Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH 3/3 nf-next v2] netfilter: nft_osf: implement Passive OS fingerprint module in nft_osf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/3 nf-next v2] netfilter: nfnetlink_osf: extract nfnetlink_subsystem code from xt_osf.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/3 nf-next v2] netfilter: nf_osf: rename nf_osf.c to nfnetlink_osf.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libnetfilter_conntrack: bsf.c: fix verdict
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: shaochun chen <cscnull@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: shaochun chen <cscnull@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak of dump
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netlink: fix memory leak of dump
- From: Shaochun Chen <cscnull@xxxxxxxxx>
- Re: iptables-save - suggest patch to add functionality
- From: Alban Vidal <alban.vidal@xxxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netlink: fix memory leak
- From: "Jason A. Donenfeld" <Jason@xxxxxxxxx>
- [PATCH] netlink: fix memory leak
- From: Shaochun Chen <cscnull@xxxxxxxxx>
- Re: typo found in socket.h at nftables repository
- From: Florian Westphal <fw@xxxxxxxxx>
- typo found in socket.h at nftables repository
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [RFC PATCH ghak90 (was ghak32) V3 08/10] audit: NETFILTER_PKT: record each container ID associated with a netNS
- From: Laura Garcia <nevola@xxxxxxxxx>
- [PATCH] libnetfilter_conntrack: bsf.c: fix verdict
- From: Florian Lehner <nfct@xxxxxxxxxxx>
- Re: [PATCH 00/38] Netfilter/IPVS updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v8] netfilter: nft_ct: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH] ipvs: don't show negative times in ip_vs_conn
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH] ipvs: don't show negative times in ip_vs_conn
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH] ipvs: don't show negative times in ip_vs_conn
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- [PATCH libnftnl v2] expr: add osf support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 3/3 nf-next v2] netfilter: nft_osf: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 2/3 nf-next v2] netfilter: nfnetlink_osf: extract nfnetlink_subsystem code from xt_osf.c
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/3 nf-next v2] netfilter: nf_osf: rename nf_osf.c to nfnetlink_osf.c
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: dccp: treat SYNC/SYNCACK as invalid if no prior state
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 02/38] netfilter: flowtables: use fixed renew timeout on teardown
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: nf_tables: fix resource leaks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v8] netfilter: nft_ct: add ct timeout support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 02/38] netfilter: flowtables: use fixed renew timeout on teardown
- From: Felix Fietkau <nbd@xxxxxxxx>
- [PATCH 05/38] netfilter: utils: move nf_ip6_checksum* from ipv6 to utils
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/38] netfilter: conntrack: avoid l4proto pkt_to_tuple calls
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/38] netfilter: nf_conncount: Move locking into count_tree()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/38] netfilter: nf_conncount: Split insert and traversal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/38] netfilter: nf_conncount: Switch to plain list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/38] netfilter: nf_conncount: Add list lock and gc worker, and RCU for init tree search
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 30/38] netfilter: nf_tables: take module reference when starting a batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 32/38] netfilter: nf_tables: use dedicated mutex to guard transactions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 38/38] netfilter: nf_osf: add missing definitions to header file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 37/38] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 34/38] netfilter: nf_osf: add struct nf_osf_hdr_ctx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 36/38] netfilter: nft_socket: Expose socket mark
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 35/38] netfilter: nft_socket: Break evaluation if no socket found
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/38] netfilter: conntrack: remove l3proto abstraction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 31/38] netfilter: nf_tables: avoid global info storage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 28/38] netfilter: nf_tables: add and use helper for module autoload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 33/38] netfilter: nf_osf: add nf_osf_match_one()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 29/38] netfilter: nf_tables: make valid_genid callback mandatory
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 26/38] ipvs: drop conn templates under attack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 27/38] netfilter: Remove useless param helper of nf_ct_helper_ext_add
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 24/38] ipvs: provide just conn to ip_vs_state_name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 25/38] ipvs: add assured state for conn templates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 23/38] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/38] netfilter: conntrack: remove get_timeout() indirection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/38] netfilter: nf_conncount: Early exit in nf_conncount_lookup() and cleanup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/38] netfilter: Kconfig: Change select IPv6 dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/38] netfilter: nf_conncount: Early exit for garbage collection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/38] netfilter: conntrack: remove get_l4proto indirection from l3 protocol trackers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/38] netfilter: conntrack: remove invert_tuple indirection from l3 protocol trackers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/38] netfilter: conntrack: avoid calls to l4proto invert_tuple
