Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH] netfilter: bridge: drop a broken include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] extensions: fix iptables-{nft,translate} with conntrack EXPECTED
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Fix add_bitwise_u16() on Big Endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] nft: Fix add_bitwise_u16() on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] src: meter: avoid double-space in list ruleset output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] src: Enable doxygen to generate Function Documentation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: allow lookups in dynamic sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] src: Enable doxygen to generate Function Documentation
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [BUG] nft: "XT target TCPMSS not found" when TCPMSS clamp to PMTU rule is added for *both* ip and ip6
- From: "Timo Sigurdsson" <public_timo.s@xxxxxxxxxxxxxx>
- netfilter.org HTTPS certificate expired today (Sept 19)
- From: Dan Williams <dcbw@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: allow lookups in dynamic sets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Contributing to the Netfilter Project.
- From: Florian Westphal <fw@xxxxxxxxx>
- Contributing to the Netfilter Project.
- From: Wambui Karuga <wambui.dev@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: meter: avoid double-space in list ruleset output
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v6 0/8] netfilter: nf_tables_offload: support tunnel offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH ghak90 V7 21/21] audit: add proc interface for capcontid
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 20/21] audit: add capcontid to set contid outside init_user_ns
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 19/21] audit: check cont depth
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 18/21] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 17/21] audit: add support for loginuid/sessionid set/get by netlink
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 16/21] audit: add support for contid set/get by netlink
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 15/21] sched: pull task_is_descendant into kernel/sched/core.c
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 14/21] audit: contid check descendancy and nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 13/21] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 12/21] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 11/21] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 10/21] audit: add containerid support for user records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 09/21] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 08/21] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 07/21] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 06/21] audit: contid limit of 32k imposed to avoid DoS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 05/21] audit: log drop of contid on exit of last task
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 04/21] audit: convert to contid list to check for orch/engine ownership
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 03/21] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 02/21] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 01/21] audit: collect audit task parameters
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V7 00/21] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: What is 'dynamic' set flag supposed to mean?
- From: Laura Garcia <nevola@xxxxxxxxx>
- What is 'dynamic' set flag supposed to mean?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v6 0/8] netfilter: nf_tables_offload: support tunnel offload
- From: wenxu <wenxu@xxxxxxxxx>
- icmp_hdr is wrong on CentOS 6 kernels (2.6.32-754.12.1)
- From: Olivia Nelson <the.warl0ck.1989@xxxxxxxxx>
- [PATCH] extensions: fix iptables-{nft,translate} with conntrack EXPECTED
- From: Quentin Armitage <quentin@xxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: bridge: drop a broken include
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH 07/14] nft Increase mnl_talk() receive buffer size
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: bridge: drop a broken include
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] netfilter: bridge: drop a broken include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 07/14] nft Increase mnl_talk() receive buffer size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 02/14] tests/shell: Speed up ipt-restore/0004-restore-race_0
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH 07/14] nft Increase mnl_talk() receive buffer size
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 14/14] nft: Reduce impact of nft_chain_builtin_init()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 08/14] xtables-restore: Avoid cache population when flushing
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 09/14] nft: Rename have_cache into have_chain_cache
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 11/14] nft: Allow to fetch only a specific chain from kernel
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 05/14] nft: Introduce nft_bridge_commit()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 10/14] nft: Fetch rule cache only if needed
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 02/14] tests/shell: Speed up ipt-restore/0004-restore-race_0
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 06/14] nft: Fix for add and delete of same rule in single batch
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 04/14] nft: Use nftnl_*_set_str() functions
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 13/14] nft: Optimize flushing all chains of a table
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 03/14] DEBUG: Print to stderr to not disturb iptables-save
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 01/14] tests/shell: Make ebtables-basic test more verbose
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 00/14] Improve iptables-nft performance with large rulesets
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 12/14] nft: Support fetching rules for a single chain only
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf 2/2] netfilter: nf_tables_offload: fix always true policy is unset check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nf_tables: add NFT_CHAIN_POLICY_UNSET and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: parser_json: fix crash while restoring secmark object
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: bridge: drop a broken include
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH RFC nftables 3/4] cli: add upstream linenoise source.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH RFC nftables 1/4] configure: remove unused AC_SUBST macros.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH RFC nftables 0/4] Add Linenoise support to the CLI.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH RFC nftables 4/4] cli: add linenoise CLI implementation.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH RFC nftables 2/4] cli: remove unused declaration.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2] src: parser_json: fix crash while restoring secmark object
- From: Eric Jallot <ejallot@xxxxxxxxx>
- [PATCH nft] src: parser_json: fix crash while restoring secmark object
- From: Eric Jallot <ejallot@xxxxxxxxx>
