Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH net-next 11/11] selftests: netfilter: add fib expression forward test case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 02/11] netfilter: ecache: move to separate structure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 05/11] netfilter: nf_log_syslog: Merge MAC header dumpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 08/11] netfilter: bitwise: replace hard-coded size with `sizeof` expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 10/11] netfilter: nft_fib: reverse path filter for policy-based routing on iif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 06/11] netfilter: nf_log_syslog: Don't ignore unknown protocols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 07/11] netfilter: nf_log_syslog: Consolidate entry checks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 03/11] netfilter: conntrack: split inner loop of list dumping to own function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 04/11] netfilter: cttimeout: inc/dec module refcount per object, not per use refcount
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 00/11] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 01/11] netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_socket: make cgroup match work in input too
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [RFC PATCH] datatype: accept abbrevs and ignore case on parsing symbolic constants
- From: Jo-Philipp Wich <jo@xxxxxxx>
- Re: [PATCH nft] tests: py: Add meta time tests without 'meta' keyword
- From: Martin Gignac <martin.gignac@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_fib: reverse path filter for policy-based routing on iif
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next RFC 2/2] netfilter: conntrack: skip event delivery for the netns exit path
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_socket: make cgroup match work in input too
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next RFC 2/2] netfilter: conntrack: skip event delivery for the netns exit path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: py: Add meta time tests without 'meta' keyword
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnetfilter_log PATCH] doc: correct non-native solecism
- From: Florian Westphal <fw@xxxxxxxxx>
- [libnetfilter_log PATCH] doc: correct non-native solecism
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables 9/9] segtree: add support for get element with sets that contain ifnames
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 8/9] segtree: use correct byte order for 'element get'
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 7/9] tests: add testcases for interface names in sets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 6/9] segtree: add string "range" reversal support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 5/9] src: make interval sets work with string datatypes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 4/9] evaluate: string prefix expression must retain original length
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 3/9] segtree: split prefix and range creation to a helper function
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 2/9] evaluate: keep prefix expression length
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 1/9] evaluate: make byteorder conversion on string base type a no-op
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables 0/9] nftables: add support for wildcard string as set keys
- From: Florian Westphal <fw@xxxxxxxxx>
- [nf-next PATCH v3 1/3] netfilter: bitwise: keep track of bit-length of expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v3 2/3] netfilter: bitwise: rename some boolean operation functions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v3 0/3] netfilter: bitwise: support boolean operations with variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v3 3/3] netfilter: bitwise: add support for doing AND, OR and XOR directly
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- [PATCH nft] tests: py: Add meta time tests without 'meta' keyword
- From: Martin Gignac <martin.gignac@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_socket: make cgroup match work in input too
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_socket: make cgroup match work in input too
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [nf-next PATCH v2 3/5] netfilter: bitwise: improve error goto labels
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next PATCH v2 2/5] netfilter: bitwise: replace hard-coded size with `sizeof` expression
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] doc: Document that kernel may accept unimplemented expressions
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [nft PATCH v4 00/32] Extend values assignable to packet marks and payload fields
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next RFC 2/2] netfilter: conntrack: skip event delivery for the netns exit path
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 08/15] landlock: add support network rules
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [iptables PATCH v2 0/9] extensions: Merge *_DNAT and *_REDIRECT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] tests: py: Don't colorize output if stderr is redirected
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] tests: monitor: Hide temporary file names from error output
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] tests: py: Don't colorize output if stderr is redirected
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next RFC 2/2] netfilter: conntrack: skip event delivery for the netns exit path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next RFC 1/2] netfilter: conntrack: add nf_ct_iter_data object for nf_ct_iterate_cleanup*()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: py: extend meta time coverage
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next PATCH] netfilter: nf_log_syslog: Consolidate entry checks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH 2/2] netfilter: nf_log_syslog: Don't ignore unknown protocols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH 1/2] netfilter: nf_log_syslog: Merge MAC header dumpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: py: extend meta time coverage
- From: Martin Gignac <martin.gignac@xxxxxxxxx>
- Re: [PATCH nf-next v3 00/16] netfilter: conntrack: remove percpu lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 00/16] netfilter: conntrack: remove percpu lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 00/16] netfilter: conntrack: remove percpu lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 00/16] netfilter: conntrack: remove percpu lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 00/16] netfilter: conntrack: remove percpu lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 09/16] netfilter: nfnetlink_cttimeout: use rcu protection in cttimeout_get_timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: py: extend meta time coverage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 8/9] x86/crypto: eliminate anonymous module_init & module_exit
- From: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
- [PATCH nf-next v2 1/1] netfilter: conntrack: skip verification of zero UDP checksum
- From: Kevin Mitchell <kevmitch@xxxxxxxxxx>
- [PATCH v34 18/29] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v34 16/29] LSM: Use lsmcontext in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v34 15/29] LSM: Ensure the correct LSM context releaser
