Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH 07/31] netfilter: ctnetlink: Support L3 protocol-filter on flush
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH 07/31] netfilter: ctnetlink: Support L3 protocol-filter on flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 07/31] netfilter: ctnetlink: Support L3 protocol-filter on flush
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_flow_offload: add entry to flowtable after confirmation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_flow_offload: add entry to flowtable after confirmation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Netlink socket protocol NETLINK_NFLOG
- From: Vijay Pasapuleti <vijaypas@xxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- [PATCH][nf-next] netfilter: slightly optimize nf_inet_addr_mask
- From: Li RongQing <lirongqing@xxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Re: [PATCH v2] ipvs:set sock send/receive buffer correctly
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: Netfilter fixes for 4.19 -stable
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/4] netfilter: nft_flow_offload: do not make un-established tcp flow_offload session.
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 07/31] netfilter: ctnetlink: Support L3 protocol-filter on flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/4] netfilter: nft_flow_offload: do not make un-established tcp flow_offload session.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Jakub Kicinski <jakub.kicinski@xxxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Netfilter fixes for 4.19 -stable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Jakub Kicinski <jakub.kicinski@xxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/4] netfilter: nft_flow_offload: do not make un-established tcp flow_offload session.
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH nf 4/4] netfilter: nf_flow_table: do not use deleted CT's flow offload
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH xtables-nft 0/6] handle parallel restore case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/4] netfilter: nft_flow_offload: do not make un-established tcp flow_offload session.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 4/4] netfilter: nf_flow_table: do not use deleted CT's flow offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] ipset: drop ipset_nest_start() and ipset_nest_end()
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCH nf 4/4] netfilter: nf_flow_table: do not use deleted CT's flow offload
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 3/4] netfilter: nf_flow_table: check ttl value in flow offload data path
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 2/4] netfilter: nft_flow_offload: do not make un-established tcp flow_offload session.
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 1/4] netfilter: nf_flow_table: fix netdev refcnt leak
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 0/4] netfilter: nf_flow_table: fix several flowtable bugs
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 7/9] net: use tcf_block_setup() infrastructure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] net: netfilter: Fix rpfilter dropping vrf packets by mistake
- From: David Ahern <dsahern@xxxxxxxxx>
- [PATCH] extensions: libxt_owner: Add complementary groups option
- From: Lukasz Pawelczyk <l.pawelczyk@xxxxxxxxxxx>
- [PATCH] netfilter: xt_owner: Add complementary groups option
- From: Lukasz Pawelczyk <l.pawelczyk@xxxxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH net-next 1/3] netlink: make nla_nest_start() add NLA_F_NESTED flag
- From: David Ahern <dsahern@xxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: David Ahern <dsahern@xxxxxxxxx>
- Re: [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH net-next,RFC 7/9] net: use tcf_block_setup() infrastructure
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH nft] ct: Add support for the 'id' key
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH net-next 1/3] netlink: make nla_nest_start() add NLA_F_NESTED flag
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Re: [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- [PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH net-next 1/3] netlink: make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH net-next 2/3] ipset: drop ipset_nest_start() and ipset_nest_end()
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH net-next 3/3] net: fix two coding style issues
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH ulogd2,v2 2/2] IPFIX: Introduce template record support
- [PATCH ulogd2,v2 1/2] IPFIX: Add IPFIX output plugin
- Re: [nft PATCH RFC 0/2] JSON schema for nftables.py
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next,RFC 2/9] net: sched: add tcf_block_cb_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 1/9] net: sched: move tcf_block_cb before indr_block
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 3/9] net: sched: add tcf_block_cb_free()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 6/9] net: sched: add tcf_setup_block_offload()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 8/9] net: sched: remove tcf_block_cb_{register,unregister}()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 4/9] net: sched: add tcf_block_setup()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 7/9] net: use tcf_block_setup() infrastructure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 8/9] net: cls_api: do not expose tcf_block to drivers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 9/9] net: cls_api: do not expose tcf_block to drivers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 5/9] net: sched: add release callback to struct tcf_block_cb
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 0/9] net: sched: prepare to reuse per-block callbacks from netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nf_ct_h323: restore boundary check correctness
- From: Jakub Jankowski <shasta@xxxxxxxxxxx>
- Re: [nft PATCH RFC 0/2] JSON schema for nftables.py
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH 07/31] netfilter: ctnetlink: Support L3 protocol-filter on flush
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba <mespio@xxxxxxxxx>
