Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH nft 1/7] parser: merge sack-perm/sack-permitted and maxseg/mss
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/7] rework tcp option handling
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 0/8] Netfilter updates for net-next
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH v22 16/23] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- Re: [PATCH nf 2/2] netfilter: nftables_offload: build mask based from the matching bytes
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH net] ipv6/netfilter: Discard first fragment not including all headers
- From: "Georg Kohmann (geokohma)" <geokohma@xxxxxxxxx>
- [PATCH net-next 2/8] netfilter: nft_reject: unify reject init and dump into nft_reject
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/8] netfilter: nf_reject: add reject skbuff creation helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 6/8] netfilter: ipset: Expose the initval hash parameter to userspace
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 8/8] netfilter: nft_reject_inet: allow to use reject from inet ingress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 5/8] netfilter: ipset: Add bucketsize parameter to all hash types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 4/8] netfilter: ipset: Support the -exist flag with the destroy command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 7/8] netfilter: nftables: Add __printf() attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 3/8] netfilter: nft_reject: add reject verdict support for netdev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 0/8] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/8] conntrack: accept parameters from stdin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] ipv6/netfilter: Discard first fragment not including all headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 2/2] ebtables: Optimize masked MAC address matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2 1/2] nft: Optimize class-based IP prefix matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 0/2] src: Optimize prefix matches on byte-boundaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/3] json: resolve multiple test case failures
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] ipv6/netfilter: Discard first fragment not including all headers
- From: Georg Kohmann <geokohma@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: nftables_offload: build mask based from the matching bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nftables_offload: set address type in control dissector
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 0/2] fixes for nftables offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC] ipvs: add genetlink cmd to dump all services and destinations
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH nft 3/3] json: add missing nat_type flag and netmap nat flag
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/3] tests: avoid warning and add missing json test cases
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] tests: json: add missing test case output
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/3] json: resolve multiple test case failures
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC] ipvs: add genetlink cmd to dump all services and destinations
- From: Cezar Sá Espinola <cezarsa@xxxxxxxxx>
- Re: [PATCH RFC] ipvs: add genetlink cmd to dump all services and destinations
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH conntrack] conntrack: do not allow to update offload status bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack] conntrack: do not allow to update offload status bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 2/2] conntrack.8: man update for opts format support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/2] conntrack: implement save output format
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables 5/5] tests: py: add netdev folder and reject.t icmp cases
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables 4/5] evaluate: add netdev support for reject default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: ipset 7.7 modules fail to build on kernel 4.19.152
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- ipset 7.7 modules fail to build on kernel 4.19.152
- From: Oskar Berggren <oskar.berggren@xxxxxxxxx>
- Re: [PATCH] doc: correct chain name in example of adding a rule.
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] doc: correct chain name in example of adding a rule.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nft_reject_inet: allow to use reject from inet ingress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nft_reject_inet: allow to use reject from inet ingress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 0/5] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH net 4/5] netfilter: nf_tables: missing validation from the abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/5] netfilter: ipset: Update byte and packet counters regardless of whether they match
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/5] netfilter: use actual socket sk rather than skb sk when routing harder
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/5] wireguard: selftests: check that route_me_harder packets use the right sk
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/5] netfilter: nftables: fix netlink report logic in flowtable and genid
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/4] netfilter: ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [ANNOUNCE] iptables 1.8.6 release
- From: Phil Sutter <phil@xxxxxxxxxxxxx>
- Re: [PATCH 0/5] add support for reject verdict in netdev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_reject_inet: allow to use reject from inet ingress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/4] netfilter: ipset: Update byte and packet counters regardless of whether they match
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] route_me_harder routing loop with tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] route_me_harder routing loop with tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] route_me_harder routing loop with tunnels
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH RFC] ipvs: add genetlink cmd to dump all services and destinations
- From: Cezar Sa Espinola <cezarsa@xxxxxxxxx>
- [PATCH nft] tests: shell: exercise validate with nft -c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] route_me_harder routing loop with tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] raw2packet: fix comma instead of semicolon
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH v2 1/2] nft: Optimize class-based IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/2] ebtables: Optimize masked MAC address matches
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf] netfilter: nf_tables: missing validation from the abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] netfilter: ipset: Expose the initval hash parameter to userspace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 2/4] netfilter: ipset: Support the -exist flag with the destroy command
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 3/4] netfilter: ipset: Add bucketsize parameter to all hash types
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 1/4] netfilter: ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 0/4] ipset patches for nf-next
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [nft PATCH] tests/shell: Improve fix in sets/0036add_set_element_expiration_0
