Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH net-next 00/10] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] audit: log nftables configuration change events once per table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] audit: log nftables configuration change events once per table
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Associate extra information to conntrack entries
- From: Major Dávid <major.david@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtable: separate replace, destroy and stats to different workqueues
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- [PATCH] nftables: add flags offload to flowtable
- From: Frank Wunderlich <linux@xxxxxxxxx>
- Re: [PATCH libnetfilter_conntrack] conntrack: Don't use ICMP attrs in decision to build repl tuple
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] audit: log nftables configuration change events once per table
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH] audit: log nftables configuration change events once per table
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net 8/9] netfilter: flowtable: Make sure GC works periodically in idle system
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 9/9] netfilter: nftables: skip hook overlap logic if flowtable is stale
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/9] Revert "netfilter: x_tables: Update remaining dereference to RCU"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/9] netfilter: nftables: report EOPNOTSUPP on unsupported flowtable flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 7/9] netfilter: nftables: allow to update flowtable flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/9] netfilter: x_tables: Use correct memory barriers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/9] netfilter: conntrack: Fix gre tunneling over ipv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/9] Revert "netfilter: x_tables: Switch synchronization to RCU"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/9] netfilter: ctnetlink: fix dump of the expect mask attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_conntrack] conntrack: Don't use ICMP attrs in decision to build repl tuple
- From: Luuk Paulussen <luuk.paulussen@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] audit: log nftables configuration change events once per table
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH] audit: log nftables configuration change events once per table
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH] audit: log nftables configuration change events once per table
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] audit: log nftables configuration change events once per table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] audit: log nftables configuration change events once per table
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft 6/6] src: allow arbitary chain name in implicit rule add case
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 6/6] src: allow arbitary chain name in implicit rule add case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Bug when updating ICMP flows using conntrack tools
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft 6/6] src: allow arbitary chain name in implicit rule add case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft 6/6] src: allow arbitary chain name in implicit rule add case
- From: Phil Sutter <phil@xxxxxx>
- Bug when updating ICMP flows using conntrack tools
- From: Luuk Paulussen <Luuk.Paulussen@xxxxxxxxxxxxxxxxxxx>
- [nf-next,v2] netfilter: nftables: update table flags from the commit phase
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nftables: update table flags from the commit phase
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nftables: missing transaction object on flowtable deletion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: flowtable: Make sure GC works periodically in idle system
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nft,v2] conntrack: Fix gre tunneling over ipv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: Remove unused variable declaration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RESEND][next] netfilter: Fix fall-through warnings for Clang
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtable: separate replace, destroy and stats to different workqueues
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: shell: flowtable add after delete in batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nftables: missing transaction object on flowtable deletion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nftables: skip hook overlap logic if flowtable is stale
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 1/8] conntrack: reset optind in do_parse
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- Re: [PATCH v3 4/8] conntrack: introduce ct_cmd_list
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- Re: [PATCH v3 3/8] conntrack: per-command entries counters
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH nf-next,v2 5/6] netfilter: flowtable: call dst_check() to fall back to classic forwarding
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2 1/6] netfilter: flowtable: consolidate skb_try_make_writable() call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2 4/6] netfilter: flowtable: fast NAT functions never fail
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2 3/6] netfilter: flowtable: move FLOW_OFFLOAD_DIR_MAX away from enumeration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2 2/6] netfilter: flowtable: move skb_try_make_writable() before NAT in IPv4
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2 6/6] netfilter: flowtable: refresh timeout after dst and writable checks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: flowtable: Make sure GC works periodically in idle system
- From: Simon Horman <simon.horman@xxxxxxxxxxxxx>
- Ethernet Frame capture with nfqueue
- From: ilker <ilkery@xxxxxxxxx>
- [PATCH 2/2,v2] netfilter: nftables: allow to update flowtable flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: flowtable: move FLOW_OFFLOAD_DIR_MAX away from enumeration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: flowtable: fast NAT functions never fail
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: flowtable: consolidate skb_try_make_writable() call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nftables: allow to update flowtable flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nftables: report EOPNOTSUPP on unsupported flowtable flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [syzbot] KMSAN: uninit-value in iptable_mangle_hook (5)
- From: syzbot <syzbot+9b5e12c49c015d4c1aeb@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft] segtree: release single element already contained in an interval
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 5/6] scanner: support arbitrary chain names
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 6/6] src: allow arbitary chain name in implicit rule add case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/6] arbirary table/chain names
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/6] scanner: add support for scope nesting
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/6] scanner: support arbitary table names
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/6] scanner: counter: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/6] scanner: log: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- CFS for Netdev 0x15 open!
