Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_ext_cleanup
- From: syzbot <syzbot+c400f7b04cadb5df6ea7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/5] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] netfilter: nf_flow_table: reload iph in nf_flow_tuple_ip
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 3/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_tuple_ipv6
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 2/4] netfilter: nf_flow_table: reload iph in nf_flow_nat_ip
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/6] nft_set_pipapo: Performance improvements: Season 1
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: cache: Fix iptables-save segfault under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] ipvs: optimize tunnel dumps for icmp errors
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] ipvs: optimize tunnel dumps for icmp errors
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] ipvs: optimize tunnel dumps for icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH] ipvs: optimize tunnel dumps for icmp errors
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_port_ext_cleanup
- From: syzbot <syzbot+7b6206fb525c1f5ec3f8@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: BUG: corrupted list in __nf_tables_abort
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_port_destroy
- From: syzbot <syzbot+b96275fd6ad891076ced@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: BUG: corrupted list in __nf_tables_abort
- From: syzbot <syzbot+437bf61d165c87bd40fb@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_destroy
- From: syzbot <syzbot+a85062dec5d65617cc1c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [iptables PATCH] nft: cache: Fix iptables-save segfault under stress
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] nft: cache: Fix for unused variable warnings
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: WARNING in geneve_exit_batch_net (2)
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the net-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: WARNING in geneve_exit_batch_net (2)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/3 V2] inet: Use fallthrough;
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 2/3 V2] inet: Use fallthrough;
- From: Joe Perches <joe@xxxxxxxxxxx>
- Re: [PATCH 2/3] net: [IPv4/IPv6]: Use fallthrough;
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH 2/3] net: [IPv4/IPv6]: Use fallthrough;
- From: Joe Perches <joe@xxxxxxxxxxx>
- [PATCH 0/3] treewide: Convert unscriptable /* fallthrough */ comments to fallthrough;
- From: Joe Perches <joe@xxxxxxxxxxx>
- rebasing nf-next...
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: WARNING in geneve_exit_batch_net (2)
- From: syzbot <syzbot+68a8ed58e3d17c700de5@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nft 2/2] src: support for restoring element counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] netlink: remove unused parameter from netlink_gen_stmt_stateful()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH 5/5] netfilter: nft_lookup: update element stateful expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/5] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/5] netfilter: nf_tables: add elements with stateful expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/5] netfilter: nf_tables: add nft_set_elem_expr_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/5] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5 nf-next,v2] enhance stateful expression support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] set_elem: missing set and build for NFTNL_SET_ELEM_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: nft_lookup: update element stateful expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/4] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/4] netfilter: nf_tables: add elements with stateful expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/4] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/4] enhance stateful expression support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: Support netdev egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: Generalize ingress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: Rename ingress hook include file
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 0/3] Netfilter egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH 4/8] netfilter: Add missing annotation for ctnetlink_parse_nat_setup()
- From: Jules Irenge <jbi.octave@xxxxxxxxx>
- [PATCH 5/8] netfilter: conntrack: Add missing annotations for nf_conntrack_all_lock() and nf_conntrack_all_unlock()
- From: Jules Irenge <jbi.octave@xxxxxxxxx>
- Re: [nft PATCH] tests/py: Move tcpopt.t to any/ directory
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] tests/py: Move tcpopt.t to any/ directory
- From: Phil Sutter <phil@xxxxxx>
- Re: Restoring rulesets containing dynamic sets with counters
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- Re: Restoring rulesets containing dynamic sets with counters
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- Re: [PATCH nft 0/4] Help and getopt improvements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Restoring rulesets containing dynamic sets with counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 1/2] parser_json: Support ranges in concat expressions
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nf-next V2] netfilter: ctnetlink: add kernel side filtering for dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: fix rshift statement expression.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: fix rshift statement expression.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next V2] netfilter: ctnetlink: add kernel side filtering for dump
- From: Florent Fourcot <florent.fourcot@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: shift_stmt_expr grammar question
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- shift_stmt_expr grammar question
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 5/6] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 6/6] nft_set_pipapo: Prepare for single ranged field usage
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 4/6] nft_set_pipapo: Prepare for vectorised implementation: helpers
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 3/6] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 2/6] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 1/6] nft_set_pipapo: Generalise group size for buckets
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 0/6] nft_set_pipapo: Performance improvements: Season 1