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 2/2] netfilter: use actual socket sk rather than skb sk when routing harder
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: [PATCH nf 2/2] netfilter: use actual socket sk rather than skb sk when routing harder
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH v2 2/2] conntrack.8: man update for opts format support
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v2 0/2] conntrack: save output format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH v2 1/2] conntrack: implement save output format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- Re: [nft PATCH] tests/shell: Restore testcases/sets/0036add_set_element_expiration_0
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] tests/shell: Restore testcases/sets/0036add_set_element_expiration_0
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH libnetfilter_conntrack] conntrack: add flush filter command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_conntrack] conntrack: add flush filter command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools] conntrack: allow to flush per family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/2] netfilter: use actual socket sk rather than skb sk when routing harder
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: use actual socket sk rather than skb sk when routing harder
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH nf 1/2] wireguard: selftests: check that route_me_harder packets use the right sk
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH nf 0/2] route_me_harder routing loop with tunnels
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: [nft PATCH] tests/shell: Restore testcases/sets/0036add_set_element_expiration_0
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] tests/shell: Restore testcases/sets/0036add_set_element_expiration_0
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] tests/shell: Restore testcases/sets/0036add_set_element_expiration_0
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH conntrack] conntrack: allow to filter event by family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack] conntrack: allow to filter event by family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH 2/2] src: Optimize prefix matches on byte-boundaries
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/2] src: Optimize prefix matches on byte-boundaries
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/2] src: Support odd-sized payload matches
- From: Phil Sutter <phil@xxxxxx>
- [PATCH conntrack] conntrack: default to unspec family for dualstack setups
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] nftables 0.9.7 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] libnftnl 1.1.8 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [UPDATES] Renewing Netfilter coreteam PGP keys
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- [iptables PATCH] tests: shell: Improve concurrent noflush restore test a bit
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Phil Sutter <phil@xxxxxx>
- Re: [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH xtables-addons] pnock: pknlusr: mention the group ID command-line paramater in the man-page.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Saeed Mirzamohammadi <saeed.mirzamohammadi@xxxxxxxxxx>
- Re: [PATCH v3 1/1] uapi: Move constants from <linux/kernel.h> to <linux/const.h>
- From: Petr Vorel <petr.vorel@xxxxxxxxx>
- [PATCH xtables-addons] pnock: pknlusr: mention the group ID command-line paramater in the man-page.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH xtables-addons v2 00/13] pknlusr improvements
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH xtables-addons v2 09/13] pknock: pknlusr: fix hard-coded netlink multicast group ID.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 10/13] pknock: xt_pknock: use IS_ENABLED.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 11/13] pknock: xt_pknock: use kzalloc.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 13/13] pknock: xt_pknock: remove DEBUG definition and disable debug output.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 12/13] pknock: xt_pknock: use `pr_err`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 02/13] pknock: pknlusr: remove dest_addr and rename src_addr.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 03/13] pknock: pknlusr: tighten up variable scopes.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 08/13] pknock: pknlusr: always close socket.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 07/13] pknock: pknlusr: don't treat recv return value of zero as an error.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 05/13] pknock: pknlusr: use NLMSG macros and proper types, rather than arithmetic on char pointers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 06/13] pknock: pknlusr: use macro to define inet_ntop buffer size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 04/13] pknock: pknlusr: tidy up initialization of local address.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 00/13] pknlusr improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 00/13] pknlusr improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons v2 01/13] pknock: pknlusr: ensure man-page is included by `make dist`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH xtables-addons 3/3] pknock: pknlusr: add man-page.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH xtables-addons 2/3] pknock: pknlusr: fix hard-coded netlink multicast group ID.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH nft] Revert "monitor: do not print generation ID with --echo"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 6/8] conntrack: implement options output format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- Re: [PATCH xtables-addons 3/3] pknock: pknlusr: add man-page.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH xtables-addons 2/3] pknock: pknlusr: fix hard-coded netlink multicast group ID.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH nf] netfilter: nftables: fix netlink report logic in flowtable and genid
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5] add support for reject verdict in netdev
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH nftables 5/5] tests: py: add netdev folder and reject.t icmp cases
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH nftables 4/5] evaluate: add netdev support for reject default
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH nf-next 3/5] net: netfilter: add reject verdict support for netdev
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH nf-next 2/5] net: netfilter: unify reject init and dump into nft_reject
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH nf-next 1/5] net: netfilter: add reject skbuff creation helpers
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [PATCH 1/7] ipvs: adjust the debug info in function set_tcp_state
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH 0/7] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH xtables-addons 0/3] pknlusr improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 3/3] pknock: pknlusr: add man-page.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 2/3] pknock: pknlusr: fix hard-coded netlink multicast group ID.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH xtables-addons 1/3] pknock: pknlusr: fix formatting.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH 3/7] netfilter: Drop fragmented ndisc packets assembled in netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/7] netfilter: conntrack: connection timeout after re-register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/7] netfilter: nftables_offload: KASAN slab-out-of-bounds Read in nft_flow_rule_create