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/38] netfilter: conntrack: remove ctnetlink callbacks from l3 protocol trackers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/38] netfilter: conntrack: remove pkt_to_tuple indirection from l3 protocol trackers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/38] netfilter: Kconfig: Make NETFILTER_XT_MATCH_SOCKET select NF_SOCKET_IPV4/6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/38] openvswitch: use nf_ct_get_tuplepr, invert_tuplepr
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/38] netfilter: utils: move nf_ip_checksum* from ipv4 to utils
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/38] netfilter: nft_tproxy: Move nf_tproxy_assign_sock() to nf_tproxy.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/38] netfilter: flowtables: use fixed renew timeout on teardown
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/38] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/38] netfilter: nft_reject_bridge: remove unnecessary ttl set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 01/17] xtables: Fix crash if nft_rule_list_get() fails
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v3 nft] tests: py: Add test cases for tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2 nft] tests: py: Add test cases for tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v2 nft] tests: py: Add test cases for tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v3 nft] Add tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v2 libnftnl] Add tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v4 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH xtables] nft: decode meta l4proto
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 00/17] xtables: Implement ebtables-{save,restore}
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 01/17] xtables: Fix crash if nft_rule_list_get() fails
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH V2 nf 3/3] netfilter: nf_tables: add default set size
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [iptables PATCH 06/17] xtables: Use new callbacks in nft_rule_print_save()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 00/17] xtables: Implement ebtables-{save,restore}
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 09/17] xtables: Merge nft_ipv{4,6}_parse_target()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 02/17] iptables: Replace memset by c99-style initializers
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 10/17] xtables: Eliminate nft_ipv{4,6}_rule_find()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 04/17] xtables: Simplify struct nft_xt_ctx
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 12/17] xtables: Rename {print,save}_rule functions
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 03/17] xtables: Merge {ip,arp}tables_command_state structs
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 08/17] xtables: Get rid of nft_ipv{4,6}_print_header()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 15/17] xtables: Parameter to add_argv() may be const
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 01/17] xtables: Fix crash if nft_rule_list_get() fails
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 14/17] xtables: Pass format to nft_rule_save()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 17/17] xtables: Implement ebtables-{save,restore}
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 13/17] xtables: Introduce save_chain callback
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 07/17] xtables: arp: Make rule_to_cs callback private
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 16/17] xtables: Introduce nft_init_eb()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 11/17] xtables: Get rid of nft_ipv{4,6}_save_counters()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 05/17] xtables: Introduce rule_to_cs/clear_cs callbacks
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: David Ahern <dsahern@xxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: David Ahern <dsahern@xxxxxxxxx>
- [PATCH] netfilter: use PTR_ERR_OR_ZERO()
- From: YueHaibing <yuehaibing@xxxxxxxxxx>
- Re: [PATCH nf-next v8] netfilter: nft_ct: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCHv2 net-next 0/3] Drop IPVS conn templates under attack
- From: Simon Horman <horms@xxxxxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: Michael Richardson <mcr@xxxxxxxxxxxx>
- Re: [PATCH nf-next v8] netfilter: nft_ct: add ct timeout support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v8] netfilter: nft_ct: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH nf-next v2 2/2] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH nf-next v2 1/2] netfilter: Kconfig: Make NF_CT_NETLINK_TIMEOUT depend on NF_CONNTRACK_TIMEOUT
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH V2 nf 3/3] netfilter: nf_tables: add default set size
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: linux-next: Tree for Jul 18 (netfilter)
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- Re: [PATCH V2 nf 3/3] netfilter: nf_tables: add default set size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Matthew Wilcox <willy@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Matthew Wilcox <willy@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Matthew Wilcox <willy@xxxxxxxxxxxxx>
- Re: linux-next: build failure after merge of the ida tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Failed to run nft script with ingress hook for netdev family
- From: "Rosysong" <rosysong@xxxxxxxxxxxx>
- Re: [PATCH v3] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- linux-next: build failure after merge of the ida tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: David Miller <davem@xxxxxxxxxxxxx>
- linux-next: manual merge of the ipvs-next tree with the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- linux-next: build failure after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the net tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH nf] netfilter: conntrack: dccp: treat SYNC/SYNCACK as invalid if no prior state
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: David Ahern <dsahern@xxxxxxxxx>
- heads up, rebasing nf-next ahead