- [nft PATCH RFC 0/2] JSON schema for nftables.py
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH RFC 2/2] tests/py: Support JSON validation
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH RFC 1/2] py: Implement JSON validation in nftables module
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v3] net: netfilter: Fix rpfilter dropping vrf packets by mistake
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- [nft PATCH 1/4] tests: monitor: Adjust to changed events ordering
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/4] Misc minor fixes
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 3/4] parser_json: Fix typo in ct timeout policy parser
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/4] tests/py: Fix error messages in chain_delete()
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 4/4] parser_json: Fix parser for list maps command
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] use UDATA defines from libnftnl
- From: Phil Sutter <phil@xxxxxx>
- Issue related to conntrack while insert new rule with conntrack command in linux
- From: Mojtaba Esfandiari <Esfandiari@xxxxxxxxxxxxxxxx>
- Re: [PATCH 07/31] netfilter: ctnetlink: Support L3 protocol-filter on flush
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [RFC PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH v2] net: netfilter: Fix ipv6 rp_filter dropping vrf packets by mistake
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: Add ct id support
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC PATCH net-next 2/3] ipset: drop ipset_nest_start() and ipset_nest_end()
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [RFC PATCH net-next 3/3] net: fix two coding style issues
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [RFC PATCH net-next 1/3] netlink: make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [RFC PATCH net-next 0/3] make nla_nest_start() add NLA_F_NESTED flag
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH v2] net: netfilter: Fix ipv6 rp_filter dropping vrf packets by mistake
- From: David Ahern <dsahern@xxxxxxxxx>
- [PATCH v2] netfilter: nft_ct: Add ct id support
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- [PATCH v2] net: netfilter: Fix ipv6 rp_filter dropping vrf packets by mistake
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: [PATCH] net: netfilter: Fix ipv6 rp_filter dropping vrf packets by mistake
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: [PATCH] net: netfilter: Fix ipv6 rp_filter dropping vrf packets by mistake
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] net: netfilter: Fix ipv6 rp_filter dropping vrf packets by mistake
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: KASAN: use-after-free Read in seccomp_notify_release (2)
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in seccomp_notify_release (2)
- From: Tycho Andersen <tycho@xxxxxxxx>
- Re: KASAN: use-after-free Read in seccomp_notify_release (2)
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- Re: [PATCH nft] ct: Add support for the 'id' key
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_ct: Add ct id support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- [PATCH nft] ct: Add support for the 'id' key
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- [PATCH libnftnl] src: Add ct id support
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- [PATCH] netfilter: nft_ct: Add ct id support
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH v2 61/79] docs: leds: convert to ReST
- From: Jacek Anaszewski <jacek.anaszewski@xxxxxxxxx>
- [PATCH xtables-nft 6/6] tests: add test script for race-free restore
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft 5/6] xtables: handle concurrent ruleset modifications
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft 4/6] xtables: add and set "implict" flag on transaction objects
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft 3/6] xtables: add and use nft_build_cache
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft 2/6] xtables: add skip flag to objects
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft 1/6] xtables: unify user chain add/flush for restore case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft 0/6] handle parallel restore case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: fix double free on xt stmt destruction
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH 00/10] Netfilter/IPVS fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH iptables] xshared: check for maximum buffer length in dd_param_to_argv()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/10] netfilter: ebtables: CONFIG_COMPAT: drop a bogus WARN_ON
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/10] selftests: netfilter: check icmp pkttoobig errors are set as related
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/10] netfilter: conntrack: initialize ct->timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/10] netfilter: nat: fix icmp id randomization
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/10] netfilter: never get/set skb->tstamp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/10] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/10] netfilter: fix nf_l4proto_log_invalid to log invalid packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/10] netfilter: conntrack: don't set related state for different outer address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/10] netfilter: ctnetlink: don't use conntrack/expect object addresses as id
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/10] ipvs: do not schedule icmp errors from tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/10] Netfilter/IPVS fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.0 16/98] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 17/98] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 19/98] netfilter: ip6t_srh: fix NULL pointer dereferences
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 20/98] netfilter: nf_tables: bogus EBUSY in helper removal from transaction