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ctnetlink: fix dump of the expect mask attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 0/3] Don't use RCU for x_tables synchronization
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 1/8] conntrack: reset optind in do_parse
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 4/8] conntrack: introduce ct_cmd_list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 3/8] conntrack: per-command entries counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack 4/6] conntrack: pass cmd to filter nat, mark and network functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack 5/6] conntrack: move options flag to ct_cmd object
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack 1/6] conntrack: pass command object to callbacks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack 6/6] conntrack: add function to print command stats
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack 3/6] conntrack: pass cmd to nfct_filter()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack 2/6] conntrack: pass ct_cmd to nfct_filter_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: ctnetlink: fix dump of the expect mask attribute
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: xtables-addons-3.17 fail build on armv7 with musl libc
- From: Milan P. Stanić <mps@xxxxxxxxxxx>
- Re: [PATCH net-next 23/23] net: ethernet: mtk_eth_soc: fix parsing packets in GDM
- From: Felix Fietkau <nbd@xxxxxxxx>
- Re: [PATCH net-next 00/23] netfilter: flowtable enhancements
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/23] netfilter: flowtable enhancements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/23] netfilter: flowtable enhancements
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: xtables-addons-3.17 fail build on armv7 with musl libc
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH v2 0/3] Don't use RCU for x_tables synchronization
- From: Tyler Hicks <tyhicks@xxxxxxxxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH 2/2] tests: conntrackd: silence sysctl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH 1/2] tests: conntrackd: add testcase for missing hashtable buckets and max entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 12/12] scanner: secmark: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 11/12] scanner: move until,over,used keywords away from init state
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 10/12] scanner: quota: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 09/12] scanner: limit: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 06/12] scanner: arp: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 08/12] scanner: vlan: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 07/12] scanner: remove saddr/daddr from initial state
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 04/12] scanner: add fib scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 03/12] scanner: ip6: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 05/12] scanner: add ether scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 01/12] scanner: ct: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 02/12] scanner: ip: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 00/12] move more keywords away from initial scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: move remaining cache in rule.c function to cache.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next] netfilter: conntrack: Remove unused variable declaration
- From: YueHaibing <yuehaibing@xxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- [PATCH net-next 23/23] net: ethernet: mtk_eth_soc: fix parsing packets in GDM
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 22/23] net: ethernet: mtk_eth_soc: add flow offloading support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 20/23] dsa: slave: add support for TC_SETUP_FT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 21/23] net: ethernet: mtk_eth_soc: add support for initializing the PPE
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 19/23] netfilter: flowtable: support for FLOW_ACTION_PPPOE_PUSH
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 18/23] net: flow_offload: add FLOW_ACTION_PPPOE_PUSH
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 17/23] netfilter: flowtable: bridge vlan hardware offload and switchdev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 16/23] netfilter: nft_flow_offload: use direct xmit if hardware offload is enabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 14/23] selftests: netfilter: flowtable bridge and vlan support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 15/23] netfilter: flowtable: add offload support for xmit path types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 10/23] netfilter: flowtable: add vlan support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 13/23] netfilter: flowtable: add dsa support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 12/23] netfilter: flowtable: add pppoe support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 11/23] netfilter: flowtable: add bridge vlan filtering support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 09/23] netfilter: flowtable: use dev_fill_forward_path() to obtain egress device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 07/23] netfilter: flowtable: add xmit path types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 08/23] netfilter: flowtable: use dev_fill_forward_path() to obtain ingress device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 05/23] net: ppp: resolve forwarding path for bridge pppoe devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 06/23] net: dsa: resolve forwarding path for dsa slave ports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 03/23] net: bridge: resolve forwarding path for bridge devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 04/23] net: bridge: resolve forwarding path for VLAN tag actions in bridge devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 02/23] net: 8021q: resolve forwarding path for vlan devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 01/23] net: resolve forwarding path from virtual netdevice and HW destination address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 00/23] netfilter: flowtable enhancements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- [conntrack-tools PATCH 2/2] tests: conntrackd: silence sysctl
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH 1/2] tests: conntrackd: add testcase for missing hashtable buckets and max entries
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [PATCH RFC nf-next 0/2] ct helper object name matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC nf-next 0/2] ct helper object name matching
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH RFC nf-next 0/2] ct helper object name matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nftables: add NFT_CT_HELPER_OBJNAME
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nftables: rename NFT_CT_HELPER to NFT_CT_HELPER_TYPE
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [libnftnl PATCH 04/10] object: Fix for wrong parameter passed to snprintf callback
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 03/10] obj/ct_timeout: Fix snprintf buffer length updates
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 02/10] obj/ct_expect: Fix snprintf buffer length updates
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 10/10] ruleset: Eliminate tag and separator helpers
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 07/10] obj: Drop type parameter from snprintf callback
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 08/10] Drop pointless local variable in snprintf callbacks
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 09/10] Get rid of single option switch statements
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 06/10] expr/data_reg: Drop output_format parameter
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 00/10] Kill non-default output leftovers
