Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [syzbot] WARNING: kmalloc bug in hash_netport_create
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [syzbot] WARNING: kmalloc bug in hash_ipmark_create
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [syzbot] WARNING: kmalloc bug in hash_netport_create
- From: syzbot <syzbot+3f5904753c2388727c6c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [syzbot] WARNING: kmalloc bug in hash_ipmark_create
- From: syzbot <syzbot+5a5a70ab7329b98649e7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [syzbot] WARNING: kmalloc bug in nf_tables_newset
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [syzbot] WARNING: kmalloc bug in hash_ip_create
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [syzbot] WARNING: kmalloc bug in hash_net_create
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [syzbot] WARNING: kmalloc bug in hash_ipmac_create
- From: syzbot <syzbot+cf28dc7802e9fcee1305@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [syzbot] WARNING: kmalloc bug in hash_net_create
- From: syzbot <syzbot+2b8443c35458a617c904@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [syzbot] WARNING: kmalloc bug in nf_tables_newset
- From: syzbot <syzbot+cd43695a64bcd21b8596@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [syzbot] WARNING: kmalloc bug in hash_ip_create
- From: syzbot <syzbot+3493b1873fb3ea827986@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH net 4/5] netfilter: refuse insertion if chain has grown too large
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/5] netfilter: socket: icmp6: fix use-after-scope
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/5] netfilter: conntrack: switch to siphash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/5] netfilter: conntrack: sanitize table size default settings
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/5] netfilter: nft_ct: protect nft_ct_pcpu_template_refcnt with mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: socket: icmp6: fix use-after-scope
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] iptables-test.py: print with color escapes only when stdout isatty
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] iptables-test.py: print with color escapes only when stdout isatty
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: socket: icmp6: fix use-after-scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: socket: icmp6: fix use-after-scope
- From: Benjamin Hesmans <benjamin.hesmans@xxxxxxxxxxxx>
- Re: [PATCH iptables] Fix a few doc typos
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] iptables-test.py: print with color escapes only when stdout isatty
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] include: add NFT_CTX_OUTPUT_NUMERIC_TIME to NFT_CTX_OUTPUT_NUMERIC_ALL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] datatype: time_print() ignores -T
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: Fix rendering of verbatim '\n"' in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH iptables] Fix a few doc typos
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- [PATCH iptables] iptables-test.py: print with color escapes only when stdout isatty
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- [PATCH libnetfilter_log 1/1] build: doc: `make` generates requested documentation
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 0/1] build: doc: `make` generates requested documentation
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [nft PATCH] parser_json: Fix error reporting for invalid syntax
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 1/1] src: doc: Eliminate doxygen warnings
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 0/1] src: doc: Eliminate doxygen warnings
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Netdevconf 0x15 videos, slides and papers up
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Netdevconf 0x15 slides and papers up
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [iptables PATCH 2/2] nft: Use xtables_{m,c}alloc() everywhere
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/2] nft: Use xtables_malloc() in mnl_err_list_node_add()
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 3/3] build: doc: remove trailing whitespace from doxygen.cfg.in
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 2/3] build: doc: reduce doxygen.cfg.in to non-default entries only
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 1/3] src: whitespace: Remove trailing whitespace and inconsistent indents
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 0/3] Miscellaneous cleanups
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nft 2/2] rule: remove redundant meta protocol from the evaluation step
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] netlink_delinearize: incorrect meta protocol dependency kill again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] extensions: libxt_mac: Fix for missing space in listing
- From: Phil Sutter <phil@xxxxxx>
- Re: System crash in netfilter 5.10.25
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] netlink_delinearize: incorrect meta protocol dependency kill
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] netlink_delinearize: incorrect meta protocol dependency kill
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] netlink_delinearize: incorrect meta protocol dependency kill
- From: Phil Sutter <phil@xxxxxx>
- Re: System crash in netfilter 5.10.25
- From: Yuri Lipnesh <yuri.lipnesh@xxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH net-next 1/8] netfilter: ecache: remove one indent level
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH nf 0/3] netfilter: conntrack: switch to siphash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 3/8] netfilter: ecache: add common helper for nf_conntrack_eventmask_report
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 7/8] netfilter: x_tables: handle xt_register_template() returning an error value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 6/8] netfilter: ctnetlink: missing counters and timestamp in nfnetlink_{log,queue}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 8/8] netfilter: add netfilter hooks to SRv6 data plane
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 5/8] netfilter: ecache: remove nf_exp_event_notifier structure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 4/8] netfilter: ecache: prepare for event notifier merge
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/8] netfilter: ecache: remove one indent level
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/8] netfilter: ecache: remove another indent level
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 0/8] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Patch for iptables v 1.8.7 mac extension
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Patch for iptables v 1.8.7 mac extension
- From: "a.wojcik hyp.home.pl" <a.wojcik@xxxxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 5/6] build: doc: Allow to specify whether to produce man pages, html, neither or both
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: Be sure to rerun doxygen after ./configure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Eliminate warning from ./autogen.sh