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v34 09/29] LSM: Use lsmblob in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v34 08/29] LSM: Use lsmblob in security_secctx_to_secid
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- Re: linux 5.17.1 disregarding ACK values resulting in stalled TCP connections
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: linux 5.17.1 disregarding ACK values resulting in stalled TCP connections
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: linux 5.17.1 disregarding ACK values resulting in stalled TCP connections
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next] net: netfilter: reports ct direction in CT lookup helpers for XDP and TC-BPF
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: linux 5.17.1 disregarding ACK values resulting in stalled TCP connections
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnftnl 0/3] add description infrastructure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl 0/3] add description infrastructure
- From: Phil Sutter <phil@xxxxxx>
- Re: [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: conntrack: skip verification of zero UDP checksum
- From: Kevin Mitchell <kevmitch@xxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH v2 0/1] UDP traceroute packets with no checksum
- From: Kevin Mitchell <kevmitch@xxxxxxxxxx>
- Re: [PATCH net 1/2] netfilter: bitwise: fix reduce comparisons
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: meta time broken
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] nf_flow_table_offload: offload the vlan encap in the flowtable
- From: wenx05124561@xxxxxxx
- Re: [PATCH] meta.c: fix compiler warning in date_type_parse()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: meta time broken
- From: Lukas Straub <lukasstraub2@xxxxxx>
- [ANNOUNCE] libmnl 1.0.5 release
- From: Phil Sutter <phil@xxxxxxxxxxxxx>
- Re: [PATCH nft] meta time: use uint64_t instead of time_t
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v4 05/32] ct: support `NULL` symbol-tables when looking up labels
- From: Florian Westphal <fw@xxxxxxxxx>
- [ANNOUNCE] libnfnetlink 1.0.2 release
- From: Phil Sutter <phil@xxxxxxxxxxxxx>
- Re: [nft PATCH v4 05/32] ct: support `NULL` symbol-tables when looking up labels
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft] meta time: use uint64_t instead of time_t
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v4 01/32] examples: add .gitignore file
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: meta time broken
- From: Phil Sutter <phil@xxxxxx>
- Re: [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: meta time broken
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] meta.c: fix compiler warning in date_type_parse()
- From: Lukas Straub <lukasstraub2@xxxxxx>
- Re: [PATCH v2] nft: memcg accounting for dynamically allocated objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] meta time: use uint64_t instead of time_t
- From: Lukas Straub <lukasstraub2@xxxxxx>
- Re: [PATCH v2] netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/2] netfilter: nf_tables: memcg accounting for dynamically allocated objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/2] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/2] netfilter: bitwise: fix reduce comparisons
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: meta time broken
- From: Lukas Straub <lukasstraub2@xxxxxx>
- meta time broken
- From: Lukas Straub <lukasstraub2@xxxxxx>
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [nft PATCH v4 19/32] evaluate: don't eval unary arguments
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 13/32] evaluate: support shifts larger than the width of the left operand
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 14/32] evaluate: relax type-checking for integer arguments in mark statements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 22/32] evaluate: insert byte-order conversions for expressions between 9 and 15 bits
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 26/32] netlink_delinearize: add support for processing variable payload statement arguments
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 23/32] evaluate: set eval context to leftmost bitwise operand
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 10/32] netlink_delinearize: correct type and byte-order of shifts
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 25/32] netlink_delinearize: refactor stmt_payload_binop_postprocess
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 31/32] tests: shell: add tests for binops with variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 18/32] include: add new bitwise boolean attributes to nf_tables.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 11/32] netlink_delinearize: correct length of right bitwise operand
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 12/32] payload: set byte-order when completing expression
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 32/32] tests: py: add tests for binops with variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 28/32] netlink: support (de)linearization of new bitwise boolean operations
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 17/32] tests: py: add test-cases for ct and packet mark payload expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 20/32] evaluate: prevent nested byte-order conversions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 29/32] parser_json: allow RHS ct, meta and payload expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 30/32] evaluate: allow binop expressions with variable right-hand operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 21/32] evaluate: don't clobber binop lengths
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 16/32] tests: shell: add test-cases for ct and packet mark payload expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 15/32] tests: shell: rename some test-cases
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 27/32] netlink: rename bitwise operation functions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 24/32] netlink_delinearize: fix typo
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 05/32] ct: support `NULL` symbol-tables when looking up labels
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 09/32] netlink_delinearize: add postprocessing for payload binops
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 08/32] netlink: send bit-length of bitwise binops to kernel
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 04/32] datatype: support `NULL` symbol-tables when printing constants
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 07/32] include: add new bitwise bit-length attribute to nf_tables.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 06/32] include: update nf_tables.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 00/32] Extend values assignable to packet marks and payload fields
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 01/32] examples: add .gitignore file
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 03/32] src: move `byteorder_names` array
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v4 02/32] include: add missing `#include`
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 7/9] expr: bitwise: add support for kernel space AND, OR and XOR operations
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 8/9] tests: bitwise: refactor shift tests
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 9/9] tests: bitwise: add tests for new boolean operations
