Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH 18/22] selftests: netfilter: add ebtables broute test case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/22] netfilter: x_tables: merge ip and ipv6 masquerade modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/22] bridge: reduce size of input cb to 16 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/22] kselftests: extend nft_nat with inet family based nat hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/22] netfilter: replace NF_NAT_NEEDED with IS_ENABLED(CONFIG_NF_NAT)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/22] netfilter: nat: add inet family nat support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/22] netfilter: nft_redir: Make nft_redir_dump static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/22] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH] [NETFILTER]: nf_conntrack_h323: fix spelling mistake "authenticaton" -> "authentication"
- From: Colin King <colin.king@xxxxxxxxxxxxx>
- [PATCH v3] netfilter: nf_conntrack_sip: fix expectation clash
- From: xiao ruizhu <katrina.xiaorz@xxxxxxxxx>
- [nf-next:nft-bridge8 8/8] net/netfilter/nf_conntrack_proto.c:557 nf_ct_netns_do_put() error: we previously assumed 'nf_ct_bridge_info' could be null (see line 552)
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- linux-next: build failure after merge of the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the netfiler tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: ebtables: CONFIG_COMPAT: drop a bogus WARN_ON
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: WARNING in compat_copy_entries (2)
- From: Florian Westphal <fw@xxxxxxxxx>
- linux-next: build warning after merge of the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: WARNING in compat_copy_entries (2)
- From: Andy Lutomirski <luto@xxxxxxxxxxxxxx>
- Re: WARNING in compat_copy_entries (2)
- From: syzbot <syzbot+659574e7bcc7f7eb4df7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH net-next v2 8/8] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 7/8] netfilter: nf_nat: register tftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 6/8] netfilter: nf_nat: register sip NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 5/8] netfilter: nf_nat: register irc NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 4/8] netfilter: nf_nat: register ftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 3/8] netfilter: nf_nat: register amanda NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 1/8] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 0/8] openvswitch: load and reference the NAT helper
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: fix build on 32bit arches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: fix icmp id endianness when protocol mapping was given
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v5 5/5] net: Replace CONFIG_DEBUG_KERNEL with CONFIG_DEBUG_MISC
- From: Sinan Kaya <okaya@xxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: fix build on 32bit arches
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nat: fix icmp id endianness when protocol mapping was given
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: iptables: undefined symbol: xtables_find_target_revision
- From: "Neal P. Murphy" <neal.p.murphy@xxxxxxxxxxxx>
- [nf:master 7/7] net/netfilter/nf_nat_core.c:422:29: sparse: incorrect type in assignment (different base types)
- From: kbuild test robot <lkp@xxxxxxxxx>
- [nf:master 5/7] net//netfilter/nf_conntrack_core.c:483:54: error: passing argument 3 of 'hsiphash' from incompatible pointer type
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: fix icmp id randomization
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ctnetlink: don't use conntrack/expect object addresses as id
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: initialize ct->timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/2] netfilter: conntrack: don't set related state for different outer address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] selftests: netfilter: check icmp pkttoobig errors are set as related
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [PATCH netfilter-next] bridge: only include nf_queue.h if needed
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the netfilter-next tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: delay chain policy update until transaction is complete
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: linux-next: build failure after merge of the netfilter-next tree
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 5/5] net: Replace CONFIG_DEBUG_KERNEL with CONFIG_DEBUG_MISC
- From: Florian Westphal <fw@xxxxxxxxx>
- linux-next: build failure after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [nf-next:master 20/21] include/net/netfilter/nf_queue.h:16:23: error: field 'state' has incomplete type
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH v4 5/5] net: Replace CONFIG_DEBUG_KERNEL with CONFIG_DEBUG_MISC
- From: Sinan Kaya <okaya@xxxxxxxxxx>
- Re: [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: Nikolay Aleksandrov <nikolay@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: masquerade: unify ip/ip6 notifier registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_json: Disallow ct helper as type to map to
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/8] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] bridge: broute: make broute a real ebtables table
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/4] bridge: netfilter: unroll NF_HOOK helper in bridge input path
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/4] bridge: reduce size of input cb to 16 bytes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/4] selftests: netfilter: add ebtables broute test case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 1/2] iptables-save: add option to show zeroed counters when saving rulesets
- From: Alban Vidal <alban.vidal@xxxxxxxxxx>
- Re: [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [nft PATCH] parser_json: Disallow ct helper as type to map to
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] parser_json: fix segfault in translating string to nft object
- From: Phil Sutter <phil@xxxxxx>
- Re: ESTABLISHED tcp conntrack timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_json: fix segfault in translating string to nft object
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] parser_json: fix segfault in translating string to nft object
- From: Laura Garcia Liebana <nevola@xxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Phil Sutter <phil@xxxxxx>
- ESTABLISHED tcp conntrack timeout