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/7] netfilter: nf_fwd_netdev: clear timestamp in forwarding path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/7] docs: nf_flowtable: fix typo.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/7] netfilter: ebtables: Fixes dropping of small packets in bridge nat
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/7] ipvs: adjust the debug info in function set_tcp_state
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/7] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_fwd_netdev: clear timestamp in forwarding path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 6/8] conntrack: implement options output format
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 6/8] conntrack: implement options output format
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v2 4/9] bridge: resolve forwarding path for bridge devices
- From: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Saeed Mirzamohammadi <saeed.mirzamohammadi@xxxxxxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_dup_netdev: clear timestamp in forwarding path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_dup_netdev: clear timestamp in forwarding path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Network namespace, ipvlan and IPVS source NAT
- From: Mahesh Bandewar (महेश बंडेवार) <maheshb@xxxxxxxxxx>
- [PATCH nft] monitor: do not print generation ID with --echo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Network namespace, ipvlan and IPVS source NAT
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Saeed Mirzamohammadi <saeed.mirzamohammadi@xxxxxxxxxx>
- Re: [PATCH v5] ipvs: adjust the debug info in function set_tcp_state
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net V2] netfilter: Drop fragmented ndisc packets assembled in netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] docs: nf_flowtable: fix typo.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] Fixes dropping of small packets in bridge nat
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_sip: Fix inconsistent of format with argument type in nf_nat_sip.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Network namespace, ipvlan and IPVS source NAT
- From: Damien Claisse <d.claisse@xxxxxxxxxx>
- Re: [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] conntrack: fix zone sync issue
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create
- From: saeed.mirzamohammadi@xxxxxxxxxx
- [PATCH nft 2/2] src: improve rule error reporting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] rule: larger number of error locations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] expr: add nftnl_rule_del_expr()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v2 8/9] netfilter: flowtable: bridge port support
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH net-next,v2 6/9] netfilter: flowtable: use dev_fill_forward_path() to obtain egress device
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH] conntrack: fix zone sync issue
- [PATCH] conntrack: fix zone sync issue
- [PATCH AUTOSEL 5.8 086/101] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 69/80] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 50/56] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 46/52] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.4 29/33] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 37/41] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.9 092/111] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH] docs: nf_flowtable: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH] docs: nf_flowtable: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnfnl] expr: expose nftnl_expr_build_payload()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [bugreport] [5.10] warning at net/netfilter/nf_tables_api.c:622
- From: Mikhail Gavrilov <mikhail.v.gavrilov@xxxxxxxxx>
- Re: bpf-next test error: BUG: program execution failed: executor 0: exit status 67
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- [bugreport] [5.10] warning at net/netfilter/nf_tables_api.c:622
- From: Mikhail Gavrilov <mikhail.v.gavrilov@xxxxxxxxx>
- Re: [PATCH net-next,v2 0/9] netfilter: flowtable bridge and vlan enhancements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v2 0/9] netfilter: flowtable bridge and vlan enhancements
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [nft] Bug 1444 - Segfault
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: bpf-next test error: BUG: program execution failed: executor 0: exit status 67
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: bpf-next test error: BUG: program execution failed: executor 0: exit status 67
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: bpf-next test error: BUG: program execution failed: executor 0: exit status 67
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 7/9] netfilter: flowtable: add direct xmit path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 6/9] netfilter: flowtable: use dev_fill_forward_path() to obtain egress device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 5/9] netfilter: flowtable: use dev_fill_forward_path() to obtain ingress device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 9/9] netfilter: flowtable: add vlan support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 8/9] netfilter: flowtable: bridge port support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 4/9] bridge: resolve forwarding path for bridge devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 2/9] net: resolve forwarding path from virtual netdevice and HW destination address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 3/9] net: 8021q: resolve forwarding path for vlan devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 1/9] netfilter: flowtable: add xmit path types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 0/9] netfilter: flowtable bridge and vlan enhancements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 9/9] netfilter: flowtable: add vlan support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 9/9] netfilter: flowtable: add vlan support
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nft] segtree: copy expr data to closing element
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: Fix kmemleak false positive reports
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: conntrack: Fix kmemleak false positive reports
- From: Kavana Ravindra <kavana.c.ravindra@xxxxxxxxx>
- Re: selftests: netfilter: nft_nat.sh: /dev/stdin:2:9-15: Error: syntax error, unexpected counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: ingress inet support
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/9] net: 8021q: resolve forwarding path for vlan devices
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: restore NF_INET_NUMHOOKS
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: selftests: netfilter: nft_nat.sh: /dev/stdin:2:9-15: Error: syntax error, unexpected counter
- From: Naresh Kamboju <naresh.kamboju@xxxxxxxxxx>
