Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH nf 1/1] netfilter: expect: Make sure the max_expected limit is effective
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf V2] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/4] netfilter: ipset: generalize netmask to support cidr and mask values
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH nf 1/1] netfilter: expect: Make sure the max_expected limit is effective
- From: gfree.wind@xxxxxxxxxxx
- [ANNOUNCE] Linux Security Summit 2017 - CFP
- From: James Morris <jmorris@xxxxxxxxx>
- [ANNOUNCE]: New sponsor and accepted talk
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH V4 2/2] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH V4 1/2] netfilter: xt_AUDIT: use consistent ipv4 network offset
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH nf V2] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nft] tests: nft removes required payload protocol expressions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Florian Westphal <fw@xxxxxxxxx>
- [Netdev] ANNOUNCE: New silver sponsor!
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ulogd: add +1 char for null char
- From: Alexandru Ardelean <ardeleanalex@xxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/5] netfilter: Clean up tests if NULL returned on failure
- From: SIMRAN SINGHAL <singhalsimran0@xxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 0/5] netfilter: Clean up tests if NULL returned on failure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_statistic: Complete nft translator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnetfilter_cthelper] examples: kill the "invalid argument" error in nftc-helper-add
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH libnetfilter_cthelper] examples: kill the "invalid argument" error in nftc-helper-add
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH V4 1/2] netfilter: xt_AUDIT: use consistent ipv4 network offset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: add nft_is_base_chain() helper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 3/3] sets: Fix for missing space after last element
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2,v3] netfilter: nfnetlink_cthelper: fix runtime expectation policy updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 2/3] tests: shell: netns/0003many_0: Fix cleanup after error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 1/3] tests: Add test cases for nested anonymous sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH V4 1/2] netfilter: xt_AUDIT: use consistent ipv4 network offset
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH V4 1/2] netfilter: xt_AUDIT: use consistent ipv4 network offset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 2/3] tests: shell: netns/0003many_0: Fix cleanup after error
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: [PATCH] ulogd: add +1 char for null char
- From: Alexandru Ardelean <ardeleanalex@xxxxxxxxx>
- [PATCH V4 2/2] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH V4 1/2] netfilter: xt_AUDIT: use consistent ipv4 network offset
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nf 1/2,v3] netfilter: nfnetlink_cthelper: fix runtime expectation policy updates
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH nf v2 1/1] netfilter: helper: Add the rcu lock when call __nf_conntrack_helper_find
- From: gfree.wind@xxxxxxxxxxx
- RE: [PATCH RESENT nf 1/1] netfilter: ctlink: Fix one possible use-after-free in ctnetlink_create_expect
- From: "Gao Feng" <gfree.wind@xxxxxxxxxxx>
- Re: [PATCH 2/2 nf] netfilter: cthelper: Fix memory leak
- From: jeffy <jeffy.chen@xxxxxxxxxxxxxx>
- [PATCH nf-next v2 1/1] netfilter: helper: Remove useless rcu lock when get expectfn
- From: gfree.wind@xxxxxxxxxxx
- [PATCH 1/2] netfilter: ipset: warn users of list:set that parameter 'size' is ignored
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH] netfilter: ipset: print out warnings generated by commands
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- [PATCH 2/2] netfilter: ipset: warn users of list:set that parameter 'size' is ignored
- From: Vishwanath Pai <vpai@xxxxxxxxxx>
- RE: [PATCH RESENT nf 1/1] netfilter: ctlink: Fix one possible use-after-free in ctnetlink_create_expect
- From: "Gao Feng" <gfree.wind@xxxxxxxxxxx>
- [PATCH RESENT nf 1/1] netfilter: ctlink: Fix one possible use-after-free in ctnetlink_create_expect
- From: gfree.wind@xxxxxxxxxxx
- [PATCH nf v4 0/2] Fix invoking expectfn unloaded
- From: gfree.wind@xxxxxxxxxxx
- [PATCH nf v4 1/2] netfilter: helper: Rename struct nf_ct_helper_expectfn to nf_ct_nat_helper
- From: gfree.wind@xxxxxxxxxxx
- [PATCH nf v4 2/2] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: gfree.wind@xxxxxxxxxxx
- [nft PATCH 1/3] tests: Add test cases for nested anonymous sets
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 3/3] sets: Fix for missing space after last element
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/3] tests: shell: netns/0003many_0: Fix cleanup after error