- From: Naruto Nguyen <narutonguyen2018@xxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] segtree: fix memleak in interval_map_decompose()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: memleak in expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [RFC nf-next 2/2] iptables: connmark - add savedscp option
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- [RFC nf-next v2 1/2] netfilter: connmark: introduce savedscp
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- [RFC nf-next v2 0/2] xt_connmark: add savedscp-mark action
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [ebtables PATCH] Fix segfault with missing lockfile directory
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nat: fix icmp id randomization
- From: Florian Westphal <fw@xxxxxxxxx>
- [ebtables PATCH] Fix segfault with missing lockfile directory
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: netfilter fixes for 5.0.7 stable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- netfilter fixes for 5.0.7 stable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: 5.0.7: WARNING: CPU: 1 PID: 169 at net/netfilter/nft_compat.c:82 and genreal protection fault
- From: Frederik Himpe <fhimpe@xxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nf_nat_masquerade: unify ipv4/6 notifier registration
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: x_tables: merge ip and ipv6 masquerade modules
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_nat: merge ip/ip6 masquerade headers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/3] netfilter: masquerade: unify ip/ip6 notifier registration
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- [PATCH] netfilter: conntrack: limit sysctl setting for boolean options
- From: xiangxia.m.yue@xxxxxxxxx
- Re: [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- [PATCH ghak90 V6 07/10] audit: add containerid support for user records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 04/10] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 02/10] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 01/10] audit: collect audit task parameters
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH 1/1] netfilter: connmark: introduce savedscp
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack: restrict conntrack_buckets value
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH 1/1] netfilter: connmark: introduce savedscp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] src: add nat support for the inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/6 nft v3] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl v3] expr: osf: add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][v2] time: Introduce jiffies64_to_msecs()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: make two functions static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3] netfilter: nft_osf: Add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/6] netfilter: nat: add inet family nat support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nf-next] netfilter: optimize nf_inet_addr_cmp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_redir: Make nft_redir_dump static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack: restrict conntrack_buckets value
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: remove unused parameter ctx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: 5.0.7: WARNING: CPU: 1 PID: 169 at net/netfilter/nft_compat.c:82 and genreal protection fault
- From: Florian Westphal <fw@xxxxxxxxx>
- 5.0.7: WARNING: CPU: 1 PID: 169 at net/netfilter/nft_compat.c:82 and genreal protection fault
- From: Frederik Himpe <fhimpe@xxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_conntrack: restrict conntrack_buckets value
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v2] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH nft v2] doc: update nft list plural form parameters
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft] src: missing destroy function in statement definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: type_identifier string memleak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- nft - Extracting the value from a variable_expr
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: Typo in extensions/libxt_osf.man
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] doc: update nft list plural form parameters
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft 2/2] evaluate: improve error reporting in tproxy with inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2,v2] parser_bison: missing tproxy syntax with port only for inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 1/8] net: use kfree_skb_list() from ip_do_fragment()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: make two functions static
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH nft] parser_bison: missing tproxy syntax with port only for inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH v4 1/2] iptables-save: add option to show zeroed counters when saving rulesets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] xtables-legacy: add missing config.h include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_json: Rewrite echo support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] man: nft.8: Add minimal description of (v)map statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] man: iptables-save: Add note about module autoloading
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: Install symlinks as such
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ebtables PATCH 0/3] Misc items found in Fedora package
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 1/8] net: use kfree_skb_list() from ip_do_fragment()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 5/8] net: ipv6: split skbuff into fragments transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 4/8] net: ipv4: split skbuff into fragments transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 7/8] net: ipv4: place cb handling away from fragment transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 6/8] net: ipv4: place cb handling away from fraglist iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 8/8] netfilter: bridge: add basic conntrack support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 3/8] net: ipv6: add skbuff fraglist split iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 2/8] net: ipv4: add skbuff fraglist split iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 0/8] connection tracking support for bridge
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/3] ipvs: allow rs_table to contain different real server types
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [no subject]
- From: H Craig <hicksycle@xxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [nft PATCH] man: nft.8: Add minimal description of (v)map statements
