Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH nf] netfilter: nft_fwd: really validate family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nft_dup: validate family and chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_fwd: really validate family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_dup: validate family and chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_payload: report ERANGE for too long offset and length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nft_payload: do not truncate csum_offset and csum_type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: make table handle allocation per-netns friendly
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/1] netfilter: flowtable: Fix use after free after freeing flow table
- From: Paul Blakey <paulb@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: make table handle allocation per-netns friendly
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: disallow updates of implicit chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [External] : [PATCH nf] netfilter: ebtables: reject blobs that don't provide all entry points
- From: Harshit Mogalapalli <harshit.m.mogalapalli@xxxxxxxxxx>
- Re: [PATCH nf] nefilter: nft_tproxy: restrict to prerouting hook
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [External] : Re: [PATCH] netfilter: ebtables: fix a NULL pointer dereference in ebt_do_table()
- From: Harshit Mogalapalli <harshit.m.mogalapalli@xxxxxxxxxx>
- [PATCH nf] netfilter: ebtables: reject blobs that don't provide all entry points
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: ebtables: fix a NULL pointer dereference in ebt_do_table()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] nefilter: nft_tproxy: restrict to prerouting hook
- From: Florian Westphal <fw@xxxxxxxxx>
- [BUG] nft_tproxy: Null pointer dereference on local-send UDP
- From: Shell Chen <xierch@xxxxxxxxx>
- [PATCH] netfilter: ebtables: fix a NULL pointer dereference in ebt_do_table()
- From: Harshit Mogalapalli <harshit.m.mogalapalli@xxxxxxxxxx>
- Re: [PATCH bpf-next v3 4/5] bpf: Add support for writing to nf_conn:mark
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/5] bpf: Add support for writing to nf_conn:mark
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/5] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/5] bpf: Add support for writing to nf_conn:mark
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/5] bpf: Add support for writing to nf_conn:mark
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v3 4/5] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v3 1/5] bpf: Remove duplicate PTR_TO_BTF_ID RO check
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v3 0/5] Support direct writes to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v3 2/5] bpf: Add stub for btf_struct_access()
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v3 5/5] selftests/bpf: Add tests for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v3 3/5] bpf: Use 0 instead of NOT_INIT for btf_struct_access() writes
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- [PATCH 5.10 283/545] netfilter: xtables: Bring SPDX identifier back
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: data-race in nf_tables_newtable / nf_tables_newtable
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Raw payload matching beyond 2040 bits
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] bridge: move from strlcpy with unused retval to strscpy
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: move from strlcpy with unused retval to strscpy
- From: Simon Horman <horms@xxxxxxxxxx>
- [PATCH nft v3] src: Don't parse string as verdict in map
- From: Xiao Liang <shaw.leon@xxxxxxxxx>
- [PATCH nft v2] src: Don't parse string as verdict in map
- From: Xiao Liang <shaw.leon@xxxxxxxxx>
- Re: [PATCH net 1/1] netfilter: flowtable: Fix use after free after freeing flow table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: work around exceeded receive window
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: move from strlcpy with unused retval to strscpy
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH] netfilter: move from strlcpy with unused retval to strscpy
- From: Wolfram Sang <wsa+renesas@xxxxxxxxxxxxxxxxxxxx>
- [PATCH] bridge: move from strlcpy with unused retval to strscpy
- From: Wolfram Sang <wsa+renesas@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH nft] src: Don't parse string as verdict in map
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: Don't parse string as verdict in map
- From: Xiao Liang <shaw.leon@xxxxxxxxx>
- Re: [PATCH nft] src: Don't parse string as verdict in map
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: Don't parse string as verdict in map
- From: Xiao Liang <shaw.leon@xxxxxxxxx>
- [PATCH net 1/1] netfilter: flowtable: Fix use after free after freeing flow table
- From: Paul Blakey <paulb@xxxxxxxxxx>
- Re: [PATCH net-next] Remove DECnet support from kernel
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH net 01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net-next] Remove DECnet support from kernel
- From: Stephen Hemminger <stephen@xxxxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Martin KaFai Lau <kafai@xxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH bpf-next v2 2/4] bpf: Add stub for btf_struct_access()
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v2 1/4] bpf: Remove duplicate PTR_TO_BTF_ID RO check
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v2 4/4] selftests/bpf: Add tests for writing to nf_conn:mark
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v2 4/4] selftests/bpf: Add tests for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v2 2/4] bpf: Add stub for btf_struct_access()
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v2 1/4] bpf: Remove duplicate PTR_TO_BTF_ID RO check
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v2 3/4] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v2 0/4] Support direct writes to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: "Daniel Xu" <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: "Daniel Xu" <dxu@xxxxxxxxx>
- [PATCH net 16/17] testing: selftests: nft_flowtable.sh: use random netns names
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 17/17] testing: selftests: nft_flowtable.sh: rework test to detect offload failure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 15/17] netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 14/17] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 13/17] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 12/17] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 11/17] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 06/17] netfilter: nf_ct_ftp: prefer skb_linearize
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 07/17] netfilter: nf_ct_irc: cap packet search space to 4k
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 10/17] netfilter: nf_tables: really skip inactive sets when allocating name
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 09/17] netfilter: nfnetlink: re-enable conntrack expectation events
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 08/17] netfilter: nf_tables: fix scheduling-while-atomic splat