- Re: [PATCH] nftables: don't crash in 'list ruleset' if policy is not set
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] nftables: don't crash in 'list ruleset' if policy is not set
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH] nftables: don't crash in 'list ruleset' if policy is not set
- From: Sergei Trofimovich <slyfox@xxxxxxxxxx>
- [PATCH] netfilter: bridge: drop a broken include
- From: Adam Borowski <kilobyte@xxxxxxxxxx>
- Re: [PATCH nft] json: tests: fix typo in ct expectation json test
- From: Florian Westphal <fw@xxxxxxxxx>
- [nf-next:master 7/27] net/netfilter/nf_tables_offload.c:316 nft_flow_offload_chain() warn: always true condition '(policy != -1) => (0-255 != (-1))'
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH nft] json: tests: fix typo in ct expectation json test
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [iptables PATCH] iptables-test: Support testing host binaries
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] src: Enable doxygen to generate Function Documentation
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [iptables PATCH] iptables-test: Support testing host binaries
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2] parser_bison: Fix 'exists' keyword on Big Endian
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH v2] parser_bison: Fix 'exists' keyword on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2] parser_bison: Fix 'exists' keyword on Big Endian
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] json: fix type mismatch on "ct expect" json exporting
- From: Stéphane Veyret <sveyret@xxxxxxxxx>
- [nft PATCH v2] parser_bison: Fix 'exists' keyword on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] parser_bison: Fix 'exists' keyword on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] json: fix type mismatch on "ct expect" json exporting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_bison: Fix 'exists' keyword on Big Endian
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] parser_bison: Fix 'exists' keyword on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next v6 5/8] netfilter: nft_tunnel: support tunnel meta match offload
- [PATCH nf-next v6 6/8] netfilter: nft_tunnel: add NFTA_TUNNEL_KEY_RELEASE action
- [PATCH nf-next v6 7/8] netfilter: nft_objref: add nft_objref_type offload
- [PATCH nf-next v6 8/8] netfilter: nft_tunnel: support nft_tunnel_obj offload
- [PATCH nf-next v6 2/8] netfilter: nft_tunnel: support NFT_TUNNEL_IP_SRC/DST match
- [PATCH nf-next v6 0/8] netfilter: nf_tables_offload: support tunnel offload
- [PATCH nf-next v6 1/8] netfilter: nft_tunnel: add nft_tunnel_mode_validate function
- [PATCH nf-next v6 3/8] netfilter: nft_tunnel: add ipv6 check in nft_tunnel_mode_validate
- [PATCH nf-next v6 4/8] netfilter: nft_tunnel: support NFT_TUNNEL_IP6_SRC/DST match
- Re: [PATCH] netfilter: trivial: remove extraneous space from message
- From: Rui Salvaterra <rsalvaterra@xxxxxxxxx>
- Re: [PATCH 00/27] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nft] json: fix type mismatch on "ct expect" json exporting
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v5] src: add synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/27] netfilter: nf_tables: Fix an Oops in nf_tables_updobj() error handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/27] netfilter: nf_tables_offload: refactor the nft_flow_offload_rule function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/27] netfilter: nf_tables_offload: add __nft_offload_get_chain function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/27] netfilter: nft_{fwd,dup}_netdev: add offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/27] netfilter: ip_tables: remove unused function declarations.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/27] netfilter: nft_synproxy: add synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/27] netfilter: fix coding-style errors.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/27] netfilter: remove nf_conntrack_icmpv6.h header.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/27] netfilter: move inline nf_ip6_ext_hdr() function to a more appropriate header.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/27] netfilter: update include directives.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 23/27] netfilter: conntrack: move code to linux/nf_conntrack_common.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 24/27] netfilter: conntrack: remove CONFIG_NF_CONNTRACK check from nf_conntrack_acct.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 26/27] netfilter: conntrack: remove CONFIG_NF_CONNTRACK checks from nf_conntrack_zones.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/27] netfilter: conntrack: wrap two inline functions in config checks.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/27] netfilter: br_netfilter: update stub br_nf_pre_routing_ipv6 parameter to `void *priv`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/27] netfilter: replace defined(CONFIG...) || defined(CONFIG...MODULE) with IS_ENABLED(CONFIG...).
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/27] netfilter: synproxy: move code between headers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 25/27] netfilter: remove CONFIG_NETFILTER checks from headers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 27/27] netfilter: conntrack: remove two unused functions from nf_conntrack_timestamp.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/27] netfilter: move nf_bridge_frag_data struct definition to a more appropriate header.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/27] netfilter: conntrack: use consistent style when defining inline functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/27] netfilter: inline xt_hashlimit, ebt_802_3 and xt_physdev headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/27] netfilter: nf_tables_offload: remove rules when the device unregisters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/27] netfilter: fix include guards.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/27] netfilter: nf_tables_offload: refactor the nft_flow_offload_chain function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/27] netfilter: nf_tables_offload: move indirect flow_block callback logic to core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/27] netfilter: nf_tables_offload: avoid excessive stack usage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/27] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v6 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 00/18] Remove config option checks from netfilter headers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 14/18] netfilter: move nf_conntrack code to linux/nf_conntrack_common.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 00/18] Remove config option checks from netfilter headers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 14/18] netfilter: move nf_conntrack code to linux/nf_conntrack_common.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v3 12/18] netfilter: wrap two inline functions in config checks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 10/18] netfilter: use consistent style when defining inline functions in nf_conntrack_ecache.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 14/18] netfilter: move nf_conntrack code to linux/nf_conntrack_common.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 11/18] netfilter: replace defined(CONFIG...) || defined(CONFIG...MODULE) with IS_ENABLED(CONFIG...).