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nfnetlink_osf: add netlink support for osf module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nfnetlink_osf: add netlink support for osf module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: David Ahern <dsahern@xxxxxxxxx>
- Re: [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nfnetlink_osf: add netlink support for osf module
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH nf-next v2] netfilter: nfnetlink_osf: add netlink support for osf module
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH V2 nf 0/3] netfilter: nf_tables: fix set destroying bugs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v3 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Remove useless param helper of nf_ct_helper_ext_add
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/3 nf-next] netfilter: add missing definitions in nf_osf.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next 2/2] netfilter: fix IPV6=m CONNTRACK=y link failure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- KMSAN: uninit-value in __nf_conntrack_find_get
- From: syzbot <syzbot+6f18401420df260e37ed@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: nft_socket: Expose socket mark
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_socket: Break evaluation if no socket found
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: handle meta/lookup with direct call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/5] netfilter: nf_tables: per-netns transactions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 net-next 0/3] Drop IPVS conn templates under attack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Kconfig: Change select dependencies from IPV6 to NF_TABLES_IPV6 and IP6_NF_IPTABLES
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v6] net: netfilter: nf_tables_api: Use id allocation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/6] netfilter: nf_conncount: optimize nf_conncount performance
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 net-next 0/3] Drop IPVS conn templates under attack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 net-next 0/3] Drop IPVS conn templates under attack
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH RFC/RFT net-next 00/17] net: Convert neighbor tables to per-namespace
- [PATCH RFC/RFT net-next 01/17] net/ipv4: rename ipv4_neigh_lookup to ipv4_dst_neigh_lookup
- [PATCH RFC/RFT net-next 02/17] net/neigh: export neigh_find_table
- [PATCH RFC/RFT net-next 04/17] net/ipv4: Remove open coded use of arp table
- [PATCH RFC/RFT net-next 03/17] net/ipv4: wrappers for arp table references
- [PATCH RFC/RFT net-next 05/17] net/ipv6: wrappers for neighbor table references
- [PATCH RFC/RFT net-next 07/17] drivers/net: remove open coding of neighbor tables
- [PATCH RFC/RFT net-next 06/17] net/ipv6: Remove open coded use of neighbor table
- [PATCH RFC/RFT net-next 09/17] net: Remove arp_tbl and nd_tbl from headers
- [PATCH RFC/RFT net-next 08/17] net: Remove nd_tbl from ipv6 stub
- [PATCH RFC/RFT net-next 11/17] net: Change neigh_table_init and neigh_table_clear signature
- [PATCH RFC/RFT net-next 13/17] net/neighbor: Convert internal functions away from neigh_tables
- [PATCH RFC/RFT net-next 10/17] net: Add key_len to neighbor constructor
- [PATCH RFC/RFT net-next 12/17] net/neigh: Change neigh_xmit to take an address family
- [PATCH RFC/RFT net-next 14/17] net/ipv4: Convert arp table to per namespace
- [PATCH RFC/RFT net-next 17/17] net/neighbor: Remove neigh_tables and NEIGH enum
- [PATCH RFC/RFT net-next 16/17] net/decnet: Move neighbor table to per-namespace
- [PATCH RFC/RFT net-next 15/17] net/ipv6: Convert neighbor table to per-namespace
- Re: [PATCH nf-next 3/3] netfilter: nf_osf: add nf_osf_find()
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 1/3 nf-next] netfilter: add missing definitions in nf_osf.h
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: Failed to run nft script with ingress hook for netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH V2 nf 2/3] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- Failed to run nft script with ingress hook for netdev family
- From: "Rosysong" <rosysong@xxxxxxxxxxxx>
- [PATCH nf 4/4] netfilter: nf_tables: don't allow to rename to already-pending name
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 3/4] netfilter: nf_tables: fix memory leaks on chain rename
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/4] netfilter: nf_tables: free flow table struct too
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/4] netfilter: nf_tables: use dev->name directly
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/4] netfilter: nf_tables: fix resource leaks
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] tests: add test case for rename-to-same-name
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: ipset: export indexes via netlink
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH v3] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH V2 nf 2/3] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH V2 nf 2/3] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: add tests for listing objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/3 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [next-20180713][NET] linux-next kernel panics when booting powerpc
- From: Abdul Haleem <abdhalee@xxxxxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: export indexes via netlink
- From: Florent Fourcot <florent.fourcot@xxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- [PATCH v3] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 2/3 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 3/3 nf-next] netfilter: add netlink support for osf module
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 2/3 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/3 nf-next] netfilter: add missing definitions in nf_osf.h
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next v7] netfilter: nft_ct: add ct timeout support
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next v7] netfilter: nft_ct: add ct timeout support
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: nf_osf: add nf_osf_find()
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH v3 nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH nf-next] netfilter: cttimeout: move ctnl_untimeout to nf_conntrack