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 02/17] netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERVAL_END flag
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 04/17] netfilter: nf_ct_sane: remove pseudo skb linearization
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 00/17] netfilter: conntrack and nf_tables bug fixes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 05/17] netfilter: nf_ct_h323: cap packet size at 64k
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 03/17] netfilter: nf_tables: possible module reference underflow in error path
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libmnl v3 1/2] libmnl: update attribute function comments to use \return
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl v3 2/2] libmnl: add support for signed types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset-translate: allow invoking with a path name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH nf-next] netfilter: ipvs: Divide estimators into groups
- From: Jiri Wiesner <jwiesner@xxxxxxx>
- [PATCH nf 2/2] testing: selftests: nft_flowtable.sh: rework test to detect offload failure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] testing: selftests: nft_flowtable.sh: use random netns names
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/2] testing: selftests: nft_flowtable.sh: unbreak test script
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: "Daniel Xu" <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- [PATCH 5.19 0617/1157] netfilter: xtables: Bring SPDX identifier back
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH bpf-next 3/3] selftests/bpf: Add tests for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH 5.18 0573/1095] netfilter: xtables: Bring SPDX identifier back
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH bpf-next 1/3] bpf: Remove duplicate PTR_TO_BTF_ID RO check
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next 0/3] Support direct writes to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next 2/3] bpf: Add support for writing to nf_conn:mark
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Add more bpf_*_ct_lookup() selftests
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH 5.15 418/779] netfilter: xtables: Bring SPDX identifier back
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v4 2/2] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y
- From: Geert Uytterhoeven <geert@xxxxxxxxxxxxxx>
- Optimization works only on specific syntax? (was [ANNOUNCE] nftables 1.0.5 release)
- From: Amish <anon.amish@xxxxxxxxx>
- [PATCH nf,v3 2/2] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 2/2] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH nf-next] netfilter: ipvs: Divide estimators into groups
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net 1/3] netfilter: nf_conntrack_tcp: re-init for syn packets only
- From: Thomas Backlund <tmb@xxxxxx>
- Re: [PATCH net 1/3] netfilter: nf_conntrack_tcp: re-init for syn packets only
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nf_tables: validate NFTA_SET_ELEM_KEY_END based on NFT_SET_CONCAT flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: nf_conntrack_tcp: re-init for syn packets only
- From: Neal Cardwell <ncardwell@xxxxxxxxxx>
- [RFC PATCH nf-next] netfilter: ipvs: Divide estimators into groups
- From: Jiri Wiesner <jwiesner@xxxxxxx>
- [PATCH bpf-next v4 0/3] Add more bpf_*_ct_lookup() selftests
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v4 3/3] selftests/bpf: Update CI kconfig
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v4 2/3] selftests/bpf: Add connmark read test
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v4 1/3] selftests/bpf: Add existing connection bpf_*_ct_lookup() test
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Add more bpf_*_ct_lookup() selftests
- From: "Daniel Xu" <dxu@xxxxxxxxx>
- [PATCH] ipset-translate: allow invoking with a path name
- From: Quentin Armitage <quentin@xxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix scheduling-while-atomic splat
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: conntrack: remove 64kb max size assumptions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/2] --optimize fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Upgrading iptables firewall on Red Hat Enterprise Linux 9.0
- From: Phil Sutter <phil@xxxxxx>
- Re: Upgrading iptables firewall on Red Hat Enterprise Linux 9.0
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: Upgrading iptables firewall on Red Hat Enterprise Linux 9.0
- From: Phil Sutter <phil@xxxxxx>
- Re: Upgrading iptables firewall on Red Hat Enterprise Linux 9.0
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix scheduling-while-atomic splat
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] tests: shell: check for a tainted kernel
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: CFS for Netdev 0x16 open!
- From: Ferenc Fejes <ferenc.fejes@xxxxxxxxxxxx>
- Re: Upgrading iptables firewall on Red Hat Enterprise Linux 9.0
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] evaluate: allow implicit ether -> vlan dep
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC] concat with dynamically sized fields like vlan id
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Add more bpf_*_ct_lookup() selftests
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH] Extends py/nftables.py
- From: Peter Collinson <11645080+pcollinson@xxxxxxxxxxxxxxxx>
- Re: [PATCH net 0/8] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/8] netfilter: nf_tables: validate variable length element extension
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 0/8] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 1/8] netfilter: nf_tables: validate variable length element extension
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH nf 3/4] netfilter: conntrack_ftp: prefer skb_linearize
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 5/8] netfilter: ip6t_LOG: Fix a typo in a comment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/8] netfilter: nf_tables: do not allow RULE_ID to refer to another chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 8/8] netfilter: nf_tables: fix null deref due to zeroed list head
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/8] netfilter: nf_tables: upfront validation of data via nft_data_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 7/8] netfilter: nf_tables: disallow jump to implicit chain from set element
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/8] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/8] netfilter: nf_tables: validate variable length element extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/8] netfilter: nf_tables: do not allow CHAIN_ID to refer to another table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/8] netfilter: nf_tables: do not allow SET_ID to refer to another table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf,v2 1/2] netfilter: nf_tables: upfront validation of data via nft_data_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix null deref due to zeroed list head
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] optimize: merging concatenation is unsupported