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [nft PATCH v2 2/2] tests/py: Add tests involving concatenated ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH 00/11] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [nft PATCH v2 1/2] parser_json: Support ranges in concat expressions
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 2/2] tests/py: Add tests involving concatenated ranges
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] tests/py: Fix JSON output for changed timezone
- From: Phil Sutter <phil@xxxxxx>
- [PATCH 05/11] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/11] netfilter: nf_conntrack: ct_cpu_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/11] netfilter: cthelper: add missing attribute validation for cthelper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/11] netfilter: x_tables: xt_mttg_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/11] netfilter: nft_payload: add missing attribute validation for payload csum flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/11] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/11] netfilter: nft_tunnel: add missing attribute validation for tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/11] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/11] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/11] netfilter: xt_recent: recent_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/11] netfilter: synproxy: synproxy_cpu_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/11] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: missing module ownership in chain type definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: missing module ownership in chain type definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_json: Support ranges in concat expressions
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] parser_json: Support ranges in concat expressions
- From: Eric Garver <eric@xxxxxxxxxxx>
- [nft PATCH] parser_json: Support ranges in concat expressions
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nft] tests: Introduce test for insertion of overlapping and non-overlapping ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 3/4] nft_set_rbtree: Introduce and use nft_rbtree_interval_start()
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 2/4] nft_set_pipapo: Separate partial and complete overlap cases on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 1/4] nf_tables: Allow set back-ends to report partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 0/4] nftables: Consistently report partial and entire set overlaps
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 24/58] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 25/58] netfilter: ipset: Fix forceadd evaluation path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 29/67] netfilter: ipset: Fix forceadd evaluation path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 28/67] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nft 4/4] main: use one data-structure to initialize getopt_long(3) arguments and help.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 1/4] main: include '-d' in help.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 0/4] Help and getopt improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 2/4] main: include '--reversedns' in help.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 3/4] main: interpolate default include path into help format-string.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] main: add more information to `nft -V`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next,RFC 0/5] Netfilter egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH v2] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next,RFC 0/5] Netfilter egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] main: add more information to `nft -V`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH netfilter 0/3] netfilter: add missing attribute validation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 0/4] netfilter: seq_file .next functions should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] main: add more information to `nft -V`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: support for offload chain flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH libnftnl] chain: add NFTNL_CHAIN_FLAGS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v3 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 11/18] evaluate: don't clobber binop bitmask lengths.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 17/18] tests: shell: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 12/18] netlink_delinearize: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 16/18] tests: shell: remove stray debug flag.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 15/18] netlink_delinearize: add postprocessing for payload binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 09/18] src: support (de)linearization of bitwise op's with variable right operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 04/18] evaluate: convert the byte-order of payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 08/18] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 07/18] src: fix leaks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 03/18] evaluate: don't evaluate payloads twice.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 06/18] netlink_delinearize: set shift RHS byte-order.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 02/18] evaluate: simplify calculation of payload size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 01/18] evaluate: add separate variables for lshift and xor binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 11/18] netlink_linearize: round binop bitmask length up.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: + seq_read-info-message-about-buggy-next-functions.patch added to -mm tree
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH netfilter 1/3] netfilter: add missing attribute validation for cthelper
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH netfilter 3/3] netfilter: nf_tables: add missing attribute validation for tunnels
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH netfilter 2/3] netfilter: add missing attribute validation for payload csum flags
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH netfilter 0/3] netfilter: add missing attribute validation
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [iptables PATCH 4/4] nft: cache: Review flush_cache()
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Phil Sutter <phil@xxxxxx>
