Linux TCP/IP Netfilter Devel
Thread Index
[
Prev Page
][
Next Page
]
[PATCH nf-next] netfilter: nf_tables: do not update stateful expressions if lookup is inverted
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf v2 4/4] nft_set_rbtree: Detect partial overlaps on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf v2 4/4] nft_set_rbtree: Detect partial overlaps on insertion
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 2/2] parser_bison: simplify error in chain type and hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 1/2] evaluate: check for device in non-netdev chains
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] netfilter: IDLETIMER target v1 - match Android layout
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] netfilter: IDLETIMER target v1 - match Android layout
From
: Jan Engelhardt <jengelh@xxxxxxx>
Re: [PATCH] netfilter: IDLETIMER target v1 - match Android layout
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[ANNOUNCE] nftlb 0.6 release
From
: Laura Garcia <nevola@xxxxxxxxx>
Re: [PATCH] netfilter: IDLETIMER target v1 - match Android layout
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH] netfilter: IDLETIMER target v1 - match Android layout
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH] netfilter: IDLETIMER target v1 - match Android layout
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
[PATCH v3] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
[PATCH nft 1/3] rule: add hook_spec
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 3/3] evaluate: improve error reporting in netdev ingress chain
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 2/3] parser_bison: store location of basechain definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 5.5 138/170] netfilter: nft_fwd_netdev: allow to redirect to ifb via ingress
From
: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
Re: [PATCH 5.5 138/170] netfilter: nft_fwd_netdev: allow to redirect to ifb via ingress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 00/28] Netfilter/IPVS updates for net-next
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH nf-next v4 1/2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Florent Fourcot <florent.fourcot@xxxxxxxxxx>
[PATCH nf-next v5 1/1] netfilter: ctnetlink: add kernel side filtering for dump
From
: Romain Bellan <romain.bellan@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
[PATCH 19/28] netfilter: nf_queue: do not release refcouts until nf_reinject is done
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 01/28] netfilter: nf_tables: move nft_expr_clone() to nf_tables_api.c
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 22/28] netfilter: nft_set_bitmap: initialize set element extension in lookups
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 00/28] Netfilter/IPVS updates for net-next
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 03/28] netfilter: nf_tables: allow to specify stateful expression in set definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 24/28] netfilter: nf_tables: skip set types that do not support for expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 04/28] netfilter: nf_tables: fix double-free on set expression from the error path
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 26/28] netfilter: flowtable: add counter support in HW offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 07/28] netfilter: ctnetlink: Add missing annotation for ctnetlink_parse_nat_setup()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 28/28] ipvs: fix uninitialized variable warning
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 08/28] netfilter: conntrack: Add missing annotations for nf_conntrack_all_lock() and nf_conntrack_all_unlock()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 25/28] netfilter: conntrack: add nf_ct_acct_add()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 11/28] netfilter: nf_tables: add enum nft_flowtable_flags to uapi
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 17/28] netfilter: nf_queue: make nf_queue_entry_release_refs static
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 12/28] netfilter: flowtable: add counter support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 09/28] ipvs: optimize tunnel dumps for icmp errors
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 27/28] netfilter: nft_exthdr: fix endianness of tcp option cast
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 10/28] netfilter: conntrack: export nf_ct_acct_update()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 13/28] netfilter: flowtable: Fix incorrect tc_setup_type type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 16/28] netfilter: flowtable: Use work entry per offload command
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 14/28] netfilter: nf_tables: silence a RCU-list warning in nft_table_lookup()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 18/28] netfilter: nf_queue: place bridge physports into queue_entry struct
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 15/28] netfilter: flowtable: Use rw sem as flow block lock
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 06/28] netfilter: flowtable: fix NULL pointer dereference in tunnel offload support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 05/28] netfilter: nf_tables: add nft_set_elem_expr_destroy() and use it
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 23/28] netfilter: nft_dynset: validate set expression definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 02/28] netfilter: nf_tables: pass context to nft_set_destroy()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 21/28] netfilter: ctnetlink: be more strict when NF_CONNTRACK_MARK is not set
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 20/28] netfilter: nf_queue: prefer nf_queue_entry_free
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 00/26] Netfilter/IPVS updates for net-next
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH 00/26] Netfilter/IPVS updates for net-next
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH nf-next] ipvs: fix uninitialized variable warning
From
: Julian Anastasov <ja@xxxxxx>
[PATCH nf-next] ipvs: fix uninitialized variable warning
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
[PATCH 01/26] netfilter: nf_tables: move nft_expr_clone() to nf_tables_api.c
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 06/26] netfilter: flowtable: fix NULL pointer dereference in tunnel offload support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 03/26] netfilter: nf_tables: allow to specify stateful expression in set definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 02/26] netfilter: nf_tables: pass context to nft_set_destroy()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 08/26] netfilter: conntrack: Add missing annotations for nf_conntrack_all_lock() and nf_conntrack_all_unlock()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 07/26] netfilter: ctnetlink: Add missing annotation for ctnetlink_parse_nat_setup()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 04/26] netfilter: nf_tables: fix double-free on set expression from the error path
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 10/26] netfilter: conntrack: export nf_ct_acct_update()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 11/26] netfilter: nf_tables: add enum nft_flowtable_flags to uapi