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] optimize: check for mergeable rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/2] --optimize fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] nftables 1.0.5 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] Extends py/nftables.py
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] libnftnl 1.2.3 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RESEND (v2) PATCH] netfilter: Fix a typo in a comment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf,v4] netfilter: nf_tables: validate variable length element extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/3] netfilter: nf_tables: do not allow RULE_ID to refer to another chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nfnetlink: re-enable conntrack expectation events
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/3] netfilter: nf_tables: do not allow CHAIN_ID to refer to another table
- From: Thadeu Lima de Souza Cascardo <cascardo@xxxxxxxxxxxxx>
- [PATCH 3/3] netfilter: nf_tables: do not allow RULE_ID to refer to another chain
- From: Thadeu Lima de Souza Cascardo <cascardo@xxxxxxxxxxxxx>
- [PATCH 1/3] netfilter: nf_tables: do not allow SET_ID to refer to another table
- From: Thadeu Lima de Souza Cascardo <cascardo@xxxxxxxxxxxxx>
- RE: [PATCH nf 3/4] netfilter: conntrack_ftp: prefer skb_linearize
- From: Alexander Duyck <alexanderduyck@xxxxxx>
- Re: [PATCH bpf-next] net: netfilter: Remove ifdefs for code shared by BPF and ctnetlink
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH nf] netfilter: nf_tables: fix null deref due to zeroed list head
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 3/4] netfilter: conntrack_ftp: prefer skb_linearize
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: [PATCH nf 3/4] netfilter: conntrack_ftp: prefer skb_linearize
- From: Alexander Duyck <alexanderduyck@xxxxxx>
- [PATCH] netfilter: nf_tables: possible module reference underflow in error path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: really skip inactive sets when allocating name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 4/4] netfilter: conntrack_irc: cap packet search space to 4k
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/4] netfilter: conntrack: h323: cap packet size at 64k
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/4] netfilter: conntrack: sane: remove pseudo skb linearization
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 3/4] netfilter: conntrack_ftp: prefer skb_linearize
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/4] netfilter: conntrack: remove 64kb max size assumptions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERVAL_END flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v4] netfilter: nf_tables: validate variable length element extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] meta: don't use non-POSIX formats in strptime()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] tests/py: disable arp family for queue statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables] meta: don't use non-POSIX formats in strptime()
- From: Jo-Philipp Wich <jo@xxxxxxx>
- [PATCH libmnl v3 1/2] libmnl: update attribute function comments to use \return
- From: Jacob Keller <jacob.e.keller@xxxxxxxxx>
- [PATCH libmnl v3 2/2] libmnl: add support for signed types
- From: Jacob Keller <jacob.e.keller@xxxxxxxxx>
- Re: [PATCH libmnl v2 2/2] libmnl: add support for signed types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: [PATCH libmnl v2 2/2] libmnl: add support for signed types
- From: "Keller, Jacob E" <jacob.e.keller@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: nf_tables: disallow jump to implicit chain from set element
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 1/2] netfilter: nf_tables: upfront validation of data via nft_data_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: [PATCH libmnl v2 2/2] libmnl: add support for signed types
- From: "Keller, Jacob E" <jacob.e.keller@xxxxxxxxx>
- Re: [PATCH libmnl v2 1/2] libmnl: update attribute function comments to use \return
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl v2 2/2] libmnl: add support for signed types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: upfront validation of data via nft_data_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_tables: validate variable length element extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [net] 2638eb8b50: WARNING:suspicious_RCU_usage
- From: kernel test robot <oliver.sang@xxxxxxxxx>
- [RESEND (v2) PATCH] netfilter: Fix a typo in a comment
- From: Christophe JAILLET <christophe.jaillet@xxxxxxxxxx>
- [RESEND PATCH] netfilter: Fix a typo in a comment
- From: Christophe JAILLET <christophe.jaillet@xxxxxxxxxx>
- Re: [PATCH libmnl v2 1/2] libmnl: update attribute function comments to use \return
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next] net: netfilter: Remove ifdefs for code shared by BPF and ctnetlink
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH libmnl v2 1/2] libmnl: update attribute function comments to use \return
- From: Jacob Keller <jacob.e.keller@xxxxxxxxx>
- [PATCH libmnl v2 2/2] libmnl: add support for signed types
- From: Jacob Keller <jacob.e.keller@xxxxxxxxx>
- [PATCH nf] netfilter: nfnetlink: re-enable conntrack expectation events
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: Update build_man.sh to find bash in PATH
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libmnl] libmnl: add support for signed types
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- RE: [PATCH libmnl] libmnl: add support for signed types
- From: "Keller, Jacob E" <jacob.e.keller@xxxxxxxxx>
- Re: [PATCH libmnl] libmnl: add support for signed types
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: validate variable length element extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libmnl] libmnl: add support for signed types
- From: Jacob Keller <jacob.e.keller@xxxxxxxxx>
- LPC 2022 Networking and BPF Track CFP (Final Reminder)
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 0/8] really handle stacked l2 headers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v2 0/8] really handle stacked l2 headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl 0/6] Doxygen Build Improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH libmnl 0/6] Doxygen Build Improvements
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libmnl] build: doc: refer to bash as bash, not /bin/bash
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libmnl] build: doc: refer to bash as bash, not /bin/bash
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: flowtable: fix incorrect Kconfig dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl 5/6] doc: move man-page sym-link shell-script into a separate file
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libmnl 5/6] doc: move man-page sym-link shell-script into a separate file
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH libmnl 4/6] doc: move doxygen config file into doxygen directory
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libmnl 0/6] Doxygen Build Improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libmnl 3/6] doc: change `INPUT` doxygen setting to `@top_srcdir@`
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libmnl 6/6] doc: fix doxygen `clean-local` rule
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libmnl 5/6] doc: move man-page sym-link shell-script into a separate file