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 15/18] netfilter: remove CONFIG_NF_CONNTRACK check from nf_conntrack_acct.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 16/18] netfilter: remove CONFIG_NETFILTER checks from headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 17/18] netfilter: remove CONFIG_NF_CONNTRACK checks from nf_conntrack_zones.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 13/18] netfilter: update stub br_nf_pre_routing_ipv6 parameter to `void *priv`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 18/18] netfilter: remove two unused functions from nf_conntrack_timestamp.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 06/18] netfilter: remove nf_conntrack_icmpv6.h header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 01/18] netfilter: fix include guards.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 09/18] netfilter: move struct definition function to a more appropriate header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 02/18] netfilter: fix coding-style errors.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 00/18] Remove config option checks from netfilter headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 03/18] netfilter: remove unused function declarations.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 04/18] netfilter: inline three headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 05/18] netfilter: update include directives.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 08/18] netfilter: move code between synproxy headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v3 07/18] netfilter: move inline function to a more appropriate header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v5] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v4] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v4] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH ebtables-nft] ebtables: fix over-eager -o checks on custom chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] netfilter: hashlimit: prefer PRIu64 to avoid warnings on 32bit platforms
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] libnftables: use-after-free in exit path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: userspace conntrack helper and confirming the master conntrack
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: iptables release
- From: Fabio Pedretti <pedretti.fabio@xxxxxxxxx>
- [PATCH nf-next v6 4/4] netfilter: nf_offload: clean offload things when the device unregister
- [PATCH nf-next v6 1/4] netfilter: nf_tables_offload: add __nft_offload_get_chain function
- [PATCH nf-next v6 2/4] netfilter: nf_offload: refactor the nft_flow_offload_chain function
- [PATCH nf-next v6 3/4] netfilter: nf_offload: refactor the nft_flow_offload_rule function
- [PATCH nf-next v6 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- Re: [PATCH nf-next v5 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: wenxu <wenxu@xxxxxxxxx>
- Re: userspace conntrack helper and confirming the master conntrack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH ebtables-nft] ebtables: fix over-eager -o checks on custom chains
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH iptables] netfilter: hashlimit: prefer PRIu64 to avoid warnings on 32bit platforms
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v3] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v3] src: add synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] src: synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_synproxy: add synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 2/4] netfilter: nf_offload: refactor the nft_flow_offload_chain function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 3/4] netfilter: nf_offload: refactor the nft_flow_offload_rule function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] netlink_delinearize: fix wrong conversion to "list" in ct mark
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- iptables release
- From: Fabio Pedretti <pedretti.fabio@xxxxxxxxx>
- Re: [conntrack-tools PATCH] nfct: helper: Fix NFCTH_ATTR_PROTO_L4NUM size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_json: fix crash on insert rule to bad references
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 1/3] tests: shell: verify huge transaction returns expected number of rules
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] parser_json: fix crash on insert rule to bad references
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH nft 3/3] tests: shell: add huge transaction from firewalld
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH nft 2/3] tests: shell: add huge JSON transaction
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH nft 1/3] tests: shell: verify huge transaction returns expected number of rules
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nft] src: mnl: fix --echo buffer size -- again
- From: Eric Garver <eric@xxxxxxxxxxx>
- [conntrack-tools PATCH] nfct: helper: Fix NFCTH_ATTR_PROTO_L4NUM size
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] src: mnl: fix --echo buffer size -- again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: mnl: fix --echo buffer size -- again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: mnl: fix --echo buffer size -- again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: mnl: fix --echo buffer size -- again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: mnl: fix --echo buffer size -- again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nftables 3/3] src: mnl: retry when we hit -ENOBUFS
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nftables 3/3] src: mnl: retry when we hit -ENOBUFS
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH nft] netlink_delinearize: fix wrong conversion to "list" in ct mark
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next v4 4/4] netfilter: nf_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v5 4/4] netfilter: nf_offload: clean offload things when the device unregister
- [PATCH nf-next v5 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- [PATCH nf-next v5 2/4] netfilter: nf_offload: refactor the nft_flow_offload_chain function
- [PATCH nf-next v5 3/4] netfilter: nf_offload: refactor the nft_flow_offload_rule function
- [PATCH nf-next v5 1/4] netfilter: nf_tables_offload: add __nft_offload_get_chain function
- Re: [PATCH nf-next v4 4/4] netfilter: nf_offload: clean offload things when the device unregister
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_{fwd,dup}_netdev: add offload support
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH nft v3] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v2] src: add synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next v2 00/30] Add config option checks to netfilter headers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_{fwd,dup}_netdev: add offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nf_tables_offload: move indirect flow_block callback logic to core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 4/4] netfilter: nf_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: Fix an Oops in nf_tables_updobj() error handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v6 0/8] netfilter: nf_tables_offload: support tunnel offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v6 7/8] netfilter: nft_objref: add nft_objref_type offload
- [PATCH nf-next v6 5/8] netfilter: nft_tunnel: support tunnel meta match offload
- [PATCH nf-next v6 1/8] netfilter: nft_tunnel: add nft_tunnel_mode_validate function
- [PATCH nf-next v6 8/8] netfilter: nft_tunnel: support nft_tunnel_obj offload
- [PATCH nf-next v6 2/8] netfilter: nft_tunnel: support NFT_TUNNEL_IP_SRC/DST match
- [PATCH nf-next v6 3/8] netfilter: nft_tunnel: add ipv6 check in nft_tunnel_mode_validate
- [PATCH nf-next v6 6/8] netfilter: nft_tunnel: add NFTA_TUNNEL_KEY_RELEASE action
- [PATCH nf-next v6 0/8] netfilter: nf_tables_offload: support tunnel offload
- [PATCH nf-next v6 4/8] netfilter: nft_tunnel: support NFT_TUNNEL_IP6_SRC/DST match