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 12/26] netfilter: flowtable: add counter support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 13/26] netfilter: flowtable: Fix incorrect tc_setup_type type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 09/26] ipvs: optimize tunnel dumps for icmp errors
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 17/26] netfilter: nf_queue: make nf_queue_entry_release_refs static
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 15/26] netfilter: flowtable: Use rw sem as flow block lock
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 20/26] netfilter: nf_queue: prefer nf_queue_entry_free
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 16/26] netfilter: flowtable: Use work entry per offload command
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 18/26] netfilter: nf_queue: place bridge physports into queue_entry struct
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 19/26] netfilter: nf_queue: do not release refcouts until nf_reinject is done
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 21/26] netfilter: ctnetlink: be more strict when NF_CONNTRACK_MARK is not set
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 23/26] netfilter: nft_dynset: validate set expression definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 26/26] netfilter: flowtable: add counter support in HW offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 24/26] netfilter: nf_tables: skip set types that do not support for expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 25/26] netfilter: conntrack: add nf_ct_acct_add()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 22/26] netfilter: nft_set_bitmap: initialize set element extension in lookups
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 14/26] netfilter: nf_tables: silence a RCU-list warning in nft_table_lookup()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 05/26] netfilter: nf_tables: add nft_set_elem_expr_destroy() and use it
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 00/26] Netfilter/IPVS updates for net-next
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
linux-next: build warning after merge of the netfilter-next tree
From
: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
Re: [PATCH nf-next v4 1/2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: Suggestion: replacement for physdev-is-bridged in nft
From
: jaroslav@xxxxxxxxxxx
Re: [PATCH 2/2] netfilter: flowtable: add counter support in HW offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 1/2] netfilter: conntrack: add nf_ct_acct_add()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: Suggestion: replacement for physdev-is-bridged in nft
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH nf-next v4 2/2] netfilter: ctnetlink: be more strict when NF_CONNTRACK_MARK is not set
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next v4 1/2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 0/4] netfilter: nf_queue: rework refcount handling
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Suggestion: replacement for physdev-is-bridged in nft
From
: jaroslav@xxxxxxxxxxx
Re: [PATCH nf] netfilter: nft_exthdr: fix endianness of tcp option cast
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf] netfilter: nft_exthdr: fix endianness of tcp option cast
From
: Sergey Marinkevich <sergey.marinkevich@xxxxxxxxxxx>
[iptables] avoid raw sockets which requires CAP_NET_RAW
From
: Youfu Zhang <zhangyoufu@xxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
From
: wenxu <wenxu@xxxxxxxxx>
[PATCH 2/2] netfilter: flowtable: add counter support in HW offload
From
: wenxu@xxxxxxxxx
[PATCH 1/2] netfilter: conntrack: add nf_ct_acct_add()
From
: wenxu@xxxxxxxxx
[PATCH nft] evaluate: display error if statement is missing
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next v2] netfilter: Fix incorrect tc_setup_type type for flowtable offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next v2 2/3] netfilter: flowtable: Use work entry per offload command
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next v2 1/3] netfilter: flowtable: Use rw sem as flow block lock
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 5/8] netfilter: conntrack: Add missing annotations for nf_conntrack_all_lock() and nf_conntrack_all_unlock()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 4/8] netfilter: Add missing annotation for ctnetlink_parse_nat_setup()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 3/3] netfilter: nf_tables: skip set types that do not support for expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 2/3] netfilter: nft_dynset: validate set expression definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 1/3] netfilter: nft_set_bitmap: initialize set element extension in lookups
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next v2] netfilter: Fix incorrect tc_setup_type type for flowtable offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next v2 0/3] netfilter: flowtable: Support offload of tuples in parallel
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH net-next v2 3/3] net/mlx5: CT: Use rhashtable's ct entries instead of a seperate list
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH net-next v2 1/3] netfilter: flowtable: Use rw sem as flow block lock
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH net-next v2 2/3] netfilter: flowtable: Use work entry per offload command
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH net-next v2 0/3] netfilter: flowtable: Support offload of tuples in parallel
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH nf-next v4 2/2] netfilter: ctnetlink: be more strict when NF_CONNTRACK_MARK is not set
From
: Romain Bellan <romain.bellan@xxxxxxxxxx>
[PATCH nf-next v4 1/2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Romain Bellan <romain.bellan@xxxxxxxxxx>
Re: [PATCH net-next 0/3] netfilter: flowtable: Support offload of tuples in parallel
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH net-next v2] netfilter: Fix incorrect tc_setup_type type for flowtable offload
From
: David Miller <davem@xxxxxxxxxxxxx>
[PATCH nf-next 4/4] netfilter: nf_queue: prefer nf_queue_entry_free
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf-next 3/4] netfilter: nf_queue: do not release refcouts until nf_reinject is done
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf-next 2/4] netfilter: nf_queue: place bridge physports into queue_entry struct
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf-next 1/4] netfilter: nf_queue: make nf_queue_entry_release_refs static
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf-next 0/4] netfilter: nf_queue: rework refcount handling
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH v2] iptables: open eBPF programs in read only mode
From
: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
Re: [PATCH v2] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH v2] iptables: open eBPF programs in read only mode
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
[PATCH nf-next v3 1/2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Romain Bellan <romain.bellan@xxxxxxxxxx>
[PATCH nf-next v3 2/2] netfilter: ctnetlink: be more strict when NF_CONNTRACK_MARK is not set
From
: Romain Bellan <romain.bellan@xxxxxxxxxx>
[PATCH nft] netlink: Show the handles of unknown rules in "nft monitor trace"
From
: Luis Ressel <aranea@xxxxxxxx>
[PATCH v2] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH] iptables: open eBPF programs in read only mode