- linux-next: manual merge of the netfilter-next tree with Linus' tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nft v2 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 12/18] netlink_delinearize: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 17/18] tests: shell: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 16/18] tests: shell: remove stray debug flag.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 11/18] netlink_linearize: round binop bitmask length up.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 15/18] netlink_delinearize: add postprocessing for payload binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 04/18] evaluate: convert the byte-order of payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 09/18] src: support (de)linearization of bitwise op's with variable right operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 07/18] src: fix leaks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 08/18] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 06/18] netlink_delinearize: set shift RHS byte-order.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 03/18] evaluate: don't evaluate payloads twice.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 01/18] evaluate: add separate variables for lshift and xor binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 02/18] evaluate: simplify calculation of payload size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 4/4] nft: cache: Review flush_cache()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- memory leak in nf_tables_parse_netdev_hooks (2)
- From: syzbot <syzbot+a2ff6fa45162a5ed4dd3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [iptables PATCH 4/4] nft: cache: Review flush_cache()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/4] nft: cache: Simplify chain list allocation
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/4] Fix for iptables-nft-restore under pressure
- From: Phil Sutter <phil@xxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH nft 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH libnftnl 0/3] bitwise: support for passing mask and xor via registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][next] netfilter: Replace zero-length array with flexible-array member
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipt_CLUSTERIP: Pass lockdep expression to RCU lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: clean up some indenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] netfilter: bitwise: support variable RHS operands
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][next] netfilter: Replace zero-length array with flexible-array member
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- general protection fault in gc_worker
- From: syzbot <syzbot+2a2fe383b2ce0e44b6ea@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH net] netlink: Use netlink header as base to calculate bad attribute offset
- From: David Miller <davem@xxxxxxxxxxxxx>
- 0x14: COVID-19 update, postponement of Netdev conf 0x14
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 16/18] tests: shell: remove stray debug flag.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 12/18] netlink_delinearize: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 15/18] netlink_delinearize: add postprocessing for payload binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 17/18] tests: shell: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 11/18] netlink_linearize: round binop bitmask length up.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 04/18] evaluate: convert the byte-order of payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 06/18] netlink_delinearize: set shift RHS byte-order.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 03/18] evaluate: don't evaluate payloads twice.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 02/18] evaluate: simplify calculation of payload size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 01/18] evaluate: add separate variables for lshift and xor binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 09/18] src: support (de)linearization of bitwise op's with variable right operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 07/18] src: fix leaks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 08/18] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Phil Sutter <phil@xxxxxx>
- Ipv6 address in concatenation
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: [PATCH 0/6] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 3/6] selftests: nft_concat_range: Move option for 'list ruleset' before command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] nft_set_pipapo: Actually fetch key data in nft_pipapo_remove()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] selftests: nft_concat_range: Add test for reported add/flush/add issue
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] netfilter: ipset: Fix forceadd evaluation path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netlink: Use netlink header as base to calculate bad attribute offset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/2] ipset patches for nf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] expressions: concat: add typeof support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] tests: update nat_addr_port with typeof+concat maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] expressions: concat: add typeof support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Null Pointer Dereference in nf_nat
- From: Alex Buie <alex.buie@xxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf] selftests: nft_concat_range: Move option for 'list ruleset' before command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH v2 4/4] xt_mttg_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 3/4] recent_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 2/4] synproxy_cpu_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 1/4] ct_cpu_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 0/4] netfilter: seq_file .next functions should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH] netfilter: clean up some indenting
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- Re: [PATCH nft 0/6] allow s/dnat to map to both addr and port
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/6] allow s/dnat to map to both addr and port
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/6 nft,v2] tests: shell: adjust tests to new nat concatenation syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/6 nft,v2] src: nat concatenation support with anonymous maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft 6/6] tests: nat: add and use maps with both address and service