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 18/98] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 10/68] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 11/68] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 12/68] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 04/43] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 05/43] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 05/29] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 04/29] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.4 02/21] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 13/68] netfilter: ip6t_srh: fix NULL pointer dereferences
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH v2 61/79] docs: leds: convert to ReST
- From: Mauro Carvalho Chehab <mchehab+samsung@xxxxxxxxxx>
- Re: [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH] netfilter: fix nf_l4proto_log_invalid to log invalid packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: never get/set skb->tstamp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ebtables: CONFIG_COMPAT: drop a bogus WARN_ON
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] ipvs:set sock send/receive buffer correctly
- From: Julian Anastasov <ja@xxxxxx>
- standalone fuzzing tool to debug net/netfilter
- From: Reindl Harald <h.reindl@xxxxxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH] netfilter: connlabels: fix spelling mistake "trackling" -> "tracking"
- From: Mukesh Ojha <mojha@xxxxxxxxxxxxxx>
- [PATCH] netfilter: connlabels: fix spelling mistake "trackling" -> "tracking"
- From: Colin King <colin.king@xxxxxxxxxxxxx>
- [tip:core/rcu] net/ipv4/netfilter: Update comment from call_rcu_bh() to call_rcu()
- From: "tip-bot for Paul E. McKenney" <tipbot@xxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next v3 0/4] openvswitch: load and reference the NAT helper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH net-next v3 0/4] openvswitch: load and reference the NAT helper
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH] ipvs:set sock send/receive buffer correctly
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: [PATCH] ipvs:set sock send/receive buffer correctly
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH] ipvs:set sock send/receive buffer correctly
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: [PATCH] netfilter: fix nf_l4proto_log_invalid to log invalid packets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [External Email] Re: RFC: NAT's default behavior of forwarding un-NATed packets
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH] netfilter: fix nf_l4proto_log_invalid to log invalid packets
- From: Andrei Vagin <avagin@xxxxxxxxx>
- [PATCH net-next v3 4/4] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v3 3/4] netfilter: nf_nat: register NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v3 2/4] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v3 1/4] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v3 0/4] openvswitch: load and reference the NAT helper
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH] ipvs:set sock send/receive buffer correctly
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [External Email] Re: RFC: NAT's default behavior of forwarding un-NATed packets
- From: Xiaozhou Liu <liuxiaozhou@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: never get/set skb->tstamp
- From: Michal Soltys <soltys@xxxxxxxx>
- Re: RFC: NAT's default behavior of forwarding un-NATed packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] ipvs:set sock send/receive buffer correctly
- From: linmiaohe <linmiaohe@xxxxxxxxxx>
- Re: RFC: NAT's default behavior of forwarding un-NATed packets
- From: Jan Engelhardt <jengelh@xxxxxxx>
- RFC: NAT's default behavior of forwarding un-NATed packets
- From: Xiaozhou Liu <liuxiaozhou@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: never get/set skb->tstamp
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net-next 04/10] net: ipv6: split skbuff into fragments transformer
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: never get/set skb->tstamp
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 08/10] netfilter: bridge: add support for conntrack support
- From: Nikolay Aleksandrov <nikolay@xxxxxxxxxxxxxxxxxxx>
- Re: ESTABLISHED tcp conntrack timeout
- From: Naruto Nguyen <narutonguyen2018@xxxxxxxxx>
- Re: ulogd2 question - meaning of flow.start.sec when hash_mode == 0 (NFCT input, JSON output)
- From: Michal Soltys <soltys@xxxxxxxx>
- ulogd2 question - meaning of flow.start.sec when hash_mode == 0 (NCFT input, JSON output)
- From: Michal Soltys <soltys@xxxxxxxx>
- Re: [PATCH] [NETFILTER]: nf_conntrack_h323: fix spelling mistake "authenticaton" -> "authentication"
- From: Colin Ian King <colin.king@xxxxxxxxxxxxx>
- Re: [PATCH] [NETFILTER]: nf_conntrack_h323: fix spelling mistake "authenticaton" -> "authentication"
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] [NETFILTER]: nf_conntrack_h323: fix spelling mistake "authenticaton" -> "authentication"
- From: Mukesh Ojha <mojha@xxxxxxxxxxxxxx>
- Re: linux-next: manual merge of the netfilter-next tree with the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: linux-next: manual merge of the netfilter-next tree with the netfiler tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 04/10] net: ipv6: split skbuff into fragments transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 02/10] net: ipv6: add skbuff fraglist split iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 03/10] net: ipv4: split skbuff into fragments transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 05/10] net: ipv4: place cb handling away from fraglist iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 07/10] netfilter: nf_conntrack: allow to register bridge support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 06/10] net: ipv4: place cb handling away from fragment transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 09/10] netfilter: nf_conntrack_bridge: add support for IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 10/10] netfilter: nf_conntrack_bridge: register inet conntrack for bridge
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 08/10] netfilter: bridge: add support for conntrack support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 01/10] net: ipv4: add skbuff fraglist split iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 00/10] connection tracking support for bridge