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libmnl 2/6] doc: add .gitignore for Doxygen artefacts
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libmnl 1/6] build: add `make dist` tar-balls to .gitignore
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [syzbot] general protection fault in br_nf_pre_routing_finish (2)
- From: syzbot <syzbot+dc42341ea62e8eb6c1f7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH iptables] tests: add ebtables among testcase
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libmnl] build: doc: refer to bash as bash, not /bin/bash
- From: Mark Mentovai <mark@xxxxxxxxxxxx>
- [PATCH iptables] nft: fix ebtables among match when mac+ip addresses are used
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: iptables v1.6.2 EOS date
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft,v3] parser_json: fix device parsing in netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2] parser_json: fix device parsing in netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables v1.6.2 EOS date
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH nf-next v2] netfilter: nf_flow_table: delay teardown the offload flow until fin packet recv from both direction
- From: wenxu@xxxxxxxxxxxxxxx
- iptables v1.6.2 EOS date
- From: Nicolas MAFFRE <nicolas.maffre.external@xxxxxxxxxx>
- Re: Re: [PATCH nf-next v2 2/3] nf_flow_table_offload: offload the PPPoE encap in the flowtable
- From: "wenxu@xxxxxxxxxxxxxxx" <wenxu@xxxxxxxxxxxxxxx>
- Re: Re: [PATCH nf-next v2 1/3] nf_flow_table_offload: offload the vlan encap in the flowtable
- From: "wenxu@xxxxxxxxxxxxxxx" <wenxu@xxxxxxxxxxxxxxx>
- Re: Re: [PATCH nf-next v2 1/3] nf_flow_table_offload: offload the vlan encap in the flowtable
- From: "wenxu@xxxxxxxxxxxxxxx" <wenxu@xxxxxxxxxxxxxxx>
- Re: Re: [PATCH nf-next] netfilter: nf_flow_table: delay teardown the offload flow until fin packet recv from both direction
- From: "wenxu@xxxxxxxxxxxxxxx" <wenxu@xxxxxxxxxxxxxxx>
- Re: [PATCH libmnl] build: doc: refer to bash as bash, not /bin/bash
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: "U'ren, Aaron" <Aaron.U'ren@xxxxxxxx>
- [PATCH AUTOSEL 4.19 3/4] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 5/6] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.10 6/7] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.15 7/8] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.18 09/10] netfilter: nft_queue: only allow supported familes and hooks
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.18 08/10] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH libmnl] build: doc: refer to bash as bash, not /bin/bash
- From: Mark Mentovai <mark@xxxxxxxxxxxx>
- [PATCH nf 0/2] netfilter: nf_tables: fix nf_trace related crash
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] netfilter: nf_tables: fix crash when nf_trace is enabled
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/2] selftests: netfilter: add test case for nf trace infrastructure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] parser_json: fix device parsing in netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v2 8/8] src: allow anon set concatenation with ether and vlan
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 7/8] evaluate: search stacked header list for matching payload dep
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 6/8] netlink_delinearize: also postprocess OP_AND in set element context
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 5/8] tests: add a test case for ether and vlan listing
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 4/8] debug: dump the l2 protocol stack
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 3/8] proto: track full stack of seen l2 protocols, not just cumulative offset
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 2/8] netlink_delinearize: postprocess binary ands in concatenations
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 1/8] netlink_delinearize: allow postprocessing on concatenated elements
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v2 0/8] really handle stacked l2 headers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] src: proto: support DF, LE PHB, VA for DSCP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/7] netlink_delinearize: postprocess binary ands in set expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v2 2/3] nf_flow_table_offload: offload the PPPoE encap in the flowtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 1/3] nf_flow_table_offload: offload the vlan encap in the flowtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_flow_table: delay teardown the offload flow until fin packet recv from both direction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/7] netlink_delinearize: postprocess binary ands in set expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: [RFC] Remove DECNET support from kernel
- From: David Laight <David.Laight@xxxxxxxxxx>
- [PATCH] ebtables: add "allstatic" build target
- From: Justin Swartz <justin.swartz@xxxxxxxxxxxxxxxx>
- Re: [RFC] Remove DECNET support from kernel
- From: David Ahern <dsahern@xxxxxxxxxx>
- Re: [RFC] Remove DECNET support from kernel
- From: Pali Rohár <pali@xxxxxxxxxx>
- [RFC] Remove DECNET support from kernel
- From: Stephen Hemminger <stephen@xxxxxxxxxxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: "U'ren, Aaron" <Aaron.U'ren@xxxxxxxx>
- Re: [iptables PATCH 1/3] tests: shell: Fix testcases for changed ip6tables opts output
- From: Erik Skultety <eskultet@xxxxxxxxxx>
- Re: [iptables PATCH 1/3] tests: shell: Fix testcases for changed ip6tables opts output
- From: Phil Sutter <phil@xxxxxx>
- [PATCH libnftnl RFC 1/3] src: add string API support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl RFC 3/3] examples: update nft-rule-add to match on string
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl RFC 2/3] expr: add string expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 1/3] src: add string API support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 2/3] netfilter: nf_tables: add string set API
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 3/3] netfilter: nf_tables: add string expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 1/3] netfilter: add Aho-Corasick string match implementation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 0/3] nf_tables string match support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [iptables PATCH 1/3] tests: shell: Fix testcases for changed ip6tables opts output
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v6 11/17] seltests/landlock: adds tests for bind() hooks
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [iptables PATCH 3/3] xshared: Print protocol numbers if --numeric was given
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] tests: shell: Fix testcases for changed ip6tables opts output
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/3] xshared: Fix for missing space after 'prot' column
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH resend] ebtables: extend the 'static' build target fix.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 17/17] samples/landlock: adds network demo
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH resend] ebtables: extend the 'static' build target fix.