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 5/5] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [PATCH v2] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Stephen Hemminger <stephen@xxxxxxxxxxxxxxxxxx>
- [PATCH v2] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- Re: [PATCH 00/22] Netfilter/IPVS updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH] ulogd: use strncpy instead of memcpy
- From: Eric Leblond <eric@xxxxxxxxx>
- Re: [PATCH] ulogd: add +1 char for null char
- From: Eric Leblond <eric@xxxxxxxxx>
- [PATCH nft] src: allow update of net base w. meta l4proto icmpv6
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 3/5] ipset: hash:ipport: netmask support
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 2/5] ipset: hash:ip: add support for new netmask types
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 5/5] hash:ip,port: add netmask support to man page
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 0/5] ipset: Extend netmask support for userspace
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 4/5] hash:ip: add new netmask support to man page
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 1/5] ipset: netmask: expand to support cidr and full mask
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 0/4] netfilter: ipset: Extend netmask support for kernel
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 3/4] netfilter: ipset: hash:ip: add support for new netmask types
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 1/4] net: netfilter: add nf_inet_addr_mask_inplace helper fn
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 4/4] netfilter: ipset: hash:ipport: add netmask support
- From: Josh Hunt <johunt@xxxxxxxxxx>
- [PATCH 2/4] netfilter: ipset: generalize netmask to support cidr and mask values
- From: Josh Hunt <johunt@xxxxxxxxxx>
- Re: [PATCH 2/2] netfilter: ipvs: Compress return logic
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf 5/5] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [Netdev ANNOUNCE]: Two new talks on network emulators and zero copy sendmsg
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nf 5/5] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH nf 1/2,v3] netfilter: nfnetlink_cthelper: fix runtime expectation policy updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 3/5] netfilter: drop const qualifier from struct nf_conntrack_expect_policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 3/5] netfilter: drop const qualifier from struct nf_conntrack_expect_policy
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [PATCH nf 2/5] netfilter: nfnl_cthelper: fix incorrect helper->expect_class_max
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 5/5] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- RE: [PATCH net-next 1/1] netfilter: helper: Remove the rcu lock in nf_ct_helper_expectfn_find_by_name and nf_ct_helper_expectfn_find_by_symbol.
- From: 高峰 <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: Interrest in a ASA-like packet tracer?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/5] netfilter: nfnl_cthelper: fix incorrect helper->expect_class_max
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- RE: [PATCH nf v3 2/2] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: "Gao Feng" <gfree.wind@xxxxxxxxxxx>
- Re: [PATCH net-next 1/1] netfilter: helper: Remove the rcu lock in nf_ct_helper_expectfn_find_by_name and nf_ct_helper_expectfn_find_by_symbol.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/5] netfilter: nfnl_cthelper: don't report error if NFCTH_PRIV_DATA_LEN is empty
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [PATCH nf v3 2/2] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables v2 2/2] iptables-restore: support acquiring the lock.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 2/2] netfilter: ipvs: Compress return logic
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH v2 1/2] netfilter: ipset: Compress return logic
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH v2 0/2] netfilter: Compress return logic
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- Re: [nft PATCH 0/2] Some fixes for nested sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/2] netfilter: ipset: Compress return logic
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 1/2,v2] netfilter: nfnetlink_cthelper: fix runtime expectation policy updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2] netfilter: ipvs: Compress return logic
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- Re: [PATCH nf 4/5] netfilter: nfnl_cthelper: fix memory leak when do update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/2] netfilter: ,netdev@xxxxxxxxxxxxxxx
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 2/2 nf] netfilter: cthelper: Fix memory leak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/2 nf] netfilter: nfnetlink_cthelper: fix runtime expectation policy updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/2] netfilter: Remove unnecessary cast on void pointer