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH nf-next v7] netfilter: nft_ct: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH v2 nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH v2 nf-next 2/2] netfilter: fix IPV6=m CONNTRACK=y link failure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: nf_osf: add struct nf_osf_hdr_ctx
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nf_osf: add nf_osf_find()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_osf: add nf_osf_match_one()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH 1/2 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH V2 nf] netfilter: nf_tables: fix jumpstack depth validation
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nft] Expose socket mark via socket expression
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v2 nf-next] netfilter: nft_socket: Expose socket mark
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_socket: Break evaluation if no socket found
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: Expose socket mark
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: fix jumpstack depth validation
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: fix IPV6=m CONNTRACK=y link failure
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/2] ipv6: remove dependency of nf_defrag_ipv6 on ipv6 module
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: Expose socket mark
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: Expose socket mark
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH 1/2 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: Expose socket mark
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nf_tables: Expose socket mark
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/2 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH WIP libnftnl] expr: add osf support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 2/2 WIP nf-next] nft: implement the nf_tables_api changes to add osf signatures in nft
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH 1/2 WIP nf-next] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net] netfilter: nf_conntrack: prevent uninit-value in gc_worker
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [PATCH] iptables-restore: free the table lock when skipping a table
- From: Joel Goguen <contact+netfilter@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: Expose socket mark
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH libnftnl] Expose socket mark via socket expression
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nft] Expose socket mark via socket expression
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- nf_tables: Expose socket mark
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: fix jumpstack depth validation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v19 0/8] sched: Add Common Applications Kept Enhanced (cake) qdisc
- From: Toke Høiland-Jørgensen <toke@xxxxxxx>
- [PATCH nf-next 5/5] netfilter: nf_tables: use dedicated mutex to guard transactions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/5] netfilter: nf_tables: avoid global info storage
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/5] netfilter: nf_tables: take module reference when starting a batch
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/5] netfilter: nf_tables: make valid_genid callback mandatory
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/5] netfilter: nf_tables: add and use helper for module autoload
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/5] netfilter: nf_tables: per-netns transactions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] xtables: Support nft suffix for arptables and ebtables
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] xtables: Support nft suffix for arptables and ebtables
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next v19 0/8] sched: Add Common Applications Kept Enhanced (cake) qdisc
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nft] tests: shell: add tests for listing objects
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH V2 nf 3/3] netfilter: nf_tables: add default set size
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH V2 nf 2/3] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH V2 nf 1/3] netfilter: nft_set_hash: add rcu_barrier() in the nft_rhash_destroy()
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH V2 nf 0/3] netfilter: nf_tables: fix set destroying bugs
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH v2 nf-next] netfilter: Kconfig: Change select dependencies from IPV6 to NF_TABLES_IPV6 and IP6_NF_IPTABLES
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH] rule: obj: list only the table containing object
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v6] netfilter: nft_ct: add ct timeout support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] iptables: tests: add test for iptables-save and iptables-restore
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [ANNOUNCE] iptables 1.8.0 release
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [ANNOUNCE] iptables 1.8.0 release
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf 0/4] netfilter: nf_tables: fix set destroying bugs
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf 3/4] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH] netfilter: NFT_SOCKET don't use NF_SOCKET_IPV6 without NF_TABLES_IPV6
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH 0/6] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: ipvs: Fix invalid bytes in IP_VS_MH_TAB_INDEX help text
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] netfilter: x_tables: set module owner for icmp(6) matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/6] netfilter: nf_tables: place all set backends in one single module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] netfilter: nft_compat: explicitly reject ERROR and standard target
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] netfilter: ipv6: nf_defrag: drop skb dst before queueing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] netfilter: nf_conntrack: Fix possible possible crash on module loading.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] nf_conntrack: Fix possible possible crash on module loading.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ipv6: nf_defrag: drop skb dst before queueing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nf-next 1/7] netfilter: nf_conncount: Early exit for garbage collection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nf-next 1/7] netfilter: nf_conncount: Early exit for garbage collection