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] parser_json: Rewrite echo support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [PATCH] IPFIX output plugin
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [nftables v1] Add support for https://www.ietf.org/id/draft-ietf-tsvwg-le-phb-10.txt which is close to being published as an RFC.
- From: Loganaden Velvindron <logan@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: ctnetlink: don't use conntrack/expect object addresses as id
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/8] netfilter: use macros to create module aliases.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 0/8] openvswitch: load and reference the NAT helper.
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next 1/3] ipvs: allow rs_table to contain different real server types
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next 0/3] Add UDP tunnel support for ICMP errors in IPVS
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [nf-next:nft-bridge5 5/8] net/ipv6/ip6_output.c:755:16: sparse: Using plain integer as NULL pointer
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH AUTOSEL 4.19 09/57] netfilter: xt_cgroup: shrink size of v2 path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 22/57] netfilter: nf_flow_table: remove flowtable hook flush routine in netns exit routine
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 06/37] netfilter: xt_cgroup: shrink size of v2 path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 2/4] netlink: add generic object description infrastructure
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 1/4] netlink: add NLA_PAD definition
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 0/8] openvswitch: load and reference the NAT helper.
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: initialize ct->timeout
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH] netfilter: conntrack: initialize ct->timeout
- From: Alexander Potapenko <glider@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 04/10] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 07/10] audit: add containerid support for user records
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 04/10] audit: log container info of syscalls
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 02/10] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 02/10] audit: add container id
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 01/10] audit: collect audit task parameters
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 020/262] netfilter: nf_tables: fix set double-free in abort path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 053/262] netfilter: nf_tables: check the result of dereferencing base_chain->stats
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 055/262] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 153/262] netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrack_confirm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 233/262] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 041/192] netfilter: nf_tables: check the result of dereferencing base_chain->stats
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 042/192] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 106/192] netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrack_confirm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 171/192] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 070/123] netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrack_confirm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 110/123] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 77/87] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.4 57/63] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: Inability to IPVS DR with nft dnat since 9971a514ed26
- From: Simon Kirby <sim@xxxxxxxxxx>
- Re: netfilter: nf_tables: fix set double-free in abort path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH 6/6 nft v3] files: pf.os: merge the signatures spllited by version
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 5/6 nft v3] files: osf: update pf.os with newer OS fingerprints
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 4/6 nft v3] doc: add osf version option to man page
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 3/6 nft v3] tests: py: add osf tests with versions
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 2/6 nft v3] json: osf: add version json support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/6 nft v3] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH libnftnl v3] expr: osf: add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nf-next v3] netfilter: nft_osf: Add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: Inability to IPVS DR with nft dnat since 9971a514ed26
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 6/6] kselftests: extend nft_nat with inet family based nat hooks
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 5/6] netfilter: nft_redir: add inet support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/6] netfilter: nft_masq: add inet support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/6] netfilter: replace NF_NAT_NEEDED with IS_ENABLED(CONFIG_NF_NAT)
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/6] netfilter: nf_tables: merge route type into core
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/6] netfilter: nat: add inet family nat support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/6] netfilter: nat: add inet family nat support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables] src: add nat support for the inet family
- From: Florian Westphal <fw@xxxxxxxxx>
- Inability to IPVS DR with nft dnat since 9971a514ed26
- From: Simon Kirby <sim@xxxxxxxxxx>
- netfilter: nf_tables: fix set double-free in abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH tip/core/rcu 2/2] net/ipv4/netfilter: Update comment from call_rcu_bh() to call_rcu()
- From: "Paul E. McKenney" <paulmck@xxxxxxxxxxxxx>
- [PATCH net-next 8/8] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 7/8] netfilter: nf_nat: register tftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 6/8] netfilter: nf_nat: register sip NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 5/8] netfilter: nf_nat: register irc NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 4/8] netfilter: nf_nat: register ftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 3/8] netfilter: nf_nat: register amanda NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 1/8] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 0/8] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH net-next v2] openvswitch: add seqadj extension when NAT is used.