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH -next 3/3] netfilter: nf_tables: drop include of module.h from nf_tables.h
- From: Paul Gortmaker <paul.gortmaker@xxxxxxxxxxxxx>
- [PATCH -next 2/3] netfilter: nf_tables: fix implicit include of module.h
- From: Paul Gortmaker <paul.gortmaker@xxxxxxxxxxxxx>
- [PATCH -next 0/3] netfilter: header cleanup
- From: Paul Gortmaker <paul.gortmaker@xxxxxxxxxxxxx>
- [PATCH -next 1/3] netfilter: nf_tables: relocate header content to consumer
- From: Paul Gortmaker <paul.gortmaker@xxxxxxxxxxxxx>
- Re: [PATCH 00/22] Netfilter/IPVS updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 06/22] netfilter: optimize nf_inet_addr_cmp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/22] netfilter: nft_redir: add inet support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/22] netfilter: nf_tables: remove unused parameter ctx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/22] netfilter: nf_flowtable: skip device lookup from interface index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/22] time: Introduce jiffies64_to_msecs()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/22] ipvs: allow tunneling with gue encapsulation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/22] netfilter: nft_masq: add inet support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/22] netfilter: nf_tables: merge route type into core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/22] netfilter: nft_osf: Add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/22] netfilter: nf_nat: merge ip/ip6 masquerade headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/22] netfilter: make two functions static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/22] netfilter: nf_nat_masquerade: unify ipv4/6 notifier registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/22] bridge: broute: make broute a real ebtables table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/22] bridge: only include nf_queue.h if needed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/22] bridge: netfilter: unroll NF_HOOK helper in bridge input path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/22] selftests: netfilter: add ebtables broute test case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/22] netfilter: x_tables: merge ip and ipv6 masquerade modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/22] bridge: reduce size of input cb to 16 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/22] kselftests: extend nft_nat with inet family based nat hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/22] netfilter: replace NF_NAT_NEEDED with IS_ENABLED(CONFIG_NF_NAT)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/22] netfilter: nat: add inet family nat support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/22] netfilter: nft_redir: Make nft_redir_dump static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/22] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH] [NETFILTER]: nf_conntrack_h323: fix spelling mistake "authenticaton" -> "authentication"
- From: Colin King <colin.king@xxxxxxxxxxxxx>
- [PATCH v3] netfilter: nf_conntrack_sip: fix expectation clash
- From: xiao ruizhu <katrina.xiaorz@xxxxxxxxx>
- [nf-next:nft-bridge8 8/8] net/netfilter/nf_conntrack_proto.c:557 nf_ct_netns_do_put() error: we previously assumed 'nf_ct_bridge_info' could be null (see line 552)
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- linux-next: build failure after merge of the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the netfiler tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: ebtables: CONFIG_COMPAT: drop a bogus WARN_ON
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: WARNING in compat_copy_entries (2)
- From: Florian Westphal <fw@xxxxxxxxx>
- linux-next: build warning after merge of the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: WARNING in compat_copy_entries (2)
- From: Andy Lutomirski <luto@xxxxxxxxxxxxxx>
- Re: WARNING in compat_copy_entries (2)
- From: syzbot <syzbot+659574e7bcc7f7eb4df7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH net-next v2 8/8] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 7/8] netfilter: nf_nat: register tftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 6/8] netfilter: nf_nat: register sip NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 5/8] netfilter: nf_nat: register irc NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 4/8] netfilter: nf_nat: register ftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 3/8] netfilter: nf_nat: register amanda NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 1/8] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH net-next v2 0/8] openvswitch: load and reference the NAT helper
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: fix build on 32bit arches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: fix icmp id endianness when protocol mapping was given
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v5 5/5] net: Replace CONFIG_DEBUG_KERNEL with CONFIG_DEBUG_MISC
- From: Sinan Kaya <okaya@xxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: fix build on 32bit arches
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nat: fix icmp id endianness when protocol mapping was given
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: iptables: undefined symbol: xtables_find_target_revision
- From: "Neal P. Murphy" <neal.p.murphy@xxxxxxxxxxxx>
- [nf:master 7/7] net/netfilter/nf_nat_core.c:422:29: sparse: incorrect type in assignment (different base types)
- From: kbuild test robot <lkp@xxxxxxxxx>
- [nf:master 5/7] net//netfilter/nf_conntrack_core.c:483:54: error: passing argument 3 of 'hsiphash' from incompatible pointer type
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: fix icmp id randomization
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ctnetlink: don't use conntrack/expect object addresses as id
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: initialize ct->timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/2] netfilter: conntrack: don't set related state for different outer address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] selftests: netfilter: check icmp pkttoobig errors are set as related