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 6/9] expr: bitwise: rename some boolean operation functions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 4/9] include: add new bitwise boolean attributes to nf_tables.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 5/9] expr: bitwise: fix a couple of white-space mistakes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 3/9] expr: bitwise: pass bit-length to and from the kernel
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 2/9] include: add new bitwise bit-length attribute to nf_tables.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 1/9] include: update nf_tables.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [libnftnl PATCH v2 0/9] bitwise: support for boolean operations with variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v2 4/5] netfilter: bitwise: rename some boolean operation functions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v2 0/5] netfilter: bitwise: support boolean operations with variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v2 5/5] netfilter: bitwise: add support for doing AND, OR and XOR directly
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v2 3/5] netfilter: bitwise: improve error goto labels
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v2 1/5] netfilter: bitwise: keep track of bit-length of expressions
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nf-next PATCH v2 2/5] netfilter: bitwise: replace hard-coded size with `sizeof` expression
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [RFC PATCH v4 01/15] landlock: access mask renaming
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Vasily Averin <vvs@xxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH bpf-next] net: netfilter: reports ct direction in CT lookup helpers for XDP and TC-BPF
- From: Lorenzo Bianconi <lorenzo@xxxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Nikita Yushchenko <nikita.yushchenko@xxxxxxxxxx>
- Re: troubles caused by conntrack overlimit in init_netns
- From: Florian Westphal <fw@xxxxxxxxx>
- troubles caused by conntrack overlimit in init_netns
- From: Vasily Averin <vvs@xxxxxxxxxx>
- [PATCH v2] nft: memcg accounting for dynamically allocated objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Roman Gushchin <roman.gushchin@xxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 01/15] landlock: access mask renaming
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- [no subject]
- [PATCH AUTOSEL 5.16 103/109] netfilter: conntrack: revisit gc autotuning
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.15 92/98] netfilter: conntrack: revisit gc autotuning
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.17 143/149] netfilter: conntrack: revisit gc autotuning
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Florian Westphal <fw@xxxxxxxxx>
- Conntrack offload and ingress_ifindex
- From: Edward Cree <ecree.xilinx@xxxxxxxxx>
- Re: [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Roman Gushchin <roman.gushchin@xxxxxxxxx>
- Re: [PATCH net 2/5] netfilter: conntrack: sanitize table size default settings
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_fib: reverse path filter for policy-based routing on iif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nft_fib: reverse path filter for policy-based routing on iif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [PATCH net 2/5] netfilter: conntrack: sanitize table size default settings
- From: Vincent Pelletier <plr.vincent@xxxxxxxxx>
- [PATCH nf-next] selftests: netfilter: add fib expression forward test case
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH v2 3/9] extensions: ipt_DNAT: Merge v1 and v2 parsers
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 4/9] extensions: ipt_DNAT: Merge v1/v2 print/save code
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 8/9] extensions: Merge REDIRECT into DNAT
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 1/9] man: DNAT: Describe shifted port range feature
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 2/9] Revert "libipt_[SD]NAT: avoid false error about multiple destinations specified"
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 5/9] extensions: ipt_DNAT: Combine xlate functions also
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 7/9] extensions: Merge IPv4 and IPv6 DNAT targets
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 0/9] extensions: Merge *_DNAT and *_REDIRECT
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 6/9] extensions: DNAT: Rename from libipt to libxt
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 9/9] extensions: man: Document service name support in DNAT and REDIRECT
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 9/9] extensions: DNAT: Support service names in all spots
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] nft: memcg accounting for dynamically allocated objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [iptables PATCH 9/9] extensions: DNAT: Support service names in all spots
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH nf-next] netfilter: nft_fib: reverse path filter for policy-based routing on iif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 9/9] extensions: DNAT: Support service names in all spots
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 9/9] extensions: DNAT: Support service names in all spots
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [no subject]
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- [iptables PATCH] xlate-test: Fix for empty source line on failure
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 6/9] extensions: DNAT: Rename from libipt to libxt
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 7/9] extensions: Merge IPv4 and IPv6 DNAT targets
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 4/9] extensions: ipt_DNAT: Merge v1/v2 print/save code
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 5/9] extensions: ipt_DNAT: Combine xlate functions also
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 9/9] extensions: DNAT: Support service names in all spots
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/9] man: DNAT: Describe shifted port range feature
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 8/9] extensions: Merge REDIRECT into DNAT
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/9] extensions: ipt_DNAT: Merge v1 and v2 parsers
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/9] extensions: Merge *_DNAT and *_REDIRECT
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/9] Revert "libipt_[SD]NAT: avoid false error about multiple destinations specified"
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 5/9] virtio-scsi: eliminate anonymous module_init & module_exit
- From: "Martin K. Petersen" <martin.petersen@xxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf PATCH v2] netfilter: bitwise: fix reduce comparisons
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnfnetlink PATCH 1/2] include: Silence gcc warning in linux_list.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnfnetlink PATCH 2/2] libnfnetlink: Check getsockname() return code
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnetfilter_conntrack PATCH] expect/conntrack: Avoid spurious covscan overrun warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- [PATCH nft] tests: py: add inet/vmap tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 2/4] src: allow to use typeof of raw expressions in set declaration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 4/4] optimize: Restore optimization for raw payload expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 3/4] src: allow to use integer type header fields via typeof set declaration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 1/4] expression: typeof verdict needs verdict datatype