- From: Justin Swartz <justin.swartz@xxxxxxxxxxxxxxxx>
- Re: [PATCH resend] ebtables: extend the 'static' build target fix.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v6 17/17] samples/landlock: adds network demo
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [PATCH nft 5/7] tests: add a test case for ether and vlan listing
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/7] debug: dump the l2 protocol stack
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 6/7] evaluate: search stacked header list for matching payload dep
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 7/7] src: allow anon set concatenation with ether and vlan
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/7] proto: track full stack of seen l2 protocols, not just cumulative offset
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/7] netlink_delinearize: allow postprocessing on concatenated elements
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/7] netlink_delinearize: postprocess binary ands in set expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/7] really handle stacked l2 headers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_queue: only allow supported families
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf] netfilter: nft_queue: only allow supported familes and hooks
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v6 00/17] Network support for Landlock
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_queue: only allow supported families
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_queue: do not allow packet truncation below transport header offset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Roberto Sassu <roberto.sassu@xxxxxxxxxx>
- Re: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: add rescheduling points during loop detection walks
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_queue: only allow supported families
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_queue: do not allow packet truncation below transport header offset
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Roberto Sassu <roberto.sassu@xxxxxxxxxx>
- Re: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Erik Skultety <eskultet@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_flow_table: delay teardown the offload flow until fin packet recv from both direction
- From: wenxu@xxxxxxxxxxxxxxx
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Roberto Sassu <roberto.sassu@xxxxxxxxxx>
- Re: [PATCH bpf-next v7 07/13] net: netfilter: Add kfuncs to allocate and insert CT
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next] net: netfilter: Remove ifdefs for code shared by BPF and ctnetlink
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Phil Sutter <phil@xxxxxx>
- Re: iptables 1.8.8 misses -j CT calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v7 07/13] net: netfilter: Add kfuncs to allocate and insert CT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables 1.8.8 misses -j CT calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v7 07/13] net: netfilter: Add kfuncs to allocate and insert CT
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v7 07/13] net: netfilter: Add kfuncs to allocate and insert CT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- A probable bug in nftables doc
- From: Eve Adam <adameve1981zero@xxxxxxxxx>
- Re: [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH bpf-next v7 00/13] New nf_conntrack kfuncs for insertion, changing timeout, status
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH bpf-next v7 02/13] tools/resolve_btfids: Add support for 8-byte BTF sets
- From: Jiri Olsa <olsajiri@xxxxxxxxx>
- Re: [PATCH bpf-next v7 00/13] New nf_conntrack kfuncs for insertion, changing timeout, status
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v7 00/13] New nf_conntrack kfuncs for insertion, changing timeout, status
- From: Zvi Effron <zeffron@xxxxxxxxxxxxx>
- iptables 1.8.8 misses -j CT calls
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH bpf-next v7 12/13] selftests/bpf: Add negative tests for new nf_conntrack kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 13/13] selftests/bpf: Fix test_verifier failed test in unprivileged mode
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 11/13] selftests/bpf: Add tests for new nf_conntrack kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 10/13] selftests/bpf: Add verifier tests for trusted kfunc args
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 08/13] net: netfilter: Add kfuncs to set and change CT timeout
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 02/13] tools/resolve_btfids: Add support for 8-byte BTF sets
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 05/13] bpf: Add documentation for kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 06/13] net: netfilter: Deduplicate code in bpf_{xdp,skb}_ct_lookup
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 00/13] New nf_conntrack kfuncs for insertion, changing timeout, status
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 07/13] net: netfilter: Add kfuncs to allocate and insert CT
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 01/13] bpf: Introduce 8-byte BTF set
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 03/13] bpf: Switch to new kfunc flags infrastructure
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 09/13] net: netfilter: Add kfuncs to set and change CT status
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v7 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next 01/18] netfilter: conntrack: use fallthrough to cleanup
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH nf-next 17/18] netfilter: flowtable: prefer refcount_inc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 13/18] netfilter: nf_tables: use correct integer types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 16/18] netfilter: ipvs: Use the bitmap API to allocate bitmaps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 14/18] netfilter: nf_tables: move nft_cmp_fast_mask to where its used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 15/18] netfilter: nf_nat: in nf_nat_initialized(), use const struct nf_conn *
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 18/18] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 12/18] netfilter: nf_tables: add and use BE register load-store helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 11/18] netfilter: nf_tables: use the correct get/put helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 09/18] netfilter: nfnetlink: add missing __be16 cast
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 10/18] netfilter: x_tables: use correct integer types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 03/18] net/sched: act_ct: set 'net' pointer when creating new nf_flow_table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 07/18] netfilter: h323: merge nat hook pointers into one
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 02/18] netfilter: conntrack: use correct format characters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 08/18] netfilter: nft_set_bitmap: Fix spelling mistake