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [PATCH netfilter-next] bridge: only include nf_queue.h if needed
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the netfilter-next tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: delay chain policy update until transaction is complete
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: linux-next: build failure after merge of the netfilter-next tree
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 5/5] net: Replace CONFIG_DEBUG_KERNEL with CONFIG_DEBUG_MISC
- From: Florian Westphal <fw@xxxxxxxxx>
- linux-next: build failure after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [nf-next:master 20/21] include/net/netfilter/nf_queue.h:16:23: error: field 'state' has incomplete type
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH v4 5/5] net: Replace CONFIG_DEBUG_KERNEL with CONFIG_DEBUG_MISC
- From: Sinan Kaya <okaya@xxxxxxxxxx>
- Re: [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: Nikolay Aleksandrov <nikolay@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: dict: A netfilter expression for dictionary lookups
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: masquerade: unify ip/ip6 notifier registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_json: Disallow ct helper as type to map to
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/8] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] bridge: broute: make broute a real ebtables table
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/4] bridge: netfilter: unroll NF_HOOK helper in bridge input path
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/4] bridge: reduce size of input cb to 16 bytes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/4] selftests: netfilter: add ebtables broute test case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/4] netfilter: bridge: remove broute hook
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 1/2] iptables-save: add option to show zeroed counters when saving rulesets
- From: Alban Vidal <alban.vidal@xxxxxxxxxx>
- Re: [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [nft PATCH] parser_json: Disallow ct helper as type to map to
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] parser_json: fix segfault in translating string to nft object
- From: Phil Sutter <phil@xxxxxx>
- Re: ESTABLISHED tcp conntrack timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_json: fix segfault in translating string to nft object
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] parser_json: fix segfault in translating string to nft object
- From: Laura Garcia Liebana <nevola@xxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Phil Sutter <phil@xxxxxx>
- ESTABLISHED tcp conntrack timeout
- From: Naruto Nguyen <narutonguyen2018@xxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] segtree: fix memleak in interval_map_decompose()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: memleak in expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [RFC nf-next 2/2] iptables: connmark - add savedscp option
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- [RFC nf-next v2 1/2] netfilter: connmark: introduce savedscp
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- [RFC nf-next v2 0/2] xt_connmark: add savedscp-mark action
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [ebtables PATCH] Fix segfault with missing lockfile directory
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nat: fix icmp id randomization
- From: Florian Westphal <fw@xxxxxxxxx>
- [ebtables PATCH] Fix segfault with missing lockfile directory
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] evaluate: disallow anonymous set with empty elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: netfilter fixes for 5.0.7 stable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- netfilter fixes for 5.0.7 stable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: 5.0.7: WARNING: CPU: 1 PID: 169 at net/netfilter/nft_compat.c:82 and genreal protection fault
- From: Frederik Himpe <fhimpe@xxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nf_nat_masquerade: unify ipv4/6 notifier registration
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: x_tables: merge ip and ipv6 masquerade modules
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_nat: merge ip/ip6 masquerade headers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/3] netfilter: masquerade: unify ip/ip6 notifier registration
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: fix dangling pointer access of fake_rtable
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- [PATCH] netfilter: conntrack: limit sysctl setting for boolean options
- From: xiangxia.m.yue@xxxxxxxxx
- Re: [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- [PATCH ghak90 V6 07/10] audit: add containerid support for user records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 05/10] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 04/10] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 02/10] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak90 V6 01/10] audit: collect audit task parameters
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH 1/1] netfilter: connmark: introduce savedscp
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack: restrict conntrack_buckets value
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH 1/1] netfilter: connmark: introduce savedscp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] IPFIX output plugin
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nftables] src: add nat support for the inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/6 nft v3] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl v3] expr: osf: add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][v2] time: Introduce jiffies64_to_msecs()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: make two functions static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3] netfilter: nft_osf: Add version option support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/6] netfilter: nat: add inet family nat support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nf-next] netfilter: optimize nf_inet_addr_cmp
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_redir: Make nft_redir_dump static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack: restrict conntrack_buckets value