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 05/10] expr: Check output type once and for all
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 01/10] expr: Fix snprintf buffer length updates
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] nftables: xt: fix misprint in nft_xt_compatible_revision
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] nftables: xt: fix misprint in nft_xt_compatible_revision
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- [PATCH nft] nftables: xt: fix misprint in nft_xt_compatible_revision
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- [PATCH v25 18/25] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v25 16/25] LSM: Use lsmcontext in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v25 15/25] LSM: Ensure the correct LSM context releaser
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v25 08/25] LSM: Use lsmblob in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v25 07/25] LSM: Use lsmblob in security_secctx_to_secid
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- Re: [libnftnl PATCH 5/5] expr: data_reg: Reduce indenting level a bit
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] net: bridge: fix error return code of do_update_counters()
- From: Jia-Ju Bai <baijiaju1990@xxxxxxxxx>
- Re: [HEADS UP] bugzilla.netfilter.org is under maintainance
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 3/3] netfilter: x_tables: Use correct memory barriers.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net: bridge: fix error return code of do_update_counters()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] doc: use symbolic names for chain priorities
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- Re: [RFC PATCH] doc: use symbolic names for chain priorities
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] conntrackd: set default hashtable buckets and max entries if not specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] conntrackd: set default hashtable buckets and max entries if not specified
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- [PATCH] net: bridge: fix error return code of do_update_counters()
- From: Jia-Ju Bai <baijiaju1990@xxxxxxxxx>
- Re: [PATCH 0/3] Minor documentation improvements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [HEADS UP] bugzilla.netfilter.org is under maintainance
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- xtables-addons-3.17 fail build on armv7 with musl libc
- From: Milan P. Stanić <mps@xxxxxxxxxxx>
- [PATCH nft 6/6] scanner: socket: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 5/6] scanner: rt: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/6] scanner: introduce start condition stack
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/6] scanner: ipsec: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/6] scanner: queue: move to own scope
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/6] scanner rework part 1
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/6] scanner: remove unused tokens
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- Re: {PATCH nf] x_tables: Allow REJECT targets in PREROUTING chains
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- [PATCH conntrack-tools] conntrackd: set default hashtable buckets and max entries if not specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] tests/py: Fix for missing JSON equivalent in any/ct.t.json
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] mnl: Set NFTNL_SET_DATA_TYPE before dumping set elements
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH] set_elem: Fix printing of verdict map elements
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] tests/py: Adjust payloads for fixed nat statement dumps
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH] expr/{masq,nat}: Don't print unused regs
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 0/5] A few cosmetic changes
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 2/5] expr/tunnel: Kill dead code
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 5/5] expr: data_reg: Reduce indenting level a bit
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 3/5] expr/xfrm: Kill dead code
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 1/5] expr/socket: Kill dead code
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH 4/5] rule: Avoid printing trailing spaces
- From: Phil Sutter <phil@xxxxxx>
- Re: {PATCH nf] x_tables: Allow REJECT targets in PREROUTING chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH] doc: use symbolic names for chain priorities
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- Re: [RFC PATCH] doc: use symbolic names for chain priorities
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- [PATCH nf] netfilter REJECT: Fix destination MAC in RST packets
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- [PATCH v2 3/3] netfilter: x_tables: Use correct memory barriers.
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH v2 2/3] Revert "netfilter: x_tables: Switch synchronization to RCU"
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH v2 1/3] Revert "netfilter: x_tables: Update remaining dereference to RCU"
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH v2 0/3] Don't use RCU for x_tables synchronization
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- {PATCH nf] x_tables: Allow REJECT targets in PREROUTING chains
- From: Marc Aurèle La France <tsi@xxxxxxxxxx>
- Re: [RFC PATCH] doc: use symbolic names for chain priorities
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- [RFC PATCH] doc: use symbolic names for chain priorities
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- [PATCH 0/3] Minor documentation improvements
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- [PATCH 2/3] doc: remove duplicate tables in synproxy example
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- [PATCH 3/3] doc: move drop rule on a separate line in blackhole example
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- [PATCH 1/3] doc: add * to include example to actually include files
- From: Simon Ruderich <simon@xxxxxxxxxxxx>
- Re: [PATCH net 1/9] uapi: nfnetlink_cthelper.h: fix userspace compilation error
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 3/9] netfilter: nf_nat: undo erroneous tcp edemux lookup
- From: Mika Penttilä <mika.penttila@xxxxxxxxxxxx>
- Re: [PATCH net 3/9] netfilter: nf_nat: undo erroneous tcp edemux lookup
- From: Mika Penttilä <mika.penttila@xxxxxxxxxxxx>
- [PATCH net 4/9] netfilter: conntrack: avoid misleading 'invalid' in log message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 8/9] netfilter: nftables: fix possible double hook unregistration with table owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/9] netfilter: conntrack: Remove a double space in a log message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/9] selftests: netfilter: test nat port clash resolution interaction with tcp early demux
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/9] netfilter: nf_nat: undo erroneous tcp edemux lookup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 9/9] netfilter: nftables: bogus check for netlink portID with table owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/9] netfilter: x_tables: gpf inside xt_find_revision()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/9] uapi: nfnetlink_cthelper.h: fix userspace compilation error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 7/9] netfilter: nftables: disallow updates on table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] parser: compact map RHS type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] expression: memleak in verdict_expr_parse_udata()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Kernel Error FLOW OFFLOAD on nftables
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- Kernel Error FLOW OFFLOAD on nftables
- From: Максим <maxbur89@xxxxxxxxx>
- [PATCH RESEND][next] netfilter: Fix fall-through warnings for Clang
- From: "Gustavo A. R. Silva" <gustavoars@xxxxxxxxxx>
- Re: [PATCH 3/3] netfilter: x_tables: Use correct memory barriers.