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v7 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- Re: libnetfilter_queue: automake portability warning
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: Be sure to rerun doxygen after ./configure
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] build: doc: Eliminate warning from ./autogen.sh
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: libnetfilter_queue: automake portability warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: libnetfilter_queue: automake portability warning
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log 4/6] src: use calloc instead of malloc + memset.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 5/6] libipulog: use correct index to find attribute in packet.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 6/6] libipulog: fill in missing packet fields.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 3/6] doc: fix typo's in example.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 1/6] Add doxygen directory to .gitignore.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 2/6] build: remove references to non-existent man-pages.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_log 0/6] Implementation of some fields omitted by `ipulog_get_packet`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: libnetfilter_queue: automake portability warning
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_log] build: remove broken code from autogen.sh.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 4/6] build: doc: fix `make distcleancheck`
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 3/6] build: doc: Avoid having to special-case `make distcheck`
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 2/6] build: doc: Add a man page post-processor to build_man.sh
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 1/6] build: doc: Fix man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Verion info
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 6/6] build: doc: Eliminate warning from ./autogen.sh
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 5/6] build: doc: Allow to specify whether to produce man pages, html, neither or both
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 4/6] build: doc: fix `make distcleancheck`
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 3/6] build: doc: Avoid having to special-case `make distcheck`
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 2/6] build: doc: Add a man page post-processor to build_man.sh
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 1/6] build: doc: Fix man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: libnetfilter_queue: automake portability warning
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- libnetfilter_queue: automake portability warning
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_log] build: remove broken code from autogen.sh.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf 3/3] netfilter: refuse insertion if chain has grown too large
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 3/3] netfilter: conntrack: refuse insertion if chain has grown too large
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/3] netfilter: conntrack: switch to siphash
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/3] netfilter: conntrack: sanitize table size default settings
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/3] netfilter: conntrack: switch to siphash
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] netlink_delinearize: incorrect meta protocol dependency kill
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [Bug] Reverse translation skips "leading" meta protocol match
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] netlink_delinearize: incorrect meta protocol dependency kill
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Bug] Reverse translation skips "leading" meta protocol match
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- [Bug] Reverse translation skips "leading" meta protocol match
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- [PATCH libnetfilter_queue v2 5/5] build: doc: Allow to specify whether to produce man pages, html, neither or both
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2 4/5] build: doc: fix `make distcleancheck`
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2 3/5] build: doc: Avoid having to special-case `make distcheck`
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2 2/5] build: doc: Add a man page post-processor to build_man.sh
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2 1/5] build: doc: Fix man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] cache: provide a empty list for flowtables and objects when request fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: x_tables: handle xt_register_template() returning an error value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/5] netfilter: ecache: simplify event registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 4/4] build: doc: split off shell script from within doxygen/Makefile.am
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 3/4] build: doc: VPATH builds work again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 4/4] build: doc: split off shell script from within doxygen/Makefile.am
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: Fix man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 4/4] build: doc: split off shell script from within doxygen/Makefile.am
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 3/4] build: doc: VPATH builds work again
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 3/4] build: doc: VPATH builds work again
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 2/4] build: doc: can choose what to build and install
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: Request for a backport to Linux v5.4
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: Request for a backport to Linux v5.4
- From: Florian Westphal <fw@xxxxxxxxx>
- Request for a backport to Linux v5.4
- From: Gianluca Anzolin <gianluca@xxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 2/4] build: doc: can choose what to build and install
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 4/4] build: doc: split off shell script from within doxygen/Makefile.am
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v4 3/4] build: doc: VPATH builds work again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] cache: skip set element netlink dump for add/delete element command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: x_tables: handle xt_register_template() returning an error value
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Suspicious pattern for use of function xt_register_template()
- From: Lukas Bulwahn <lukas.bulwahn@xxxxxxxxx>
- [PATCH] netfilter: x_tables: handle xt_register_template() returning an error value
- From: Lukas Bulwahn <lukas.bulwahn@xxxxxxxxx>
- Re: Suspicious pattern for use of function xt_register_template()
- From: Florian Westphal <fw@xxxxxxxxx>
- Suspicious pattern for use of function xt_register_template()
- From: Lukas Bulwahn <lukas.bulwahn@xxxxxxxxx>
- [PATCH 2/2] conntrack: use same nfct handle for all entries
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH 1/2] tests/conntrack: script for stress-testing ct load
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- [PATCH 0/2] Reusing nfct handle for bulk ct loads