- [PATCH nf-next v4 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- [PATCH nf-next v4 4/4] netfilter: nf_offload: clean offload things when the device unregister
- [PATCH nf-next v4 2/4] netfilter: nf_offload: refactor the nft_flow_offload_rule function
- [PATCH nf-next v4 1/4] netfilter: nf_offload: refactor the nft_flow_offload_chain function
- [PATCH nf-next v4 3/4] netfilter: nf_tables_offload: add __nft_offload_get_chain function
- [PATCH] src: Enable doxygen to generate Function Documentation
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 00/30] Add config option checks to netfilter headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft v2] src: add synproxy stateful object support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nf_tables: avoid excessive stack usage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nf_tables: avoid excessive stack usage
- From: Arnd Bergmann <arnd@xxxxxxxx>
- [PATCH nft v2] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nf_tables: avoid excessive stack usage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH libnftnl] src: synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_synproxy: add synproxy stateful object support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 0/8] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: flag fwd and queue statements as terminal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nf_tables: avoid excessive stack usage
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: flag fwd and queue statements as terminal
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH xtables-addons v2 1/2] xt_pknock, xt_SYSRQ: don't set shash_desc::flags.
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] netfilter: nf_tables: Fix an Oops in nf_tables_updobj() error handling
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH] netfilter: nf_tables: Fix an Oops in nf_tables_updobj() error handling
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH nf-next v3 3/4] netfilter: nf_tables_offload: add nft_offload_netdev_iterate function
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next v3 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH 2/2] tests: shell: check that rule add with index works with echo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2] cache: fix --echo with index/position
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 3/4] netfilter: nf_tables_offload: add nft_offload_netdev_iterate function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2] tests: shell: check that rule add with index works with echo
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH 1/2] cache: fix --echo with index/position
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nf-next v3 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v3 4/4] netfilter: nft_payload: packet mangling offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v3 3/4] net: flow_offload: mangle action at byte level
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v3 2/4] net: flow_offload: bitwise AND on mangle action value field
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v3 1/4] net: flow_offload: flip mangle action mask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v3 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] cache: fix --echo with index/position
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] cache: fix --echo with index/position
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] cache: fix --echo with index/position
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH 4/8] netfilter: nft_dynset: support for element deletion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/8] netfilter: nfnetlink_log: add support for VLAN information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/8] netfilter: not mark a spinlock as __read_mostly
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/8] netfilter: nft_meta: support for time matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/8] netfilter: nf_tables: Introduce stateful object update operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/8] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/8] netfilter: nft_quota: add quota object update support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/8] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/8] netfilter: nf_tables: Introduce new 64-bit helper register functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/8] netfilter: nf_tables_offload: support tunnel offload
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH nf-next v3 4/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- [PATCH nf-next v3 1/4] netfilter: nf_tables_offload: refactor the nft_flow_offload_chain function
- [PATCH nf-next v3 2/4] netfilter: nf_tables_offload: refactor the nft_flow_offload_rule function
- [PATCH nf-next v3 0/4] netfilter: nf_tables_offload: clean offload things when the device unregister
- [PATCH nf-next v3 3/4] netfilter: nf_tables_offload: add nft_offload_netdev_iterate function
- Re: [PATCH nf-next v2 3/3] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH 0/5] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_tables_offload: clean offload things when the device unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/5] netfilter: nf_flow_table: set default timeout after successful insertion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/5] netfilter: ctnetlink: honor IPS_OFFLOAD flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/5] netfilter: nft_socket: fix erroneous socket assignment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/5] netfilter: nft_fib_netdev: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/5] netfilter: bridge: Drops IPv6 packets if IPv6 module is not loaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 00/30] Add config option checks to netfilter headers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.2 24/94] netfilter: xt_nfacct: Fix alignment mismatch in xt_nfacct_match_info
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 78/94] netfilter: nf_flow_table: clear skb tstamp before xmit
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 16/52] netfilter: ebtables: Fix argument order to ADD_COUNTER
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 32/52] netfilter: nf_conntrack_ftp: Fix debug output
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 08/36] netfilter: xt_nfacct: Fix alignment mismatch in xt_nfacct_match_info
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.4 10/20] netfilter: nf_conntrack_ftp: Fix debug output
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 15/27] netfilter: nf_conntrack_ftp: Fix debug output
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 19/36] netfilter: nf_conntrack_ftp: Fix debug output
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 31/52] netfilter: xt_physdev: Fix spurious error message in physdev_mt_check
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 18/52] netfilter: xt_nfacct: Fix alignment mismatch in xt_nfacct_match_info
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 17/52] netfilter: nft_flow_offload: missing netlink attribute policy
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 77/94] netfilter: nf_flow_table: fix offload for flows that are subject to xfrm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 57/94] netfilter: conntrack: make sysctls per-namespace again
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 52/94] netfilter: nf_conntrack_ftp: Fix debug output
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 51/94] netfilter: xt_physdev: Fix spurious error message in physdev_mt_check
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 23/94] netfilter: nft_flow_offload: missing netlink attribute policy
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 22/94] netfilter: ebtables: Fix argument order to ADD_COUNTER
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH nf-next v2 30/30] netfilter: wrap headers in CONFIG checks.