- [PATCH net-next 3/9] net: 8021q: resolve forwarding path for vlan devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 5/9] netfilter: flowtable: use dev_fill_forward_path() to obtain ingress device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 6/9] netfilter: flowtable: use dev_fill_forward_path() to obtain egress device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 9/9] netfilter: flowtable: add vlan support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 7/9] netfilter: flowtable: add direct xmit path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 8/9] netfilter: flowtable: bridge port support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 4/9] bridge: resolve forwarding path for bridge devices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/9] net: resolve forwarding path from virtual netdevice and HW destination address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/9] netfilter: flowtable: add xmit path types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 0/9] netfilter: flowtable bridge and vlan enhancements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next] netfilter: restore NF_INET_NUMHOOKS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: selftests: netfilter: nft_nat.sh: /dev/stdin:2:9-15: Error: syntax error, unexpected counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: ingress inet support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: ingress inet support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Francesco Ruggeri <fruggeri@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: restore NF_INET_NUMHOOKS
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: [PATCH nft] src: ingress inet support
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: restore NF_INET_NUMHOOKS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- iptables userspace API broken due to added value in nf_inet_hooks
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: iptables userspace API broken due to added value in nf_inet_hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables userspace API broken due to added value in nf_inet_hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] Fixes dropping of small packets in bridge nat
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] Fixes dropping of small packets in bridge nat
- From: <timothee.cocault@xxxxxxxxxx>
- selftests: netfilter: nft_nat.sh: /dev/stdin:2:9-15: Error: syntax error, unexpected counter
- From: Naresh Kamboju <naresh.kamboju@xxxxxxxxxx>
- Re: WARNING: at net/netfilter/nf_tables_api.c:622 lockdep_nfnl_nft_mutex_not_held+0x28/0x38 [nf_tables]
- From: Naresh Kamboju <naresh.kamboju@xxxxxxxxxx>
- Re: Bug: ebtables snat drops small packets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Phil Sutter <phil@xxxxxx>
- Bug: ebtables snat drops small packets
- From: <timothee.cocault@xxxxxxxxxx>
- WARNING: at net/netfilter/nf_tables_api.c:622 lockdep_nfnl_nft_mutex_not_held+0x28/0x38 [nf_tables]
- From: Naresh Kamboju <naresh.kamboju@xxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/4] selftests: netfilter: extend nfqueue test case
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH 0/4] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/4] netfilter: nftables: extend error reporting for chain updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/4] ipvs: clear skb->tstamp in forwarding path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] netfilter: nf_log: missing vlan offload tag and proto
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/4] selftests: netfilter: extend nfqueue test case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/8] conntrack: fix icmp entry creation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/8] tests: icmp entry create/delete
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net V2] netfilter: Drop fragmented ndisc packets assembled in netfilter
- From: Georg Kohmann <geokohma@xxxxxxxxx>
- [PATCH nft] src: ingress inet support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH v2 06/10] nft: Introduce struct nft_chain
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH v2 04/10] nft: Eliminate nft_chain_list_get()
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH v2 02/10] nft: Implement nft_chain_foreach()
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH v2 01/10] nft: Fix selective chain compatibility checks
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 0/6] Netfilter/IPVS updates for net-next
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nf] netfilter: nftables: extend error reporting for chain updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_log: missing vlan offload tag and proto
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v21 16/23] LSM: security_secid_to_secctx in netlink netfilter
- From: Casey Schaufler <casey@xxxxxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: Drop fragmented ndisc packets assembled in netfilter
- From: "Georg Kohmann (geokohma)" <geokohma@xxxxxxxxx>
- Re: [nft PATCH] json: Fix memleak in set_dtype_json()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: Drop fragmented ndisc packets assembled in netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2 06/10] nft: Introduce struct nft_chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2 04/10] nft: Eliminate nft_chain_list_get()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2 03/10] nft: cache: Introduce nft_cache_add_chain()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2 02/10] nft: Implement nft_chain_foreach()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2 01/10] nft: Fix selective chain compatibility checks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] netfilter: flowtable: reduce calls to pskb_may_pull()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] netfilter: add nf_static_key_{inc,dec}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] netfilter: add inet ingress support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/6] netfilter: add nf_ingress_hook() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] netfilter: nf_tables: add inet ingress support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] ipvs: inspect reply packets from DR/TUN real servers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/3] tests: py: fixes for failing JSON tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v8 net-next] ipvs: inspect reply packets from DR/TUN real servers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] ipvs: clear skb->tstamp in forwarding path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] selftests: netfilter: extend nfqueue test case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: flowtable: reduce calls to pskb_may_pull()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/3] tests: py: add missing test JSON output for TCP flag tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 2/3] tests: py: correct order of set elements in test JSON output.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 1/3] tests: py: add missing JSON output for ct test.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 0/3] tests: py: fixes for failing JSON tests
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [ulogd2] Problem while running
- From: Amiq Nahas <m992493@xxxxxxxxx>
- Re: [PATCH net] ipvs: clear skb->tstamp in forwarding path
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Francesco Ruggeri <fruggeri@xxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH 0/4] Netfilter fixes for net
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH net] ipvs: clear skb->tstamp in forwarding path
- From: Julian Anastasov <ja@xxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Phil Sutter <phil@xxxxxx>
- 0x14: Videos posted
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf v2] selftests: netfilter: extend nfqueue test case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_sip: Fix inconsistent of format with argument type in nf_nat_sip.