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxx>
- Re: [PATCH nftables] src: Optimize prefix match only if is big-endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH xtables-addons 0/8] xt_condition: per-net improvements
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH xtables-addons 1/8] build: bump minimum supported kernel version from 4.15 to 4.16.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Seemingly random crashes with CONFIG_HARDENED_USERCOPY=y on ppc64be
- From: Stijn Tintel <stijn@xxxxxxxxxxxxx>
- [PATCH xtables-addons 3/8] xt_condition: use `xt_check_proc_name` to validate /proc file-name.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 7/8] xt_condition: don't delete variables in `condition_net_exit`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 8/8] xt_condition: simplify clean-up of variables.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 4/8] xt_condition: make mutex per-net.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 6/8] xt_condition: use `proc_net_condition` member of `struct condition_net`to signal that `condition_net_exit` has been called.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 5/8] xt_condition: remove `wmb` when adding new variable.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 2/8] xt_condition: use sizeof_field macro to size variable name.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 1/8] build: bump minimum supported kernel version from 4.15 to 4.16.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 0/8] xt_condition: per-net improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] xtables-addons 3.18 condition - Improved network namespace support
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Old good cBPF and program size
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: [PATCH] xtables-addons 3.18 condition - Improved network namespace support
- From: Grzegorz Kuczyński <grzegorz.kuczynski@xxxxxxxxxx>
- Re: [PATCH] xtables-addons 3.18 condition - Improved network namespace support
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] xtables-addons 3.18 condition - Improved network namespace support
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] Add DWARF object files to .gitignore.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH libnetfilter_queue v3 1/3] build: doc: Fix NAME entry in man pages
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnetfilter_queue v4 4/4] build: doc: split off shell script from within doxygen/Makefile.am
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v4 3/4] build: doc: VPATH builds work again
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v4 2/4] build: doc: can choose what to build and install
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v4 1/4] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 1/3] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 1/3] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH] Add DWARF object files to .gitignore.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH] Add DWARF object files to .gitignore.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 1/3] build: doc: Fix NAME entry in man pages
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH net-next v4] net: ipvs: add sysctl_run_estimation to support disable estimation
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH libnetfilter_queue v3 3/3] build: doc: VPATH builds work again
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 2/3] build: doc: can choose what to build and install
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 1/3] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Read in nf_tables_dump_sets
- From: syzbot <syzbot+8cc940a9689599e10587@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH] xtables-addons 3.18 condition - Improved network namespace support
- From: Grzegorz Kuczyński <grzegorz.kuczynski@xxxxxxxxxx>
- [PATCH nftables] src: Optimize prefix match only if is big-endian
- From: Xiao Liang <shaw.leon@xxxxxxxxx>
- [PATCH nft,v3] src: queue: consolidate queue statement syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2] src: queue: consolidate queue statement syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: shell: add nft-f/0022variables_0 dump file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: queue: consolidate queue statement syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: restore variable expression in queue statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser: permit symbolic defines for 'queue num' again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [ANNOUNCE] nftables 1.0.0 release
- From: Amish <anon.amish@xxxxxxxxx>
- [ANNOUNCE] nftables 1.0.0 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: ctnetlink: missing counters and timestamp in nfnetlink_{log,queue}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 40/63] netfilter: conntrack: Use memset_startat() to zero struct nf_conn
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- [PATCH v2 iptables] iptables-nft: allow removal of empty builtin chains
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v7 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v7 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v7 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- Re: [PATCH v6 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v6 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v6 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v6 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.4 3/5] netfilter: conntrack: collect all entries in one cycle
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 3/4] netfilter: conntrack: collect all entries in one cycle
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.10 5/9] netfilter: conntrack: collect all entries in one cycle
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.13 07/12] netfilter: conntrack: collect all entries in one cycle
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.13 06/12] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 5/5] netfilter: ecache: remove nf_exp_event_notifier structure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/5] netfilter: ecache: prepare for event notifier merge
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/5] netfilter: ecache: add common helper for nf_conntrack_eventmask_report
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/5] netfilter: ecache: remove another indent level
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/5] netfilter: ecache: remove one indent level
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/5] netfilter: ecache: simplify event registration
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] netlink_delinearize: skip flags / mask notation for singleton bitmask again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3 1/1] src: doc: Insert SYNOPSIS sections for man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libxt_ACCOUNT_cl: correct LDFLAGS variable name.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- Re: nfnetlink_queue -- why linear lookup ?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] libxt_ACCOUNT_cl: correct LDFLAGS variable name.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- nfnetlink_queue -- why linear lookup ?