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 3/3] bitwise: add support for passing mask and xor via registers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 1/3] tests: bitwise: fix error message.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 2/3] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 0/3] bitwise: support for passing mask and xor via registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 7/6] src: nat concatenation support with anonymous maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: bitwise: use more descriptive variable-names.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: bitwise: add support for passing mask and xor values in registers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: bitwise: support variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v5 4/4] netfilter: flowtable: add tunnel encap/decap action offload support
- [PATCH nf-next v5 2/4] netfilter: flowtable: add indr block setup support
- [PATCH nf-next v5 3/4] netfilter: flowtable: add tunnel match offload support
- [PATCH nf-next v5 1/4] netfilter: flowtable: add nf_flow_table_block_offload_init()
- [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- [PATCH libnetfilter_queue v3] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nft 6/6] tests: nat: add and use maps with both address and service
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 5/6] src: allow nat maps containing both ip(6) address and port
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/6] evaluate: add two new helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/6] netlink: handle concatenations on set elements mappings
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/6] evaluate: process concat expressions when used as mapped-to expr
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/6] tests: add initial nat map test
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/6] allow s/dnat to map to both addr and port
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue 1/1] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 5/5] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH 1/3] xtables: Align effect of -4/-6 options with legacy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ulogd: printpkt: always print IPv6 protocol
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nf-next] netfilter: cleanup unused macro
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/2] netfilter: nf_tables: make sets built-in
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 nf-next] netfilter: nft_tunnel: add support for geneve opts
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [nf-next,v4] netfilter: xtables: Add snapshot of hardidletimer target
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtable: Use nf_flow_offload_tuple for stats as well
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 5/5] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 4/5] nft_set_pipapo: Prepare for vectorised implementation: helpers
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 2/5] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 0/5] nft_set_pipapo: Performance improvements: Season 1
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 1/5] nft_set_pipapo: Generalise group size for buckets
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH 2/2] netfilter: Pass lockdep expression to instance_lookup traversal
- From: Amol Grover <frextrite@xxxxxxxxx>
- [PATCH 1/2] netfilter: Pass lockdep expression to __instance_lookup traversal
- From: Amol Grover <frextrite@xxxxxxxxx>
- [PATCH nft] expression: use common code for expr_ops/expr_ops_by_type
- From: Florian Westphal <fw@xxxxxxxxx>
- [ANNOUNCE] ipset 7.6 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- KMSAN: uninit-value in nf_flow_table_offload_setup
- From: syzbot <syzbot+8fbe17d9bdd5c8815211@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/2] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 2/2] netfilter: ipset: Fix forceadd evaluation path
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 0/2] ipset patches for nf
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [iptables PATCH] iptables-test.py: Fix --host mode
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [nft PATCH 3/4] segtree: Fix for potential NULL-pointer deref in ei_insert()
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Phil Sutter <phil@xxxxxx>
- Re: KASAN: slab-out-of-bounds Write in bitmap_ip_del
- From: syzbot <syzbot+24d0577de55b8b8f6975@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/2] parser_json: fix parsing prefix inside concat
- From: Eric Garver <eric@xxxxxxxxxxx>
- [iptables PATCH 3/3] xtables: Review nft_init()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] xtables: Align effect of -4/-6 options with legacy
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/3] xtables: Drop -4 and -6 support from xtables-{save,restore}
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] ulogd: printpkt: always print IPv6 protocol
- From: Andreas Jaggi <andreas.jaggi@xxxxxxxxxxxx>
- [PATCH nf] selftests: nft_concat_range: Move option for 'list ruleset' before command
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 2/2] selftests: nft_concat_range: Add test for reported add/flush/add issue
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 1/2] nft_set_pipapo: Actually fetch key data in nft_pipapo_remove()
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH 2/2] tests: shell: json parsing prefix inside concat
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH 1/2] parser_json: fix parsing prefix inside concat
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH][next] netfilter: Replace zero-length array with flexible-array member
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 0/9] nftables: Set implementation for arbitrary concatenation of ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v4 0/9] nftables: Set implementation for arbitrary concatenation of ranges
- From: Phil Sutter <phil@xxxxxx>
- [PATCH][nf-next] netfilter: cleanup unused macro
- From: Li RongQing <lirongqing@xxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- [PATCH nft 2/2,v2] mnl: do not use expr->identifier to fetch device name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] mnl: do not use expr->identifier to fetch device name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] parser_bison: memleak in device parser
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v5] tests: Introduce test for set with concatenated ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ipmac_ext_cleanup
- From: syzbot <syzbot+33fc3ad6fa11675e1a7e@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft 3/3] src: improve error reporting when remove rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/3] src: improve error reporting when setting policy on non-base chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] mnl: extended error support for create command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [libnftnl PATCH] src: Fix for reading garbage in nftnl_chain getters