- From: David Miller <davem@xxxxxxxxxxxxx>
- [iptables PATCH] man: iptables-save: Add note about module autoloading
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next v2] openvswitch: add seqadj extension when NAT is used.
- From: Pravin Shelar <pshelar@xxxxxxx>
- [PATCH nft] evaluate: skip binary transfer for named sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH][nf-next] netfilter: optimize nf_inet_addr_cmp
- From: Li RongQing <lirongqing@xxxxxxxxx>
- [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v6] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v6] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: conntrack: don't set related state for different outer address
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] selftests: netfilter: check icmp pkttoobig errors are set as related
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next v2] openvswitch: add seqadj extension when NAT is used.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next] openvswitch: add seqadj extension when NAT is used.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH] netfilter: nat: avoid unused-variable warning
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Phil Sutter <phil@xxxxxx>
- KASAN: use-after-free Read in seccomp_notify_release (2)
- From: syzbot <syzbot+b562969adb2e04af3442@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: connmark: introduce savedscp
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- [RFC PATCH 0/1] netfilter: xt_connmark: add savedscp-mark action
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: WARNING in xt_compat_add_offset
- From: syzbot <syzbot+276ddebab3382bbf72db@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next] openvswitch: add seqadj extension when NAT is used.
- From: Pravin Shelar <pshelar@xxxxxxx>
- [iptables PATCH] extensions: Install symlinks as such
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Christoph Berg <myon@xxxxxxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Typo in extensions/libxt_osf.man
- From: Sam Banks <sam.banks.nz@xxxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next] openvswitch: add seqadj extension when NAT is used.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH 0/9] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] build: adjust configure for postgresql 10/11
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH] build: adjust configure for postgresql 11
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 1/9] netfilter: nf_conntrack_sip: remove direct dependency on IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/9] netfilter: nft_redir: fix module autoload with ip4
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/9] netfilter: nf_tables: bogus EBUSY in helper removal from transaction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/9] netfilter: ip6t_srh: fix NULL pointer dereferences
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 9/9] netfilter: nf_tables: add missing ->release_ops() in error path of newrule()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/9] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/9] netfilter: nf_flowtable: remove duplicated transition in diagram
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/9] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/9] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack_sip: fix rtcp expectation clash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Phil Sutter <phil@xxxxxx>
- Implementing Deletion of Set Elements in Rulesets
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft,v2 1/2] src: use 'flow add' syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] build: missing misspell.h in Makefile.am
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] src: use 'flow add' syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- a2x - unsupported parameter
- From: Václav Zindulka <vaclav.zindulka@xxxxxxxxxx>
- Re: [ebtables PATCH 3/3] extensions: Add AUDIT target
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: nf_flowtable: skip device lookup from interface index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: add missing ->release_ops() in error path of newrule()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] Allow protocol number zero
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ebtables PATCH 1/3] extensions: Drop Makefile
- From: Phil Sutter <phil@xxxxxx>
- [ebtables PATCH 2/3] Allow customizing lockfile location at configure time
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V5 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH conntrack-tools] Allow protocol number zero
- From: Brian Haley <bhaley@xxxxxxxxxx>
- Re: [ebtables PATCH 3/3] extensions: Add AUDIT target
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [ebtables PATCH 3/3] extensions: Add AUDIT target
- From: Phil Sutter <phil@xxxxxx>
- [ebtables PATCH 0/3] Misc items found in Fedora package
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] xtables-legacy: add missing config.h include
- From: Lucas Stach <l.stach@xxxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nft_redir: Make nft_redir_dump static
- From: Yue Haibing <yuehaibing@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_flowtable: remove duplicated transition in diagram
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nftables,v2] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: add missing ->release_ops() in error path of newrule()
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 07/10] audit: add containerid support for user records