- From: <alexandre.ferrieux@xxxxxxxxxx>
- [PATCH libnetfilter_queue v3 1/1] src: doc: Insert SYNOPSIS sections for man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v3 0/1] src: doc: Insert SYNOPSIS sections for man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [syzbot] WARNING in destroy_conntrack
- From: Pavel Skripkin <paskripkin@xxxxxxxxx>
- [PATCH nft] evaluate: expand variable containing set into multiple mappings
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: remove duplicate code
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2 1/1] src: doc: Insert SYNOPSIS sections for man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2 0/1] Insert SYNOPSIS sections for man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [nft PATCH 1/3] tests: json_echo: Print errors to stderr
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 3/3] tests: monitor: Continue on error
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/3] tests: monitor: Print errors to stderr
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] iptables-test: Make netns spawning more robust
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nft] evaluate: element key cannot in map cannot be a set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 01/10] netfilter: nft_compat: use nfnetlink_unicast()
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v2] netfilter: protect nft_ct_pcpu_template_refcnt with mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 10/10] netfilter: nf_queue: move hookfn registration out of struct net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 08/10] netfilter: ctnetlink: allow to filter dump by status bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 09/10] netfilter: x_tables: never register tables by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 06/10] netfilter: ebtables: do not hook tables by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 07/10] netfilter: ctnetlink: add and use a helper for mark parsing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 05/10] netfilter: remove xt pernet data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 04/10] netfilter: ipt_CLUSTERIP: use clusterip_net to store pernet warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 03/10] netfilter: ipt_CLUSTERIP: only add arp mangle hook when required
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 02/10] netfilter: flowtable: remove nf_ct_l4proto_find() call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 01/10] netfilter: nft_compat: use nfnetlink_unicast()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 00/10] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nft] tcpopt: bogus assertion on undefined options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Netdevconf 0x15 slides and papers up
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl] src: doc: Fix messed-up Netlink message batch diagram
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_queue: move hookfn registration out of struct net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] x_tables: never register tables by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] tests/py: Make netns spawning more robust
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] netfilter: protect nft_ct_pcpu_template_refcnt with mutex
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2] netfilter: protect nft_ct_pcpu_template_refcnt with mutex
- From: Pavel Skripkin <paskripkin@xxxxxxxxx>
- [PATCH] netfiler: protect nft_ct_pcpu_template_refcnt with mutex
- From: Pavel Skripkin <paskripkin@xxxxxxxxx>
- Re: [nft PATCH RFC] scanner: nat: Move to own scope
- From: Phil Sutter <phil@xxxxxx>
- [ANNOUNCE] ipset 7.15 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: syzbot <syzbot+649e339fa6658ee623d3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: syzbot <syzbot+649e339fa6658ee623d3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: Pavel Skripkin <paskripkin@xxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 3/3] extensions: libxf_NFLOG: remove `--nflog-range` Python unit-tests.
- From: Kyle Bowman <kbowman@xxxxxxxxxxxxxx>
- [PATCH 2/3] extensions: libxt_NFLOG: dont truncate log prefix on print/save
- From: Kyle Bowman <kbowman@xxxxxxxxxxxxxx>
- [PATCH 1/3] extensions: libtxt_NFLOG: use nft built-in logging instead of xt_NFLOG
- From: Kyle Bowman <kbowman@xxxxxxxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: Pavel Skripkin <paskripkin@xxxxxxxxx>
- Re: [nft PATCH RFC] scanner: nat: Move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: remove duplicate code
- From: Kangmin Park <l4stpr0gr4m@xxxxxxxxx>
- [iptables PATCH] extensions: hashlimit: Fix tests with HZ=100
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH RFC] scanner: nat: Move to own scope
- From: Phil Sutter <phil@xxxxxx>
- [syzbot] WARNING in destroy_conntrack
- From: syzbot <syzbot+a1eb62c681423ee5c0d7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [syzbot] KASAN: use-after-free Read in nf_tables_dump_sets
- From: syzbot <syzbot+8cc940a9689599e10587@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [nft PATCH RFC] scanner: nat: Move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH RFC] scanner: nat: Move to own scope
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH RFC libnetfilter_queue 1/1] src: doc: supply missing SYNOPSIS in pktbuff man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH RFC libnetfilter_queue 1/1] src: doc: supply missing SYNOPSIS in pktbuff man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] src: doc: Insert SYNOPSIS sections for man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: Fix NAME entry in man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH net-next 3/3] selftests: netfilter: Add RFC-7597 Section 5.1 PSID selftests
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH net-next 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH net-next 1/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support xtables API
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH net-next 0/3] Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH v5 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: proelbtn <contact@xxxxxxxxxxxx>
- [PATCH v5 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: proelbtn <contact@xxxxxxxxxxxx>
- [PATCH v5 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows
- From: proelbtn <contact@xxxxxxxxxxxx>
- [PATCH libmnl] src: doc: Fix messed-up Netlink message batch diagram
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: syzbot <syzbot+649e339fa6658ee623d3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu
- From: syzbot <syzbot+649e339fa6658ee623d3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libmnl] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH] netfilter: remove duplicate code