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 05/18] netfilter: nf_conntrack: add missing __rcu annotations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 06/18] netfilter: nf_conntrack: use rcu accessors where needed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 04/18] netfilter: nf_flow_table: count pending offload workqueue tasks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 01/18] netfilter: conntrack: use fallthrough to cleanup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 00/18] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipvs: Use the bitmap API to allocate bitmaps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtable: prefer refcount_inc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v6 05/13] bpf: Add documentation for kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v6 01/13] bpf: Introduce BTF ID flags and 8-byte BTF set
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: conntrack: remove unneeded indent level
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: conntrack: ignore overly delayed tcp packets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: conntrack: prepare tcp_in_window for ternary return value
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/3] netfilter: conntrack: ignore overly delayed tcp packets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next v6 05/13] bpf: Add documentation for kfuncs
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Erik Skultety <eskultet@xxxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Erik Skultety <eskultet@xxxxxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] iptables: xshared: Ouptut '--' in the opt field in ipv6's fake mode
- From: Erik Skultety <eskultet@xxxxxxxxxx>
- Re: [PATCH v2] net-next: improve handling of ICMP_EXT_ECHO icmp type
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH v2] net-next: improve handling of ICMP_EXT_ECHO icmp type
- From: Mathias Lark <mathiaslark@xxxxxxxxx>
- Re: [PATCH bpf-next v6 01/13] bpf: Introduce BTF ID flags and 8-byte BTF set
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH bpf-next v6 03/13] bpf: Switch to new kfunc flags infrastructure
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 05/13] bpf: Add documentation for kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 11/13] selftests/bpf: Add tests for new nf_conntrack kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 13/13] selftests/bpf: Fix test_verifier failed test in unprivileged mode
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 07/13] net: netfilter: Add kfuncs to allocate and insert CT
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 04/13] bpf: Add support for forcing kfunc args to be trusted
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 12/13] selftests/bpf: Add negative tests for new nf_conntrack kfuncs
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 06/13] net: netfilter: Deduplicate code in bpf_{xdp,skb}_ct_lookup
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 09/13] net: netfilter: Add kfuncs to set and change CT status
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 10/13] selftests/bpf: Add verifier tests for trusted kfunc args
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 08/13] net: netfilter: Add kfuncs to set and change CT timeout
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 02/13] tools/resolve_btfids: Add support for resolving kfunc flags
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 01/13] bpf: Introduce BTF ID flags and 8-byte BTF set
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- [PATCH bpf-next v6 00/13] New nf_conntrack kfuncs for insertion, changing timeout, status
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH v2] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Justin Stitt <justinstitt@xxxxxxxxxx>
- [PATCH nft 2/2,v4] cache: validate handle string length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] cache: report an error message if cache initialization fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Add support for new bitmask parameter
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH nft 2/2,v3] cache: validate handle string length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] cache: validate handle string length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] cache: prepare nft_cache_evaluate() to return error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: bail out on too long names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: bail out on too long names
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] parser_bison: bail out on too long names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net-next] improve handling of ICMP_EXT_ECHO icmp type
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: libnftnl broken examples
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft] parser_bison: bail out on too long names
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: ipvs: Use the bitmap API to allocate bitmaps
- From: Simon Horman <horms@xxxxxxxxxx>
- [PATCH nft] parser_bison: bail out on too long names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] improve handling of ICMP_EXT_ECHO icmp type
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] improve handling of ICMP_EXT_ECHO icmp type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- LPC 2022 Networking and BPF Track CFP (Reminder)
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH net-next] improve handling of ICMP_EXT_ECHO icmp type
- From: Mathias Lark <mathiaslark@xxxxxxxxx>
- Re: [PATCH] netfilter: ipset: ipset list may return wrong member count on bitmap types
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: ipset list may return wrong member count on bitmap types
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH 1/6] netfilter: ipset: include linux/nf_inet_addr.h
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: regression in ip_set_hash_ip.c
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH 1/6] netfilter: ipset: include linux/nf_inet_addr.h
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Add support for new bitmask parameter
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [IPTABLES][PATCHv3] xt_sctp: support a couple of new chunk types
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: ipset: regression in ip_set_hash_ip.c
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: ipset list may return wrong member count on bitmap types
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH v2] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Justin Stitt <justinstitt@xxxxxxxxxx>
- Re: [PATCH] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Justin Stitt <justinstitt@xxxxxxxxxx>
- Re: [PATCH] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Nathan Chancellor <nathan@xxxxxxxxxx>
- [PATCH] netfilter: xt_TPROXY: remove pr_debug invocations
- From: Justin Stitt <justinstitt@xxxxxxxxxx>
- Re: [PATCH nf, v2 1/2] netfilter: nf_tables: release element key when parser fails
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH] netfilter: xt_TPROXY: fix clang -Wformat warnings:
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_TPROXY: fix clang -Wformat warnings:
- From: Justin Stitt <justinstitt@xxxxxxxxxx>
- Re: [PATCH nf v3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- [IPTABLES][PATCHv3] xt_sctp: support a couple of new chunk types
- From: Yuxuan Luo <luoyuxuan.carl@xxxxxxxxx>
- Re: [PATCH] netfilter: Fix spelling mistake
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: in nf_nat_initialized(), use const struct nf_conn *