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 1/2] netfilter: ipset: Remove unnecessary cast on void pointer
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 2/2] netfilter: Remove unnecessary cast on void pointer
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- Re: [PATCH] [RESENT]netfilter: nfnetlink_cthelper: Fix memory leak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [RESENT]netfilter: nfnetlink_cthelper: Fix memory leak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_cthelper] examples: fix double free in nftc-helper-add
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 2/5] netfilter: nfnl_cthelper: fix incorrect helper->expect_class_max
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 3/5] netfilter: drop const qualifier from struct nf_conntrack_expect_policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 5/5] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 4/5] netfilter: nfnl_cthelper: fix memory leak when do update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Bridge] [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/5] netfilter: nfnl_cthelper: don't report error if NFCTH_PRIV_DATA_LEN is empty
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5] netfilter: Clean up tests if NULL returned on failure
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 1/5] netfilter: ipvs: Clean up tests if NULL returned on failure
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 5/5] netfilter: xt_TEE: Clean up tests if NULL returned on failure
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 2/5] netfilter: Clean up tests if NULL returned on failure
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 3/5] netfilter: nf_tables_api: Clean up tests if NULL returned on failure
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH 4/5] netfilter: nfnetlink: Clean up tests if NULL returned on failure
- From: simran singhal <singhalsimran0@xxxxxxxxx>
- [PATCH nf v3 1/2] netfilter: helper: Rename struct nf_ct_helper_expectfn to nf_ct_nat_helper
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf v3 0/2] Fix invoking expectfn unloaded
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf v3 2/2] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [Bridge] [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- [PATCH nf v3 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: [NetDev-tech] [NetDev] [Netdev ANNOUNCE]: New tc workshop accepted
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [NetDev] [Netdev ANNOUNCE]: New tc workshop accepted
- From: Mathieu Desnoyers <mathieu.desnoyers@xxxxxxxxxxxx>
- [Netdev ANNOUNCE]: New tc workshop accepted
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [nft PATCH 1/2] evaluate: set: Allow for set elems to be sets
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/2] Some fixes for nested sets
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/2] evaluate: set: Fix nested set merge size adjustment
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- [PATCH libnetfilter_cthelper] src: fix incorrect building and parsing of the NFCTH_POLICY_SETX attribute
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf] netfilter: invoke synchronize_rcu after set the _hook_ to NULL
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] [netfilter-next] netfilter: remove unused refcount variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Interrest in a ASA-like packet tracer?
- From: Oliver Schröder <netfilter@xxxxxxxxxxxx>
- [PATCH] [netfilter-next] netfilter: remove unused refcount variable
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: [PATCH nft 2/3] parser_bison: Allow flushing maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 3/3] doc: Document add / delete element operations of sets and maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/3] parser_bison: Allow flushing flow tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/22] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/22] netfilter: nft_hash: support of symmetric hash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/22] netfilter: Use pr_cont where appropriate
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/22] netfilter: nft_hash: rename nft_hash to nft_jhash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- [PATCH 12/22] netfilter: nft_fib: Support existence check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/22] netfilter: bridge: remove unneeded rcu_read_lock
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/22] netfilter: nf_conntrack: reduce resolve_normal_ct args
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/22] netfilter: arp_tables: remove redundant check on ret being non-zero
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/22] netfilter: nf_reject: remove unused variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/22] ipvs: Document sysctl sync_ports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/22] ipvs: Document sysctl sync_qlen_max and sync_sock_size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/22] netfilter: fix the warning on unused refcount variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/22] ipvs: fix sync_threshold description and add sync_refresh_period, sync_retries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/22] netfilter: nf_tables: validate the expr explicitly after init successfully