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH net-next,v2 3/4] net: flow_offload: mangle action at byte level
- From: Vlad Buslov <vladbu@xxxxxxxxxxxx>
- [PATCH nf-next v2] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: userspace conntrack helper and confirming the master conntrack
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [conntrack-tools PATCH v2] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH v2] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [conntrack-tools PATCH] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [conntrack-tools PATCH] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next v2 3/3] netfilter: nf_tables_offload: clean offload things when the device unregister
- [PATCH nf-next v2 2/3] netfilter: nf_offload: refactor the nft_flow_offload_rule function
- [PATCH nf-next v2 1/3] netfilter: nf_offload: refactor the nft_flow_offload_chain function
- [PATCH nf-next v2 0/3] netfilter: nf_tables_offload: clean offload things when the device unregister
- Re: [PATCH nf] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Phil Sutter <phil@xxxxxx>
- Re: [conntrack-tools PATCH] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: nf_table_offload: Fix check the offload flags in nft_indr_block_cb
- [PATCH nft] tests: shell: check that rule add with index works with echo
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nf-next v3] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_cb
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix possible null-pointer dereference in object update
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [conntrack-tools PATCH] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_cb
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/3] netfilter: nf_offload: Make nft_flow_offload_chain public
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_cb
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2 nf-next v3] netfilter: nft_quota: add quota object update support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v3] netfilter: nf_tables: Introduce stateful object update operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 4/4] netfilter: nft_payload: packet mangling offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 3/4] net: flow_offload: mangle action at byte level
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 2/4] net: flow_offload: bitwise AND on mangle action value field
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 1/4] net: flow_offload: flip mangle action mask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,v2 0/4] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v3] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_cb
- Re: [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 23/30] netfilter: wrap some nat-related conntrack code in a CONFIG_NF_NAT check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 20/30] netfilter: wrap union nf_conntrack_proto members in CONFIG_NF_CT_PROTO_* check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 10/30] netfilter: include the right header in nf_conntrack_zones.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 18/30] netfilter: use consistent style when defining inline functions in nf_conntrack_ecache.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 27/30] netfilter: add NF_TPROXY config option.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 22/30] netfilter: wrap inline timeout function in CONFIG_NETFILTER_TIMEOUT check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 24/30] netfilter: wrap some ipv6 tables code in a CONFIG_NF_TABLES_IPV6 check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 25/30] netfilter: wrap some conntrack code in a CONFIG_NF_CONNTRACK check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 12/30] netfilter: added missing includes.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 14/30] netfilter: remove superfluous header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 17/30] netfilter: move struct definition function to a more appropriate header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 21/30] netfilter: wrap inline synproxy function in CONFIG_NETFILTER_SYNPROXY check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 15/30] netfilter: move inline function to a more appropriate header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 29/30] netfilter: add IP_SET_HASH config option.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 11/30] netfilter: fix inclusions of <linux/netfilter/nf_nat.h>.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 19/30] netfilter: replace defined(CONFIG...) || defined(CONFIG...MODULE) with IS_ENABLED(CONFIG...).
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 30/30] netfilter: wrap headers in CONFIG checks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 28/30] netfilter: add IP_SET_BITMAP config option.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 16/30] netfilter: move code between synproxy headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 26/30] netfilter: add CONFIG_NETFILTER check to linux/netfilter.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 13/30] netfilter: inline three headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 06/30] netfilter: fix Kconfig formatting error.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 04/30] netfilter: add GPL-2.0 SPDX ID's to a couple of headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 03/30] netfilter: fix include guard comment.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 05/30] netfilter: remove trailing white-space.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 08/30] netfilter: remove unused function declarations.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 09/30] netfilter: remove unused includes.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 02/30] netfilter: add include guard to nf_conntrack_labels.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 01/30] netfilter: add include guard to nf_conntrack_h323_types.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 00/30] Add config option checks to netfilter headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 07/30] netfilter: remove stray semicolons.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nft_socket: fix erroneous socket assignment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5 1/1] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_get_and_ing_cmd
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nf_tables_offload: save one indent level in nft_indr_block_cb()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nf_tables_offload: move indirect flow_block callback logic to core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nf_flow_table: set default timeout after successful insertion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: ctnetlink: honor IPS_OFFLOAD flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH] conntrack: Fix CIDR to mask conversion on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 29/29] netfilter: wrap headers in CONFIG checks.