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/6] netfilter: sparse fixups
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/3] netfilter: conntrack sparse annotations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v4 0/2] Conntrack offload debuggability improvements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 12/12] netfilter: conntrack: use correct format characters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: use fallthrough to cleanup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [IPTABLES][PATCHv2] xt_sctp: support a couple of new chunk types
- From: Yuxuan Luo <luoyuxuan.carl@xxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH v2] src: proto: support DF, LE PHB, VA for DSCP
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- Re: [PATCH] src: proto: support DF, LE, VA for DSCP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] xt_sctp: support a couple of new chunk types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nf_log: incorrect offset to network header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nf_tables: replace BUG_ON by element length check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_TPROXY: fix clang -Wformat warnings:
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: FTBS on Debian Bullseye with xtables-addons-dkms 3.13-1 and kernel 5.10.0-16-amd64
- From: Lupe Christoph <lupe@xxxxxxxxxxxxxxxxx>
- Re: FTBS on Debian Bullseye with xtables-addons-dkms 3.13-1 and kernel 5.10.0-16-amd64
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- FTBS on Debian Bullseye with xtables-addons-dkms 3.13-1 and kernel 5.10.0-16-amd64
- From: Lupe Christoph <lupe@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nf,v2 1/2] netfilter: nf_tables: release element key when parser fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_tables: replace BUG_ON by element length check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf,v2 1/2] netfilter: nf_tables: release element key when parser fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_TPROXY: fix clang -Wformat warnings:
- From: Nick Desaulniers <ndesaulniers@xxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: "U'ren, Aaron" <Aaron.U'ren@xxxxxxxx>
- libnftnl broken examples
- From: Serg <jpo39rxtfl@xxxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 01/17] landlock: renames access mask
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v2 0/3] conntrack: -A command implementation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 1/3] conntrack: update manpage with new -A command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 2/3] conntrack: use IPPROTO_RAW
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 3/3] conntrack: slightly simplify parse_proto_num() by using strtoul()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 2/2] netfilter: nf_tables: replace BUG_ON by element length check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 1/2] netfilter: nf_tables: release element key when parser fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [linux-next:master] BUILD REGRESSION 088b9c375534d905a4d337c78db3b3bfbb52c4a0
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: release key_end if element deletion fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: validate variable length element extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: release key if get element fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: flowtable: prefer refcount_inc
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: xt_TPROXY: fix clang -Wformat warnings:
- From: Justin Stitt <justinstitt@xxxxxxxxxx>
- Re: [PATCH nf v3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH v6 02/17] landlock: refactors landlock_find/insert_rule
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [PATCH] Extends py/nftables.py
- From: Peter Collinson <pc@xxxxxxxxxxxxxx>
- Re: [linux-next:master] BUILD REGRESSION 088b9c375534d905a4d337c78db3b3bfbb52c4a0
- From: Guenter Roeck <linux@xxxxxxxxxxxx>
- [PATCH nft] rule: crash when uncollapsing command with unexisting table or set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: Thorsten Leemhuis <regressions@xxxxxxxxxxxxx>
- Re: [linux-next:master] BUILD REGRESSION 088b9c375534d905a4d337c78db3b3bfbb52c4a0
- From: "Chen, Rong A" <rong.a.chen@xxxxxxxxx>
- Re: [PATCH nf v3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: Will Deacon <will@xxxxxxxxxx>
- Re: [linux-next:master] BUILD REGRESSION 088b9c375534d905a4d337c78db3b3bfbb52c4a0
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- [linux-next:master] BUILD REGRESSION 088b9c375534d905a4d337c78db3b3bfbb52c4a0
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- [PATCH nft] scanner: allow prefix in ip6 scope
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- [PATCH AUTOSEL 4.14 3/8] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 3/8] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 3/9] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.10 03/11] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.15 07/18] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.18 08/22] netfilter: nf_tables: avoid skb access on nf_stolen
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.18 09/22] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nf v3] netfilter: conntrack: fix crash due to confirmed bit load reordering
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Peter Zijlstra <peterz@xxxxxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Will Deacon <will@xxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Peter Zijlstra <peterz@xxxxxxxxxxxxx>
- [PATCH nft] cache: release pending rules when chain binding lookup fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- [linux-next:master] BUILD REGRESSION 2a2aa3f05338270aecbe2492fda910d6c17e0102
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: replace BUG_ON by element length check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- Re: [PATCH v6 01/17] landlock: renames access mask
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_log: incorrect offset to network header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v6 01/17] landlock: renames access mask
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Will Deacon <will@xxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Will Deacon <will@xxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Will Deacon <will@xxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- Re: [PATCH] netfilter: ipvs: Use the bitmap API to allocate bitmaps
- From: Julian Anastasov <ja@xxxxxx>
- [linux-next:master] BUILD REGRESSION b6f1f2fa2bddd69ff46a190b8120bd440fd50563
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH] netfilter: ipvs: Use the bitmap API to allocate bitmaps
- From: Christophe JAILLET <christophe.jaillet@xxxxxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Daniel Gröber <dxld@xxxxxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- Re: [PATCH v6 01/17] landlock: renames access mask
- From: "Konstantin Meskhidze (A)" <konstantin.meskhidze@xxxxxxxxxx>
- [BUG] ARP packet "parsing" broken in output hook of arp and netdev family table
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: [PATCH net 1/2] netfilter: nf_tables: stricter validation of element data
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH resend] ebtables: extend the 'static' build target fix.