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH nft] tests: Introduce test for insertion of overlapping and non-overlapping ranges
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
[PATCH nft] src: add support for flowtable counter
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH v2] ipvs: optimize tunnel dumps for icmp errors
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] iptables: open eBPF programs in read only mode
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] netfilter/nf_tables: silence a RCU-list warning
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 1/3] netfilter: conntrack: export nf_ct_acct_update()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next 3/3] net/mlx5: CT: Use rhashtable's ct entries instead of a seperate list
From
: Saeed Mahameed <saeedm@xxxxxxxxxxxx>
Re: [PATCH] netfilter/nf_tables: silence a RCU-list warning
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH net-next 2/3] netfilter: flowtable: Use work entry per offload command
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net-next 1/3] netfilter: flowtable: Use rw sem as flow block lock
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net] net: Fix CONFIG_NET_CLS_ACT=n and CONFIG_NFT_FWD_NETDEV={y,m} build
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Florian Westphal <fw@xxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH] netfilter/nf_tables: silence a RCU-list warning
From
: Qian Cai <cai@xxxxxx>
[PATCH net] net: Fix CONFIG_NET_CLS_ACT=n and CONFIG_NFT_FWD_NETDEV={y,m} build
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH net-next] netfilter: flowtable: Fix accessing null dst entry
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
Re: [PATCH] netfilter: nft_fwd_netdev: Fix CONFIG_NET_CLS_ACT=n build
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] netfilter: nft_fwd_netdev: Fix CONFIG_NET_CLS_ACT=n build
From
: Geert Uytterhoeven <geert@xxxxxxxxxxxxxx>
Re: [PATCH net-next] netfilter: flowtable: Fix accessing null dst entry
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH net-next] netfilter: flowtable: Fix accessing null dst entry
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
Re: [PATCH] netfilter: nft_fwd_netdev: Fix CONFIG_NET_CLS_ACT=n build
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH] netfilter: nft_fwd_netdev: Fix CONFIG_NET_CLS_ACT=n build
From
: Geert Uytterhoeven <geert@xxxxxxxxxxxxxx>
Re: [PATCH nf-next 1/3] netfilter: conntrack: export nf_ct_acct_update()
From
: wenxu <wenxu@xxxxxxxxx>
Re: [PATCH 0/7] Netfilter fixes for net
From
: David Miller <davem@xxxxxxxxxxxxx>
[PATCH 0/7] Netfilter fixes for net
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 1/7] netfilter: nf_tables: Allow set back-ends to report partial overlaps on insertion
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 5/7] netfilter: nft_fwd_netdev: validate family and chain type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 4/7] netfilter: nft_set_rbtree: Detect partial overlaps on insertion
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 6/7] netfilter: nft_fwd_netdev: allow to redirect to ifb via ingress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 3/7] netfilter: nft_set_rbtree: Introduce and use nft_rbtree_interval_start()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 7/7] selftests: netfilter: add nfqueue test case
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 2/7] netfilter: nft_set_pipapo: Separate partial and complete overlap cases on insertion
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH v3 nf] selftests: netfilter: add nfqueue test case
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf v2 0/4] nftables: Consistently report partial and entire set overlaps
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 3/3] netfilter: flowtable: add counter support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 2/3] netfilter: nf_tables: add enum nft_flowtable_flags to uapi
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 1/3] netfilter: conntrack: export nf_ct_acct_update()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH net-next 1/3] netfilter: flowtable: Use rw sem as flow block lock
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH net-next 3/3] net/mlx5: CT: Use rhashtable's ct entries instead of a seperate list
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH net-next 2/3] netfilter: flowtable: Use work entry per offload command
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
[PATCH net-next 0/3] netfilter: flowtable: Support offload of tuples in parallel
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf 1/2] netfilter: nft_fwd_netdev: validate family and chain type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf 2/2] netfilter: nft_fwd_netdev: allow to redirect to ifb via ingress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
[PATCH net-next v2] netfilter: Fix incorrect tc_setup_type type for flowtable offload
From
: wenxu@xxxxxxxxx
Re: [PATCH net-next] flow_offload: add TC_SETP_FT type in flow_indr_block_call
From
: David Miller <davem@xxxxxxxxxxxxx>
[PATCH v3 nf] selftests: netfilter: add nfqueue test case
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH nf] selftests: netfilter: add nfqueue test case
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf] selftests: netfilter: add nfqueue test case
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf] selftests: netfilter: add nfqueue test case
From
: Florian Westphal <fw@xxxxxxxxx>
Re: general protection fault in nf_flow_table_offload_setup
From
: Florian Westphal <fw@xxxxxxxxx>
Re: general protection fault in nf_flow_table_offload_setup
From
: syzbot <syzbot+e93c1d9ae19a0236289c@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_ip_add
From
: syzbot <syzbot+f3e96783d74ee8ea9aa3@xxxxxxxxxxxxxxxxxxxxxxxxx>
[PATCH nf v2 4/4] nft_set_rbtree: Detect partial overlaps on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf v2 3/4] nft_set_rbtree: Introduce and use nft_rbtree_interval_start()
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf v2 2/4] nft_set_pipapo: Separate partial and complete overlap cases on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf v2 1/4] nf_tables: Allow set back-ends to report partial overlaps on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf v2 0/4] nftables: Consistently report partial and entire set overlaps
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH NOMERGE iptables 2/2] man: xt_set: Describe --update-counters-first flag
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH NOMERGE iptables 1/2] man: xt_set: Reflect current behaviour of counter update and match flags
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH NOMERGE iptables 0/2] man: xt_set: Describe existing behaviour and new counters update flag
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next 3/3] net/sched: act_ct: add nf_conn_acct for SW act_ct flowtable offload
From
: wenxu@xxxxxxxxx
[PATCH nf-next 0/3] netfilter: nf_flow_table_offload: add nf_conn_acct for flowtable offload
From
: wenxu@xxxxxxxxx
[PATCH nf-next 1/3] netfilter: nf_flow_table: add nf_conn_acct for SW flowtable offload
From
: wenxu@xxxxxxxxx
[PATCH nf-next 2/3] netfilter: nf_flow_table: add nf_conn_acct for HW flowtable offload
From
: wenxu@xxxxxxxxx
Re: [PATCH 0/4] Netfilter fixes for net
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
From
: wenxu <wenxu@xxxxxxxxx>