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Arnd Bergmann <arnd@xxxxxxxx>
- [PATCH] netfilter: xt_tee: fix calling nf_dup_ipv6
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH xtables] extensions: don't bother to build libebt/libarp extensions if nft backend was disabled
- From: Thomas Deutschmann <whissi@xxxxxxxxxx>
- [PATCH v4 nft] Set/print standard chain prios with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH xtables] extensions: don't bother to build libebt/libarp extensions if nft backend was disabled
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: ipv6: nf_defrag: drop skb dst before queueing
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: iptables-1.8.0: Cannot build without libnftnly
- From: Florian Westphal <fw@xxxxxxxxx>
- iptables-1.8.0: Cannot build without libnftnl
- From: Thomas Deutschmann <whissi@xxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: nft_compat: explicitly reject ERROR and standard target
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: nf_tables: fix set destroying bugs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 3/4] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: ipv6: nf_defrag: drop skb dst before queueing
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: Remove useless param helper of nf_ct_helper_ext_add
- From: gfree.wind@xxxxxxxxxxx
- [PATCH] iptables: tests: add test for iptables-save and iptables-restore
- From: Arushi Singhal <arushisinghal19971997@xxxxxxxxx>
- [PATCH nft] tests: py: add ct timeout tests
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH] rule: obj: list only the table containing object
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH v2] ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v6] netfilter: nft_ct: add ct timeout support
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH] iptables: tests: shell: Add README
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl v3 3/3] examples: Add test for assigning timeout objects via rule
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH libnftnl v3 2/3] examples: add nft-ct-timeout-{add,del,get}
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH libnftnl v3 1/3] src: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH libnftnl v3 0/3] Add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH nft v2] src: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- [PATCH nft v2] src: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- [PATCH] iptables: tests: shell: Add README
- From: Arushi Singhal <arushisinghal19971997@xxxxxxxxx>
- Re: KASAN: stack-out-of-bounds Read in vmalloc_fault
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- KASAN: stack-out-of-bounds Read in vmalloc_fault
- From: syzbot <syzbot+7b269953d076326d7de0@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft] nft: set: print dynamic flag when set
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] doc: describe dynamic flag and caveats for packet-path updates
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] evaluate: skip evaluation of datatype concatenations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 nf] netfilter: nft_compat: explicitly reject ERROR and standard target
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: place all set backends in one single module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] src: add --literal option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] doc: update manpage to document --literal option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_compat: explicitly reject builtin targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next v19 4/8] netfilter: Add nf_ct_get_tuple_skb global lookup function
- From: Toke Høiland-Jørgensen <toke@xxxxxxx>
- [PATCH net-next v19 5/8] sch_cake: Add NAT awareness to packet classifier
- From: Toke Høiland-Jørgensen <toke@xxxxxxx>
- [PATCH net-next v19 0/8] sched: Add Common Applications Kept Enhanced (cake) qdisc
- From: Toke Høiland-Jørgensen <toke@xxxxxxx>
- Re: [PATCH v4 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] nf_conntrack: Fix possible possible crash on module loading.
- From: Andrey Ryabinin <aryabinin@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_compat: explicitly reject builtin targets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Arnd Bergmann <arnd@xxxxxxxx>
- [PATCH] netfilter: conntrack: add weak IPV6 dependency
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH nf] netfilter: nft_compat: explicitly reject builtin targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_compat: explicitly reject builtin targets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_compat: explicitly reject builtin targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next] netfilter: fix NETFILTER_XT_TARGET_TEE dependencies
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH v4 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: git.netfilter.org:git is closed - intentionally?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [bug report] net: ipv4: listified version of ip_rcv
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- [ANNOUNCE] iptables 1.8.0 release
- From: Florian Westphal <fw@xxxxxxxxx>
- [bug report] net: ipv4: listified version of ip_rcv
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: git.netfilter.org:git is closed - intentionally?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: export indexes via netlink
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCHv2 net-next 1/3] ipvs: provide just conn to ip_vs_state_name
- From: Julian Anastasov <ja@xxxxxx>
- [PATCHv2 net-next 3/3] ipvs: drop conn templates under attack
- From: Julian Anastasov <ja@xxxxxx>
- [PATCHv2 net-next 2/3] ipvs: add assured state for conn templates
- From: Julian Anastasov <ja@xxxxxx>
- [PATCHv2 net-next 0/3] Drop IPVS conn templates under attack
- From: Julian Anastasov <ja@xxxxxx>
- Re: git.netfilter.org:git is closed - intentionally?