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] xtables-legacy: add missing config.h include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [v2] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_sip: remove direct dependency on IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/2 v2] configure.ac: Clean up AC_ARG_{WITH,ENABLE} invocations, s/==/=/
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] configure.ac: Fix a2x check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipv6: ip6t_srh: fix NULL pointer dereferences
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ip6t_srh: Fix potential NULL pointer dereference
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [ANNOUNCE] nftlb 0.4 release
- From: Laura Garcia <nevola@xxxxxxxxx>
- [nftables] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH v4] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH v4] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v4] ipvs: allow tunneling with gue encapsulation
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH nft 2/2 v2] configure.ac: Clean up AC_ARG_{WITH,ENABLE} invocations, s/==/=/
- From: Luis Ressel <aranea@xxxxxxxx>
- Re: [PATCH nft 2/2] configure.ac: Clean up AC_ARG_{WITH,ENABLE} invocations
- From: Luis Ressel <aranea@xxxxxxxx>
- Re: [PATCH nft 2/2] configure.ac: Clean up AC_ARG_{WITH,ENABLE} invocations
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH nft 1/2] configure.ac: Fix a2x check
- From: Luis Ressel <aranea@xxxxxxxx>
- [PATCH nft 2/2] configure.ac: Clean up AC_ARG_{WITH,ENABLE} invocations
- From: Luis Ressel <aranea@xxxxxxxx>
- [PATCH] netfilter: nf_tables: remove unused parameter ctx
- From: Colin King <colin.king@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH v4] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v2] ipvs: allow tunneling with gue encapsulation
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH ghak90 V5 04/10] audit: log container info of syscalls
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 02/10] audit: add container id
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 01/10] audit: collect audit task parameters
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH v3] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH v3] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v3] ipvs: allow tunneling with gue encapsulation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v3] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH v2] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 07/10] audit: add containerid support for user records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 04/10] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 02/10] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 01/10] audit: collect audit task parameters
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V5 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2] src: file descriptor leak in include_file()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nft_redir: module autoload with ip4
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [PATCH nft] src: file descriptor leak in include_file()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint supportg
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: bogus EBUSY in helper removal from transaction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: no need for statement separator for ct object commands
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: no need for statement separator for ct object commands
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: shell: bogus EBUSY on helper deletion from transaction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack_sip: fix rtcp expectation clash
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- [PATCH] ipv6: ip6t_srh: fix NULL pointer dereferences
- From: Kangjie Lu <kjlu@xxxxxxx>
- [PATCH v2] netfilter: nf_conntrack_sip: fix rtcp expectation clash
- From: xiao ruizhu <katrina.xiaorz@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_ct_helper: Fix possible panic when nf_conntrack_helper_unregister is used in an unloadable module
- From: "Su Yanjun <suyj.fnst@xxxxxxxxxxxxxx>" <suyj.fnst@xxxxxxxxxxxxxx>
- Re: [iptables PATCH 0/6] Man pages for arptables and ebtables
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] [v2] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Arnd Bergmann <arnd@xxxxxxxx>
- [iptables PATCH 3/6] doc: Add ebtables man page
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/6] doc: Add arptables-nft man pages
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 6/6] xtables-save: Point at existing man page in help text
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/6] doc: Adjust arptables man pages
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 4/6] doc: Adjust ebtables man page
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/6] Man pages for arptables and ebtables
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 5/6] xtables-legacy.8: Remove stray colon
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [ebtables PATCH] Adjust .gitignore to renamed files
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_sip: fix rtcp expectation clash
- From: xiao ruizhu <katrina.xiaorz@xxxxxxxxx>
- [ebtables PATCH] Adjust .gitignore to renamed files
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] tests: shell: bogus ENOENT on element deletion in interval set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH 4.19 2/2] netfilter: xt_TEE: add missing code to get interface index in checkentry.