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/22] netfilter: nft_set_rbtree: use per-set rwlock to improve the scalability
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/22] netfilter: provide nft_ctx in object init function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/22] netfilter: nf_tables: add nft_set_lookup()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/22] ipvs: Document sysctl pmtu_disc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/22] netfilter: refcounter conversions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/22] netfilter: limit: use per-rule spinlock to improve the scalability
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/22] ipvs: remove an annoying printk in netns init
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/22] netfilter: nft_ct: add helper set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/22] netfilter: nft_exthdr: Allow checking TCP option presence, too
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf v2 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH] netfilter: fix the warning on unused refcount variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: fix the warning on unused refcount variable
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- Re: linux-next: build warning after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [PATCH] ulogd: add +1 char for null char
- From: Alexandru Ardelean <ardeleanalex@xxxxxxxxx>
- RE: linux-next: build warning after merge of the netfilter-next tree
- From: "Reshetova, Elena" <elena.reshetova@xxxxxxxxx>
- [PATCH nf 1/1] netfilter: snmp: Fix one possible panic when snmp_trap_helper fail to register
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- linux-next: build warning after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- [PATCH nf 3/5] netfilter: drop const qualifier from struct nf_conntrack_expect_policy
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf 2/5] netfilter: nfnl_cthelper: fix incorrect helper->expect_class_max
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf 1/5] netfilter: nfnl_cthelper: don't report error if NFCTH_PRIV_DATA_LEN is empty
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf 4/5] netfilter: nfnl_cthelper: fix memory leak when do update
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH libnetfilter_cthelper] examples: fix double free in nftc-helper-add
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf 5/5] netfilter: nfnl_cthelper: fix a race when walk the nf_ct_helper_hash table
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf 0/5] netfilter: nfnl_cthelper: fix some bugs
- From: Liping Zhang <zlpnobody@xxxxxxx>
- ANNOUNCE: New talk accepted! Droplet: DDoS countermeasures powered by BPF + XDP
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [NetDev] [NetDev-tech] ANNOUNCE: New sponsor Netronome
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- Re: [NetDev-tech] [NetDev] ANNOUNCE: New sponsor Netronome
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [NetDev-tech] [NetDev] ANNOUNCE: New sponsor Netronome
- From: Alexis Green <agreen@xxxxxxxxxxxxx>
- Re: [NetDev-tech] [NetDev] ANNOUNCE: New sponsor Netronome
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [NetDev-tech] [NetDev] ANNOUNCE: New sponsor Netronome
- From: Amine Aouled Hamed <amine.ahd@xxxxxxxxx>
- Re: [NetDev] ANNOUNCE: New sponsor Netronome
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- ANNOUNCE: New talk accepted on TCP algorithms performance on wireless LTE networks
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [NetDev] ANNOUNCE: New sponsor Netronome
- From: Mathieu Desnoyers <mathieu.desnoyers@xxxxxxxxxxxx>
- Re: ANNOUNCE: New sponsor Netronome
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: ANNOUNCE: New sponsor Netronome
- From: Amine Aouled Hamed <amine.ahd@xxxxxxxxx>
- ANNOUNCE: New sponsor Netronome
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- [PATCH v2 nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nf 1/1] netfilter: ctlink: Fix one possible use-after-free in ctnetlink_create_expect
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: ctlink: Fix one possible use-after-free in ctnetlink_create_expect
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf 1/1] netfilter: ctlink: Fix one possible use-after-free in ctnetlink_create_expect
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH 1/7] net, netfilter: convert ip_vs_conn.refcnt from atomic_t to refcount_t
- From: kbuild test robot <lkp@xxxxxxxxx>
- [nf-next:master 1/1] net/netfilter/nfnetlink_acct.c:329: warning: unused variable 'refcount'
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- Re: [PATCH iptables v2 2/2] iptables-restore: support acquiring the lock.