- From: Mark Tomlinson <Mark.Tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH nft,v2] mnl: remove nft_mnl_socket_reopen()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nft,v2] conntrack: Fix gre tunneling over ipv6
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH][nft,v2] conntrack: Fix gre tunneling over ipv6
- From: Ludovic Senecaux <linuxludo@xxxxxxx>
- Re: [PATCH 3/3] netfilter: x_tables: Use correct memory barriers.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/3] Revert "netfilter: x_tables: Switch synchronization to RCU"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/3] Revert "netfilter: x_tables: Update remaining dereference to RCU"
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: nftables: bogus check for netlink portID with table owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2,v2] netfilter: nftables: fix possible double hook unregistration with table owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nftables: fix possible double hook unregistration with table owner
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/3] netfilter: x_tables: Use correct memory barriers.
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH 2/3] Revert "netfilter: x_tables: Switch synchronization to RCU"
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH 0/3] Don't use RCU for x_tables synchronization
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- [PATCH 1/3] Revert "netfilter: x_tables: Update remaining dereference to RCU"
- From: Mark Tomlinson <mark.tomlinson@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/3] parser: compact ct obj list types
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/3] parser: compact map RHS type
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] parser: squash duplicated spec/specid rules
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- RE: [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- From: Ludovic Sénécaux <linuxludo@xxxxxxx>
- Re: [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtable: separate replace, destroy and stats to different workqueues
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: flowtable: separate replace, destroy and stats to different workqueues
- From: Oz Shlomo <ozsh@xxxxxxxxxx>
- [PATCH] netfilter: Fix GRE over IPv6 with conntrack module
- Re: [nf:master 7/7] net/netfilter/nf_tables_api.c:920:15: warning: converting the enum constant to a boolean
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH 1/2] xtables-translate: Fix translation of odd netmasks
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/2] libxtables: Simplify xtables_ipmask_to_cidr() a bit
- From: Phil Sutter <phil@xxxxxx>
- [nf:master 7/7] net/netfilter/nf_tables_api.c:920:15: warning: converting the enum constant to a boolean
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH nft] mnl: remove nft_mnl_socket_reopen()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] cache: memleak list of chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] table: support for the table owner flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] table: add table owner support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: [PATCH] xtables-addons 3.15 doesn't compile on 32-bit x86
- From: Jan Engelhardt <jengelh@xxxxxxx>
- RE: [PATCH] xtables-addons 3.15 doesn't compile on 32-bit x86
- From: <andy@xxxxxxxxxxxxx>
- linux-next: Fixes tag needs some work in the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Remove a double space in a log message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: gpf inside xt_find_revision()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] uapi: nfnetlink_cthelper.h: fix userspace compilation error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/3] netfilter: nat: fix ancient dnat+edemux bug
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nftables: disallow updates on table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: gpf inside xt_find_revision()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: gpf inside xt_find_revision()
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH nf 3/3] selftests: netfilter: test nat port clash resolution interaction with tcp early demux
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/3] netfilter: conntrack: avoid misleading 'invalid' in log message
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/3] netfilter: nf_nat: undo erroneous tcp edemux lookup
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/3] netfilter: nat: fix ancient dnat+edemux bug
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptables-nft] iptables-nft: fix -Z option
- From: Phil Sutter <phil@xxxxxx>
- [PATCH iptables-nft] iptables-nft: fix -Z option
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] xtables-addons 3.15 doesn't compile on 32-bit x86
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: increasing ip_list_tot in net/netfilter/xt_recent.c for a non-modular kernel
- From: Toralf Förster <toralf.foerster@xxxxxx>
- Re: increasing ip_list_tot in net/netfilter/xt_recent.c for a non-modular kernel
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: increasing ip_list_tot in net/netfilter/xt_recent.c for a non-modular kernel
- From: Toralf Förster <toralf.foerster@xxxxxx>
- [PATCH] uapi: nfnetlink_cthelper.h: fix userspace compilation error
- From: "Dmitry V. Levin" <ldv@xxxxxxxxxxxx>
- Re: increasing ip_list_tot in net/netfilter/xt_recent.c for a non-modular kernel
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH nft] table: rework flags printing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- increasing ip_list_tot in net/netfilter/xt_recent.c for a non-modular kernel
- From: Toralf Förster <toralf.foerster@xxxxxx>
- Re: [nft PATCH 2/2] doc: nft: fix some typos and formatting issues
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 1/2] main: fix nft --help output fallout from 719e4427
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: allow use of 'verdict' in typeof definitions
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH 2/2] doc: nft: fix some typos and formatting issues
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- [nft PATCH 1/2] main: fix nft --help output fallout from 719e4427
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- [PATCH] xtables-addons 3.15 doesn't compile on 32-bit x86
- From: <andy@xxxxxxxxxxxxx>
- [PATCH] netfilter: Remove a double space in a log message
- From: Klemen Košir <klemen.kosir@xxxxxxxx>
- [ANNOUNCE] ipset 7.11 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [iptables PATCH] nft: Fix bitwise expression avoidance detection
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] json: init parser state for every new buffer/file
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] json: init parser state for every new buffer/file
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3] src: fix IPv6 header handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH 2/2 v2] Avoid out of bounds read from data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [libnftnl PATCH 2/2 v2] Avoid out of bounds read from data
- From: Maya Rashish <mrashish@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [libnftnl PATCH 1/2] Avoid out of bound reads in tests.