- From: Justin Swartz <justin.swartz@xxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v1] netfilter: nf_tables: fix nft_set_elem_init heap buffer overflow
- From: Hugues ANGUELKOV <hanguelkov@xxxxxxxxxxxxx>
- Re: [PATCH v1] netfilter: nf_tables: fix nft_set_elem_init heap buffer overflow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/2] netfilter: nf_tables: stricter validation of element data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/2] netfilter: nft_set_pipapo: release elements in clone from abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/2] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v1] netfilter: nf_tables: fix nft_set_elem_init heap buffer overflow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Willy Tarreau <w@xxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- Re: [PATCH nf] netfilter: nft_set_pipapo: release elements in clone from abort path
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_set_pipapo: release elements in clone from abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nft_set_pipapo: release elements in clone from abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: stricter validation of element data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [linux-next:master] BUILD REGRESSION 6cc11d2a1759275b856e464265823d94aabd5eaf
- From: Roman Gushchin <roman.gushchin@xxxxxxxxx>
- [linux-next:master] BUILD REGRESSION c4185b16aba73929aa76f0d030efbe79ae867808
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: "U'ren, Aaron" <Aaron.U'ren@xxxxxxxx>
- Re: [iptables PATCH] libxtables: Fix unsupported extension warning corner case
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_set_pipapo: release elements in clone from abort path
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v6 01/17] landlock: renames access mask
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [vs] Netfilter vulnerability disclosure
- From: Hugues ANGUELKOV <hanguelkov@xxxxxxxxxxxxx>
- Re: [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra #forregzbot
- From: Thorsten Leemhuis <regressions@xxxxxxxxxxxxx>
- [Regression] stress-ng udp-flood causes kernel panic on Ampere Altra
- From: Kajetan Puchalski <kajetan.puchalski@xxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Peter Tirsek <peter@xxxxxxxxxx>
- [linux-next:master] BUILD REGRESSION 6cc11d2a1759275b856e464265823d94aabd5eaf
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Daniel Gröber <dxld@xxxxxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [iptables PATCH] libxtables: Fix unsupported extension warning corner case
- From: Phil Sutter <phil@xxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: "U'ren, Aaron" <Aaron.U'ren@xxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH] xt_sctp: support a couple of new chunk types
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- [PATCH 4/6] netfilter: ipset: Add bitmask support to hash:ipport
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 6/6] netfilter: ipset: Update the man page to include netmask/bitmask options
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 1/6] netfilter: ipset: include linux/nf_inet_addr.h
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 0/6] netfilter: ipset: Add support for new bitmask parameter
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 5/6] netfilter: ipset: Add bitmask support to hash:netnet
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 2/6] netfilter: ipset: Add support for new bitmask parameter
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 3/6] netfilter: ipset: Add bitmask support to hash:ip
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH] netfilter: ipset: Add support for new bitmask parameter
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH] netfilter: ipset: ipset list may return wrong member count on bitmap types
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH] netfilter: ipset: regression in ip_set_hash_ip.c
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- Re: [PATCH] xt_sctp: support a couple of new chunk types
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH] xt_sctp: support a couple of new chunk types
- From: Yuxuan Luo <luoyuxuan.carl@xxxxxxxxx>
- [PATCH] netfilter: in nf_nat_initialized(), use const struct nf_conn *
- From: James Yonan <james@xxxxxxxxxxx>
- Re: [PATCH] src: proto: support DF, LE, VA for DSCP
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- Re: [PATCH] src: proto: support DF, LE, VA for DSCP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nf_tables: avoid skb access on nf_stolen
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: nft_dynset: restore set element counter when failing to update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 0/3] conntrack: -A command implementation
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH v2 1/3] conntrack: generalize command parsing
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH v2 2/3] conntrack: use C99 initializer syntax for opts map
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH v2 3/3] conntrack: introduce new -A command
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH libmnl] nlmsg: Only print ECMA-48 colour sequences to terminals
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: report missing interval flag when using prefix/range in concatenation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] nft_set_rbtree: Switch to node list walk for overlap detection
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH bpf-next v5 1/8] bpf: Add support for forcing kfunc args to be referenced
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Daniel Gröber <dxld@xxxxxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Jason Gunthorpe <jgg@xxxxxxxx>
- Re: [PATCH] src: proto: support DF, LE, VA for DSCP
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] Allow resetting the include search path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: br_netfilter: do not skip all hooks with 0 priority
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: avoid skb access on nf_stolen
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_dynset: restore set element counter when failing to update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_set_pipapo: release elements in clone from abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] flow_table: do not try to add already offloaded entries
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH nf-next] flow_table: do not try to add already offloaded entries
- From: Oz Shlomo <ozsh@xxxxxxxxxx>
- Re: [PATCH nf-next] flow_table: do not try to add already offloaded entries
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Jason Gunthorpe <jgg@xxxxxxxx>
- Re: [PATCH nf-next] flow_table: do not try to add already offloaded entries
- From: Oz Shlomo <ozsh@xxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Geert Uytterhoeven <geert@xxxxxxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
- [PATCH v37 19/33] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v37 15/33] LSM: Ensure the correct LSM context releaser
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v37 16/33] LSM: Use lsmcontext in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v37 09/33] LSM: Use lsmblob in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v37 08/33] LSM: Use lsmblob in security_secctx_to_secid
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Jason Gunthorpe <jgg@xxxxxxxx>
- [PATCH nftables] Allow resetting the include search path
- From: Daniel Gröber <dxld@xxxxxxxxxxxxx>
- RE: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Dan Williams <dan.j.williams@xxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Stephen Hemminger <stephen@xxxxxxxxxxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
- Re: [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH][next] treewide: uapi: Replace zero-length arrays with flexible-array members
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]