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- git.netfilter.org:git is closed - intentionally?
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- FINAL Reminder: Linux Plumbers Networking Track CFP
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nf-next v6] netfilter: nft_ct: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH nf-next v5] netfilter: nft_ct: add ct timeout support
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: stable request: don't set F_IFACE on ipv6 fib lookups and followup fix
- From: Greg KH <greg@xxxxxxxxx>
- Re: [PATCH 4.14.y] netfilter: nf_tables: fix NULL-ptr in nf_tables_dump_obj()
- From: Greg KH <greg@xxxxxxxxx>
- [PATCH 4.14.y] netfilter: nf_tables: fix NULL-ptr in nf_tables_dump_obj()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v5] netfilter: nft_ct: add ct timeout support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v5] netfilter: nft_ct: add ct timeout support
- From: Harsha Sharma <harshasharmaiitr@xxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH] netfilter: ipset: export indexes via netlink
- From: Florent Fourcot <florent.fourcot@xxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH v4 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH v3 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: x_tables: set module owner for icmp(6) matches
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v3 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: WARNING: ODEBUG bug in do_arpt_get_ctl
- From: Eric Biggers <ebiggers3@xxxxxxxxx>
- Re: WARNING: ODEBUG bug in do_ipt_get_ctl
- From: Eric Biggers <ebiggers3@xxxxxxxxx>
- [PATCH nf] netfilter: nft_compat: explicitly reject builtin targets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v2 nf] netfilter: x_tables: set module owner for icmp(6) matches
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next 0/8] netfilter: conntrack: move ipv4/v6 trackers into core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Kconfig: Make NETFILTER_XT_MATCH_SOCKET select NF_SOCKET_IPV4/6 instead of dependinf on it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Kconfig: Change select dependencies from IPV6 to NF_TABLES_IPV6 and IP6_NF_IPTABLES
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] rule: limit: don't print default burst value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH RFC nft] src: meta: always prefix 'meta' for all tokens
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: display service name with -NN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- netdev 0x12 conference update
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nft] rule: limit: don't print default burst value
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: display service name with -NN
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: handle meta/lookup with direct call
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: BUG: unable to handle kernel (3)
- From: syzbot <syzbot+adfeaaee641dd4fdac43@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft] doc: update manpage to document --literal option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: display service name with -NN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 3/4] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH RFC nft] src: meta: always prefix 'meta' for all tokens
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nft] doc: Add socket expression to man page
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] doc: Add tproxy statement to man page
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nft] doc: Add socket expression to man page
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH RFC nft] src: meta: always prefix 'meta' for all tokens
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: services: remove more exotic protocol names
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 4/4] netfilter: nf_tables: check set->size before decreasing set->nelems
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 4/4] netfilter: nf_tables: check set->size before decreasing set->nelems
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH] netfilter: ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 3/4] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] include: missing C++ linkage in headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nft] Set/print standard chain priorities with textual names
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nf-next 6/6] netfilter: nf_conncount: Add list lock and gc worker, and RCU for init tree search
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- [PATCH nf-next 5/6] netfilter: nf_conncount: Split insert and traversal
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- [PATCH nf-next 4/6] netfilter: nf_conncount: Move locking into count_tree()
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- [PATCH nf-next 3/6] netfilter: nf_conncount: Early exit in nf_conncount_lookup() and cleanup
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- [PATCH nf-next 2/6] netfilter: nf_conncount: Switch to plain list
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- [PATCH nf-next 1/6] netfilter: nf_conncount: Early exit for garbage collection
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- [PATCH nf-next 0/6] netfilter: nf_conncount: optimize nf_conncount performance
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- Re: [RFC nf-next 0/7] netfilter: nf_conncount: optimize nf_conncount performance
- From: Yi-Hung Wei <yihung.wei@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] netfilter: ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCH] netfilter: ipvs: Fix invalid bytes in IP_VS_MH_TAB_INDEX help text
- From: Ben Hutchings <ben@xxxxxxxxxxxxxxx>
- Re: [RFC nf-next 0/7] netfilter: nf_conncount: optimize nf_conncount performance
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC nf-next 6/7] netfilter: nf_conncount: Add list lock and use RCU for init tree search
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] nftables: tests: shell: Replace "%" with "#" or "$"
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- Re: [PATCH] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- Re: [PATCH nf 1/4] netfilter: nft_set_hash: fix panic when destroying set