[PATCH 1/4] netfilter: flowtable: reload ip{v6}h in nf_flow_nat_ip{v6}
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 4/4] netfilter: flowtable: populate addr_type mask
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 3/4] netfilter: flowtable: Fix flushing of offloaded flows on free
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 2/4] netfilter: flowtable: reload ip{v6}h in nf_flow_tuple_ip{v6}
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 0/4] Netfilter fixes for net
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
From
: wenxu@xxxxxxxxx
Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft] tests: py: update nat expressions payload to include proto flags
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH libnftnl 2/2] expr: nat: snprint flags in hexadecimal
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH libnftnl 1/2] expr: masq: revisit _snprintf()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
From
: wenxu <wenxu@xxxxxxxxx>
Re: [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
From
: wenxu <wenxu@xxxxxxxxx>
Re: [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
From
: wenxu@xxxxxxxxx
Re: INFO: task hung in htable_put
From
: syzbot <syzbot+84936245a918e2cddb32@xxxxxxxxxxxxxxxxxxxxxxxxx>
[PATCH] iptables: open eBPF programs in read only mode
From
: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH net] netfilter: nf_flow_table: populate addr_type mask
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix potential NULL pointer dereference for dst_cache in handling lwtstate
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH v2 2/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_tuple_ip{v6}
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH v2 1/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_nat_ip{v6}
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH net] netfilter: flowtable: Fix flushing of offloaded flows on free
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [PATCH net-next 6/6] netfilter: nf_flow_table: hardware offload support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH net] netfilter: nf_flow_table: populate addr_type mask
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [PATCH net-next 6/6] netfilter: nf_flow_table: hardware offload support
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Eric Dumazet <eric.dumazet@xxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Eric Dumazet <eric.dumazet@xxxxxxxxx>
Re: [PATCH net-next 6/6] netfilter: nf_flow_table: hardware offload support
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [PATCH 19/29] nft_set_pipapo: Introduce AVX2-based lookup implementation
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Florian Westphal <fw@xxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH 19/29] nft_set_pipapo: Introduce AVX2-based lookup implementation
From
: Linus Walleij <linus.walleij@xxxxxxxxxx>
Re: [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH net] netfilter: flowtable: Fix flushing of offloaded flows on free
From
: Paul Blakey <paulb@xxxxxxxxxxxx>
Re: [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
From
: Сергей Маринкевич <s@xxxxxxxxxxxxxx>
Re: [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
From
: Сергей Маринкевич <s@xxxxxxxxxxxxxx>
[PATCH nf-next] netfilter: nf_flow_table_offload: fix potential NULL pointer dereference for dst_cache in handling lwtstate
From
: wenxu@xxxxxxxxx
Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 13/16] audit: track container nesting
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
[PATCH AUTOSEL 5.4 20/73] netfilter: cthelper: add missing attribute validation for cthelper
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 21/73] netfilter: nft_payload: add missing attribute validation for payload csum flags
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 26/73] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 27/73] netfilter: nf_tables: fix infinite loop when expr is not available
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 31/73] netfilter: nft_chain_nat: inet family is missing module ownership
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 4.19 16/37] netfilter: nft_payload: add missing attribute validation for payload csum flags
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 4.19 15/37] netfilter: cthelper: add missing attribute validation for cthelper
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 4.19 17/37] netfilter: nft_tunnel: add missing attribute validation for tunnels
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 4.14 13/28] netfilter: cthelper: add missing attribute validation for cthelper
From
: Sasha Levin <sashal@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
[PATCH AUTOSEL 4.14 14/28] netfilter: nft_payload: add missing attribute validation for payload csum flags
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 4.9 08/15] netfilter: cthelper: add missing attribute validation for cthelper
From
: Sasha Levin <sashal@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
[PATCH AUTOSEL 4.4 06/12] netfilter: cthelper: add missing attribute validation for cthelper
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 22/73] netfilter: nft_tunnel: add missing attribute validation for tunnels
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next] netfilter: nf_tables: add nft_set_elem_expr_destroy() and use it
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH v2] ipvs: optimize tunnel dumps for icmp errors
From
: Julian Anastasov <ja@xxxxxx>
Re: compilation of netfilter missing libnftnl functions - undefined reference - (RASPBERRY pi 3B)
From
: Phil Sutter <phil@xxxxxx>
[PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
From
: wenxu@xxxxxxxxx
Re: [bug report] netfilter: nf_tables: add elements with stateful expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[bug report] netfilter: nf_tables: add elements with stateful expressions
From
: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
[PATCH net-next] flow_offload: add TC_SETP_FT type in flow_indr_block_call
From
: wenxu@xxxxxxxxx
Re: [PATCH 00/29] Netfilter updates for net-next
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH 00/29] Netfilter updates for net-next
From
: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
[PATCH 01/29] netfilter: flowtable: Use nf_flow_offload_tuple for stats as well
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 05/29] netfilter: nf_tables: make all set structs const
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 06/29] netfilter: cleanup unused macro
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 09/29] netfilter: bitwise: use more descriptive variable-names.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 07/29] netfilter: nft_set_pipapo: make the symbol 'nft_pipapo_get' static
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 14/29] netfilter: flowtable: add tunnel encap/decap action offload support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 10/29] netfilter: xt_IDLETIMER: clean up some indenting
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 11/29] netfilter: flowtable: add nf_flow_table_block_offload_init()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 13/29] netfilter: flowtable: add tunnel match offload support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 21/29] netfilter: nf_tables: add nft_set_elem_expr_alloc()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 08/29] netfilter: Replace zero-length array with flexible-array member