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] netfilter: ipt_CLUSTERIP: Pass lockdep expression to RCU lists
- From: Amol Grover <frextrite@xxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ip_ext_cleanup
- From: syzbot <syzbot+b554d01b6c7870b17da2@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ip_destroy
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ip_destroy
- From: syzbot <syzbot+8b5f151de2f35100bbc5@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 0/9] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak25 v2 4/9] audit: record nfcfg params
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak25 v2 7/9] netfilter: ebtables audit table registration
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH 2/9] netfilter: xt_hashlimit: limit the max size of hashtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/9] netfilter: conntrack: remove two args from resolve_clash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/9] netfilter: flowtable: skip offload setup if disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/9] netfilter: conntrack: place confirm-bit setting in a helper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/9] netfilter: nft_set_pipapo: Fix mapping table example in comments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/9] netfilter: conntrack: allow insertion of clashing entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 9/9] netfilter: nft_set_pipapo: Don't abuse unlikely() in pipapo_refill()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/9] netfilter: conntrack: split resolve_clash function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/9] netfilter: xt_hashlimit: reduce hashlimit_mutex scope for htable_put()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] Two non-functional fixes for nft_set_pipapo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] src: add nftnl_*_{get,set}_array()
- From: Phil Sutter <phil@xxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] ebtables: among: Support mixed MAC and MAC/IP entries
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] ebtables: among: Support mixed MAC and MAC/IP entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] src: add nftnl_*_{get,set}_array()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Drop pointless assignment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: combine extended netlink error reporting with mispelling support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 0/1] ipset patch for nf
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Strange nf_conntrack_tcp_timeout_established behavior
- From: FUSTE Emmanuel <emmanuel.fuste@xxxxxxxxxxxxxxx>
- [PATCH nf-next v2 2/2] netfilter: nf_tables: make all set structs const
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 1/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 0/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: initial extended netlink error reporting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH][next] netfilter: ebtables: Replace zero-length array with flexible-array member
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: conntrack: allow insertion of clashing entries
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: conntrack: allow insertion of clashing entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Strange nf_conntrack_tcp_timeout_established behavior
- From: FUSTE Emmanuel <emmanuel.fuste@xxxxxxxxxxxxxxx>
- Re: Proposing to add a structure to UserData
- From: Phil Sutter <phil@xxxxxx>
- Re: Proposing to add a structure to UserData
- From: sbezverk <sbezverk@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nf_tables: make all set structs const
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nf_tables: make all set structs const
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: Proposing to add a structure to UserData
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] nft: Drop pointless assignment
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next 2/2] netfilter: nf_tables: make all set structs const
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: WARNING in nf_tables_table_destroy
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: WARNING in nf_tables_table_destroy
- From: syzbot <syzbot+2a3b1b28cad90c608e20@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH] netfilter: ipset: Pass lockdep expression to RCU lists
- From: Amol Grover <frextrite@xxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- 0x14: Schedule out!
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v4 5/9] nf_tables: Add set type for arbitrary concatenation of ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v4 5/9] nf_tables: Add set type for arbitrary concatenation of ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 5/9] nf_tables: Add set type for arbitrary concatenation of ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v4 5/9] nf_tables: Add set type for arbitrary concatenation of ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.5 126/542] netfilter: flowtable: Fix hardware flush order on nf_flow_table_cleanup
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 125/542] netfilter: flowtable: Fix missing flush hardware on table free
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 220/542] netfilter: nft_tunnel: add the missing ERSPAN_VERSION nla_policy
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 386/542] netfilter: flowtable: restrict flow dissector match on meta ingress device
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH nft v5] tests: Introduce test for set with concatenated ranges
- From: Phil Sutter <phil@xxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- [PATCH AUTOSEL 5.4 193/459] netfilter: nft_tunnel: add the missing ERSPAN_VERSION nla_policy
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH nf-next 0/2] Two non-functional fixes for nft_set_pipapo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_set_pipapo: Don't abuse unlikely() in pipapo_refill()
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 0/2] Two non-functional fixes for nft_set_pipapo
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nft_set_pipapo: Fix mapping table example in comments
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 100/252] netfilter: nft_tunnel: add the missing ERSPAN_VERSION nla_policy
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nft v5] tests: Introduce test for set with concatenated ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [iptables PATCH] xtables-translate: Fix for iface++
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] ebtables: among: Support mixed MAC and MAC/IP entries
- From: Phil Sutter <phil@xxxxxx>
- Thank you for your fundamental work!