- From: Ye Bin <yebin10@xxxxxxxxxx>
- Re: [PATCH v2] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: Francesco Ruggeri <fruggeri@xxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] json: Fix memleak in set_dtype_json()
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf] selftests: netfilter: extend nfqueue test case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf] selftests: netfilter: extend nfqueue test case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 3/4] netfilter: add inet ingress support
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 3/4] netfilter: add inet ingress support
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 0/4] Add nf_tables ingress hook for the inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: nf_tables: add inet ingress support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/4] netfilter: add inet ingress support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/4] netfilter: add nf_ingress_hook() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/4] netfilter: add nf_static_key_{inc,dec}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/4] Add nf_tables ingress hook for the inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf v2] netfilter: conntrack: connection timeout after re-register
- From: fruggeri@xxxxxxxxxx (Francesco Ruggeri)
- [PATCH v2] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [PATCH 1/1] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- [PATCH 3/4] selftests: netfilter: remove unused cnt and simplify command testing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] selftests: netfilter: add time counter check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/4] selftests: netfilter: fix nft_meta.sh error reporting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/4] selftests: netfilter: add cpu counter check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 0/3] libxtables: Fix for pointless socket() calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH v2] libxtables: Make sure extensions register in revision order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V9 11/13] audit: contid check descendancy and nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [iptables PATCH] extensions: libipt_icmp: Fix translation of type 'any'
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] extensions: libipt_icmp: Fix translation of type 'any'
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 1/1] Solves Bug 1462 - `nft -j list set` does not show counters
- From: "Jose M. Guisado" <guigom@xxxxxxxxxx>
- Re: INFO: task hung in hub_port_init
- From: Andrey Konovalov <andreyknvl@xxxxxxxxxx>
- Re: [PATCH 1/1] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- [PATCH] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: WARNING in ieee80211_check_rate_mask
- From: syzbot <syzbot+be0e03ca215b06199629@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2] libxtables: Make sure extensions register in revision order
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/1] Solves Bug 1462 - `nft -j list set` does not show counters
- From: "Jose M. Guisado" <guigom@xxxxxxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 3/3] libxtables: Register multiple extensions in ascending order
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: INFO: task hung in hub_port_init
- From: Oliver Neukum <oneukum@xxxxxxx>
- INFO: task hung in hub_port_init
- From: syzbot <syzbot+74d6ef051d3d2eacf428@xxxxxxxxxxxxxxxxxxxxxxxxx>
- INFO: task hung in usb_get_descriptor
- From: syzbot <syzbot+31ae6d17d115e980fd14@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: connection timeout after re-register
- From: fruggeri@xxxxxxxxxx (Francesco Ruggeri)
- Re: [iptables PATCH 3/3] libxtables: Register multiple extensions in ascending order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 2/3] libxtables: Simplify pending extension registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 2/3] nft: Fix error reporting for refreshed transactions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 1/3] nft: Make batch_add_chain() return the added batch object
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v8 net-next] ipvs: inspect reply packets from DR/TUN real servers
- From: Julian Anastasov <ja@xxxxxx>
- [iptables PATCH 2/3] nft: Fix error reporting for refreshed transactions
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] nft: Make batch_add_chain() return the added batch object
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/3] nft: Fix for concurrent noflush restore calls
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/3] nft: Fix transaction refreshing
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 00/11] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 10/11] netfilter: nf_tables: Enable fast nft_cmp for inverted matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/11] netfilter: nfnetlink: place subsys mutexes in distinct lockdep classes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/11] netfilter: nf_tables: Implement fast bitwise expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/11] netfilter: nf_tables: Remove ununsed function nft_data_debug
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/11] netfilter: conntrack: proc: rename stat column
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/11] netfilter: nf_tables: use nla_memdup to copy udata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/11] netfilter: nf_tables: add userdata attributes to nft_chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/11] netfilter: ipset: enable memory accounting for ipset allocations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/11] netfilter: nf_tables_offload: Remove unused macro FLOW_SETUP_BLOCK
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/11] netfilter: nf_tables: fix userdata memleak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/11] ipvs: Remove unused macros
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/11] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [net-next PATCH 2/2] net: netfilter: Implement fast bitwise expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [net-next PATCH 1/2 v2] net: netfilter: Enable fast nft_cmp for inverted matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nfnetlink: place subsys mutexes in distinct lockdep classes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] ipset: enable memory accounting for ipset allocations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nf_tables_offload: Remove unused macro FLOW_SETUP_BLOCK
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v6] ipvs: adjust the debug info in function set_tcp_state
- From: "longguang.yue" <bigclouds@xxxxxxx>
- [PATCH v6] ipvs: inspect reply packets from DR/TUN real servers
- From: "longguang.yue" <bigclouds@xxxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v5] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v5] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: "longguang.yue" <bigclouds@xxxxxxx>
- [PATCH 1/1] Solves Bug 1462 - `nft -j list set` does not show counters
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V9 05/13] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH v4] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: "longguang.yue" <bigclouds@xxxxxxx>
- Re: [PATCH v4] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH ghak90 V9 06/13] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [net-next PATCH 1/2 v2] net: netfilter: Enable fast nft_cmp for inverted matches
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: nfnetlink: place subsys mutexes in distinct lockdep classes
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] iptables-nft: fix basechain policy configuration
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: iptables-nft-restore issue