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 12/29] netfilter: flowtable: add indr block setup support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 22/29] netfilter: nf_tables: statify nft_expr_init()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 20/29] nft_set_pipapo: Prepare for single ranged field usage
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 17/29] nft_set_pipapo: Prepare for vectorised implementation: alignment
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 23/29] netfilter: nf_tables: add elements with stateful expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 25/29] netfilter: nft_lookup: update element stateful expression
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 24/29] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 16/29] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 26/29] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 27/29] netfilter: Rename ingress hook include file
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 28/29] netfilter: Generalize ingress hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 19/29] nft_set_pipapo: Introduce AVX2-based lookup implementation
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 29/29] netfilter: Introduce egress hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 18/29] nft_set_pipapo: Prepare for vectorised implementation: helpers
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 15/29] nft_set_pipapo: Generalise group size for buckets
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 04/29] netfilter: nf_tables: make sets built-in
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 02/29] netfilter: xtables: Add snapshot of hardidletimer target
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 03/29] netfilter: nft_tunnel: add support for geneve opts
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 00/29] Netfilter updates for net-next
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 0/3] Netfilter egress hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next] netfilter: nf_tables: fix double-free on set expression from the error path
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
[PATCH ghak25 v3 2/3] netfilter: add audit table unregister actions
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
[PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
[PATCH ghak25 v3 0/3] Address NETFILTER_CFG issues
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 13/16] audit: track container nesting
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
[PATCH nft] src: support for counter in set definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH libnftnl] set: support for NFTNL_SET_EXPR
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 3/3] netfilter: nf_tables: allow to specify stateful expression in set definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 2/3] netfilter: nf_tables: pass context to nft_set_destroy()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 1/3] netfilter: nf_tables: move nft_expr_clone() to nf_tables_api.c
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 0/3] support for stateful expressions in set definition
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH v2 2/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_tuple_ip{v6}
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
[PATCH v2 1/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_nat_ip{v6}
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_gc
From
: syzbot <syzbot+c1a1fb435465986efe35@xxxxxxxxxxxxxxxxxxxxxxxxx>
compilation of netfilter missing libnftnl functions - undefined reference - (RASPBERRY pi 3B)
From
: "MELCHOR PENA, Bernardo Santiago" <B.S.Melchor-Pena@xxxxxxxx>
[PATCH] netfilter: nft_masq: add range specified flag setting
From
: Sergey Marinkevich <s@xxxxxxxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_ip_ext_cleanup
From
: syzbot <syzbot+6491ea8f6dddbf04930e@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_ext_cleanup
From
: syzbot <syzbot+c400f7b04cadb5df6ea7@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 2/5] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 1/1] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 4/4] netfilter: nf_flow_table: reload iph in nf_flow_tuple_ip
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
[PATCH 3/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_tuple_ipv6
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
[PATCH 2/4] netfilter: nf_flow_table: reload iph in nf_flow_nat_ip
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
[PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Re: [PATCH nf-next v2 0/6] nft_set_pipapo: Performance improvements: Season 1
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [iptables PATCH] nft: cache: Fix iptables-save segfault under stress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH v2] ipvs: optimize tunnel dumps for icmp errors
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Re: [PATCH] ipvs: optimize tunnel dumps for icmp errors
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Re: [PATCH] ipvs: optimize tunnel dumps for icmp errors
From
: Julian Anastasov <ja@xxxxxx>
[PATCH] ipvs: optimize tunnel dumps for icmp errors
From
: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_port_ext_cleanup
From
: syzbot <syzbot+7b6206fb525c1f5ec3f8@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: BUG: corrupted list in __nf_tables_abort
From
: Florian Westphal <fw@xxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_port_destroy
From
: syzbot <syzbot+b96275fd6ad891076ced@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: BUG: corrupted list in __nf_tables_abort
From
: syzbot <syzbot+437bf61d165c87bd40fb@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_destroy
From
: syzbot <syzbot+a85062dec5d65617cc1c@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 13/16] audit: track container nesting
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
[iptables PATCH] nft: cache: Fix iptables-save segfault under stress
From
: Phil Sutter <phil@xxxxxx>
[iptables PATCH] nft: cache: Fix for unused variable warnings
From
: Phil Sutter <phil@xxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 13/16] audit: track container nesting
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Steve Grubb <sgrubb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Paul Moore <paul@xxxxxxxxxxxxxx>
Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: WARNING in geneve_exit_batch_net (2)
From
: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
linux-next: manual merge of the netfilter-next tree with the net-next tree
From
: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
Re: WARNING in geneve_exit_batch_net (2)
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH 2/3 V2] inet: Use fallthrough;
From
: David Miller <davem@xxxxxxxxxxxxx>
[PATCH 2/3 V2] inet: Use fallthrough;
From
: Joe Perches <joe@xxxxxxxxxxx>
Re: [PATCH 2/3] net: [IPv4/IPv6]: Use fallthrough;
From
: David Miller <davem@xxxxxxxxxxxxx>
Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 13/16] audit: track container nesting
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
From
: Richard Guy Briggs <rgb@xxxxxxxxxx>
[PATCH 2/3] net: [IPv4/IPv6]: Use fallthrough;
From
: Joe Perches <joe@xxxxxxxxxxx>
[PATCH 0/3] treewide: Convert unscriptable /* fallthrough */ comments to fallthrough;
From
: Joe Perches <joe@xxxxxxxxxxx>
rebasing nf-next...