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: remove unused parameter ctx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: 5.0.7: WARNING: CPU: 1 PID: 169 at net/netfilter/nft_compat.c:82 and genreal protection fault
- From: Florian Westphal <fw@xxxxxxxxx>
- 5.0.7: WARNING: CPU: 1 PID: 169 at net/netfilter/nft_compat.c:82 and genreal protection fault
- From: Frederik Himpe <fhimpe@xxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_conntrack: restrict conntrack_buckets value
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v2] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH nft v2] doc: update nft list plural form parameters
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft] src: missing destroy function in statement definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: type_identifier string memleak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- nft - Extracting the value from a variable_expr
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: Typo in extensions/libxt_osf.man
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nft] doc: update nft list plural form parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] doc: update nft list plural form parameters
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nft 2/2] evaluate: improve error reporting in tproxy with inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2,v2] parser_bison: missing tproxy syntax with port only for inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next,RFC 1/8] net: use kfree_skb_list() from ip_do_fragment()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: make two functions static
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH nft] parser_bison: missing tproxy syntax with port only for inet family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH v4 1/2] iptables-save: add option to show zeroed counters when saving rulesets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] xtables-legacy: add missing config.h include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_json: Rewrite echo support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] man: nft.8: Add minimal description of (v)map statements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] man: iptables-save: Add note about module autoloading
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: Install symlinks as such
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ebtables PATCH 0/3] Misc items found in Fedora package
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 1/8] net: use kfree_skb_list() from ip_do_fragment()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 5/8] net: ipv6: split skbuff into fragments transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 4/8] net: ipv4: split skbuff into fragments transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 7/8] net: ipv4: place cb handling away from fragment transformer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 6/8] net: ipv4: place cb handling away from fraglist iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 8/8] netfilter: bridge: add basic conntrack support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 3/8] net: ipv6: add skbuff fraglist split iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 2/8] net: ipv4: add skbuff fraglist split iterator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next,RFC 0/8] connection tracking support for bridge
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/3] ipvs: allow rs_table to contain different real server types
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [no subject]
- From: H Craig <hicksycle@xxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [nft PATCH] man: nft.8: Add minimal description of (v)map statements
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] parser_json: Rewrite echo support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH] netfilter:bridge: Hold bridge dev for fake_rtable to avoid the dangling pointer
- From: Rundong Ge <rdong.ge@xxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [PATCH] IPFIX output plugin
- From: Ander Juaristi <a@xxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [nftables v1] Add support for https://www.ietf.org/id/draft-ietf-tsvwg-le-phb-10.txt which is close to being published as an RFC.
- From: Loganaden Velvindron <logan@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: ctnetlink: don't use conntrack/expect object addresses as id
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/8] netfilter: use macros to create module aliases.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 0/8] openvswitch: load and reference the NAT helper.
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH net-next 3/3] ipvs: strip udp tunnel headers from icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next 2/3] ipvs: add function to find tunnels
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next 1/3] ipvs: allow rs_table to contain different real server types
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net-next 0/3] Add UDP tunnel support for ICMP errors in IPVS
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH net] ipvs: do not schedule icmp errors from tunnels
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [nf-next:nft-bridge5 5/8] net/ipv6/ip6_output.c:755:16: sparse: Using plain integer as NULL pointer
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH AUTOSEL 4.19 09/57] netfilter: xt_cgroup: shrink size of v2 path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 22/57] netfilter: nf_flow_table: remove flowtable hook flush routine in netns exit routine
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 06/37] netfilter: xt_cgroup: shrink size of v2 path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH RFC 4/4] netfilter: nf_tables: add netlink description
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 2/4] netlink: add generic object description infrastructure
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC 1/4] netlink: add NLA_PAD definition
- From: Johannes Berg <johannes@xxxxxxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next 0/8] openvswitch: load and reference the NAT helper.