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- Re: iptables-nft-restore issue
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] nft: Optimize class-based IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- Re: [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches
- From: Florian Westphal <fw@xxxxxxxxx>
- [net-next PATCH 2/2] net: netfilter: Implement fast bitwise expression
- From: Phil Sutter <phil@xxxxxx>
- [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches
- From: Phil Sutter <phil@xxxxxx>
- [net-next PATCH 1/2] net: netfilter: Enable fast nft_cmp for inverted matches
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] nft: migrate man page examples with `meter` directive to sets
- From: Devin Bayer <dev@xxxxxxxxx>
- Re: [PATCH] nft: migrate man page examples with `meter` directive to sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] nft: migrate man page examples with `meter` directive to sets
- From: Devin Bayer <dev@xxxxxxxxx>
- Re: [PATCH v3] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: Julian Anastasov <ja@xxxxxx>
- Re: iptables-nft-restore issue
- From: Phil Sutter <phil@xxxxxx>
- Re: iptables-nft-restore issue
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables-nft-restore issue
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables-nft-restore issue
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] evaluate: Reject quoted strings containing only wildcard
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: use nla_memdup to copy udata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: fix userdata memleak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- iptables-nft-restore issue
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Fix for broken address mask match detection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/1 nf] selftests: netfilter: add time counter check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5] ipvs: adjust the debug info in function set_tcp_state
- From: yue longguang <yuelongguang@xxxxxxxxx>
- [PATCH libnetfilter_queue] doc: build: Reduce size of doxygen.cfg and doxygen build o/p
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH v5] ipvs: adjust the debug info in function set_tcp_state
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH libnetfilter_queue] src: doc: Fix doxygen warning
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH v3] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: "longguang.yue" <bigclouds@xxxxxxx>
- Re: [PATCH v2] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: BUG: unable to handle kernel paging request in dqput
- From: Jan Kara <jack@xxxxxxx>
- [PATCH 2/2] tests: conntrack -L/-D ip family filtering
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 1/2] conntrack: -L/-D both ipv4/6 if no family is given
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 0/2] conntrack: -L/-D both ipv4/6 if no family is given
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- nftables bug?? Maybe
- From: Evgeniy Yakubov <yacudzer@xxxxxxx>
- [PATCH v2] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: "longguang.yue" <bigclouds@xxxxxxx>
- Re: [PATCH] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: yue longguang <yuelongguang@xxxxxxxxx>
- [PATCH] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode
- From: "longguang.yue" <bigclouds@xxxxxxx>
- Re: [PATCH v5] ipvs: adjust the debug info in function set_tcp_state
- From: yue longguang <yuelongguang@xxxxxxxxx>
- Re: KASAN: use-after-free Read in tcf_action_init
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: general protection fault in strncasecmp
- From: syzbot <syzbot+459a5dce0b4cb70fd076@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [iptables PATCH] nft: Fix for broken address mask match detection
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v4 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: use nla_memdup to copy udata
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [nftables] counter not working on kernel 5.6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] evaluate: Reject quoted strings containing only wildcard
- From: Phil Sutter <phil@xxxxxx>
- KASAN: use-after-free Read in tcf_action_init
- From: syzbot <syzbot+9f43bb6a66ff96a21931@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [nftables] counter not working on kernel 5.6
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- [PATCH v5] ipvs: adjust the debug info in function set_tcp_state
- From: "longguang.yue" <bigclouds@xxxxxxx>
- Re: [PATCH v4] ipvs: adjust the debug info in function set_tcp_state
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v4] ipvs: adjust the debug info in function set_tcp_state
- From: "longguang.yue" <bigclouds@xxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: fix userdata memleak
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: BUG: unable to handle kernel paging request in dqput
- From: Takashi Iwai <tiwai@xxxxxxx>
- BUG: unable to handle kernel paging request in dqput
- From: syzbot <syzbot+f816042a7ae2225f25ba@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 0/8] Fast bulk transfers of large sets of ct entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/8] Fast bulk transfers of large sets of ct entries
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 2/8] conntrack: fix icmp entry creation
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 3/8] conntrack: accept parameters from stdin
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 5/8] tests: conntrack parameters from stdin
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 6/8] conntrack: implement options output format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 7/8] conntrack.8: man update for opts format support
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 4/8] conntrack.8: man update for stdin params support
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 1/8] tests: icmp entry create/delete
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 0/8] Fast bulk transfers of large sets of ct entries
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [PATCH 8/8] tests: dumping ct entries in opts format
- From: Mikhail Sennikovsky <mikhail.sennikovskii@xxxxxxxxxxxxxxx>
- [nftables] dynamic flag missing from wiki and using counter
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [PATCH] ipset: enable memory accounting for ipset allocations
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH v2] ipset: enable memory accounting for ipset allocations
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: enable memory accounting for ipset allocations
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH] ipset: enable memory accounting for ipset allocations
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [nft PATCH] evaluate: Reject quoted strings containing only wildcard
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] ipvs: adjust the debug order of src and dst
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH 1/1 nf] selftests: netfilter: add time counter check
- From: Fabian Frederick <fabf@xxxxxxxxx>
- Re: [PATCH] ipvs: adjust the debug order of src and dst
- From: Julian Anastasov <ja@xxxxxx>
- [iptables PATCH v2 01/10] nft: Fix selective chain compatibility checks
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 04/10] nft: Eliminate nft_chain_list_get()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 05/10] nft: cache: Move nft_chain_find() over
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 08/10] nft: cache: Sort custom chains by name
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 07/10] nft: Introduce a dedicated base chain array
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 06/10] nft: Introduce struct nft_chain
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 00/10] nft: Sorted chain listing et al.