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: WARNING in geneve_exit_batch_net (2)
From
: syzbot <syzbot+68a8ed58e3d17c700de5@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nf-next 1/1] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Lukas Wunner <lukas@xxxxxxxxx>
[PATCH nft 2/2] src: support for restoring element counters
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 1/2] netlink: remove unused parameter from netlink_gen_stmt_stateful()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH 5/5] netfilter: nft_lookup: update element stateful expression
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 4/5] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 3/5] netfilter: nf_tables: add elements with stateful expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 1/5] netfilter: nf_tables: add nft_set_elem_expr_alloc()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 2/5] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 0/5 nf-next,v2] enhance stateful expression support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH libnftnl] set_elem: missing set and build for NFTNL_SET_ELEM_EXPR
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 4/4] netfilter: nft_lookup: update element stateful expression
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 3/4] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 2/4] netfilter: nf_tables: add elements with stateful expressions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 1/4] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf-next 0/4] enhance stateful expression support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft] src: Support netdev egress hook
From
: Lukas Wunner <lukas@xxxxxxxxx>
[PATCH nf-next 2/3] netfilter: Generalize ingress hook
From
: Lukas Wunner <lukas@xxxxxxxxx>
[PATCH nf-next 3/3] netfilter: Introduce egress hook
From
: Lukas Wunner <lukas@xxxxxxxxx>
[PATCH nf-next 1/3] netfilter: Rename ingress hook include file
From
: Lukas Wunner <lukas@xxxxxxxxx>
[PATCH nf-next 0/3] Netfilter egress hook
From
: Lukas Wunner <lukas@xxxxxxxxx>
[PATCH 4/8] netfilter: Add missing annotation for ctnetlink_parse_nat_setup()
From
: Jules Irenge <jbi.octave@xxxxxxxxx>
[PATCH 5/8] netfilter: conntrack: Add missing annotations for nf_conntrack_all_lock() and nf_conntrack_all_unlock()
From
: Jules Irenge <jbi.octave@xxxxxxxxx>
Re: [nft PATCH] tests/py: Move tcpopt.t to any/ directory
From
: Florian Westphal <fw@xxxxxxxxx>
[nft PATCH] tests/py: Move tcpopt.t to any/ directory
From
: Phil Sutter <phil@xxxxxx>
Re: Restoring rulesets containing dynamic sets with counters
From
: Frank Myhr <fmyhr@xxxxxxxxxxx>
Re: Restoring rulesets containing dynamic sets with counters
From
: Frank Myhr <fmyhr@xxxxxxxxxxx>
Re: [PATCH nft 0/4] Help and getopt improvements
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: Restoring rulesets containing dynamic sets with counters
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [nft PATCH v2 1/2] parser_json: Support ranges in concat expressions
From
: Eric Garver <eric@xxxxxxxxxxx>
Re: [PATCH nf-next V2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nft] parser_bison: fix rshift statement expression.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft] parser_bison: fix rshift statement expression.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [PATCH nf-next V2] netfilter: ctnetlink: add kernel side filtering for dump
From
: Florent Fourcot <florent.fourcot@xxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
Re: shift_stmt_expr grammar question
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
shift_stmt_expr grammar question
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nf-next v2 5/6] nft_set_pipapo: Introduce AVX2-based lookup implementation
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next v2 6/6] nft_set_pipapo: Prepare for single ranged field usage
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next v2 4/6] nft_set_pipapo: Prepare for vectorised implementation: helpers
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next v2 3/6] nft_set_pipapo: Prepare for vectorised implementation: alignment
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next v2 2/6] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next v2 1/6] nft_set_pipapo: Generalise group size for buckets
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf-next v2 0/6] nft_set_pipapo: Performance improvements: Season 1
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [nft PATCH v2 2/2] tests/py: Add tests involving concatenated ranges
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH 00/11] Netfilter fixes for net
From
: David Miller <davem@xxxxxxxxxxxxx>
[nft PATCH v2 1/2] parser_json: Support ranges in concat expressions
From
: Phil Sutter <phil@xxxxxx>
[nft PATCH v2 2/2] tests/py: Add tests involving concatenated ranges
From
: Phil Sutter <phil@xxxxxx>
[nft PATCH] tests/py: Fix JSON output for changed timezone
From
: Phil Sutter <phil@xxxxxx>
[PATCH 05/11] netfilter: nf_tables: free flowtable hooks on hook register error
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 01/11] netfilter: nf_conntrack: ct_cpu_seq_next should increase position index
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 06/11] netfilter: cthelper: add missing attribute validation for cthelper
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 04/11] netfilter: x_tables: xt_mttg_seq_next should increase position index
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 07/11] netfilter: nft_payload: add missing attribute validation for payload csum flags
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 09/11] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 08/11] netfilter: nft_tunnel: add missing attribute validation for tunnels
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 11/11] netfilter: nft_chain_nat: inet family is missing module ownership
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 10/11] netfilter: nf_tables: fix infinite loop when expr is not available
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 03/11] netfilter: xt_recent: recent_seq_next should increase position index
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 02/11] netfilter: synproxy: synproxy_cpu_seq_next should increase position index
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 00/11] Netfilter fixes for net
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf] netfilter: nft_chain_nat: inet family is missing module ownership
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH nf] netfilter: nf_tables: missing module ownership in chain type definitions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf] netfilter: nf_tables: missing module ownership in chain type definitions
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf] netfilter: nft_chain_nat: inet family is missing module ownership