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- dict: A netfilter expression for dictionary lookups
- From: Brett Mastbergen <bmastbergen@xxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: initialize ct->timeout
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH] netfilter: conntrack: initialize ct->timeout
- From: Alexander Potapenko <glider@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 04/10] audit: log container info of syscalls
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 07/10] audit: add containerid support for user records
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 04/10] audit: log container info of syscalls
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 02/10] audit: add container id
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 02/10] audit: add container id
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 01/10] audit: collect audit task parameters
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 020/262] netfilter: nf_tables: fix set double-free in abort path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 053/262] netfilter: nf_tables: check the result of dereferencing base_chain->stats
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 055/262] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 153/262] netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrack_confirm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.0 233/262] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 041/192] netfilter: nf_tables: check the result of dereferencing base_chain->stats
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 042/192] netfilter: conntrack: tcp: only close if RST matches exact sequence
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 106/192] netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrack_confirm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 171/192] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 070/123] netfilter: conntrack: fix cloned unconfirmed skb->_nfct race in __nf_conntrack_confirm
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 110/123] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 77/87] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.4 57/63] netfilter: physdev: relax br_netfilter dependency
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: Inability to IPVS DR with nft dnat since 9971a514ed26
- From: Simon Kirby <sim@xxxxxxxxxx>
- Re: netfilter: nf_tables: fix set double-free in abort path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH 6/6 nft v3] files: pf.os: merge the signatures spllited by version
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 5/6 nft v3] files: osf: update pf.os with newer OS fingerprints
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 4/6 nft v3] doc: add osf version option to man page
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 3/6 nft v3] tests: py: add osf tests with versions
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 2/6 nft v3] json: osf: add version json support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/6 nft v3] osf: add version fingerprint support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH libnftnl v3] expr: osf: add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nf-next v3] netfilter: nft_osf: Add version option support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: Inability to IPVS DR with nft dnat since 9971a514ed26
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 6/6] kselftests: extend nft_nat with inet family based nat hooks
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 5/6] netfilter: nft_redir: add inet support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/6] netfilter: nft_masq: add inet support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/6] netfilter: replace NF_NAT_NEEDED with IS_ENABLED(CONFIG_NF_NAT)
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/6] netfilter: nf_tables: merge route type into core
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/6] netfilter: nat: add inet family nat support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/6] netfilter: nat: add inet family nat support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables] src: add nat support for the inet family
- From: Florian Westphal <fw@xxxxxxxxx>
- Inability to IPVS DR with nft dnat since 9971a514ed26
- From: Simon Kirby <sim@xxxxxxxxxx>
- netfilter: nf_tables: fix set double-free in abort path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH tip/core/rcu 2/2] net/ipv4/netfilter: Update comment from call_rcu_bh() to call_rcu()
- From: "Paul E. McKenney" <paulmck@xxxxxxxxxxxxx>
- [PATCH net-next 8/8] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 7/8] netfilter: nf_nat: register tftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 6/8] netfilter: nf_nat: register sip NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 5/8] netfilter: nf_nat: register irc NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 4/8] netfilter: nf_nat: register ftp NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 3/8] netfilter: nf_nat: register amanda NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 2/8] netfilter: add API to manage NAT helpers.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 1/8] netfilter: use macros to create module aliases.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH net-next 0/8] openvswitch: load and reference the NAT helper.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH net-next v2] openvswitch: add seqadj extension when NAT is used.
- From: David Miller <davem@xxxxxxxxxxxxx>
- [iptables PATCH] man: iptables-save: Add note about module autoloading
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next v2] openvswitch: add seqadj extension when NAT is used.
- From: Pravin Shelar <pshelar@xxxxxxx>
- [PATCH nft] evaluate: skip binary transfer for named sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH][nf-next] netfilter: optimize nf_inet_addr_cmp
- From: Li RongQing <lirongqing@xxxxxxxxx>
- [PATCH v7] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v6] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH v6] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: conntrack: don't set related state for different outer address
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] selftests: netfilter: check icmp pkttoobig errors are set as related
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next v2] openvswitch: add seqadj extension when NAT is used.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH net-next] openvswitch: add seqadj extension when NAT is used.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- [PATCH] netfilter: nat: avoid unused-variable warning
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Phil Sutter <phil@xxxxxx>
- KASAN: use-after-free Read in seccomp_notify_release (2)
- From: syzbot <syzbot+b562969adb2e04af3442@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: connmark: introduce savedscp
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- [RFC PATCH 0/1] netfilter: xt_connmark: add savedscp-mark action
- From: "Kevin 'ldir' Darbyshire-Bryant" <ldir@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: WARNING in xt_compat_add_offset
- From: syzbot <syzbot+276ddebab3382bbf72db@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next] openvswitch: add seqadj extension when NAT is used.