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 10/10] nft: Avoid pointless table/chain creation
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 02/10] nft: Implement nft_chain_foreach()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 03/10] nft: cache: Introduce nft_cache_add_chain()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 09/10] tests: shell: Drop any dump sorting in place
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 0/3] libxtables: Fix for pointless socket() calls
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v3 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v3 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [PATCH] ipvs: adjust the debug order of src and dst
- From: Andrew Lunn <andrew@xxxxxxx>
- Re: [iptables PATCH 0/3] libxtables: Fix for pointless socket() calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH] ipvs: adjust the debug order of src and dst
- From: yue longguang <yuelongguang@xxxxxxxxx>
- [PATCH] ipvs: adjust the debug order of src and dst
- From: "longguang.yue" <bigclouds@xxxxxxx>
- [iptables PATCH 3/3] libxtables: Register multiple extensions in ascending order
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/3] libxtables: Fix for pointless socket() calls
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/3] libxtables: Simplify pending extension registration
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] libxtables: Make sure extensions register in revision order
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] Solves Bug 1388 - Combining --terse with --json has no effect (with test)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] Solves Bug 1388 - Combining --terse with --json has no effect (with test)
- From: Gopal <gopunop@xxxxxxxxx>
- Re: UBSAN: array-index-out-of-bounds in arch_uprobe_analyze_insn
- From: syzbot <syzbot+9b64b619f10f19d19a7c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_immediate: No increment ctx->level for NFT_GOTO
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/3 nf] selftests: netfilter: add cpu counter check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/3] netfilter: nf_tables: add userdata attributes to nft_chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] ipvs: Remove unused macros
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: proc: rename stat column
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] parser_bison: fail when specifying multiple comments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libmnl] doxygen: Fixed link to the git source tree on the website.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- KMSAN: uninit-value in gc_worker (3)
- From: syzbot <syzbot+b3dbc715a0b6201346f4@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nftables 3/3] src: add comment support for chains
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH libnftnl 2/3] chain: add userdata and comment support
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_tables: add userdata attributes to nft_chain
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- [PATCH 0/3] add userdata and comment support for chains
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- KASAN: vmalloc-out-of-bounds Read in bpf_trace_run2
- From: syzbot <syzbot+845923d2172947529b58@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next] ipvs: Remove unused macros
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Laura García Liébana <nevola@xxxxxxxxx>
- 0x14: slides and papers posted
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH iptables 1/4] xtables: Do not register matches/targets with incompatible revision
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next] netfilter: nf_tables_offload: Remove unused macro FLOW_SETUP_BLOCK
- From: YueHaibing <yuehaibing@xxxxxxxxxx>
- [PATCH net-next] ipvs: Remove unused macros
- From: YueHaibing <yuehaibing@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 215/330] netfilter: nf_tables: silence a RCU-list warning in nft_table_lookup()
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Jacob Keller <jacob.e.keller@xxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Laura García Liébana <nevola@xxxxxxxxx>
- Re: [oss-drivers] [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Simon Horman <simon.horman@xxxxxxxxxxxxx>
- Re: [PATCH] Solves Bug 1388 - Combining --terse with --json has no effect
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nf_tables: Remove ununsed function nft_data_debug
- From: YueHaibing <yuehaibing@xxxxxxxxxx>
- Re: [PATCH] Solves Bug 1388 - Combining --terse with --json has no effect
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Miquel Raynal <miquel.raynal@xxxxxxxxxxx>
- Re: [Intel-gfx] [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Jani Nikula <jani.nikula@xxxxxxxxxxxxxxx>
- [PATCH libmnl] doxygen: Fixed link to the git source tree on the website.