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH nf 1/4] netfilter: nft_set_hash: fix panic when destroying set
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 4/4] netfilter: nf_tables: check set->size before decreasing set->nelems
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: nf_conntrack: resolve clash for matching conntracks
- From: Martynas Pumputis <martynas@weave.works>
- [PATCH v2 nft] test: Add test cases for tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Reminder: Linux Plumbers Networking Track CFP
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH v2 nft] Add tproxy support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables] ebtables-nft: add stp match
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 3/4] netfilter: nft_set_rbtree: fix panic when destroying set by GC
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 4/4] netfilter: nf_tables: check set->size before decreasing set->nelems
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 2/4] netfilter: nft_set_hash: add rcu_barrier() in the nft_rhash_destroy()
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 1/4] netfilter: nft_set_hash: fix panic when destroying set
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH nf 0/4] netfilter: nf_tables: fix set destroying bugs
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH] nftables: tests: shell: Replace "%" with "#" or "$"
- From: Arushi Singhal <arushisinghal19971997@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH xtables 1/4] ebtables-nft: don't crash on ebtables -X
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH xtables] tests: add script that mimics firewalld startup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 nft] Add tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v2 nft] Add tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH v3 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH xtables] xtables: display legacy/nf_tables flavor in error messages, too
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] Add tproxy support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] Add tproxy support
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH v2 nf-next 8/8] netfilter: conntrack: remove l3proto abstraction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 7/8] netfilter: conntrack: remove get_timeout() indirection
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 6/8] netfilter: conntrack: avoid l4proto pkt_to_tuple calls
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 5/8] netfilter: conntrack: avoid calls to l4proto invert_tuple
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 4/8] netfilter: conntrack: remove get_l4proto indirection from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 3/8] netfilter: conntrack: remove invert_tuple indirection from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 2/8] netfilter: conntrack: remove pkt_to_tuple indirection from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 1/8] netfilter: conntrack: remove ctnetlink callbacks from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 0/8] netfilter: conntrack: move ipv4/v6 trackers into core
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH nf-next 6/8] netfilter: conntrack: avoid l4proto pkt_to_tuple calls
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- [PATCH xtables 4/4] tests: add a few simple tests for list/new/delete
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables 3/4] ebtables-nft: make -L, -X CHAINNAME work
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables 2/4] ebtables-nft: remove exec_style
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables 1/4] ebtables-nft: don't crash on ebtables -X
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 8/8] netfilter: conntrack: remove l3proto abstraction
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nf-next 8/8] netfilter: conntrack: remove l3proto abstraction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 7/8] netfilter: conntrack: remove get_timeout() indirection
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 6/8] netfilter: conntrack: avoid l4proto pkt_to_tuple calls
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 5/8] netfilter: conntrack: avoid calls to l4proto invert_tuple
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/8] netfilter: conntrack: remove get_l4proto indirection from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/8] netfilter: conntrack: remove invert_tuple indirection from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/8] netfilter: conntrack: remove pkt_to_tuple indirection from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/8] netfilter: conntrack: remove ctnetlink callbacks from l3 protocol trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/8] netfilter: conntrack: move ipv4/v6 trackers into core
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/6] build: rename sed source files to .in
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/6] build: drop install -o/-g root
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: Kconfig: Make NETFILTER_XT_MATCH_SOCKET select NF_SOCKET_IPV4/6 instead of dependinf on it
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nf-next] netfilter: Kconfig: Change select dependencies from IPV6 to NF_TABLES_IPV6 and IP6_NF_IPTABLES
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nf-next v6] net: netfilter: nf_tables_api: Use id allocation
- From: Varsha Rao <rvarsha016@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Configuration fixes for ip/nftables socket matching
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 nf-next] netfilter: Add native tproxy support for nf_tables
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH nf] netfilter: x_tables: set module owner for builtin matches/targets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf|nf-next] netfilter: Refactor nf_tproxy_get_sock_v{4,6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] extensions: ebt_string: take action if snprintf discards data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Eric Leblond <eric@xxxxxxxxx>
- Re: [PATCH 1/2] iptables: tests: shell: Add README
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH v2 nf] netfilter: nf_tproxy: fix possible non-linear access to transport header