- From: Kangmin Park <l4stpr0gr4m@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net 0/9,v2] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- LPC 2021 Networking and BPF Track CFP (2nd reminder)
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH net 9/9] netfilter: nfnetlink_hook: translate inet ingress to netdev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 7/9] netfilter: nfnetlink_hook: Use same family as request message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/9] netfilter: nfnetlink_hook: use the sequence number of the request message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 8/9] netfilter: conntrack: remove offload_pickup sysctl again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/9] netfilter: nfnetlink_hook: missing chain family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/9] netfilter: nfnetlink_hook: strip off module name from hookfn
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/9] netfilter: conntrack: collect all entries in one cycle
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/9] netfilter: nf_conntrack_bridge: Fix memory leak when error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/9] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/9,v2] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 3/9] netfilter: conntrack: collect all entries in one cycle
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 3/9] netfilter: conntrack: collect all entries in one cycle
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 3/9] netfilter: conntrack: collect all entries in one cycle
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH net 9/9] netfilter: nfnetlink_hook: translate inet ingress to netdev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 8/9] netfilter: conntrack: remove offload_pickup sysctl again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 7/9] netfilter: nfnetlink_hook: Use same family as request message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/9] netfilter: nfnetlink_hook: missing chain family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/9] netfilter: nfnetlink_hook: use the sequence number of the request message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/9] netfilter: nfnetlink_hook: strip off module name from hookfn
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/9] netfilter: conntrack: collect all entries in one cycle
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/9] netfilter: nf_conntrack_bridge: Fix memory leak when error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/9] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nfnetlink_hook: translate inet ingress to netdev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] netfilter: ctnetlink: allow to filter dumps via ct->status
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: collect all entries in one cycle
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2] netfilter: nf_queue: move hookfn registration out of struct net
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_queue: move hookfn registration out of struct net
- From: Florian Westphal <fw@xxxxxxxxx>
- [syzbot] WARNING: proc registration bug in clusterip_tg_check (3)
- From: syzbot <syzbot+08e6343a8cbd89b0c9d8@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH iptables] ip6tables: masquerade: use fully-random so that nft can understand the rule
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH iptables] ip6tables: masquerade: use fully-random so that nft can understand the rule
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Oz Shlomo <ozsh@xxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- [PATCH v2 nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Oz Shlomo <ozsh@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Oz Shlomo <ozsh@xxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: remove offload_pickup sysctl again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Fix maximal range check in hash_ipportnet4_uadt()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: fix uninitialized variable bug
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH] netfilter: ipset: fix uninitialized variable bug
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2 1/1] Eliminate packet copy when constructing struct pkt_buff
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nfnetlink_hook: Use same family as request message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nfnetlink_hook: use the sequence number of the request message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3] mnl: revisit hook listing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Fix maximal range check in hash_ipportnet4_uadt()
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH] netfilter: ipset: Fix maximal range check in hash_ipportnet4_uadt()
- From: Nathan Chancellor <nathan@xxxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Kyle Bowman <kbowman@xxxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH nf-next] x_tables: never register tables by default
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [iptables PATCH] tests/shell: Assert non-verbose mode is silent
- From: Phil Sutter <phil@xxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [iptables PATCH] nft: Fix for non-verbose check command
- From: Phil Sutter <phil@xxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- [PATCH nft,v2] mnl: revisit hook listing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nfnetlink_hook: missing chain family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nfnetlink_hook: strip off module name from hookfn
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] mnl: revisit hook listing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v4 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: proelbtn <contact@xxxxxxxxxxxx>
- [PATCH v4 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: proelbtn <contact@xxxxxxxxxxxx>
- [PATCH v4 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows
- From: proelbtn <contact@xxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Phil Sutter <phil@xxxxxx>
- [PATCH conntrack-tools 4/4] conntrack: add shorthand mnemonic for UNREPLIED
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH conntrack-tools 3/4] conntrack: enable kernel-based status filtering with -L -u STATUS
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH lnf-conntrack 2/4] src: add support for status dump filter
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH lnf-conntrack 1/4] include: sync uapi header with nf-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] conntrack-tools: support conntrack dump status filtering
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] ebtables: Dump atomic waste
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ebtables: do not hook tables by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libmnl] build: doc: get rid of the need for manual updating of Makefile