- From: igo95862 <igo95862@xxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nft 2/2] src: context tracking for multiple transport protocols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: py: flush log file output before running each command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] evaluate: remove one indent level in __expr_evaluate_payload()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Laura García Liébana <nevola@xxxxxxxxx>
- Re: [PATCH] Solves Bug 1388 - Combining --terse with --json has no effect
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] mnl: larger receive socket buffer for netlink errors
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] libnftables: avoid repeated command list traversal on errors
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables] TODO: Replace yy_switch_to_buffer by yypop_buffer_state and yypush_buffer_state
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- [PATCH] Solves Bug 1388 - Combining --terse with --json has no effect
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Laura García Liébana <nevola@xxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Joe Perches <joe@xxxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Robin Murphy <robin.murphy@xxxxxxx>
- [iptables] Multiple labels simultaneously
- From: Amiq Nahas <m992493@xxxxxxxxx>
- [PATCH nftables] parser_bison: fail when specifying multiple comments
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Matthias Brugger <matthias.bgg@xxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Ilya Dryomov <idryomov@xxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Steffen Maier <maier@xxxxxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Felipe Balbi <balbi@xxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: <Nicolas.Ferre@xxxxxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Wolfram Sang <wsa@xxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Mauro Carvalho Chehab <mchehab+huawei@xxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Joe Perches <joe@xxxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Jason Gunthorpe <jgg@xxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Keith Busch <kbusch@xxxxxxxxxx>
- Re: [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- [trivial PATCH] treewide: Convert switch/case fallthrough; to break;
- From: Joe Perches <joe@xxxxxxxxxxx>
- Re: [PATCH 1/3 nf] selftests: netfilter: add cpu counter check
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 3/3 nf] selftests: netfilter: remove unused cnt and simplify command testing
- From: Fabian Frederick <fabf@xxxxxxxxx>
- [PATCH 2/3 nf] selftests: netfilter: fix nft_meta.sh error reporting
- From: Fabian Frederick <fabf@xxxxxxxxx>
- [PATCH 1/3 nf] selftests: netfilter: add cpu counter check
- From: Fabian Frederick <fabf@xxxxxxxxx>
- Re: [PATCH 00/13] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH] net/netfilter: fix a typo for nf_conntrack_proto_dccp.c
- From: Simon Horman <simon.horman@xxxxxxxxxxxxx>
- Re: [nftables] TODO: Replace yy_switch_to_buffer by yypop_buffer_state and yypush_buffer_state
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- Re: [nftables] TODO: Replace yy_switch_to_buffer by yypop_buffer_state and yypush_buffer_state
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] net/netfilter: fix a typo for nf_conntrack_proto_dccp.c
- From: Wang Qing <wangqing@xxxxxxxx>
- [PATCH nf-next] netfilter: conntrack: proc: rename stat column
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 02/13] ipvs: Fix uninit-value in do_ip_vs_set_ctl()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/13] netfilter: ip6t_NPT: rewrite addresses in ICMPv6 original packet
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/13] netfilter: nf_tables: add userdata attributes to nft_table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/13] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/13] netfilter: conntrack: do not increment two error counters at same time
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/13] netfilter: conntrack: remove ignore stats
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/13] netfilter: conntrack: add clash resolution stat counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/13] netfilter: xt_HMARK: Use ip_is_fragment() helper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/13] ipvs: remove dependency on ip6_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/13] netfilter: conntrack: remove unneeded nf_ct_put
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/13] netfilter: ebt_stp: Remove unused macro BPDU_TYPE_TCN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/13] netfilter: nf_tables: add userdata support for nft_object
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/13] netfilter: nft_socket: add wildcard support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/13] selftests/net: replace obsolete NFT_CHAIN configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/5] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH 1/5] netfilter: ctnetlink: add a range check for l3/l4 protonum
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/5] netfilter: nf_tables: coalesce multiple notifications into one skbuff
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl 2/3] object: add userdata and comment support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables 3/3] src: add comment support for objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/3, v2] netfilter: nf_tables: add userdata support for nft_object
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: John Fastabend <john.fastabend@xxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- [nftables] TODO: Replace yy_switch_to_buffer by yypop_buffer_state and yypush_buffer_state
- From: Gopal Yadav <gopunop@xxxxxxxxx>
- [PATCH 3/5] netfilter: ctnetlink: fix mark based dump filtering regression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/5] netfilter: conntrack: nf_conncount_init is failing with IPv6 disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/5] netfilter: nft_meta: use socket user_ns to retrieve skuid and skgid
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3, v2] netfilter: nf_tables: add userdata support for nft_object
- From: "Jose M. Guisado Gomez" <guigom@xxxxxxxxxx>
- Re: [PATCH net-next] netfilter: ebt_stp: Remove unused macro BPDU_TYPE_TCN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: check whether dot is available when configuring doxygen.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/3] netfilter: nf_tables: add userdata support for nft_object
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/1 net-next] selftests/net: replace obsolete NFT_CHAIN configuration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-net] netfilter: conntrack: nf_conncount_init is failing with IPv6 disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ctnetlink: fix mark based dump filtering regression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: check whether dot is available when configuring doxygen.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Laura García Liébana <nevola@xxxxxxxxx>
- Re: [PATCH nf-next v3 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- INFO: trying to register non-static key in update_defense_level
- From: syzbot <syzbot+80eac45c3b92882289f6@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/1 net-next] selftests/net: replace obsolete NFT_CHAIN configuration
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH AUTOSEL 5.8 04/53] netfilter: conntrack: allow sctp hearbeat after connection re-use
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.8 06/53] netfilter: nft_set_rbtree: Detect partial overlap with start endpoint match
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 03/43] netfilter: conntrack: allow sctp hearbeat after connection re-use
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 03/26] netfilter: conntrack: allow sctp hearbeat after connection re-use
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH libnetfilter_queue] build: check whether dot is available when configuring doxygen.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH net-net] netfilter: conntrack: nf_conncount_init is failing with IPv6 disabled
- From: Simon Horman <simon.horman@xxxxxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]