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- ANNOUNCE: New tutorial on XDP
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nft 3/3] doc: Document add / delete element operations of sets and maps
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft 1/3] parser_bison: Allow flushing flow tables
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft 2/3] parser_bison: Allow flushing maps
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH iptables v2 2/2] iptables-restore: support acquiring the lock.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables v2 1/2] iptables: remove duplicated argument parsing code
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] iptables: move XT_LOCK_NAME from CFLAGS to config.h.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: cthelper: fix leak in nfnl_cthelper_del()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: ctlink: Fix one possible memleak in nfnl_cthelper_create
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: ipset 6.32 - build failure
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: cthelper: no need for rcu read side on helper creation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: ipset 6.32 - build failure
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [nft PATCH v2 2/2] doc: Describe ICMP(v6) expression and types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 1/2] proto: Add some exotic ICMPv6 types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net, netfilter: refcounter conversions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/7] net, netfilter refcounter conversions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [GIT PULL 0/5] IPVS Updates for v4.12
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] conntrack: Support IPv6 NAT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: sip: Use NF_DROP and NF_ACCEPT instead of 0 and 1
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf-next 1/4] netfilter: amanda: Correct the return value comparison of the func nf_nat_mangle_udp_packet
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf-next 3/4] netfilter: helper: Use the bool instead of int type
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf-next 2/4] netfilter: irc: Correct the return value comparison of the func nf_nat_mangle_tcp_packet
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf-next 0/4] Refine the nat helper codes
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH 05/10] netfilter: nf_tables: fix mismatch in big-endian system
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- ANNOUNCE: New Platinum sponsor - Facebook
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH 5/5] ipvs: Document sysctl pmtu_disc
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [nft PATCH v2 2/2] doc: Describe ICMP(v6) expression and types
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 1/2] proto: Add some exotic ICMPv6 types
- From: Phil Sutter <phil@xxxxxx>
- [PATCH 3/5] ipvs: Document sysctl sync_qlen_max and sync_sock_size
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH 4/5] ipvs: Document sysctl sync_ports
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [GIT PULL 0/5] IPVS Updates for v4.12
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH 1/5] ipvs: remove an annoying printk in netns init
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH 2/5] ipvs: fix sync_threshold description and add sync_refresh_period, sync_retries
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH] conntrack: Support IPv6 NAT
- From: Neil Wilson <neil@xxxxxxxxxxx>
- Re: conntrack (possibly) hangs on our ARM CPU in case we delete 5k+ connections as fast as possible
- From: Peter Marczis <peter.marczis@xxxxxxxxxxxxxxxxxxxx>
- RE: [PATCH 05/10] netfilter: nf_tables: fix mismatch in big-endian system
- From: David Laight <David.Laight@xxxxxxxxxx>
- RE: [PATCH 07/10] netfilter: Force fake conntrack entry to be at least 8 bytes aligned
- From: David Laight <David.Laight@xxxxxxxxxx>
- [PATCH] net, netfilter: refcounter conversions
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- Re: [PATCH iptables 1/2] iptables: remove duplicated argument parsing code
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH iptables v2 1/2] iptables: remove duplicated argument parsing code
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH iptables v2 2/2] iptables-restore: support acquiring the lock.
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH iptables v2]: Support the iptables lock in ip[6]tables-restore
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- RE: [PATCH 0/7] net, netfilter refcounter conversions
- From: "Reshetova, Elena" <elena.reshetova@xxxxxxxxx>
- [PATCH] iptables: move XT_LOCK_NAME from CFLAGS to config.h.
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH nf 1/1] netfilter: ctlink: Fix one possible memleak in nfnl_cthelper_create
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH iptables 1/2] iptables: remove duplicated argument parsing code
- From: Subash Abhinov Kasiviswanathan <subashab@xxxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 00/10] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] proto: Add some exotic ICMPv6 types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- Re: [nft PATCH] proto: Add some exotic ICMPv6 types
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/10] netfilter: nf_tables: set pktinfo->thoff at AH header if found
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/10] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/10] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/10] netfilter: bridge: honor frag_max_size when refragmenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/10] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/10] netfilter: nf_tables: fix mismatch in big-endian system
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/10] netfilter: nf_nat_sctp: fix ICMP packet to be dropped accidently
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/10] netfilter: don't track fragmented packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/10] netfilter: Force fake conntrack entry to be at least 8 bytes aligned
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/10] Revert "netfilter: nf_tables: add flush field to struct nft_set_iter"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/10] netfilter: nft_ct: do cleanup work when NFTA_CT_DIRECTION is invalid
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl 0/2] add backend support to define ct helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nftables 0/7] ct helper set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_ct: do cleanup work when NFTA_CT_DIRECTION is invalid
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] proto: Add some exotic ICMPv6 types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] proto: Add some exotic ICMPv6 types
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v2 nftables 0/7] ct helper set support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 2/7] evaluate: refactor CMD_OBJ_QUOTA/COUNTER handling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 1/7] src: add initial ct helper support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 6/7] tests: add insert-failure test
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 5/7] tests: py: add ct helper tests
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 7/7] doc: ct helper objects and helper set support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 3/7] src: allow listing all ct helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nftables 4/7] src: implement add/create/delete for ct helper objects
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_ct: do cleanup work when NFTA_CT_DIRECTION is invalid
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- [PATCH nf] netfilter: nft_ct: do cleanup work when NFTA_CT_DIRECTION is invalid
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH] netfilter: logging copyrights is useless
- From: Harald Welte <laforge@xxxxxxxxxxxxx>
- [PATCH iptables 1/2] iptables: remove duplicated argument parsing code
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH iptables]: Support the iptables lock in ip[6]tables-restore
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH iptables 2/2] iptables-restore: support acquiring the lock.