- From: Maya Rashish <mrashish@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [libnftnl PATCH 2/2] Avoid out of bounds read from data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH 1/2] Avoid out of bound reads in tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ebtables PATCH] Open the lockfile with O_CLOEXEC
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/3] netfilter: nftables: add helper function to release one table
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [ebtables PATCH] Open the lockfile with O_CLOEXEC
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- [libnftnl PATCH 2/2] Avoid out of bounds read from data
- From: Maya Rashish <mrashish@xxxxxxxxxx>
- [libnftnl PATCH 1/2] Avoid out of bound reads in tests.
- From: Maya Rashish <mrashish@xxxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next 0/3] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/3] netfilter: nftables: add helper function to release hooks of one single table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 3/3] netfilter: nftables: introduce table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/3] netfilter: nftables: add helper function to release one table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: fix IPv6 header handling
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- [nft PATCH] monitor: Don't print newgen message with JSON output
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] include: Drop libipulog.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] include: Drop libipulog.h
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 0/3] nft: fix ct zone handling in sets and maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- traffic shaping with tc on Linux 5.4.x
- From: Lars Noodén <lars.nooden@xxxxxxx>
- [PATCH nf-next,v3 3/3] netfilter: nftables: introduce table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 2/3] netfilter: nftables: allow to release hooks of one single table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v3 1/3] netfilter: nftables: allow to release one table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nftables: introduce table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Question about using NFT_GOTO in kernel module
- From: "Bob @ gmail" <bob.zscharnagk@xxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Balazs Scheidler <bazsi77@xxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- Re: Unable to create a chain called "trace"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- Re: Unable to create a chain called "trace"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Phil Sutter <phil@xxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- Re: Unable to create a chain called "trace"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak124 v3] audit: log nftables configuration change events
- From: Phil Sutter <phil@xxxxxx>
- [PATCH libnetfilter_queue v3] src: fix IPv6 header handling
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [PATCH net 1/2] netfilter: conntrack: skip identical origin tuple in same zone only
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net 0/2] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/2] netfilter: nftables: relax check for stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/2] netfilter: conntrack: skip identical origin tuple in same zone only
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] src: fix IPv6 header handling
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: skip identical origin tuple in same zone only
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add pkt_buff function for ICMP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: fix IPv6 header handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] evaluate: incorrect usage of stmt_binary_error() in reject
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Phil Sutter <phil@xxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nftables: relax check for stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nftables: relax check for stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Unable to create a chain called "trace"
- From: Phil Sutter <phil@xxxxxx>
- Re: Unable to create a chain called "trace"
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] trace: do not remove icmp type from packet dump
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nftables: relax check for stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/7] netfilter: ctnetlink: remove get_ct indirection
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net-next 4/7] netfilter: nftables: add nft_parse_register_load() and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 5/7] netfilter: nftables: add nft_parse_register_store() and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 6/7] netfilter: nftables: statify nft_parse_register()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 3/7] netfilter: flowtable: add hash offset field to tuple
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/7] netfilter: ctnetlink: remove get_ct indirection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/7] ipvs: add weighted random twos choice algorithm
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 7/7] netfilter: nftables: remove redundant assignment of variable err
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 0/7] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC conntrack-tools PATCH] conntrack-tools: introduce conntrackdctl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [RFC conntrack-tools PATCH] conntrack-tools: introduce conntrackdctl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: skip identical origin tuple in same zone only
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net-next v2 0/4] Fix W=1 compilation warnings in net/* folder
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH net 2/4] selftests: netfilter: fix current year
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/4] netfilter: xt_recent: Fix attempt to update deleted entry
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/4] netfilter: flowtable: fix tcp and udp header checksum update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/4] netfilter: nftables: fix possible UAF over chains from packet path in netns
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [RFC conntrack-tools PATCH] conntrack-tools: introduce conntrackdctl
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [PATCH nft,v2] src: add negation match on singleton bitmask value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: remove redundant assignment of variable err
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: remove redundant assignment of variable err
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Fix attempt to update deleted entry in xt_recent
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH 2/2] tests/py: Add a test sanitizer and fix its findings
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/2] tests/py: Write dissenting payload into the right file
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft 3/3] evaluate: do not crash if dynamic set has no statements
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/3] tests: add empty dynamic set
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] testcases: move two dump files to correct location
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/3] evaluate: fix crash on empty set restore
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/3] nft: fix ct zone handling in sets and maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/3] evaluate: set evaluation context for set elements