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH] netfilter: ip6t_srh: Fix potential NULL pointer dereference
- From: Aditya Pakki <pakki001@xxxxxxx>
- Re: [PATCH 0/5] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 2/5] netfilter: nf_tables: fix set double-free in abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/5] netfilter: nf_tables: return immediately on empty commit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/5] netfilter: nf_tables: bogus EBUSY when deleting set after flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/5] netfilter: nf_tables: use-after-free in dynamic operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/5] netfilter: nat: don't register device notifier twice
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH AUTOSEL 4.20 31/52] netfilter: compat: initialize all fields in xt_init
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.20 33/52] ipvs: fix dependency on nf_defrag_ipv6
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 28/44] netfilter: compat: initialize all fields in xt_init
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 30/44] ipvs: fix dependency on nf_defrag_ipv6
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 17/27] ipvs: fix dependency on nf_defrag_ipv6
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: return immediately on empty commit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_sip: remove direct dependency on IPv6
- From: Alin Nastac <alin.nastac@xxxxxxxxx>
- [PATCH nf-next v2] netfilter: nft_osf: Add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH libnftnl v2] expr: osf: add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v2 6/6] files: pf.os: merge the signatures spllited by version
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v2 5/6] files: osf: update pf.os with newer OS fingerprints
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v2 4/6] doc: add osf version option to man page
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v2 3/6] tests: py: add osf tests with versions
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v2 2/6] json: osf: add version json support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: return immediately on empty commit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: return immediately on empty commit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnetfilter_conntrack PATCH v2] Rename 'qa' directory to 'tests'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 4.19 2/2] netfilter: xt_TEE: add missing code to get interface index in checkentry.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: use-after-free in dynamic operations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v4] netfilter: nf_tables: bogus EBUSY when deleting set after flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [libnetfilter_conntrack PATCH v2] Rename 'qa' directory to 'tests'
- From: Phil Sutter <phil@xxxxxx>
- [libnetfilter_conntrack PATCH] Rename 'qa' directory to 'tests'
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Xin Long <lucien.xin@xxxxxxxxx>
- [PATCH 4.19 2/2] netfilter: xt_TEE: add missing code to get interface index in checkentry.