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf|nf-next] netfilter: Refactor nf_tproxy_get_sock_v{4,6}
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Configuration fixes for ip/nftables socket matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Configuration fixes for ip/nftables socket matching
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- [PATCH] netfilter: ipset: list:set: Decrease refcount synchronously on deletion and replace
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft] configure.ac: docbook2man invalid syntax error
- From: Máté Eckl <ecklm94@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Configuration fixes for ip/nftables socket matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2] iptables: tests: shell: Add README
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 2/2] iptables: tests: shell: Add testcase and update shell test-suite
- From: Arushi Singhal <arushisinghal19971997@xxxxxxxxx>
- [PATCH 1/2] iptables: tests: shell: Add README
- From: Arushi Singhal <arushisinghal19971997@xxxxxxxxx>
- Re: [PATCH 0/6] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nft] src: allow ifname use in concatenated named sets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] doc: fix some spellos and the dash escape
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] doc: fix some spellos and the dash escape
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: ebtables: modernize build
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: ebtables: modernize build
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH xtables 1/3] xtables: rename xt-multi binaries to -nft, -legacy
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Configuration fixes for ip/nftables socket matching
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] extensions: ebt_string: take action if snprintf discards data
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [PATCH nf-next WIP] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next WIP] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5] net: netfilter: nf_tables_api: Use id allocation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next WIP] netfilter: implement Passive OS fingerprint module in nft_osf
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- [PATCH libnftnl WIP] expr: add osf support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Configuration fixes for ip/nftables socket matching
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] extensions: ebt_string: take action if snprintf discards data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] netfilter: nf_queue: augment nfqa_cfg_policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] netfilter: ipv6: nf_defrag: reduce struct net memory waste
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/6] netfilter: nf_ct_helper: Fix possible panic after nf_conntrack_helper_unregister
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] netfilter: nf_log: fix uninit read in nf_log_proc_dostring
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] netfilter: nf_log: don't hold nf_log_mutex during user access
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] netfilter: nf_conncount: fix garbage collection confirm race
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_reject_bridge: remove unnecessary ttl set
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- Re: [PATCH nf|nf-next] netfilter: Refactor nf_tproxy_get_sock_v{4,6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] openvswitch: use nf_ct_get_tuplepr, invert_tuplepr
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: utils: move nf_ip6_checksum* from ipv6 to utils
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: utils: move nf_ip_checksum* from ipv4 to utils
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: Move nf_tproxy_assign_sock to nf_tproxy.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtables: use fixed renew timeout on teardown
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_reject_bridge: remove unnecessary ttl set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 net-next 1/2] netfilter: check if the socket netns is correct.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2 net-next 2/2] skbuff: preserve sock reference when scrubbing the skb.
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH v2 net-next 2/2] skbuff: preserve sock reference when scrubbing the skb.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH v2 net-next 1/2] netfilter: check if the socket netns is correct.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- [PATCH v2 net-next 0/2] net: preserve sock reference when scrubbing the skb.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH xtables 1/3] xtables: rename xt-multi binaries to -nft, -legacy
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Flavio Leitner <fbl@xxxxxxxxxx>
- Re: [PATCH xtables 1/3] xtables: rename xt-multi binaries to -nft, -legacy
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH xtables 3/3] tests: add initial save/restore test cases
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables 2/3] tests: adapt test suite to run with legacy+nftables based binaries
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables 1/3] xtables: rename xt-multi binaries to -nft, -legacy
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 6/6] build: move to automake
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 3/6] build: use autoconf-style placeholders in sed-ed files
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 5/6] Add .gitignore
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 4/6] extensions: use __attribute__((constructor)) for autoregistration
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 1/6] build: drop install -o/-g root
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 2/6] build: rename sed source files to .in
- From: Jan Engelhardt <jengelh@xxxxxxx>
- ebtables: modernize build
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH xtables] xtables-restore: init table before processing policies
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH] ebtables: abandon KERNEL_INCLUDES and use double quotes
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net-next] net: preserve sock reference when scrubbing the skb.
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]