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- [PATCH] netfilter: logging copyrights is useless
- From: Corentin Labbe <clabbe.montjoie@xxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/7] net, netfilter refcounter conversions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- ANNOUNCE: New Talk: Story of a Network Virtualization and it's future in Software and in Hardware
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nft 6/9] tests: py: add ct helper tests
- From: Florian Westphal <fw@xxxxxxxxx>
- [ANNOUNCE] 13th Netfilter Workshop nearby Faro, Portugal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/7] net, netfilter: convert ip_vs_conn.refcnt from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 0/7] net, netfilter refcounter conversions
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 2/7] net, netfilter: convert ip_vs_dest.refcnt from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 3/7] net, netfilter: convert ctnl_timeout.refcnt from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 4/7] net, netfilter: convert nf_acct.refcnt from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 6/7] net, netfilter: convert nfulnl_instance.use from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 5/7] net, netfilter: convert nf_conntrack_expect.use from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- [PATCH 7/7] net, netfilter: convert clusterip_config.refcount and clusterip_config.entries from atomic_t to refcount_t
- From: Elena Reshetova <elena.reshetova@xxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_statistic: Complete nft translator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 9/9] doc: helper assignement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 6/9] tests: py: add ct helper tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/9] ct helper set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft 5/9] ct: add conntrack event mask support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] bridge: ebtables: fix reception of frames DNAT-ed to bridge device
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: ctlink: Remove duplicated condition check in nfnl_cthelper_create
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nft 5/9] ct: add conntrack event mask support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 8/9] doc: ct zone set support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 9/9] doc: helper assignement
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 7/9] files: provide 'raw' table equivalent
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 6/9] tests: py: add ct helper tests
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 5/9] ct: add conntrack event mask support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/9] src: implement add/create/delete for ct helper objects
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/9] src: allow listing all ct helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/9] evaluate: refactor CMD_OBJ_QUOTA/COUNTER handling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/9] src: add initial ct helper support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/9] ct helper set support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 2/2] src: ct helper support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 1/2] object: extend set/get api for u8/u16 types
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 0/2] add backend support to define ct helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_statistic: Complete nft translator
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- ANNOUNCE: New talk accepted on Netesto tool suite
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: conntrack (possibly) hangs on our ARM CPU in case we delete 5k+ connections as fast as possible
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: conntrack (possibly) hangs on our ARM CPU in case we delete 5k+ connections as fast as possible
- From: Peter Marczis <peter.marczis@xxxxxxxxxxxxxxxxxxxx>
- Re: conntrack (possibly) hangs on our ARM CPU in case we delete 5k+ connections as fast as possible
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] iptables: set the path of the lock file via a configure option.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- conntrack (possibly) hangs on our ARM CPU in case we delete 5k+ connections as fast as possible
- From: Peter Marczis <peter.marczis@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH] iptables: set the path of the lock file via a configure option.
- From: Lorenzo Colitti <lorenzo@xxxxxxxxxx>
- Re: [PATCH net-next 1/1] netfilter: helper: Remove the rcu lock in nf_ct_helper_expectfn_find_by_name and nf_ct_helper_expectfn_find_by_symbol.
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- [PATCH net-next 1/1] netfilter: helper: Remove the rcu lock in nf_ct_helper_expectfn_find_by_name and nf_ct_helper_expectfn_find_by_symbol.