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 29/29] netfilter: wrap headers in CONFIG checks.
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_get_and_ing_cmd
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next 1/3] netfilter: nf_offload: Make nft_flow_offload_chain public
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next v5 1/2] netfilter: nf_flow_offload: add net in offload_ctx
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH nf-next 13/29] netfilter: remove superfluous header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 18/29] netfilter: replace defined(CONFIG...) || defined(CONFIG...MODULE) with IS_ENABLED(CONFIG...).
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 20/29] netfilter: wrap inline synproxy function in CONFIG_NETFILTER_SYNPROXY check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 14/29] netfilter: move inline function to a more appropriate header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 26/29] netfilter: add NF_TPROXY config option.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 29/29] netfilter: wrap headers in CONFIG checks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 16/29] netfilter: move struct definition function to a more appropriate header.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 28/29] netfilter: add IP_SET_HASH config option.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 21/29] netfilter: wrap inline timeout function in CONFIG_NETFILTER_TIMEOUT check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 19/29] netfilter: wrap union nf_conntrack_proto members in CONFIG_NF_CT_PROTO_* check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 17/29] netfilter: use consistent style when defining inline functions in nf_conntrack_ecache.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 23/29] netfilter: wrap some ipv6 tables code in a CONFIG_NF_TABLES_IPV6 check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 10/29] netfilter: include the right header in nf_conntrack_zones.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 27/29] netfilter: add IP_SET_BITMAP config option.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 22/29] netfilter: wrap some nat-related conntrack code in a CONFIG_NF_NAT check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 11/29] netfilter: added missing includes.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 24/29] netfilter: wrap some conntrack code in a CONFIG_NF_CONNTRACK check.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 15/29] netfilter: move code between synproxy headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 25/29] netfilter: add CONFIG_NETFILTER check to linux/netfilter.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 12/29] netfilter: inline three headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 02/29] netfilter: add include guard to nf_conntrack_labels.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 04/29] netfilter: add GPL-2.0 SPDX ID's to a couple of headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 07/29] netfilter: remove stray semicolons.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 05/29] netfilter: remove trailing white-space.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 08/29] netfilter: remove unused function declarations.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 03/29] netfilter: fix include guard comment.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 06/29] netfilter: fix Kconfig formatting error.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 00/29] Add config option checks to netfilter headers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 01/29] netfilter: add include guard to nf_conntrack_h323_types.h
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 09/29] netfilter: remove unused includes.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Jakub Kicinski <jakub.kicinski@xxxxxxxxxxxxx>
- Re: [PATCH xtables-addons v2 1/2] xt_pknock, xt_SYSRQ: don't set shash_desc::flags.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2] netfilter: nft_socket: fix erroneous socket assignment
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_socket: fix erroneous socket assignment
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_socket: fix erroneous socket assignment
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_socket: fix erroneous socket assignment
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH v4 2/2] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v5 1/1] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 2/2] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- [PATCH v5 1/1] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH 0/5] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Jakub Kicinski <jakub.kicinski@xxxxxxxxxxxxx>
- Re: [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 2/2] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- [PATCH v4 1/2] netfilter: Terminate rule eval if protocol=IPv6 and ipv6 module is disabled
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- [PATCH v4 0/2] Drop IPV6 packets if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- [PATCH v4 2/2] net: br_netfiler_hooks: Drops IPv6 packets if IPv6 module is not loaded
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/4] net: flow_offload: mangle action at byte level
- From: Vlad Buslov <vladbu@xxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v7 6/8] netfilter:nf_flow_table_ip: Support bridge family flow offload
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next v7 5/8] netfilter:nf_flow_table_core: Support bridge family flow offload
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH 4/5] netfilter: nf_flow_table: clear skb tstamp before xmit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/5] netfilter: nf_conntrack_ftp: Fix debug output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/5] netfilter: nft_meta_bridge: Fix get NFT_META_BRI_IIFVPROTO in network byteorder
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/5] netfilter: conntrack: make sysctls per-namespace again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/5] netfilter: xt_physdev: Fix spurious error message in physdev_mt_check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v6] meta: add ibrpvid and ibrvproto support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: reject: fix ICMP csum verification
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v7 1/8] netfilter:nf_flow_table: Refactor flow_offload_tuple to destination
- [PATCH nf-next v7 8/8] netfilter: Support the bridge family in flow table
- [PATCH nf-next v7 3/8] netfilter:nf_flow_table_ip: Separate inet operation to single function
- [PATCH nf-next v7 7/8] netfilter:nft_flow_offload: Support bridge family flow offload
- [PATCH nf-next v7 6/8] netfilter:nf_flow_table_ip: Support bridge family flow offload
- [PATCH nf-next v7 5/8] netfilter:nf_flow_table_core: Support bridge family flow offload