- From: Max Mehl <max.mehl@xxxxxxxx>
- Re: [iptables PATCH] xtables-translate: Fix for iface++
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 net 0/5] icmp: account for NAT when sending icmps from ndo layer
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak25 v2 8/9] netfilter: add audit operation field
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Proposing to add a structure to UserData
- From: sbezverk <sbezverk@xxxxxxxxx>
- [iptables PATCH] xtables-translate: Fix for iface++
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak25 v2 8/9] netfilter: add audit operation field
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] scanner: use list_is_first() from scanner_pop_indesc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak25 v2 8/9] netfilter: add audit operation field
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft] src: maps: update data expression dtype based on set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: maps: update data expression dtype based on set
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] tests: shell: validate error reporting with include and glob
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: [PATCH nft include v2 4/7] scanner: remove parser_state->indescs static array
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 1/7] tests: shell: add test for glob includes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/4] glob and maximum number of includes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] tests: shell: Fix skip checks with --host mode
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] xtables-restore: fix for --noflush and empty lines
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- [PATCH nft 4/4] scanner: multi-level input file stack for glob
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/4] scanner: call scanner_push_indesc() after scanner_push_file()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/4] scanner: add indesc_file_alloc() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/4] scanner: call scanner_push_file() after scanner_push_file()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/4] glob and maximum number of includes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v4 net 0/5] icmp: account for NAT when sending icmps from ndo layer
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [iptables PATCH] xtables-restore: fix for --noflush and empty lines
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v3 net 0/9] icmp: account for NAT when sending icmps from ndo layer
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: [iptables PATCH v2] xtables-translate: Fix for interface name corner-cases
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/4] netfilter: nft_tunnel: support tunnel match expr offload
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nft include v2 7/7] scanner: remove parser_state->indesc_idx
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 6/7] scanner: fix indesc_list stack to be in the correct order
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 4/7] scanner: remove parser_state->indescs static array
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 4/7] scanner: remove parser_state->indescs static array
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: WARNING: proc registration bug in hashlimit_mt_check_common
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nft include v2 3/7] scanner: move indesc list append in scanner_push_indesc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 2/7] scanner: move the file descriptor to be in the input_descriptor structure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 6/7] scanner: fix indesc_list stack to be in the correct order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft include v2 7/7] scanner: remove parser_state->indesc_idx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak25 v2 1/9] netfilter: normalize x_table function declarations
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- WARNING: proc registration bug in hashlimit_mt_check_common
- From: syzbot <syzbot+d195fd3b9a364ddd6731@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: Adding NAT64 to Netfilter
- From: Alberto Leiva <ydahhrk@xxxxxxxxx>
- Re: [PATCH nft v4 4/4] tests: Introduce test for set with concatenated ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft v4 4/4] tests: Introduce test for set with concatenated ranges
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v4 4/4] tests: Introduce test for set with concatenated ranges
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH next] nf_tables: make the symbol 'nft_pipapo_get' static
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v4 5/9] nf_tables: Add set type for arbitrary concatenation of ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft v4 3/4] src: Add support for concatenated set ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft v4 4/4] tests: Introduce test for set with concatenated ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft v4 3/4] src: Add support for concatenated set ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH v2 net 0/5] icmp: account for NAT when sending icmps from ndo layer
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: [PATCH net 3/5] sunvnet: use icmp_ndo_send helper
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- Re: [PATCH net 1/5] icmp: introduce helper for NAT'd source address in ndo context
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [iptables PATCH v2] xtables-translate: Fix for interface name corner-cases
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 1/5] icmp: introduce helper for NAT'd source address in ndo context
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 3/5] sunvnet: use icmp_ndo_send helper
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [iptables PATCH] xtables-translate: Fix for interface name corner-cases
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 2/2] scanner: Extend asteriskstring definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 1/2] doc: nft.8: Mention wildcard interface matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 2/2] scanner: Extend asteriskstring definition
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 1/2] doc: nft.8: Mention wildcard interface matching
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 2/2] scanner: Extend asteriskstring definition
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft include v2 7/7] scanner: remove parser_state->indesc_idx
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 5/7] scanner: correctly compute include depth
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 6/7] scanner: fix indesc_list stack to be in the correct order