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf 1/1] netfilter: helper: Fix possible panic caused by invoking expectfn unloaded
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH net] bridge: drop netfilter fake rtable unconditionally
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: drop netfilter fake rtable unconditionally
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_set_rbtree: use per-set rwlock to improve the scalability
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: limit: use per-rule spinlock to improve the scalability
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conntrack: reduce resolve_normal_ct args
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: ip_rcv_finish() NULL pointer kernel panic
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: ip_rcv_finish() NULL pointer kernel panic
- From: Dan Streetman <dan.streetman@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_statistic: Complete nft translator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] bridge: drop netfilter fake rtable unconditionally
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] bridge: drop netfilter fake rtable unconditionally
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] extensions: libxt_statistic: Complete nft translator
- From: Phil Sutter <phil@xxxxxx>
- ANNOUNCE: New talk Busypolling next generation
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: [nf-next PATCH] nftables: fib: Support existence check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] netfilter: helper set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Force fake conntrack entry to be at least 8 bytes aligned
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Force fake conntrack entry to be at least 8 bytes aligned
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Force fake conntrack entry to be at least 8 bytes aligned
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: bridge: honor frag_max_size when refragmenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix missmatch in big-endian system
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2 nf] Revert "netfilter: nf_tables: add flush field to struct nft_set_iter"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/2 nf] netfilter: nft_set_bitmap: keep a list of dummy elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 0/3] Follow-up to boolean type and existence checks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] expr: exthdr: Display NFT_EXTHDR_F_PRESENT in debug output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCHv2] fib: Add support for NFTA_FIB_F_PRESENT flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: fix crash when inputting an incomplete set add command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] ipset 6.32 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [ANNOUNCE] ipset 6.32 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- ANNOUNCE: New talk accepted: TIPC Overlapping Ring Neighbor Monitoring Algorithm
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_set_rbtree: use per-set rwlock to improve the scalability
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [nft PATCH v2 2/3] tests: Adjust for changed exthdr debug output
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 3/3] doc: Document boolean type and applications
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 0/3] Follow-up to boolean type and existence checks
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 1/3] fib: Support existence check
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH] expr: exthdr: Display NFT_EXTHDR_F_PRESENT in debug output
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCHv2] fib: Add support for NFTA_FIB_F_PRESENT flag
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: limit: use per-rule spinlock to improve the scalability
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nft] src: fix crash when inputting an incomplete set add command
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [nft PATCH 4/5] fib: Support existence check
- From: Phil Sutter <phil@xxxxxx>
- [PATCH 1/2] harmonize log file defaults with ulogd.conf
- From: Kaarle Ritvanen <kaarle.ritvanen@xxxxxxxxxxxxx>
- [PATCH 2/2] rotate all default output files
- From: Kaarle Ritvanen <kaarle.ritvanen@xxxxxxxxxxxxx>
- Re: [PATCH 3/3] libxtables: avoid returning duplicate address for host resolution
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 5/5] doc: Document boolean type and applications
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 4/5] fib: Support existence check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 0/5] Introduce boolean type and existence checks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH 3/5] exthdr: Implement existence check
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 5/5] doc: Document boolean type and applications
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 4/5] fib: Support existence check
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/5] Introduce boolean datatype and boolean expression
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/5] exthdr: Add support for exthdr specific flags
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/5] Introduce boolean type and existence checks
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH] fib: Add support for NFTA_FIB_F_PRESENT flag
- From: Phil Sutter <phil@xxxxxx>
- [nf-next PATCH] nftables: fib: Support existence check
- From: Phil Sutter <phil@xxxxxx>
- ANNOUNCE: New talk! Kernel HTTP/TCP/IP stack for HTTP DDoS mitigation
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH conntrackd 1/2] conntrackd: Remove obsolete rule to catch ambiguous Checksum option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrackd 2/2] conntrackd: CommitTimeout breaks DisableExternalCache set On
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: netfilter: conntrack: refine gc worker heuristics, redux
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH nf v2] netfilter: bridge: honor frag_max_size when refragmenting
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: bridge: honor frag_max_size when refragmenting
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: bridge: honor frag_max_size when refragmenting
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: per flow stats collection using libnetfilter_conntrack
