Bug report DNAT destination not work
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/3] selftests: nft_nat: ensuring the listening side is up before starting the client
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] netfilter: ctnetlink: revert to dumping mark regardless of event type
- From: Ivan Delalande <colona@xxxxxxxxxx>
- Re: [ipset PATCH 0/2] Two minor code fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] selftests: nft_nat: ensuring the listening side is up before starting the client
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nft_quota: copy content when cloning expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nft_last: copy content when cloning expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft-restore: Fix for deletion of new, referenced rule
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] nft-restore: Fix for deletion of new, referenced rule
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nf] selftests: nft_nat: ensuring the listening side is up before starting the client
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] tests: shell: use bash in 0011reset_0
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] cache: fetch more objects when resetting rule
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: allow to use quota in sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_quota: copy content when cloning expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_last: copy content when cloning expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] nft-restore: Fix for deletion of new, referenced rule
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft,v2] src: add last statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3] evaluate: expand value to range when nat mapping contains intervals
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v4] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <Sven.Auhagen@xxxxxxxxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Bryce Kahle <bryce.kahle@xxxxxxxxxxxxx>
- [PATCH nft,v2] evaluate: expand value to range when nat mapping contains intervals
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] selftests: nft_nat: ensuring the listening side is up before starting the client
- From: Hangbin Liu <liuhangbin@xxxxxxxxx>
- Re: [PATCH v3] netfilter: nf_flow_table: count offloaded flows
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v3] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <Sven.Auhagen@xxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <sven.auhagen@xxxxxxxxxxxx>
- [PATCH AUTOSEL 5.15 22/36] netfilter: nf_tables: NULL pointer dereference in nf_tables_updobj()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 6.1 28/49] netfilter: nf_tables: NULL pointer dereference in nf_tables_updobj()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 6.2 30/53] netfilter: nf_tables: NULL pointer dereference in nf_tables_updobj()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_flow_table: count offloaded flows
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v2] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <Sven.Auhagen@xxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <sven.auhagen@xxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_flow_table: count offloaded flows
- From: Julian Anastasov <ja@xxxxxx>
- RE: [PATCH nft v2] meta: introduce broute expression
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- [PATCH libnftnl] expr: meta: introduce broute meta expression
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- [PATCH nft v3] meta: introduce broute expression
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [PATCH] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <sven.auhagen@xxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_flow_table: count offloaded flows
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH] netfilter: nf_flow_table: count offloaded flows
- From: Sven Auhagen <Sven.Auhagen@xxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: bridge: introduce broute meta statement
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v2] meta: introduce broute expression
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/2,v2] src: expand table command before evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2,v2] tests: shell: cover rule insertion by index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v2] meta: introduce broute expression
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- [PATCH nf-next v2] netfilter: bridge: introduce broute meta statement
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [PATCH nf-next] netfilter: bridge: introduce broute meta statement
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: [PATCH nf-next] netfilter: bridge: introduce broute meta statement
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [PATCH nft] meta: introduce broute expression
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: bridge: introduce broute meta statement
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v9 00/12] Network support for Landlock
- From: Günther Noack <gnoack3000@xxxxxxxxx>
- [PATCH nft 2/2] src: expand table command before evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] tests: shell: cover rule insertion by index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: bridge: introduce broute meta statement
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH nft] meta: introduce broute expression
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- [PATCH nf-next] netfilter: bridge: introduce broute meta statement
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [iptables PATCH] include: Add missing linux/netfilter/xt_LOG.h
- From: Phil Sutter <phil@xxxxxx>
- Re: [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/8] netfilter: nf_tables: allow to fetch set elements when table has an owner
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: expand value to range in nat mapping with intervals
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ipset PATCH 0/2] Two minor code fixes
- From: Phil Sutter <phil@xxxxxx>
- [ipset PATCH 1/2] xlate: Fix for fd leak in error path
- From: Phil Sutter <phil@xxxxxx>
- [ipset PATCH 2/2] xlate: Drop dead code
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Phil Sutter <phil@xxxxxx>
- RE: [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- RE: [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Thomas Devoogdt <thomas@xxxxxxxxxxxx>
- [iptables PATCH] include: Add missing linux/netfilter/xt_LOG.h
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] parser_bison: missing close scope in destroy start condition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Phil Sutter <phil@xxxxxx>
- Re: [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC nf-next PATCH] netfilter: nft: introduce broute chain type
- From: Sriram Yagnaraman <sriram.yagnaraman@xxxxxxxx>
- [PATCH v2] [iptables] include: netfilter: add xt_LOG.h to fix an include error on Linux < 3.4
- From: Thomas Devoogdt <thomas@xxxxxxxxxxxx>
- [PATCH nft] py: replace distutils with setuptools