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] netfilter: nf_conntrack_bridge: Fix memory leak when error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/1] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: clusterip: don't register hook in all netns
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Kyle Bowman <kbowman@xxxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: ctnetlink: allow to filter dump by status bits
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: ctnetlink: add and use a helper for mark parsing
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: ctnetlink: allow to filter dumps via ct->status
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] ebtables: Dump atomic waste
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- [PATCH v3 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v3 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v3 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: [PATCH v2 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- [PATCH v2 2/2] netfilter: add netfilter hooks to SRv6 data plane
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v2 1/2] netfilter: add new sysctl toggle for lightweight tunnel netfilter hooks
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v2 0/2] net: add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <contact@xxxxxxxxxxxx>
- [PATCH v3] netfilter: nf_conntrack_bridge: Fix memory leak when error
- From: Yajun Deng <yajun.deng@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack_bridge: Fix memory leak when error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] netfilter: nf_conntrack_bridge: Fix memory leak when error
- From: Yajun Deng <yajun.deng@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_bridge: Fix not free when error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft] Regarding `tcp flags` (and a potential bug)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_bridge: Fix not free when error
- From: yajun.deng@xxxxxxxxx
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: [nft] Regarding `tcp flags` (and a potential bug)
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: [iptables PATCH] doc: ebtables-nft.8: Adjust for missing atomic-options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_bridge: Fix not free when error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] doc: ebtables-nft.8: Adjust for missing atomic-options
- From: Phil Sutter <phil@xxxxxx>
- [PATCH 0/1] ipset patch for the nf tree v2
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [ANNOUNCE] ipset 7.14 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] ipset 7.13 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] ipset 7.13 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] ipset 7.13 released
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] net: netfilter: Fix port selection of FTP for NF_NAT_RANGE_PROTO_SPECIFIED
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH] net: netfilter: Fix port selection of FTP for NF_NAT_RANGE_PROTO_SPECIFIED
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH nft] tests: py: check more flag match transformations to compact syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: netfilter: Fix port selection of FTP for NF_NAT_RANGE_PROTO_SPECIFIED
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: netfilter: Fix port selection of FTP for NF_NAT_RANGE_PROTO_SPECIFIED
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH] net: netfilter: Fix port selection of FTP for NF_NAT_RANGE_PROTO_SPECIFIED
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Alex Forster <aforster@xxxxxxxxxxxxxx>
- [PATCH nft,v2 3/3] tests: py: tcp flags & (fin | syn | rst | ack) == syn
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 2/3] netlink_delinearize: skip flags / mask notation for singleton bitmask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 1/3] tests: py: idempotent tcp flags & syn != 0 to tcp flag syn
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Alex Forster <aforster@xxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Alex Forster <aforster@xxxxxxxxxxxxxx>
- Re: [nft] Regarding `tcp flags` (and a potential bug)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] netlink_delinearize: skip flags / mask notation for singleton bitmask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] tests: py: idempotent tcp flags & syn != 0 to tcp flag syn
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Alex Forster <aforster@xxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes
- From: Kyle Bowman <kbowman@xxxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- [PATCH nft 2/3] netlink_linearize: incorrect netlink bytecode with binary operation and flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/3] evaluate: disallow negation with binary operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] expression: missing != in flagcmp expression print function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft] Regarding `tcp flags` (and a potential bug)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft] Regarding `tcp flags` (and a potential bug)
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- [PATCH 0/1] ipset patch for the nf tree
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [nft] Regarding `tcp flags` (and a potential bug)
- From: Tom Yan <tom.ty89@xxxxxxxxx>
- [ANNOUNCE] ipset 7.13 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: collect all entries in one cycle
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: error reporting for missing statements in set/map declaration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: promote 'reject with icmp CODE' syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: parse number as reject icmp code
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] tests: shell: Fix bogus testsuite failure with 100Hz
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] tests: shell: Fix bogus testsuite failure with 100Hz
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] parser_bison: stateful statement support in map
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_bridge: Fix not free when error
- From: Yajun Deng <yajun.deng@xxxxxxxxx>
- [PATCH 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- Re: Nf_nat_h323 module not working with Panasonic VCs
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Nf_nat_h323 module not working with Panasonic VCs
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- [PATCH nft 1/2] src: fix nft_ctx_clear_include_paths in libnftables.map
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] src: expose nft_ctx_clear_vars as API