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: egress: Report interface as outgoing
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- [PATCH nft] expression: typeof verdict needs verdict datatype
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 RESEND] memcg: enable accounting for nft objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [conntrack-tools PATCH 0/8] Fixes for a recent Coverity tool run
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] memcg: enable accounting for nft objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: egress: Report interface as outgoing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 RESEND] memcg: enable accounting for nft objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v4] src: eliminate packet copy when constructing struct pktbuff
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [nf PATCH v2] netfilter: bitwise: fix reduce comparisons
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH] netfilter: bitwise: fix reduce comparison
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: Support for loading firewall rules with cgroup(v2) expressions early
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: allow to use typeof of raw expressions in set declaration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] examples: fix compiler warning
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnetfilter_queue] examples: fix compiler warning
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Support for loading firewall rules with cgroup(v2) expressions early
- From: Topi Miettinen <toiwoton@xxxxxxxxx>
- [libnfnetlink PATCH 1/2] include: Silence gcc warning in linux_list.h
- From: Phil Sutter <phil@xxxxxx>
- [libnfnetlink PATCH 2/2] libnfnetlink: Check getsockname() return code
- From: Phil Sutter <phil@xxxxxx>
- [libnetfilter_conntrack PATCH] expect/conntrack: Avoid spurious covscan overrun warning
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 3/8] Fix potential buffer overrun in snprintf() calls
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 8/8] connntrack: Fix for memleak when parsing -j arg
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 2/8] cache: Fix features array allocation
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 1/8] hash: Flush tables when destroying
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 4/8] helpers: ftp: Avoid ugly casts
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 0/8] Fixes for a recent Coverity tool run
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 5/8] read_config_yy: Drop extra argument from dlog() call
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 7/8] Drop pointless assignments
- From: Phil Sutter <phil@xxxxxx>
- [conntrack-tools PATCH 6/8] Don't call exit() from signal handler
- From: Phil Sutter <phil@xxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- [PATCH v2 RESEND] memcg: enable accounting for nft objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [PATCH 3/9] net: mlx5: eliminate anonymous module_init & module_exit
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH v2] memcg: enable accounting for nft objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [nf-next PATCH] netfilter: nf_log_syslog: Consolidate entry checks
- From: Florian Westphal <fw@xxxxxxxxx>
- [nf-next PATCH] netfilter: nf_log_syslog: Consolidate entry checks
- From: Phil Sutter <phil@xxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [nf-next PATCH 2/2] netfilter: nf_log_syslog: Don't ignore unknown protocols
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] memcg: enable accounting for nft objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH 2/2] netfilter: nf_log_syslog: Don't ignore unknown protocols
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next PATCH 1/2] netfilter: nf_log_syslog: Merge MAC header dumpers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf PATCH] netfilter: egress: Report interface as outgoing
- From: Florian Westphal <fw@xxxxxxxxx>
- [nf-next PATCH 2/2] netfilter: nf_log_syslog: Don't ignore unknown protocols
- From: Phil Sutter <phil@xxxxxx>
- [nf-next PATCH 1/2] netfilter: nf_log_syslog: Merge MAC header dumpers
- From: Phil Sutter <phil@xxxxxx>
- [nf PATCH] netfilter: egress: Report interface as outgoing
- From: Phil Sutter <phil@xxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: bug report and future request
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [PATCH nf-next v3 16/16] netfilter: conntrack: avoid unconditional local_bh_disable
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 15/16] netfilter: conntrack: remove unconfirmed list
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 14/16] netfilter: conntrack: remove __nf_ct_unconfirmed_destroy
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 13/16] netfilter: cttimeout: decouple unlink and free on netns destruction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 12/16] netfilter: extensions: introduce extension genid count
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 10/16] netfilter: cttimeout: decouple unlink and free on netns destruction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 11/16] netfilter: remove nf_ct_unconfirmed_destroy helper
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 09/16] netfilter: nfnetlink_cttimeout: use rcu protection in cttimeout_get_timeout
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 07/16] netfilter: conntrack: remove the percpu dying list
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 08/16] netfilter: cttimeout: inc/dec module refcount per object, not per use refcount
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 05/16] netfilter: conntrack: split inner loop of list dumping to own function
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 06/16] netfilter: conntrack: include ecache dying list in dumps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 04/16] netfilter: ecache: use dedicated list for event redelivery
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 03/16] netfilter: ecache: move to separate structure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 02/16] netfilter: ctnetlink: make ecache event cb global again
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 01/16] nfnetlink: handle already-released nl socket
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v3 00/16] netfilter: conntrack: remove percpu lists
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Fix duplicate included ip_set_hash_gen.h
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Fix duplicate included ip_set_hash_gen.h
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH] netfilter: ipset: Fix duplicate included ip_set_hash_gen.h
- From: Haowen Bai <baihaowen@xxxxxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- [PATCH 1/1] conntrack: use same mnl socket for bulk operations
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH 0/1] Reusing mnl socket for bulk ct loads
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- Re: [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2] netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
- From: Jakob Koschel <jakobkoschel@xxxxxxxxx>
- Re: bug report and future request
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] memcg: enable accounting for nft objects
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- Re: bug report and future request