- From: Pravin Shelar <pshelar@xxxxxxx>
- [iptables PATCH] extensions: Install symlinks as such
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Christoph Berg <myon@xxxxxxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] build: adjust configure for postgresql 11
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxxxxx>
- Typo in extensions/libxt_osf.man
- From: Sam Banks <sam.banks.nz@xxxxxxxxx>
- Re: [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next] openvswitch: add seqadj extension when NAT is used.
- From: Flavio Leitner <fbl@xxxxxxxxxxxx>
- Re: [PATCH 0/9] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] build: adjust configure for postgresql 10/11
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH] build: adjust configure for postgresql 11
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 1/9] netfilter: nf_conntrack_sip: remove direct dependency on IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/9] netfilter: nft_redir: fix module autoload with ip4
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/9] netfilter: nf_tables: bogus EBUSY in helper removal from transaction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/9] netfilter: ip6t_srh: fix NULL pointer dereferences
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 9/9] netfilter: nf_tables: add missing ->release_ops() in error path of newrule()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/9] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/9] netfilter: nf_flowtable: remove duplicated transition in diagram
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/9] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/9] netfilter: nft_set_rbtree: check for inactive element after flag mismatch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack_sip: fix rtcp expectation clash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Implementing Deletion of Set Elements in Rulesets
- From: Phil Sutter <phil@xxxxxx>
- Implementing Deletion of Set Elements in Rulesets
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_meta: Extend support for NFT_META_TSTAMP_NS
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft,v2 1/2] src: use 'flow add' syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] build: missing misspell.h in Makefile.am
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] src: use 'flow add' syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- a2x - unsupported parameter
- From: Václav Zindulka <vaclav.zindulka@xxxxxxxxxx>
- Re: [ebtables PATCH 3/3] extensions: Add AUDIT target
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: nf_flowtable: skip device lookup from interface index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: add missing ->release_ops() in error path of newrule()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools] Allow protocol number zero
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ebtables PATCH 1/3] extensions: Drop Makefile
- From: Phil Sutter <phil@xxxxxx>
- [ebtables PATCH 2/3] Allow customizing lockfile location at configure time
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V5 00/10] audit: implement container identifier
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH conntrack-tools] Allow protocol number zero
- From: Brian Haley <bhaley@xxxxxxxxxx>
- Re: [ebtables PATCH 3/3] extensions: Add AUDIT target
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [ebtables PATCH 3/3] extensions: Add AUDIT target
- From: Phil Sutter <phil@xxxxxx>
- [ebtables PATCH 0/3] Misc items found in Fedora package
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] xtables-legacy: add missing config.h include
- From: Lucas Stach <l.stach@xxxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nft_redir: Make nft_redir_dump static
- From: Yue Haibing <yuehaibing@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_flowtable: remove duplicated transition in diagram
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nftables,v2] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nftables] tests/py: Add Test for `meta time`
- From: Karuna Grewal <karunagrewal98@xxxxxxxxx>
- [PATCH v5] ipvs: allow tunneling with gue encapsulation
- From: Jacky Hu <hengqing.hu@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: add missing ->release_ops() in error path of newrule()
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 10/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 09/10] audit: add support for containerid to network namespaces
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 08/10] audit: add containerid filtering
- From: Ondrej Mosnacek <omosnace@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 07/10] audit: add containerid support for user records
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 06/10] audit: add support for non-syscall auxiliary records
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 05/10] audit: add containerid support for ptrace and signals
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V5 03/10] audit: read container ID of a process
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft v2 1/6] osf: add version fingerprint support
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] xtables-legacy: add missing config.h include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [v2] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: bridge: set skb transport_header before entering NF_INET_PRE_ROUTING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_sip: remove direct dependency on IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/2 v2] configure.ac: Clean up AC_ARG_{WITH,ENABLE} invocations, s/==/=/
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] configure.ac: Fix a2x check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]