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH RFC libnetfilter_queue 1/1] src: doc: supply missing SYNOPSIS in pktbuff man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC libnetfilter_queue 1/1] src: doc: supply missing SYNOPSIS in pktbuff man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net 1/6] netfilter: nf_tables: fix audit memory leak in nf_tables_commit
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net 4/6] netfilter: conntrack: adjust stop timestamp to real expiry value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/6] netfilter: flowtable: avoid possible false sharing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/6] netfilter: nfnl_hook: fix unused variable warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/6] netfilter: nft_nat: allow to specify layer 4 protocol NAT only
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/6] netfilter: nf_tables: fix audit memory leak in nf_tables_commit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/6] netfilter: nft_last: avoid possible false sharing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: ebtables: do not hook tables by default
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nfnl_hook: fix unused variable warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: adjust stop timestamp to real expiry value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC libnetfilter_queue 1/1] src: doc: supply missing SYNOPSIS in pktbuff man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] parser_bison: missing initialization of ct timeout policy list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] parser_json: inconditionally initialize ct timeout list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: remove xt pernet data
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: ipt_CLUSTERIP: use clusterip_net to store pernet warning
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: ipt_CLUSTERIP: only add arp mangle hook when required
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/3] netfilter: clusterip: don't register hook in all netns
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v28 18/25] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v28 16/25] LSM: Use lsmcontext in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v28 15/25] LSM: Ensure the correct LSM context releaser
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v28 08/25] LSM: Use lsmblob in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v28 07/25] LSM: Use lsmblob in security_secctx_to_secid
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH] netfilter: nfnl_hook: fix unused variable warning
- From: Arnd Bergmann <arnd@xxxxxxxxxx>
- [PATCH nf] netfilter: nft_nat: allow to specify layer 4 protocol NAT only
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: fix inet nat with no layer 3 info
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: add --define key=value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: flowtable: remove nf_ct_l4proto_find() call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <proelbtn@xxxxxxxxx>
- [PATCH 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: adjust stop timestamp to real expiry value
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 2/2] netfilter: flowtable: remove nf_ct_l4proto_find() call
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: examples: Use libnetfilter_queue cached linux headers throughout
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2 1/1] Eliminate packet copy when constructing struct pkt_buff
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: get rid of the need for manual updating of Makefile
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libmnl] build: doc: get rid of the need for manual updating of Makefile
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nft_last: avoid possible false sharing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: flowtable: avoid possible false sharing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: flowtable: remove nf_ct_l4proto_find() call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_last: avoid possible false sharing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: flowtable: remove nf_ct_l4proto_find() call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl 1/1] build: doc: "make" builds & installs a full set of man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libmnl 1/1] build: doc: "make" builds & installs a full set of man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH RFC libnetfilter_queue 1/1] src: doc: supply missing SYNOPSIS in pktbuff man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libmnl 1/1] build: doc: "make" builds & installs a full set of man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH v3] audit: fix memory leak in nf_tables_commit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 2/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH 3/3] selftests: netfilter: Add RFC-7597 Section 5.1 PSID selftests
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH 1/3] net: netfilter: Add RFC-7597 Section 5.1 PSID support xtables API
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH 0/3] Add RFC-7597 Section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- [PATCH] extensions: masquerade: Add RFC-7597 section 5.1 PSID support
- From: Cole Dishington <Cole.Dishington@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [syzbot] general protection fault in nf_tables_dump_flowtable
- From: syzbot <syzbot+58a66a56fa9d7f98d19b@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nft_compat: use nfnetlink_unicast()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] xtables: Call init_extensions6() for static builds
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v3] audit: fix memory leak in nf_tables_commit
- From: Dongliang Mu <mudongliangabcd@xxxxxxxxx>
- Re: [PATCH v2] audit: fix memory leak in nf_tables_commit
- From: Dongliang Mu <mudongliangabcd@xxxxxxxxx>
- [PATCH] xtables: Call init_extensions6() for static builds
- From: Erik Wilson <erik.e.wilson@xxxxxxxxx>
- Re: [PATCH nftables,v2 1/2] src: infer interval from set
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nftables,v3 3/3] src: support for nat with interval concatenation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables,v3 2/3] src: infer NAT mapping with concatenation from set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables,v3 1/3] src: remove STMT_NAT_F_INTERVAL flags and interval keyword
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_compat: use nfnetlink_unicast()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] net: Use nlmsg_unicast() instead of netlink_unicast()
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v2] net: Use nlmsg_unicast() instead of netlink_unicast()
- From: David Ahern <dsahern@xxxxxxxxx>
- Re: [PATCH v2] audit: fix memory leak in nf_tables_commit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] audit: fix memory leak in nf_tables_commit