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/8] netfilter: ip6t_rpfilter: Fix regression with VRF interfaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/8] netfilter: conntrack: fix rmmod double-free race
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/8] netfilter: xt_length: use skb len to match in length_mt6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 8/8] netfilter: x_tables: fix percpu counter block leak on error path when creating new netns
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/8] netfilter: ebtables: fix table blob use-after-free
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 7/8] netfilter: ctnetlink: make event listener tracking global
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/8] Netfilterf fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/8] netfilter: ctnetlink: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/8] netfilter: nf_tables: allow to fetch set elements when table has an owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: fix percpu counter block leak on error path when creating new netns
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] [iptables] extensions: libxt_LOG.c: fix linux/netfilter/xt_LOG.h include on Linux < 3.4
- From: Thomas Devoogdt <thomas@xxxxxxxxxxxx>
- Kernel panic in nf_send_reset6() path
- From: "Thomas S." <thomashen@xxxxxxxxx>
- Re: [PATCH] netfilter: fix percpu counter block leak on error path when creating new netns
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: fix percpu counter block leak on error path when creating new netns
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ctnetlink: make event listener tracking global
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: use skb len to match in length_mt6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] ebtables: fix table blob use-after-free
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf PATCH] netfilter: Fix regression in ip6t_rpfilter with VRF interfaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: fix rmmod double-free race
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] netlink_delinearize: Sanitize concat data element decoding
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] netlink_delinearize: Sanitize concat data element decoding
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] netlink_delinearize: Sanitize concat data element decoding
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v9 06/12] landlock: Refactor _unmask_layers() and _init_layer_masks()
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH nft 2/2] rule: expand standalone chain that contains rules
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] xt_sctp: add the missing chunk types in sctp_help
- From: Phil Sutter <phil@xxxxxx>
- [PATCH iptables] xt_sctp: add the missing chunk types in sctp_help
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH v9 12/12] landlock: Document Landlock's network support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [PATCH nf] netfilter: ctnetlink: make event listener tracking global
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/6] netfilter: nf_tables: NULL pointer dereference in nf_tables_updobj()
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH nf] netfilter: use skb len to match in length_mt6
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH nf] ebtables: fix table blob use-after-free
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 1/6] extensions: libebt_redirect: Fix target translation
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/2] tests: xlate: Properly split input in replay mode
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/3] nft-shared: Lookup matches in iptables_command_state
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] tests: CLUSTERIP: Drop test file
- From: Phil Sutter <phil@xxxxxx>
- [syzbot] [bridge?] [coreteam?] KASAN: vmalloc-out-of-bounds Read in __ebt_unregister_table
- From: syzbot <syzbot+f61594de72d6705aea03@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [iptables PATCH 3/6] extensions: libebt_ip: Do not use 'ip dscp' for translation
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/6] extensions: libebt_redirect: Fix target translation
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/6] extensions: libebt_redirect: Fix for wrong syntax in translation
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 4/6] extensions: libebt_ip: Translation has to match on ether type
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 5/6] ebtables: ip and ip6 matches depend on protocol match
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 6/6] xtables-translate: Support insert with index
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/2] tests: xlate: Properly split input in replay mode
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/2] tests: xlate: Print file names even if specified
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/3] nft-shared: Use nft_create_match() in one more spot
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] nft-shared: Lookup matches in iptables_command_state
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/3] nft-shared: Simplify using nft_create_match()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] tests: CLUSTERIP: Drop test file
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next 6/6] netfilter: let reset rules clean out conntrack entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/6] netfilter: nf_tables: NULL pointer dereference in nf_tables_updobj()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/6] netfilter: nf_tables: fix wrong pointer passed to PTR_ERR()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 5/6] ipvs: avoid kfree_rcu without 2nd arg
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 0/6] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 4/6] netfilter: conntrack: remote a return value of the 'seq_print_acct' function.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 3/6] netfilter: conntrack: udp: fix seen-reply test
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Bryce Kahle <bryce.kahle@xxxxxxxxxxxxx>
- [PATCH nft 3/3] optimize: infer family for nat mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/3] evaluate: infer family from mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] evaluate: print error on missing family in nat statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: use start condition with new destroy command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/3] optimize: infer family for nat mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/3] src: use start condition with new destroy command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] evaluate: infer family from mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nf PATCH] netfilter: Fix regression in ip6t_rpfilter with VRF interfaces
- From: Phil Sutter <phil@xxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Phil Sutter <phil@xxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Phil Sutter <phil@xxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Bryce Kahle <bryce.kahle@xxxxxxxxxxxxx>
- Re: PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Florian Westphal <fw@xxxxxxxxx>