- From: Florian Westphal <fw@xxxxxxxxx>
- bug report and future request
- From: Martin Zaharinov <micron10@xxxxxxxxx>
- [PATCH nft] evaluate: copy field_count for anonymous object maps as well
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 01/19] netfilter: conntrack: revisit gc autotuning
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net-next 19/19] netfilter: flowtable: pass flowtable to nf_flow_table_iterate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 18/19] netfilter: flowtable: remove redundant field in flow_offload_work struct
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 15/19] netfilter: nft_fib: add reduce support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 14/19] netfilter: nft_tunnel: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 01/19] netfilter: conntrack: revisit gc autotuning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 11/19] netfilter: nft_immediate: cancel register tracking for data destination register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 09/19] netfilter: nft_osf: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 04/19] netfilter: nf_tables: cancel tracking for clobbered destination registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 06/19] netfilter: nft_lookup: only cancel tracking for clobbered dregs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 08/19] netfilter: nft_numgen: cancel register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 02/19] netfilter: conntrack: Add and use nf_ct_set_auto_assign_helper_warned()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 16/19] netfilter: nft_exthdr: add reduce support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 12/19] netfilter: nft_socket: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 10/19] netfilter: nft_hash: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 17/19] netfilter: nf_nat_h323: eliminate anonymous module_init & module_exit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 05/19] netfilter: nft_ct: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 07/19] netfilter: nft_meta: extend reduce support to bridge family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 13/19] netfilter: nft_xfrm: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 03/19] netfilter: nf_tables: do not reduce read-only expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 00/19] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_tcp: preserve liberal flag in tcp options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC] memcg: Enable accounting for nft objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- [PATCH v2] memcg: enable accounting for nft objects
- From: Vasily Averin <vasily.averin@xxxxxxxxx>
- Re: [PATCH 2/9] virtio_console: eliminate anonymous module_init & module_exit
- From: "Michael S. Tsirkin" <mst@xxxxxxxxxx>
- Re: [PATCH 5/9] virtio-scsi: eliminate anonymous module_init & module_exit
- From: "Michael S. Tsirkin" <mst@xxxxxxxxxx>
- Re: [PATCH 1/9] virtio_blk: eliminate anonymous module_init & module_exit
- From: "Michael S. Tsirkin" <mst@xxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next PATCH] netfilter: conntrack: Add and use nf_ct_set_auto_assign_helper_warned()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 4/9] netfilter: h323: eliminate anonymous module_init & module_exit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: revisit gc autotuning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH] netfilter: conntrack: Add and use nf_ct_set_auto_assign_helper_warned()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: replace unnecessary use of list_for_each_entry_continue()
- From: Jakob Koschel <jakobkoschel@xxxxxxxxx>
- [PATCH] ebtables: fix the 'static' build target
- From: Robert Kolchmeyer <rkolchmeyer@xxxxxxxxxx>
- Re: [PATCH 7/9] usb: usbip: eliminate anonymous module_init & module_exit
- From: Shuah Khan <skhan@xxxxxxxxxxxxxxxxxxx>
- Re: "Decoding" ipset error codes
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack_tcp: skip tracking for offloaded packets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_conntrack_tcp: skip tracking for offloaded packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: flowtable: remove redundant field in flow_offload_work struct
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: flowtable: pass flowtable to nf_flow_table_iterate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH v4 02/15] landlock: filesystem access mask helpers
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: flowtable: Fix QinQ and pppoe support for inet table
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH 2/9] virtio_console: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- Re: [PATCH 4/9] netfilter: h323: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: flowtable: Fix QinQ and pppoe support for inet table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nf_tables: validate registers coming from userspace.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nf_tables: initialize registers in nft_do_chain()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH v4 02/15] landlock: filesystem access mask helpers
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: (subset) [PATCH 0/9] treewide: eliminate anonymous module_init & module_exit
- From: Jens Axboe <axboe@xxxxxxxxx>
- Re: [PATCH 4/9] netfilter: h323: eliminate anonymous module_init & module_exit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/9] virtio_console: eliminate anonymous module_init & module_exit
- From: Amit Shah <amit@xxxxxxxxxxxxx>
- Re: [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [RFC PATCH v4 02/15] landlock: filesystem access mask helpers
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH nf,v2 2/2] netfilter: nf_tables: initialize registers in nft_do_chain()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf,v2 1/2] netfilter: nf_tables: validate registers coming from userspace.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nf_tables: registers should not go over NFT_REG32_NUM
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 2/2] netfilter: nf_tables: initialize registers in nft_do_chain()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 1/2] netfilter: nf_tables: validate registers coming from userspace.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nf_tables: registers should not go over NFT_REG32_NUM
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] netfilter: nf_tables: registers should not go over NFT_REG32_NUM
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nf_tables: initialize registers in nft_do_chain()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 5/9] virtio-scsi: eliminate anonymous module_init & module_exit
- From: Stefan Hajnoczi <stefanha@xxxxxxxxxx>
- Re: [PATCH 1/9] virtio_blk: eliminate anonymous module_init & module_exit
- From: Stefan Hajnoczi <stefanha@xxxxxxxxxx>
- Re: [PATCH 6/9] usb: gadget: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- Re: [PATCH 4/9] netfilter: h323: eliminate anonymous module_init & module_exit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 0/9] treewide: eliminate anonymous module_init & module_exit
- From: Ira Weiny <ira.weiny@xxxxxxxxx>
- Re: [PATCH 6/9] usb: gadget: eliminate anonymous module_init & module_exit
- From: Ira Weiny <ira.weiny@xxxxxxxxx>
- Re: [PATCH 1/9] virtio_blk: eliminate anonymous module_init & module_exit
- From: Jason Wang <jasowang@xxxxxxxxxx>
- Re: [PATCH 5/9] virtio-scsi: eliminate anonymous module_init & module_exit
- From: Jason Wang <jasowang@xxxxxxxxxx>