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [nft PATCH] parser_json: Support ranges in concat expressions
From
: Phil Sutter <phil@xxxxxx>
Re: [nft PATCH] parser_json: Support ranges in concat expressions
From
: Eric Garver <eric@xxxxxxxxxxx>
[nft PATCH] parser_json: Support ranges in concat expressions
From
: Phil Sutter <phil@xxxxxx>
Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nft] tests: Introduce test for insertion of overlapping and non-overlapping ranges
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf 3/4] nft_set_rbtree: Introduce and use nft_rbtree_interval_start()
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf 2/4] nft_set_pipapo: Separate partial and complete overlap cases on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf 1/4] nf_tables: Allow set back-ends to report partial overlaps on insertion
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH nf 0/4] nftables: Consistently report partial and entire set overlaps
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 24/58] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.4 25/58] netfilter: ipset: Fix forceadd evaluation path
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.5 29/67] netfilter: ipset: Fix forceadd evaluation path
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH AUTOSEL 5.5 28/67] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
From
: Sasha Levin <sashal@xxxxxxxxxx>
[PATCH nft 4/4] main: use one data-structure to initialize getopt_long(3) arguments and help.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 1/4] main: include '-d' in help.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 0/4] Help and getopt improvements
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 2/4] main: include '--reversedns' in help.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 3/4] main: interpolate default include path into help format-string.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf] netfilter: nf_tables: fix infinite loop when expr is not available
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nft] main: add more information to `nft -V`.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nf] netfilter: nf_tables: fix infinite loop when expr is not available
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
From
: wenxu <wenxu@xxxxxxxxx>
Re: [PATCH nf-next,RFC 0/5] Netfilter egress hook
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[iptables PATCH v2] connlabel: Allow numeric labels even if connlabel.conf exists
From
: Phil Sutter <phil@xxxxxx>
Re: [PATCH nf-next,RFC 0/5] Netfilter egress hook
From
: Lukas Wunner <lukas@xxxxxxxxx>
Re: [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
From
: Phil Sutter <phil@xxxxxx>
Re: [PATCH nft] main: add more information to `nft -V`.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
From
: Florian Westphal <fw@xxxxxxxxx>
[iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
From
: Phil Sutter <phil@xxxxxx>
Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
From
: Phil Sutter <phil@xxxxxx>
Re: [PATCH netfilter 0/3] netfilter: add missing attribute validation
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH v2 0/4] netfilter: seq_file .next functions should increase position index
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft] main: add more information to `nft -V`.
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft] src: support for offload chain flags
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
From
: wenxu <wenxu@xxxxxxxxx>
[PATCH libnftnl] chain: add NFTNL_CHAIN_FLAGS
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft v3 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 11/18] evaluate: don't clobber binop bitmask lengths.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 17/18] tests: shell: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 12/18] netlink_delinearize: fix typo.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 16/18] tests: shell: remove stray debug flag.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 15/18] netlink_delinearize: add postprocessing for payload binops.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 09/18] src: support (de)linearization of bitwise op's with variable right operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 04/18] evaluate: convert the byte-order of payload statement arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 08/18] include: update nf_tables.h.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 07/18] src: fix leaks.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 03/18] evaluate: don't evaluate payloads twice.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 06/18] netlink_delinearize: set shift RHS byte-order.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 02/18] evaluate: simplify calculation of payload size.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 01/18] evaluate: add separate variables for lshift and xor binops.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
Re: [PATCH nft v2 11/18] netlink_linearize: round binop bitmask length up.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: + seq_read-info-message-about-buggy-next-functions.patch added to -mm tree
From
: Vasily Averin <vvs@xxxxxxxxxxxxx>
[PATCH netfilter 1/3] netfilter: add missing attribute validation for cthelper
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
[PATCH netfilter 3/3] netfilter: nf_tables: add missing attribute validation for tunnels
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
[PATCH netfilter 2/3] netfilter: add missing attribute validation for payload csum flags
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
[PATCH netfilter 0/3] netfilter: add missing attribute validation
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
Re: [iptables PATCH 4/4] nft: cache: Review flush_cache()
From
: Phil Sutter <phil@xxxxxx>
Re: [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
From
: Phil Sutter <phil@xxxxxx>
Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
From
: Phil Sutter <phil@xxxxxx>
linux-next: manual merge of the netfilter-next tree with Linus' tree
From
: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