- [PATCH nf-next v7 2/8] netfilter:nf_flow_table_core: Separate inet operation to single function
- [PATCH nf-next v7 4/8] bridge: add br_vlan_get_info_rcu()
- [PATCH nf-next v7 0/8] netfilter: Support the bridge family in flow table
- [PATCH nft v6] meta: add ibrpvid and ibrvproto support
- Re: [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Jakub Kicinski <jakub.kicinski@xxxxxxxxxxxxx>
- [PATCH net-next 3/4] net: flow_offload: mangle action at byte level
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 4/4] netfilter: nft_payload: packet mangling offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/4] net: flow_offload: flip mangle action mask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/4] net: flow_offload: bitwise AND on mangle action value field
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/4 net-next] flow_offload: update mangle action representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_meta_bridge: Fix get NFT_META_BRI_IIFVPROTO in network byteorder
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.2 04/76] netfilter: nf_flow_table: fix offload for flows that are subject to xfrm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 11/76] netfilter: nf_flow_table: conntrack picks up expired flows
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 12/76] netfilter: nf_flow_table: teardown flow timeout race
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 10/76] netfilter: nf_tables: use-after-free in failing rule with bound set
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.2 24/76] netfilter: nft_flow_offload: skip tcp rst and fin packets
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 02/45] netfilter: nf_tables: use-after-free in failing rule with bound set
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 11/45] netfilter: nft_flow_offload: skip tcp rst and fin packets
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH] netfilter: reject: fix ICMP csum verification
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: reject: fix ICMP csum verification
- From: Alin Nastac <alin.nastac@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_flow_table: clear skb tstamp before xmit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 4/4] src: evaluate: catch invalid 'meta day' values in eval step
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/4] tests: add meta time test cases
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/4] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/4] evaluate: New internal helper __expr_evaluate_range
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/4] meta: introduce time/day/hour matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: json: add support for element deletion
- From: Phil Sutter <phil@xxxxxx>
- [PATCH AUTOSEL 4.19 15/29] netfilter: nf_tables: use-after-free in failing rule with bound set
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 22/29] netfilter: ipset: Copy the right MAC address in bitmap:ip,mac and hash:ip,mac sets
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 21/29] netfilter: ipset: Actually allow destination MAC address for hash:ip,mac sets too
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nft] src: json: add support for element deletion
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_meta_bridge: Fix get NFT_META_BRI_IIFVPROTO in network byteorder
- Re: [PATCH] netfilter: nf_conntrack_ftp: Fix debug output
- From: Thomas Jarosch <thomas.jarosch@xxxxxxxxxxxxx>
- Re: [PATCH v5 2/2] netfilter: nft_meta: support for time matching
- From: Jones Desougi <jones.desougi+netfilter@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] bridge:fragmented packets dropped by bridge
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH nft v5] meta: add ibrpvid and ibrvproto support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: make sysctls per-namespace again
- From: Shmulik Ladkani <shmulik.ladkani@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Dave Taht <dave.taht@xxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Dave Taht <dave.taht@xxxxxxxxx>
- [PATCH nf] netfilter: nf_flow_table: clear skb tstamp before xmit
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v3 1/1] netfilter: nf_tables: fib: Drop IPV6 packets if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: ipset: Fix an error code in ip_set_sockfn_get()
- From: Kadlecsik József <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl v2 2/2] expr: meta: Make NFT_DYNSET_OP_DELETE known
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: not mark a spinlock as __read_mostly
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: make sysctls per-namespace again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4] netfilter: nft_dynset: support for element deletion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl v2 1/2] expr: meta: Make NFT_META_TIME_{NS,DAY,HOUR} known
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: make sysctls per-namespace again
- From: Shmulik Ladkani <shmulik.ladkani@xxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf] netfilter: conntrack: make sysctls per-namespace again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_ftp: Fix debug output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_physdev: Fix spurious error message in physdev_mt_check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 11/14] nft: Bore up nft_parse_payload()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 11/14] nft: Bore up nft_parse_payload()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 05/14] nft: Fetch sets when updating rule cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v5] meta: add ibrpvid and ibrvproto support
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Jesper Dangaard Brouer <brouer@xxxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft v5] meta: add ibrpvid and ibrvproto support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_get_and_ing_cmd
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nft v5] meta: add ibrpvid and ibrvproto support
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH 2/2 nf-next v3] netfilter: nft_quota: add quota object update support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/2 nf-next v3] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v5] meta: add ibrpvid and ibrvproto support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nftables 0/8] add typeof keyword
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv3] netfilter: nfnetlink_log:add support for VLAN information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5 2/2] netfilter: nft_meta: support for time matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v5 1/2] netfilter: Introduce new 64-bit helper functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_table_offload: Fix the incorrect rcu usage in nft_indr_block_get_and_ing_cmd
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] bridge:fragmented packets dropped by bridge