- Re: [PATCH 9/9] testmmiotrace: eliminate anonymous module_init & module_exit
- From: Steven Rostedt <rostedt@xxxxxxxxxxx>
- Re: Intermittent performance regression related to ipset between 5.10 and 5.15
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH 9/9] testmmiotrace: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 8/9] x86/crypto: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 4/9] netfilter: h323: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 7/9] usb: usbip: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 5/9] virtio-scsi: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 2/9] virtio_console: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 1/9] virtio_blk: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 0/9] treewide: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 3/9] net: mlx5: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH 6/9] usb: gadget: eliminate anonymous module_init & module_exit
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/3] libxtables: Boost rule target checks by announcing chain names
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 2/3] libxtables: Implement notargets hash table
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 1/3] nft: Reject standard targets as chain names when restoring
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH 2/3] libxtables: Implement notargets hash table
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/3] libxtables: Boost rule target checks by announcing chain names
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] nft: Reject standard targets as chain names when restoring
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/3] Speed up restoring huge rulesets
- From: Phil Sutter <phil@xxxxxx>
- "Decoding" ipset error codes
- From: Ian Pilcher <arequipeno@xxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Feature Request: nft: support non-immediate second operand
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf] netfilter: flowtable: Fix QinQ and PPPoE support for inet table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC] conntrack event framework speedup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Feature Request: nft: support non-immediate second operand
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 1/6] Revert "netfilter: conntrack: mark UDP zero checksum as CHECKSUM_UNNECESSARY"
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [RFC PATCH v4 02/15] landlock: filesystem access mask helpers
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [RFC PATCH v4 00/15] Landlock LSM
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH net-next 8/8] netfilter: flowtable: add hardware offload tracepoints
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [iptables PATCH 3/5] xtables: Call init_extensions{,a,b}() for static builds
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 3/5] xtables: Call init_extensions{,a,b}() for static builds
- From: Etienne Champetier <champetier.etienne@xxxxxxxxx>
- [iptables PATCH 3/5] xtables: Call init_extensions{,a,b}() for static builds
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/5] Simplify static build extension loading
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/5] Fixes for static builds
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/5] libxtables: Fix for warning in xtables_ipmask_to_numeric
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 4/5] nft: Review static extension loading
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 5/5] tests: shell: Fix 0004-return-codes_0 for static builds
- From: Phil Sutter <phil@xxxxxx>
- [RFC] conntrack event framework speedup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 8/8] netfilter: flowtable: add hardware offload tracepoints
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 5/6] net/mlx5: Support GRE conntrack offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/6] netfilter: flowtable: Support GRE
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/6] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/6] netfilter: nf_tables: Reject tables of unsupported family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 6/6] netfilter: bridge: clean up some inconsistent indenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/6] act_ct: Support GRE offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/6] Revert "netfilter: conntrack: mark UDP zero checksum as CHECKSUM_UNNECESSARY"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/3] Revert "netfilter: nat: force port remap to prevent shadowing well-known ports"
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nf-next,v3 10/14] netfilter: nft_socket: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 07/14] netfilter: nft_osf: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 12/14] netfilter: nft_tunnel: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 08/14] netfilter: nft_hash: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 11/14] netfilter: nft_xfrm: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 14/14] netfilter: nft_exthdr: add reduce support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 09/14] netfilter: nft_immediate: cancel register tracking for data destination register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 13/14] netfilter: nft_fib: add reduce support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 06/14] netfilter: nft_numgen: cancel register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 05/14] netfilter: nft_meta: extend reduce support to bridge family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 04/14] netfilter: nft_lookup: only cancel tracking for clobbered dregs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 03/14] netfilter: nft_ct: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 02/14] netfilter: nf_tables: cancel tracking for clobbered destination registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 01/14] netfilter: nf_tables: do not reduce read-only expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 00/14] register tracking infrastructure follow up
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 02/12,v2] netfilter: nf_tables: cancel tracking for clobbered destination registers
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 01/12,v2] netfilter: nf_tables: do not reduce read-only expressions
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH nf-next 12/12,v2] netfilter: nft_tunnel: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 11/12,v2] netfilter: nft_xfrm: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 08/12,v2] netfilter: nft_hash: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 09/12,v2] netfilter: nft_immediate: cancel register tracking for data destination register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 07/12,v2] netfilter: nft_osf: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 04/12,v2] netfilter: nft_lookup: only cancel tracking for clobbered dregs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 00/12,v2] register tracking infrastructure follow up
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 05/12,v2] netfilter: nft_meta: extend reduce support to bridge family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 10/12,v2] netfilter: nft_socket: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 06/12,v2] netfilter: nft_numgen: cancel register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 01/12,v2] netfilter: nf_tables: do not reduce read-only expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 02/12,v2] netfilter: nf_tables: cancel tracking for clobbered destination registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 03/12,v2] netfilter: nft_ct: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Xtables-addons URL issues