[PATCH nft v2 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 12/18] netlink_delinearize: fix typo.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 17/18] tests: shell: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 16/18] tests: shell: remove stray debug flag.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 18/18] tests: py: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 11/18] netlink_linearize: round binop bitmask length up.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 15/18] netlink_delinearize: add postprocessing for payload binops.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 04/18] evaluate: convert the byte-order of payload statement arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 09/18] src: support (de)linearization of bitwise op's with variable right operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 07/18] src: fix leaks.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 08/18] include: update nf_tables.h.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 06/18] netlink_delinearize: set shift RHS byte-order.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 03/18] evaluate: don't evaluate payloads twice.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 00/18] Support for boolean binops with variable RHS operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 01/18] evaluate: add separate variables for lshift and xor binops.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft v2 02/18] evaluate: simplify calculation of payload size.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Jakub Kicinski <kuba@xxxxxxxxxx>
Re: [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [iptables PATCH 4/4] nft: cache: Review flush_cache()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
memory leak in nf_tables_parse_netdev_hooks (2)
From
: syzbot <syzbot+a2ff6fa45162a5ed4dd3@xxxxxxxxxxxxxxxxxxxxxxxxx>
[iptables PATCH 4/4] nft: cache: Review flush_cache()
From
: Phil Sutter <phil@xxxxxx>
[iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
From
: Phil Sutter <phil@xxxxxx>
[iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
From
: Phil Sutter <phil@xxxxxx>
[iptables PATCH 3/4] nft: cache: Simplify chain list allocation
From
: Phil Sutter <phil@xxxxxx>
[iptables PATCH 0/4] Fix for iptables-nft-restore under pressure
From
: Phil Sutter <phil@xxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Edward Cree <ecree@xxxxxxxxxxxxxx>
Re: [PATCH nft 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Jiri Pirko <jiri@xxxxxxxxxxx>
Re: [PATCH libnftnl 0/3] bitwise: support for passing mask and xor via registers
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH][next] netfilter: Replace zero-length array with flexible-array member
From
: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
Re: [PATCH] netfilter: ipt_CLUSTERIP: Pass lockdep expression to RCU lists
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] netfilter: clean up some indenting
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf-next 0/2] netfilter: bitwise: support variable RHS operands
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH][next] netfilter: Replace zero-length array with flexible-array member
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
general protection fault in gc_worker
From
: syzbot <syzbot+2a2fe383b2ce0e44b6ea@xxxxxxxxxxxxxxxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Jiri Pirko <jiri@xxxxxxxxxxx>
Re: [PATCH net] netlink: Use netlink header as base to calculate bad attribute offset
From
: David Miller <davem@xxxxxxxxxxxxx>
0x14: COVID-19 update, postponement of Netdev conf 0x14
From
: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 16/18] tests: shell: remove stray debug flag.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 12/18] netlink_delinearize: fix typo.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 15/18] netlink_delinearize: add postprocessing for payload binops.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 17/18] tests: shell: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 18/18] tests: py: add variable binop RHS tests.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 11/18] netlink_linearize: round binop bitmask length up.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 04/18] evaluate: convert the byte-order of payload statement arguments.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 06/18] netlink_delinearize: set shift RHS byte-order.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 03/18] evaluate: don't evaluate payloads twice.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 02/18] evaluate: simplify calculation of payload size.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 01/18] evaluate: add separate variables for lshift and xor binops.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 09/18] src: support (de)linearization of bitwise op's with variable right operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 00/18] Support for boolean binops with variable RHS operands.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 07/18] src: fix leaks.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
[PATCH nft 08/18] include: update nf_tables.h.
From
: Jeremy Sowden <jeremy@xxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: Ipv6 address in concatenation
From
: Florian Westphal <fw@xxxxxxxxx>
Re: Ipv6 address in concatenation
From
: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
Re: Ipv6 address in concatenation
From
: Florian Westphal <fw@xxxxxxxxx>
Re: Ipv6 address in concatenation
From
: Florian Westphal <fw@xxxxxxxxx>
Re: Ipv6 address in concatenation
From
: Phil Sutter <phil@xxxxxx>
Ipv6 address in concatenation
From
: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
Re: [PATCH 0/6] Netfilter fixes for net
From
: David Miller <davem@xxxxxxxxxxxxx>
[PATCH 3/6] selftests: nft_concat_range: Move option for 'list ruleset' before command
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 6/6] netfilter: xt_hashlimit: unregister proc file before releasing mutex
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 4/6] nft_set_pipapo: Actually fetch key data in nft_pipapo_remove()
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 5/6] selftests: nft_concat_range: Add test for reported add/flush/add issue
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 1/6] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 2/6] netfilter: ipset: Fix forceadd evaluation path
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH 0/6] Netfilter fixes for net
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH net] netlink: Use netlink header as base to calculate bad attribute offset
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH 0/2] ipset patches for nf
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nft 1/2] expressions: concat: add typeof support
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[PATCH nft 2/2] tests: update nat_addr_port with typeof+concat maps
From
: Florian Westphal <fw@xxxxxxxxx>
[PATCH nft 1/2] expressions: concat: add typeof support
From
: Florian Westphal <fw@xxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Null Pointer Dereference in nf_nat
From
: Alex Buie <alex.buie@xxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
From
: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
From
: Stefano Brivio <sbrivio@xxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]