- PROBLEM: nf_conntrack_events autodetect mode invalidates NETLINK_LISTEN_ALL_NSID netlink socket option
- From: Bryce Kahle <bryce.kahle@xxxxxxxxxxxxx>
- [PATCH nf v2] netfilter: conntrack: fix rmmod double-free race
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: fix rmmod double-free race
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 03/12] landlock: Refactor landlock_find_rule/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 02/12] landlock: Allow filesystem layout changes for domains without such rule type
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: fix rmmod double-free race
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 03/12] landlock: Refactor landlock_find_rule/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 02/12] landlock: Allow filesystem layout changes for domains without such rule type
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 07/12] landlock: Refactor landlock_add_rule() syscall
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 06/12] landlock: Refactor _unmask_layers() and _init_layer_masks()
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 05/12] landlock: Move and rename umask_layers() and init_layer_masks()
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 03/12] landlock: Refactor landlock_find_rule/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v9 02/12] landlock: Allow filesystem layout changes for domains without such rule type
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH net-next 05/12] netfilter: conntrack: set icmpv6 redirects as RELATED
- From: Wang Hai <wanghai38@xxxxxxxxxx>
- Re: [PATCH net-next 05/12] netfilter: conntrack: set icmpv6 redirects as RELATED
- From: Wang Hai <wanghai38@xxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: fix rmmod double-free race
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Hangyu Hua <hbh25y@xxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Hangyu Hua <hbh25y@xxxxxxxxx>
- [PATCH] netfilter: fix percpu counter block leak on error path when creating new netns
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v9 10/12] selftests/landlock: Add 10 new test suites dedicated to network
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 08/12] landlock: Add network rules and TCP hooks support
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 07/12] landlock: Refactor landlock_add_rule() syscall
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 06/12] landlock: Refactor _unmask_layers() and _init_layer_masks()
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 05/12] landlock: Move and rename umask_layers() and init_layer_masks()
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 03/12] landlock: Refactor landlock_find_rule/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v9 02/12] landlock: Allow filesystem layout changes for domains without such rule type
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] net: netfilter: fix possible refcount leak in ctnetlink_create_conntrack()
- From: Hangyu Hua <hbh25y@xxxxxxxxx>
- Re: [lvc-project] [PATCH] netfilter: xt_recent: Fix attempt to update removed entry
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [lvc-project] [PATCH] netfilter: xt_recent: Fix attempt to update removed entry
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [lvc-project] [PATCH] netfilter: xt_recent: Fix attempt to update removed entry
- From: Florian Westphal <fw@xxxxxxxxx>
- [lvc-project] [PATCH] netfilter: xt_recent: Fix attempt to update removed entry
- From: Igor Artemiev <Igor.A.Artemiev@xxxxxxx>
- [RFC nf-next 3/3] bpf: minimal support for programs hooked into netfilter framework
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC nf-next 2/3] libbpf: sync header file, add nf prog section name
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC nf-next 0/3] bpf, netfilter: minimal support for bpf progs
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC nf-next 1/3] bpf: add bpf_link support for BPF_NETFILTER programs
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: allow to fetch set elements when table has an owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v4 13/32] evaluate: support shifts larger than the width of the left operand
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/1] iptables_lib.sh: Fix for iptables-translate >= v1.8.9
- From: Petr Vorel <pvorel@xxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next] netfilter: let reset rules clean out conntrack entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] optimize: ignore existing nat mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/1] iptables_lib.sh: Fix for iptables-translate >= v1.8.9
- From: Petr Vorel <pvorel@xxxxxxx>
- [PATCH nft 2/2] rule: expand standalone chain that contains rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] rule: add helper function to expand chain rules into commands
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] optimize: select merge criteria based on candidates rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] rule: expand chain that contains rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v6] src: add support to command "destroy"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Phil Sutter <phil@xxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Phil Sutter <phil@xxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next v6 0/7] Allow offloading of UDP NEW connections via act_ct
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH nf-next] netfilter: let reset rules clean out conntrack entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2] netfilter: nf_tables: Introduce NFTA_RULE_ACTUAL_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] optimize: fix incorrect expansion into concatenation with verdict map
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] optimize: wrap code to build concatenation in helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] ipvs: avoid kfree_rcu without 2nd arg
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next] ipvs: avoid kfree_rcu without 2nd arg
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next v6 7/7] netfilter: nf_conntrack: allow early drop of offloaded UDP conns
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 6/7] net/sched: act_ct: offload UDP NEW connections
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 4/7] netfilter: flowtable: cache info of last offload
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 5/7] net/sched: act_ct: set ctinfo in meta action depending on ct state
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 2/7] netfilter: flowtable: fixup UDP timeout depending on ct state
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 3/7] netfilter: flowtable: allow unidirectional rules
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 1/7] net: flow_offload: provision conntrack info in ct_metadata
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH net-next v6 0/7] Allow offloading of UDP NEW connections via act_ct
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH nf-next] netfilter: let reset rules clean out conntrack entries
- From: Florian Westphal <fw@xxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]