- From: Subash Abhinov Kasiviswanathan <subashab@xxxxxxxxxxxxxx>
- [PATCH 4.19 1/2] netfilter: xt_TEE: fix wrong interface selection
- From: Subash Abhinov Kasiviswanathan <subashab@xxxxxxxxxxxxxx>
- Re: NULL pointer dereference in nft_set_elem_destroy()
- From: Dmitrii Tcvetkov <demfloro@xxxxxxxxxxx>
- Re: [iptables PATCH] extensions: connlabel: Fallback on missing connlabel.conf
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 5/5] iptables-test: Make use of sample connlabel.conf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] meta: Add support for `time`
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables] meta: Add support for `time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- [PATCHv3] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH][v2] time: Introduce jiffies64_to_msecs()
- From: John Stultz <john.stultz@xxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_sip: fix IPV6 dependency
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: [PATCH libnftnl] src: libnftnl: export genid functions again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_sip: fix IPV6 dependency
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_ct_helper: Fix possible panic when nf_conntrack_helper_unregister is used in an unloadable module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][v2] time: Introduce jiffies64_to_msecs()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Backport of iptables TEE target fixes to 4.19
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: nat: don't register device notifier twice
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] xtables-legacy: add missing config.h include
- From: Lucas Stach <l.stach@xxxxxxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_tables: bogus EBUSY when deleting set after flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: bogus EBUSY when deleting set after flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: shell: bogus EBUSY in set deletion after flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: bogus EBUSY when deleting set after flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf,v2] netfilter: nf_tables: fix set double-free in abort path
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: fix set double-free in abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix set double-free in abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: NULL pointer dereference in nft_set_elem_destroy()
- From: Florian Westphal <fw@xxxxxxxxx>
- NULL pointer dereference in nft_set_elem_destroy()
- From: Dmitrii Tcvetkov <demfloro@xxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix set double-free in abort path
- From: Florian Westphal <fw@xxxxxxxxx>
- Backport of iptables TEE target fixes to 4.19
- From: Subash Abhinov Kasiviswanathan <subashab@xxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix set double-free in abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: return immediately on empty commit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix set double-free in abort path
- From: "" <kfm@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix set double-free in abort path
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 0/2] br_netfilter: enable in non-initial netns
- From: Florian LAUNAY <launayflorian@xxxxxxxxx>
- [PATCH libnftnl] src: libnftnl: export genid functions again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: xtables-addons build fail with linux 5.0: "error: implicit declaration of function 'do_gettimeofday'; did you mean 'do_settimeofday64'?"
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_osf: Add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_osf: Add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_osf: Add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_osf: Add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_osf: Add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 nf] netfilter: nat: don't register device notifier twice
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: misleading error reporting
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] evaluate: misleading error reporting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2,v2] segtree: remove dummy debug_octx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Netfilter
- From: satya phanisree <phanisree1998@xxxxxxxxx>
- [PATCH nft 2/2] segtree: add missing non-matching segment to set in flat representation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] segtree: remove dummy debug_octx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [bug report] netfilter: nft_compat: use .release_ops and remove list of extension
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_sip: fix IPV6 dependency
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: xtables-addons build fail with linux 5.0: "error: implicit declaration of function 'do_gettimeofday'; did you mean 'do_settimeofday64'?"
- From: PGNet Dev <pgnet.dev@xxxxxxxxx>
- Re: xtables-addons build fail with linux 5.0: "error: implicit declaration of function 'do_gettimeofday'; did you mean 'do_settimeofday64'?"
- From: PGNet Dev <pgnet.dev@xxxxxxxxx>
- xtables-addons build fail with linux 5.0: "error: implicit declaration of function 'do_gettimeofday'; did you mean 'do_settimeofday64'?"