- From: Pander <pander@xxxxxxxxxxxxxxxxxxxxx>
- Xtables-addons geoip manual
- From: Pander <pander@xxxxxxxxxxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nf_tables: disable register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] Revert "netfilter: conntrack: tag conntracks picked up in local out hook"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] Revert "netfilter: nat: force port remap to prevent shadowing well-known ports"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 8/8] netfilter: flowtable: add hardware offload tracepoints
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [PATCH net-next 5/8] netfilter: introduce max count of hw offload 'add' workqueue tasks
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [PATCH net-next 3/8] netfilter: introduce max count of hw offloaded flow table entries
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Vlad Buslov <vladbu@xxxxxxxxxx>
- [PATCH nf-next 8/9] netfilter: nft_hash: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 9/9] netfilter: nft_immediate: cancel register tracking for data destination register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 6/9] netfilter: nft_numgen: cancel register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 7/9] netfilter: nft_osf: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 5/9] netfilter: nft_meta: extend reduce support to bridge family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/9] netfilter: nft_lookup: only cancel tracking for clobbered dregs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/9] netfilter: nft_ct: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/9] netfilter: nf_tables: do not reduce read-only expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/9] netfilter: nf_tables: cancel tracking for clobbered destination registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/9] register tracking infrastructure follow up
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_tables: disable register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: do not reduce read-only expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: disable register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: add stubs for readonly expressions
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_payload: only cancel tracking for clobbered dregs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v5] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: disable register tracking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: add stubs for readonly expressions
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: add stubs for readonly expressions
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH libnftnl 3/3] desc: add set description
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf] Revert "netfilter: conntrack: tag conntracks picked up in local out hook"
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: add stubs for readonly expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_meta: extend reduce support to bridge family
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_lookup: only cancel tracking for clobbered dregs
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf,v4] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v33 18/29] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v33 16/29] LSM: Use lsmcontext in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v33 15/29] LSM: Ensure the correct LSM context releaser
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v33 09/29] LSM: Use lsmblob in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v33 08/29] LSM: Use lsmblob in security_secctx_to_secid
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl 0/3] add description infrastructure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl 3/3] desc: add set description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: cancel register tracking if .reduce is not defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/4] netfilter: conntrack: prepare tcp_in_window for tristate return value
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: conntrack: remove unneeded indent level
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/4] netfilter: conntrack: ignore overly delayed tcp packets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/4] netfilter: conntrack: ignore overly delayed tcp packets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/4] netfilter: conntrack: remove pr_debug callsites from tcp tracker
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables RFC 2/2] libxtables: Boost rule target checks by announcing chain names
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables RFC 1/2] libxtables: Implement notargets hash table
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 3/4] xshared: Prefer xtables_chain_protos lookup over getprotoent
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables RFC 2/2] libxtables: Boost rule target checks by announcing chain names
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 3/4] xshared: Prefer xtables_chain_protos lookup over getprotoent
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables RFC 1/2] libxtables: Implement notargets hash table
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 4/4] nft: Don't pass command state opaque to family ops callbacks
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 3/4] xshared: Prefer xtables_chain_protos lookup over getprotoent
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: Simplify immediate parsing
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnftnl 0/3] add description infrastructure
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH libnftnl 3/3] desc: add set description
- From: Phil Sutter <phil@xxxxxx>
- [PATCH AUTOSEL 5.16 18/27] netfilter: egress: silence egress hook lockdep splats
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [RFC PATCH v4 15/15] seltest/landlock: invalid user input data test
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 12/15] seltest/landlock: connect() with AF_UNSPEC tests
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 13/15] seltest/landlock: rules overlapping test
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 14/15] seltest/landlock: ruleset expanding test
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 11/15] seltest/landlock: add tests for connect() hooks
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 10/15] seltest/landlock: add tests for bind() hooks
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 02/15] landlock: filesystem access mask helpers
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 03/15] landlock: landlock_find/insert_rule refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 08/15] landlock: add support network rules
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 09/15] landlock: TCP network hooks implementation
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 06/15] landlock: landlock_add_rule syscall refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 04/15] landlock: merge and inherit function refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 05/15] landlock: unmask_layers() function refactoring
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 07/15] landlock: user space API network support
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 00/15] Landlock LSM