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Toke Høiland-Jørgensen <toke@xxxxxxxxxx>
- Feature request: Add support for linenoise as alternative to readline
- From: "Priebe, Sebastian" <sebastian.priebe@xxxxxx.group>
- Re: Unable to create htb tc classes more than 64K
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH] bridge:fragmented packets dropped by bridge
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nft v9 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 04/14] nft: Eliminate pointless calls to nft_family_ops_lookup()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 03/14] nft: Keep nft_handle pointer in nft_xt_ctx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 02/14] nft: Get rid of NFT_COMPAT_EXPR_MAX define
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 01/14] nft: Fix typo in nft_parse_limit() error message
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] netfilter: ipset: Fix an error code in ip_set_sockfn_get()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- [PATCH nft v9 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- [PATCH nft v9 1/2] evaluate: New internal helper __expr_evaluate_range
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v4] meta: add ibrpvid and ibrvproto support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_ftp: Fix debug output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v5] meta: add ibrpvid and ibrvproto support
- Re: [PATCH] netfilter: nf_conntrack_ftp: Fix debug output
- From: Thomas Jarosch <thomas.jarosch@xxxxxxxxxxxxx>
- Re: [PATCH nft v1]files: add script to generate geoip.nft file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: not mark a spinlock as __read_mostly
- From: Li RongQing <lirongqing@xxxxxxxxx>
- Re: [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- Re: meter in 0.9.1 (nft noob question)
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH 0/3] rework netlink skb allocation
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 2/2 nf-next v2] netfilter: nft_quota: add quota object update support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/2 nf-next v2] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: nft equivalent of iptables command
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: nft equivalent of iptables command
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nft equivalent of iptables command
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: nft equivalent of iptables command
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: nft equivalent of iptables command
- From: Dan Williams <dcbw@xxxxxxxxxx>
- Re: nft equivalent of iptables command
- From: Florian Westphal <fw@xxxxxxxxx>
- nft equivalent of iptables command
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: meter in 0.9.1 (nft noob question)
- From: Laura Garcia <nevola@xxxxxxxxx>
- [PATCH 3/3] netlink: use generic skb_set_owner_r()
- From: Jan Dakinevich <jan.dakinevich@xxxxxxxxxxxxx>
- [PATCH 2/3] netlink: always use vmapped memory for skb data
- From: Jan Dakinevich <jan.dakinevich@xxxxxxxxxxxxx>
- [PATCH 1/3] skbuff: use kvfree() to deallocate head
- From: Jan Dakinevich <jan.dakinevich@xxxxxxxxxxxxx>
- [PATCH 0/3] rework netlink skb allocation
- From: Jan Dakinevich <jan.dakinevich@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Fix an error code in ip_set_sockfn_get()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: Fix an error code in ip_set_sockfn_get()
- From: Kadlecsik József <kadlec@xxxxxxxxxxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Akshat Kakkar <akshat.1984@xxxxxxxxx>
- [PATCH nft v1]files: add script to generate geoip.nft file
- From: Shekhar Sharma <shekhar250198@xxxxxxxxx>
- Re: Unable to create htb tc classes more than 64K
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables matching gratuitous arp
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- nftables matching gratuitous arp
- From: michael-dev <michael-dev@xxxxxxxxxxxxx>
- Re: [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: xt_physdev: Fix spurious error message in physdev_mt_check
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: xt_physdev: Fix spurious error message in physdev_mt_check
- From: Todd Seidelmann <tseidelmann@xxxxxxxxxx>
- [PATCH nft v8 2/2] meta: Introduce new conditions 'time', 'day' and 'hour'
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- [PATCH nft v8 1/2] evaluate: New internal helper __expr_evaluate_range
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- Re: [PATCH net-next 1/2] net: flow_offload: mangle 128-bit packet field with one action
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_ftp: Fix debug output
- From: Thomas Jarosch <thomas.jarosch@xxxxxxxxxxxxx>
- [PATCH v2 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [PATCH 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Leonardo Bras <leonardo@xxxxxxxxxxxxx>
- Re: [RFC 1/1] nft: abort cache creation if mnl_genid_get fails
- From: Christian Ehrhardt <christian.ehrhardt@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf-next] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [RFC 1/1] nft: abort cache creation if mnl_genid_get fails
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/2 nf-next] netfilter: nf_tables: Introduce stateful object update operation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/2 nf-next] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH iptables] doc: Note REDIRECT case of no IP address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v4] meta: add ibrpvid and ibrvproto support
- Re: [PATCH 1/2 nf-next] netfilter: nf_tables: Introduce stateful object update operation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/1] netfilter: nf_tables: fib: Drop IPV6 packages if IPv6 is disabled on boot
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2 nf-next] netfilter: nft_quota: add quota object update support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/2 nf-next] netfilter: nf_tables: Introduce stateful object update operation
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [iptables PATCH 12/14] nft: Embed rule's table name in nft_xt_ctx
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 13/14] nft: Support parsing lookup expression
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 06/14] nft: Support NFT_COMPAT_SET_ADD
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 09/14] nft: family_ops: Pass nft_handle to 'print_rule' callback
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 14/14] nft: bridge: Rudimental among extension support
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 03/14] nft: Keep nft_handle pointer in nft_xt_ctx
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 02/14] nft: Get rid of NFT_COMPAT_EXPR_MAX define
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 11/14] nft: Bore up nft_parse_payload()
- From: Phil Sutter <phil@xxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]