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 4/7] scanner: remove parser_state->indescs static array
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 0/7] Improve include behaviour
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 3/7] scanner: move indesc list append in scanner_push_indesc
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 1/7] tests: shell: add test for glob includes
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft include v2 2/7] scanner: move the file descriptor to be in the input_descriptor structure
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH next] nf_tables: make the symbol 'nft_pipapo_get' static
- From: Chen Wandun <chenwandun@xxxxxxxxxx>
- [PATCHv2 nf-next] netfilter: nft_tunnel: add support for geneve opts
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [nft PATCH 2/2] scanner: Extend asteriskstring definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/5] xfrm: interface: use icmp_ndo_send helper
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH net 4/5] wireguard: use icmp_ndo_send helper
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH net 3/5] sunvnet: use icmp_ndo_send helper
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH net 2/5] gtp: use icmp_ndo_send helper
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH net 1/5] icmp: introduce helper for NAT'd source address in ndo context
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [nft PATCH 2/2] scanner: Extend asteriskstring definition
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH 2/2] scanner: Extend asteriskstring definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/3] scanner: improving include handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 3/3] scanner: remove indescs and indescs_idx attributes from the parser, and directly use indesc_list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] scanner: correctly compute include depth
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/3] scanner: move the file descriptor to be in the input_descriptor structure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: compute mnemonic port name much easier
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4 0/6] Remaining bitwise-shift-related changes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] doc: nft.8: Describe element commands in their own section
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf v2 1/3] xt_hashlimit: avoid OOM for user-controlled vmalloc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf v2 3/3] xt_hashlimit: limit the max size of hashtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf v2 2/3] xt_hashlimit: reduce hashlimit_mutex scope for htable_put()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: compute mnemonic port name much easier
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [nft PATCH 0/4] Extend testsuites to run against installed binaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 5/9] nf_tables: Add set type for arbitrary concatenation of ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: flowtable: always init block_offload struct
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4 3/4] src: Add support for concatenated set ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4 4/4] tests: Introduce test for set with concatenated ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4 3/4] src: Add support for concatenated set ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4 2/4] src: Add support for NFTNL_SET_DESC_CONCAT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4 1/4] include: resync nf_tables.h cache copy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] doc: nft.8: Describe element commands in their own section
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] xtables-translate: Fix for interface name corner-cases
- From: Phil Sutter <phil@xxxxxx>
- Re: How to continue to use Maxmind geoip csv in xtables-addons 3.8+
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [nft PATCH 2/2] scanner: Extend asteriskstring definition
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/2] doc: nft.8: Mention wildcard interface matching
- From: Phil Sutter <phil@xxxxxx>
- How to continue to use Maxmind geoip csv in xtables-addons 3.8+
- From: jean-christophe manciot <actionmystique@xxxxxxxxx>
- [PATCH] [nf-next,v4] netfilter: xtables: Add snapshot of hardidletimer target
- From: Manoj Basapathi <manojbm@xxxxxxxxxxxxxx>
- Re: [PATCH nft v4 4/4] tests: Introduce test for set with concatenated ranges
- From: Phil Sutter <phil@xxxxxx>
- Re: Xtalbes -> Xtables ?
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Xtalbes -> Xtables ?
- From: Franta Hanzlík <franta@xxxxxxxxxxx>
- [nft PATCH 3/4] tests: monitor: Support testing host's nft binary
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/4] tests: json_echo: Support testing host binaries
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 4/4] tests: py: Support testing host binaries
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/4] tests: json_echo: Fix for Python3
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/4] Extend testsuites to run against installed binaries
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 11/16] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 04/16] audit: convert to contid list to check for orch/engine ownership
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH v2] Documentation: changes.rst: update several outdated project URLs
- From: Jonathan Corbet <corbet@xxxxxxx>
- Re: masquerade
- From: Florian Westphal <fw@xxxxxxxxx>
- masquerade
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: [PATCH libnftnl v4 0/3] Attributes for concatenated ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/3] scanner: remove indescs and indescs_idx attributes from the parser, and directly use indesc_list
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft 2/3] scanner: correctly compute include depth
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft 1/3] scanner: move the file descriptor to be in the input_descriptor structure
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- [PATCH nft 0/3] scanner: improving include handling
- From: Laurent Fasnacht <fasnacht@xxxxxxxxxxxxx>
- Re: NFT - delete rules per interface
- From: Daniel <tech@xxxxxxxxxx>
- Re: NFT - delete rules per interface
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 11/16] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 05/16] audit: log drop of contid on exit of last task
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 04/16] audit: convert to contid list to check for orch/engine ownership
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]