- From: Dongliang Mu <mudongliangabcd@xxxxxxxxx>
- Re: [PATCH v2] audit: fix memory leak in nf_tables_commit
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2] audit: fix memory leak in nf_tables_commit
- From: Dongliang Mu <mudongliangabcd@xxxxxxxxx>
- [PATCH nftables,v2 2/2] src: support for nat with interval concatenation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables,v2 1/2] src: infer interval from set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] audit: fix memory leak in nf_tables_commit
- From: Lukas Bulwahn <lukas.bulwahn@xxxxxxxxx>
- Re: [PATCH] audit: fix memory leak in nf_tables_commit
- From: Dongliang Mu <mudongliangabcd@xxxxxxxxx>
- Re: [PATCH] audit: fix memory leak in nf_tables_commit
- From: Lukas Bulwahn <lukas.bulwahn@xxxxxxxxx>
- [issue] conntrack: lack of lock during nat
- From: ze wang <wangze712@xxxxxxxxx>
- [PATCH] audit: fix memory leak in nf_tables_commit
- From: Dongliang Mu <mudongliangabcd@xxxxxxxxx>
- [PATCH v2] net: Use nlmsg_unicast() instead of netlink_unicast()
- From: Yajun Deng <yajun.deng@xxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
- [PATCH nftables] src: support for nat with interval concatenation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables] netlink_delinearize: stmt and expr error path memleaks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: Use nlmsg_unicast() instead of netlink_unicast()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] net: Use nlmsg_unicast() instead of netlink_unicast()
- From: Yajun Deng <yajun.deng@xxxxxxxxx>
- Re: [PATCH nf] Revert "netfilter: flowtable: Remove redundant hw refresh bit"
- From: Felix Fietkau <nbd@xxxxxxxx>
- Re: [PATCH nf] Revert "netfilter: flowtable: Remove redundant hw refresh bit"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] Revert "netfilter: flowtable: Remove redundant hw refresh bit"
- From: Aleksander Bajkowski <olek2@xxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <proelbtn@xxxxxxxxx>
- Re: [PATCH nf] Revert "netfilter: flowtable: Remove redundant hw refresh bit"
- From: Martin Blumenstingl <martin.blumenstingl@xxxxxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <proelbtn@xxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
- Re: [PATCH net 01/11] selftest: netfilter: add test case for unreplied tcp connections
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net 11/11] netfilter: uapi: refer to nfnetlink_conntrack.h, not nf_conntrack_netlink.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 10/11] netfilter: nft_last: incorrect arithmetics when restoring last used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 09/11] netfilter: nft_last: honor NFTA_LAST_SET on restoration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 08/11] netfilter: conntrack: Mark access for KCSAN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 06/11] netfilter: conntrack: improve RST handling when tuple is re-used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 07/11] netfilter: conntrack: add new sysctl to disable RST check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 05/11] netfilter: ctnetlink: suspicious RCU usage in ctnetlink_dump_helpinfo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 04/11] netfilter: conntrack: nf_ct_gre_keymap_flush() removal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 03/11] netfilter: nf_tables: Fix dereference of null pointer flow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 02/11] netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 01/11] selftest: netfilter: add test case for unreplied tcp connections
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 00/11] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: uapi: refer to nfnetlink_conntrack.h, not nf_conntrack_netlink.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: netfilter: Use netlink_ns_capable to verify the permisions of netlink messages
- From: iLifetruth <yixiaonn@xxxxxxxxx>
- Netdevconf 0x15 update
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: netfilter: Use netlink_ns_capable to verify the permisions of netlink messages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl 1/1] build: doc: "make" builds & installs a full set of man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: examples: Use libnetfilter_queue cached linux headers throughout
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] include: refer to nfnetlink_conntrack.h, not nf_conntrack_netlink.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] src: annotation: Correctly identify item for which header is needed
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: uapi: refer to nfnetlink_conntrack.h, not nf_conntrack_netlink.h
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: annotation: Correctly identify item for which header is needed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: annotation: Correctly identify item for which header is needed
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH 1/2] net/netfilter/nf_conntrack_core: Mark access for KCSAN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: examples: Use libnetfilter_queue cached linux headers throughout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: annotation: Correctly identify item for which header is needed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- LPC 2021 Networking and BPF Track CFP (Reminder)
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: improve RST handling when tuple is re-used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: improve RST handling when tuple is re-used
- From: Ali Abdallah <ali.abdallah@xxxxxxxx>
- [PATCH libnetfilter_queue v2] src: examples: Use libnetfilter_queue cached linux headers throughout
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows
- From: Ryoga Saito <proelbtn@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: examples: Use libnetfilter_queue cached linux headers throughout
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] src: annotation: Correctly identify item for which header is needed
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: improve RST handling when tuple is re-used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables] src: add last statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] expr: last: add NFTNL_EXPR_LAST_SET
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] include: fix header file name in 3 comments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] include: fix header file name in 3 comments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nft_last: incorrect arithmetics when restoring last used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_last: honor NFTA_LAST_SET on restoration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Documentation question
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]