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] extend_test
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/3] evaluate: pick data element byte order, not dtype one
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] tests: extend dtype test case to cover expression with integer type
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next v2 4/4] netfilter: move handlers to net/ip_vs.h
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v2 2/4] ipv6: move udp declarations to net/udp.h
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v2 3/4] net/core: move gro function declarations to separate header
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v2 1/4] ipv6: silence compilation warning for non-IPV6 builds
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v2 0/4] Fix W=1 compilation warnings in net/* folder
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH net-next v1 3/4] net/core: move gro function declarations to separate header
- From: Leon Romanovsky <leonro@xxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next v1 2/4] ipv6: move udp declarations to net/udp.h
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v1 4/4] netfilter: move handlers to net/ip_vs.h
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v1 3/4] net/core: move gro function declarations to separate header
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v1 1/4] ipv6: silence compilation warning for non-IPV6 builds
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net-next v1 0/4] Fix W=1 compilation warnings in net/* folder
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [nft PATCH] erec: Sanitize erec location indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: flowtable: fix tcp and udp header checksum update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] json: Do not abbreviate reject statement object
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 1/4] ipv6: silence compilation warning for non-IPV6 builds
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 1/4] ipv6: silence compilation warning for non-IPV6 builds
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH nft 2/2] payload: check icmp dependency before removing previous icmp expression
- From: Michael Biebl <biebl@xxxxxxxxxx>
- [PATCH] netfilter: flowtable: fix tcp and udp header checksum update
- From: sven.auhagen@xxxxxxxxxxxx
- Re: [PATCH net 1/4] ipv6: silence compilation warning for non-IPV6 builds
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 3/4] net/core: move ipv6 gro function declarations to net/ipv6
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH net 0/4] Fix W=1 compilation warnings in net/* folder
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nftables: fix possible UAF over chains from packet path in netns
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 0/4] Fix W=1 compilation warnings in net/* folder
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net 0/4] Fix W=1 compilation warnings in net/* folder
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH net 3/4] net/core: move ipv6 gro function declarations to net/ipv6
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net 0/4] Fix W=1 compilation warnings in net/* folder
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [PATCH net 1/4] ipv6: silence compilation warning for non-IPV6 builds
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net 0/4] Fix W=1 compilation warnings in net/* folder
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net 3/4] net/core: move ipv6 gro function declarations to net/ipv6
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net 4/4] netfilter: move handlers to net/ip_vs.h
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- [PATCH net 2/4] ipv6: move udp declarations to net/udp.h
- From: Leon Romanovsky <leon@xxxxxxxxxx>
- Re: [PATCH nft 2/2] payload: check icmp dependency before removing previous icmp expression
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [conntrack-tools PATCH 1/3] tests: introduce new python-based framework for running tests
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] tests: conntrackd: move basic netns scenario setup to shell script
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] payload: check icmp dependency before removing previous icmp expression
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] tests: add icmp/6 test where dependency should be left alone
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: add negation match on singleton bitmask value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH 1/3] tests: introduce new python-based framework for running tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools] tests: conntrackd: move basic netns scenario setup to shell script
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nftables: introduce table ownership
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nftables: introduce table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nftables: introduce table ownership
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [conntrack-tools PATCH 1/3] tests: introduce new python-based framework for running tests
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH 1/3] tests: introduce new python-based framework for running tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH] conntrackd: introduce yes & no config values
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 5/5] af_packet: Introduce egress hook
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [PATCH nf-next v4 5/5] af_packet: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH 1/1 nf] selftests: netfilter: fix current year
- From: Fabian Frederick <fabf@xxxxxxxxx>
- [PATCH v3 8/8] tests: conntrack -L/-D ip family filtering
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 7/8] tests: saving and loading ct entries, save format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 6/8] conntrack.8: man update for --load-file support
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 5/8] conntrack: accept commands from file
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 3/8] conntrack: per-command entries counters
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 4/8] conntrack: introduce ct_cmd_list
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 2/8] conntrack: move global options to struct ct_cmd
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 1/8] conntrack: reset optind in do_parse
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v3 0/8] conntrack: save output format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH] netfilter: Fix attempt to update deleted entry in xt_recent
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: remove redundant assignment of variable err
- From: Colin King <colin.king@xxxxxxxxxxxxx>
- Re: [PATCH] tests: monitor: use correct $nft value in EXIT trap
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: nft_dynset: honor stateful expressions in set definition
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [iptables PATCH] ebtables: Exit gracefully on invalid table names
- From: Phil Sutter <phil@xxxxxx>
- Re: https://bugzilla.kernel.org/show_bug.cgi?id=207773
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: https://bugzilla.kernel.org/show_bug.cgi?id=207773
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH] tests: monitor: use correct $nft value in EXIT trap
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] tests: monitor: use correct $nft value in EXIT trap
- From: Štěpán Němec <snemec@xxxxxxxxxx>
- Re: https://bugzilla.kernel.org/show_bug.cgi?id=207773