- From: PGNet Dev <pgnet.dev@xxxxxxxxx>
- [iptables PATCH] extensions: connlabel: Fallback on missing connlabel.conf
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 5/5] iptables-test: Make use of sample connlabel.conf
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 5/5] iptables-test: Make use of sample connlabel.conf
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [iptables PATCH 5/5] iptables-test: Make use of sample connlabel.conf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 5/5] iptables-test: Make use of sample connlabel.conf
- From: Phil Sutter <phil@xxxxxx>
- net-next is CLOSED
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH] include: Use char* for arithmetic over void*
- From: William Woodruff <william@xxxxxxxxxxxxx>
- Re: [iptables PATCH 5/5] iptables-test: Make use of sample connlabel.conf
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: [ANNOUNCE] ipset 7.1 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCH v4 2/2] xtables-save: implement showing zeroed chain counters when saving rulesets
- From: Alban Vidal <alban.vidal@xxxxxxxxxx>
- [PATCH v4 1/2] iptables-save: add option to show zeroed counters when saving rulesets
- From: Alban Vidal <alban.vidal@xxxxxxxxxx>
- [PATCH v4 0/2] iptables-save,xtables-save: add option to show zeroed counters when saving rulesets
- From: Alban Vidal <alban.vidal@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nat: don't use same refcount for notifiers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 25/29] netfilter: nf_conntrack: ensure that CONNTRACK_LOCKS is power of 2
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- [PATCH net] netfilter: set skb transport_header before calling sctp_compute_cksum
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH 00/29] Netfilter/IPVS updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 23/29] netfilter: bridge: Don't sabotage nf_hook calls for an l3mdev slave
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/29] ipvs: get sctphdr by sctphoff in sctp_csum_check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 25/29] netfilter: nf_conntrack: ensure that CONNTRACK_LOCKS is power of 2
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 28/29] netfilter: nf_tables: nat: merge nft_masq protocol specific modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 26/29] netfilter: xt_IDLETIMER: fix sysfs callback function type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 29/29] netfilter: nf_tables: merge ipv4 and ipv6 nat chain types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 27/29] netfilter: nf_tables: nat: merge nft_redir protocol specific modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 24/29] netfilter: nf_tables: check the result of dereferencing base_chain->stats
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/29] netfilter: convert the proto argument from u8 to u16
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/29] netfilter: nft_tunnel: Add dst_cache support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/29] netfilter: conntrack: avoid same-timeout update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/29] netfilter: remove unneeded switch fall-through
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/29] netfilter: nft_set_hash: fix lookups with fixed size hash on big endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/29] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/29] netfilter: nft_set_hash: remove nft_hash_key()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/29] ipvs: change some data types from int to bool
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/29] netfilter: nft_set_hash: bogus element self comparison from deactivation path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/29] netfilter: nat: remove nf_nat_l3proto.h and nf_nat_core.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/29] netfilter: nat: remove l3proto struct
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/29] netfilter: nat: remove csum_recalc hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/29] netfilter: nat: remove csum_update hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/29] netfilter: nat: move nlattr parse and xfrm session decode to core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/29] netfilter: ebtables: remove BUGPRINT messages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/29] netfilter: nat: merge nf_nat_ipv4,6 into nat core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/29] netfilter: nat: remove l3 manip_pkt hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/29] netfilter: nat: remove nf_nat_l4proto.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/29] netfilter: nat: merge ipv4 and ipv6 masquerade functionality
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/29] netfilter: nf_conntrack_amanda: add support for STATE streams
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/29] netfilter: nft_compat: use .release_ops and remove list of extension
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/29] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/5] extensions: connlabel: Allow connlabel.conf override
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: nf_tables: merge remaining nat related modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_IDLETIMER: fix sysfs callback function type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][v2] netfilter: ensure that CONNTRACK_LOCKS is power of 2
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][v2] netfilter: check the result of dereferencing base_chain->stats
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: Don't sabotage nf_hook calls for an l3mdev slave
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] ipvs: get sctphdr by sctphoff in sctp_csum_check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nf-next][v2] netfilter: convert the proto argument from u8 to u16
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_tunnel: Add dst_cache support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] ipvs: change some data types from int to bool
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] doc: update goto/jump help text
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 3/5] extensions: connlabel: Allow connlabel.conf override
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_ct_helper: Fix possible panic when nf_conntrack_helper_unregister is used in an unloadable module
- From: "Su Yanjun <suyj.fnst@xxxxxxxxxxxxxx>" <suyj.fnst@xxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_ct_helper: Fix possible panic when nf_conntrack_helper_unregister is used in an unloadable module
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- [PATCH] netfilter: nf_ct_helper: Fix possible panic when nf_conntrack_helper_unregister is used in an unloadable module
- From: Su Yanjun <suyanjun218@xxxxxxx>
- [PATCH AUTOSEL 4.20 59/81] netfilter: nf_nat: skip nat clash resolution for same-origin entries
- From: Sasha Levin <sashal@xxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]