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- [RFC PATCH v4 01/15] landlock: access mask renaming
- From: Konstantin Meskhidze <konstantin.meskhidze@xxxxxxxxxx>
- Re: [PATCH conntrack-tools] nfct: remove lazy binding
- From: Phil Sutter <phil@xxxxxx>
- Re: [conntrack-tools PATCH] nfct: Support for non-lazy binding
- From: Phil Sutter <phil@xxxxxx>
- Re: Looking for info on ipset set type revisions
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Looking for info on ipset set type revisions
- From: Ian Pilcher <arequipeno@xxxxxxxxx>
- [PATCH conntrack-tools] nfct: remove lazy binding
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 0/3] conntrack: use libmnl for various operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH] nfct: Support for non-lazy binding
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] Revert "netfilter: conntrack: tag conntracks picked up in local out hook"
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] Revert "netfilter: nat: force port remap to prevent shadowing well-known ports"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: TCP connection fails in a asymmetric routing situation
- From: "H.Janssen" <hmmsjan@xxxxxxxxxxxx>
- Re: [PATCH net-next 8/8] netfilter: flowtable: add hardware offload tracepoints
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 4/8] netfilter: introduce total count of hw offload 'add' workqueue tasks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 5/8] netfilter: introduce max count of hw offload 'add' workqueue tasks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/8] netfilter: introduce max count of hw offloaded flow table entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conditionally use ct and ctinfo
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: introduce total count of hw offloaded flow table entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/8] net/sched: act_ct: set 'net' pointer when creating new nf_flow_table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] misspell: Avoid segfault with anonymous chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conditionally use ct and ctinfo
- From: Tom Rix <trix@xxxxxxxxxx>
- Re: [PATCH] netfilter: conditionally use ct and ctinfo
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: bridge: clean up some inconsistent indenting
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: bridge: clean up some inconsistent indenting
- From: Jiapeng Chong <jiapeng.chong@xxxxxxxxxxxxxxxxx>
- [PATCH] netfilter: conditionally use ct and ctinfo
- [PATCH bpf-next v4 7/8] bpf: Replace __diag_ignore with unified __diag_ignore_all
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: nftables 1.0.2 building issues
- From: Jan Engelhardt <jengelh@xxxxxxx>
- nftables 1.0.2 building issues
- From: "Francesco Colista" <francesco@xxxxxxx>
- Re: [PATCH nft] evaluate: init cmd pointer for new on-stack context
- From: Phil Sutter <phil@xxxxxx>
- [iptables RFC 0/2] Speed up restoring huge rulesets
- From: Phil Sutter <phil@xxxxxx>
- [iptables RFC 1/2] libxtables: Implement notargets hash table
- From: Phil Sutter <phil@xxxxxx>
- [iptables RFC 2/2] libxtables: Boost rule target checks by announcing chain names
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] misspell: Avoid segfault with anonymous chains
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] evaluate: init cmd pointer for new on-stack context
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] misspell: Avoid segfault with anonymous chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: init cmd pointer for new on-stack context
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] misspell: Avoid segfault with anonymous chains
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] evaluate: init cmd pointer for new on-stack context
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] optimize: do not assume log prefix
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH bpf-next v3 7/8] bpf: Replace __diag_ignore with unified __diag_ignore_all
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
- Re: [PATCH v2] selftests: netfilter: fix a build error on openSUSE
- From: Shuah Khan <skhan@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH v2] selftests: netfilter: fix a build error on openSUSE
- From: Shuah Khan <skhan@xxxxxxxxxxxxxxxxxxx>
- [PATCH nft,v3 3/3] optimize: do not merge unsupported statement expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 2/3] optimize: incorrect assert() for unexpected expression type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 1/3] optimize: more robust statement merge with vmap
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2] optimize: do not merge unsupported statement expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nft_ct: track register operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 2/2] optimize: incorrect assert() for unexpected expression type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 1/2] optimize: more robust statement merge with vmap
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] optimize: do not merge unsupported statement expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [RFC v3 nf-next 15/15] netfilter: conntrack: remove unconfirmed list
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 14/15] netfilter: conntrack: remove __nf_ct_unconfirmed_destroy
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 13/15] netfilter: cttimeout: decouple unlink and free on netns destruction
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 12/15] netfilter: extensions: introduce extension genid count
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 11/15] netfilter: remove nf_ct_unconfirmed_destroy helper
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 10/15] netfilter: cttimeout: decouple unlink and free on netns destruction
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 09/15] netfilter: nfnetlink_cttimeout: use rcu protection in cttimeout_get_timeout
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 08/15] netfilter: cttimeout: inc/dec module refcount per object, not per use refcount
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 07/15] netfilter: conntrack: remove the percpu dying list
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 06/15] netfilter: conntrack: include ecache dying list in dumps
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 05/15] netfilter: conntrack: split inner loop of list dumping to own function
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 04/15] netfilter: ecache: use dedicated list for event redelivery
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 03/15] netfilter: ecache: move to separate structure
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 02/15] netfilter: ctnetlink: make ecache event cb global again
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 01/15] nfnetlink: handle already-released nl socket
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC v3 nf-next 00/15] netfilter: conntrack: remove percpu lists
- From: Florian Westphal <fw@xxxxxxxxx>
- heads up, rebasing nf-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] optimize: more robust statement merge with vmap
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] optimize: incorrect assert() for unexpected expression type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] optimize: fix vmap with anonymous sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH bpf-next v2 7/8] bpf: Replace __diag_ignore with unified __diag_ignore_all
- From: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]