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: https://bugzilla.kernel.org/show_bug.cgi?id=207773
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: https://bugzilla.kernel.org/show_bug.cgi?id=207773
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nft_dynset: dump expressions when set definition contains no expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- https://bugzilla.kernel.org/show_bug.cgi?id=207773
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nft_dynset: add timeout extension to template
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: nft_dynset: honor stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v24 07/25] LSM: Use lsmblob in security_secctx_to_secid
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v24 08/25] LSM: Use lsmblob in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [nft PATCH] erec: Sanitize erec location indesc
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] json: limit: Always include burst value
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v4 4/5] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nftables: introduce table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nftables: introduce table ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH 2/2] reject: Unify inet, netdev and bridge delinearization
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/2] reject: Fix for missing dependencies in netdev family
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v24 18/25] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v24 16/25] LSM: Use lsmcontext in security_secid_to_secctx
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH v24 15/25] LSM: Ensure the correct LSM context releaser
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- [PATCH nft] src: evaluate: reset context maxlen value before prio evaluation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook
- From: Phil Sutter <phil@xxxxxx>
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook
- From: Phil Sutter <phil@xxxxxx>
- Re: KASAN: use-after-free Read in dump_schedule
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH v6] ipvs: add weighted random twos choice algorithm
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: ctnetlink: remove get_ct indirection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2,v2] netfilter: nftables: add nft_parse_register_store()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v4 2/3] netfilter: nftables: add nft_parse_register_store() and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v4 1/3] netfilter: nftables: add nft_parse_register_load() and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v4 3/3] netfilter: nftables: statify nft_parse_register()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/2] netfilter: nftables: statify nft_parse_register()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2,v3] netfilter: nftables: add nft_parse_register_store()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nftables: add nft_parse_register_store()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nftables: add nft_parse_register_load() and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: flowtable: add hash offset field to tuple
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v4 5/5] af_packet: Introduce egress hook
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nft v4] src: Support netdev egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH nf-next v4 5/5] af_packet: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH v6] ipvs: add weighted random twos choice algorithm
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [conntrack-tools PATCH 3/3] tests: introduce replicating scenario and simple icmp test case
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH 2/3] tests: introduce some basic testcases for the new conntrack-tools testing framework
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH 1/3] tests: introduce new python-based framework for running tests
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in dump_schedule
- From: syzbot <syzbot+621fd33c0b53d15ee8de@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 5/5] af_packet: Introduce egress hook
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next v4 5/5] af_packet: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [PATCH nf-next v4 1/5] net: sched: Micro-optimize egress handling
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next v4 3/5] netfilter: Generalize ingress hook include file
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next v4 4/5] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next v4 2/5] netfilter: Rename ingress hook include file
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next v4 0/5] Netfilter egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nft] json: icmp: move expected parts to json.output
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] evaluate: disallow ct original {s,d}ddr from concatenations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] exthdr: remove tcp dependency for tcp option matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] exthdr: remove tcp dependency for tcp option matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/4] json: fix icmpv6.t test cases
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 3/4] json: ct: add missing rule
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 2/4] json: limit: set default burst to 5
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 4/4] json: icmp: refresh json output
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 2/4] json: limit: set default burst to 5
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/4] json: limit: set default burst to 5
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/4] json: limit: set default burst to 5
- From: Phil Sutter <phil@xxxxxx>
- [PATCH 1/4] json: fix icmpv6.t test cases
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 2/4] json: limit: set default burst to 5
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 3/4] json: ct: add missing rule
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 4/4] json: icmp: refresh json output
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/4] json test case fixups
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2] netfilter: ctnetlink: remove get_ct indirection
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: remove get_ct indirection
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: remove get_ct indirection
- From: kernel test robot <lkp@xxxxxxxxx>
- [conntrack-tools PATCH] conntrackd: introduce yes & no config values
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: ctnetlink: remove get_ct indirection
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: fix IPv6 header handling
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: add pkt_buff function for ICMP
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- Re: [PATCH] netfilter: Reverse nft_set_lookup_byid list traversal
- From: Jan-Philipp Litza <jpl@xxxxxxxxx>
- Re: [PATCH] ipset: fix print format warning
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH] ipset: fix print format warning
- From: Neutron Soutmun <neo.neutron@xxxxxxxxx>
- [PATCH nf] netfilter: nft_dynset: dump expressions when set definition contains no expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_dynset: add timeout extension to template
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_dynset: honor stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] iptables 1.8.7 release
- From: Phil Sutter <phil@xxxxxxxxxxxxx>
- [ANNOUNCE] nftables 0.9.8 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] tests/shell: Fix nft-only/0009-needless-bitwise_0
- From: Phil Sutter <phil@xxxxxx>
- [ANNOUNCE] libnftnl 1.1.9 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: disallow ct original {s,d}ddr from maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Reverse nft_set_lookup_byid list traversal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 1/3] conntrack: add struct ct_cmd
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 2/3] conntrack: add struct ct_tmpl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 3/3] conntrack: add do_command_ct()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 0/3] preparing support for command batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- KMSAN: uninit-value in nf_conntrack_udplite_packet (2)
- From: syzbot <syzbot+e5b49f0d1e69d0c0fcb4@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue] src: fix IPv6 header handling
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: fix header handling in nfq_ip6_set_transport_header
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: fix IPv6 header handling
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: add pkt_buff function for ICMP
- From: Etan Kissling <etan_kissling@xxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH net 1/3] selftests: netfilter: Pass family parameter "-f" to conntrack tool
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nf_nat: Fix memleak in nf_nat_init
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: conntrack: fix reading nf_conntrack_buckets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH ghak90 v11 08/11] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 11/11] audit: add capcontid to set contid outside init_user_ns
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 10/11] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 09/11] audit: contid check descendancy and nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 07/11] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 06/11] audit: add containerid support for user records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 05/11] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 04/11] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 03/11] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 02/11] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 00/11] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 v11 01/11] audit: collect audit task parameters
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH AUTOSEL 5.10 08/51] netfilter: ipset: fixes possible oops in mtype_resize
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 05/28] netfilter: ipset: fixes possible oops in mtype_resize
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH] netfilter: Fix memleak in nf_nat_init
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: conntrack: fix reading nf_conntrack_buckets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Fix memleak in nf_nat_init
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: Fix memleak in nf_nat_init
- From: Dinghao Liu <dinghao.liu@xxxxxxxxxx>
- Re: [PATCH net] netfilter: conntrack: fix reading nf_conntrack_buckets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net] netfilter: conntrack: fix reading nf_conntrack_buckets
- From: Jesper Dangaard Brouer <brouer@xxxxxxxxxx>
- Re: [PATCH net 0/3] net: fix netfilter defrag/ip tunnel pmtu blackhole
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 0/3] net: fix netfilter defrag/ip tunnel pmtu blackhole
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: Reverse nft_set_lookup_byid list traversal
- From: Jan-Philipp Litza <jpl@xxxxxxxxx>
- Re: [PATCH net 3/3] net: ip: always refragment ip defragmented packets
- From: Christian Perle <christian.perle@xxxxxxxxxxx>
- Re: [PATCH v6] ipvs: add weighted random twos choice algorithm
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH nft] segtree: honor set element expiration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] cli: use plain readline() interface with libedit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] main: fix typo in cli definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/2] libedit support followup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] main: fix typo in cli definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] cli: use plain readline() interface
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/2] follow up work on the libedit support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] net: ip: always refragment ip defragmented packets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 1/3] selftests: netfilter: add selftest for ipip pmtu discovery with enabled connection tracking
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 2/3] net: fix pmtu check in nopmtudisc mode
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 0/3] net: fix netfilter defrag/ip tunnel pmtu blackhole
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 0/3] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nft] cli: add libedit support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: set on flags to request multi-statement support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Potential licensing issue with libreadline
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Potential licensing issue with libreadline
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nftables: add set expression flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nft_dynset: report EOPNOTSUPP on missing set feature
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: xt_RATEEST: reject non-null terminated string from userspace
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_conntrack] examples: check return value of nfct_nlmsg_build()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_conntrack] examples: check return value of nfct_nlmsg_build()
- From: Eyal Birger <eyal.birger@xxxxxxxxx>
- WARNING: suspicious RCU usage in xt_obj_to_user
- From: syzbot <syzbot+00399fa030c641ffc5ae@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Announcing Netdev 0x15
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nftables: add set expression flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_dynset: report EOPNOTSUPP on missing set feature
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: xt_RATEEST: reject non-null terminated string from userspace
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] conntrackd: add ip netns test script
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] conntrackd: add ip netns test script
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- stack corruption with EBT_ENTRY_ITERATE
- From: sharathv@xxxxxxxxxxxxxx
- [PATCH conntrack-tools] conntrackd: add ip netns test script
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: kernel BUG at lib/string.c:LINE! (6)
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: xt_RATEEST: reject non-null terminated string from userspace
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: xt_RATEEST: reject non-null terminated string from userspace
- From: Linus Torvalds <torvalds@xxxxxxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: xt_RATEEST: reject non-null terminated string from userspace
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: kernel BUG at lib/string.c:LINE! (6)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: kernel BUG at lib/string.c:LINE! (6)
- From: Linus Torvalds <torvalds@xxxxxxxxxxxxxxxxxxxx>
- kernel BUG at lib/string.c:LINE! (6)
- From: syzbot <syzbot+e86f7c428c8c50db65b4@xxxxxxxxxxxxxxxxxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]