- From: Tarun Khanna <tkhanna@xxxxxxxxxx>
- Re: Question about getting counters for transparent terminated flows
- From: Tarun Khanna <tkhanna@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix missmatch in big-endian system
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix missmatch in big-endian system
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_conntrack: reduce resolve_normal_ct args
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptables] iptables-translate: print nft iff there are more expanded rules to print
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- [PATCH iptables] iptables-translate: print nft iff there are more expanded rules to print
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix missmatch in big-endian system
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: per flow stats collection using libnetfilter_conntrack
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Question about getting counters for transparent terminated flows
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] libxtables: duplicated loopback address via host_to_ipaddr()
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- Re: [PATCH iptables 1/2] iptables-translate: print nft command for each expand rules via dns names
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: bridge: remove unneeded rcu_read_lock
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_reject: remove unused variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Question about getting counters for transparent terminated flows
- From: Tarun Khanna <tkhanna@xxxxxxxxxx>
- Re: [PATCH v2 nf] netfilter: don't track fragmented packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [net] netfilter: nat: sctp: fix ICMP packet to be dropped accidently
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/3] libxtables: avoid returning duplicate address for host resolution
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 1/3] libxtables: remove unnecessary nesting from host_to_ip(6)addr
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH 1/3] libxtables: remove unnecessary nesting from host_to_ip(6)addr
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/3] libxtables: abolish AI_CANONNAME
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/3] libxtables: avoid returning duplicate address for host resolution
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] netfilter: helper set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/3] libxtables: avoid returning duplicate address for host resolution
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 2/3] libxtables: abolish AI_CANONNAME
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 3/3] libxtables: avoid returning duplicate address for host resolution
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 1/3] libxtables: remove unnecessary nesting from host_to_ip(6)addr
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 2/3] libxtables: abolish AI_CANONNAME
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Filter duplicate IP addresses from libxtables
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next 0/2] netfilter: untracked object removal
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH 1/3] extensions: libxt_socket: add --restore-skmark option
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 3/3] extensions: restore matching any SPI id by default
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 2/3] build: resolve build error involving libnftnl
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH] libxtables: duplicated loopback address via host_to_ipaddr()
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH nf-next 1/2] netfilter: provide nft_ctxc in object init function
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: helper set support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_ct: add helper set support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] xtables-translate: Avoid querying the kernel
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] xtables-translate: Avoid querying the kernel
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf] netfilter: nf_tables: fix missmatch in big-endian system
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH] libxtables: duplicated loopback address via host_to_ipaddr()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables 2/2] libxtables: pass AI_ADDRCONFIG flag to getaddrinfo()
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables 2/2] libxtables: pass AI_ADDRCONFIG flag to getaddrinfo()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: untracked object removal
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH iptables 1/2] iptables-translate: print nft command for each expand rules via dns names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH iptables 2/2] libxtables: pass AI_ADDRCONFIG flag to getaddrinfo()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: kill the fake untracked conntrack objects
- From: Florian Westphal <fw@xxxxxxxxx>
- ANNOUNCE: Verizon Labs New Platinum Sponsor
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: remove nf_ct_is_untracked
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] libxtables: fix wrong naddr when using localhost
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- Re: [PATCH iptables] libxtables: fix wrong naddr when using localhost
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_addrtype: Add translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 1/1] netfilter: Use bool type instead of int as the return type of some functions
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [iptables PATCH] extensions: libxt_addrtype: Add translation to nft
- From: Phil Sutter <phil@xxxxxx>
- [PATCH iptables] libxtables: fix wrong naddr when using localhost
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- [PATCH v2] netfilter: Parse ICMPv6 redirects
- From: Alin Nastac <alin.nastac@xxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] extensions: libxt_conntrack: Fix 'state' translation to nft
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ulogd2 1/2] ulogd.conf: harmonize log file options with module default values
- From: Eric Leblond <eric@xxxxxxxxx>
- [PATCH] netfilter: nf_reject: remove unused variable
- From: Taehee Yoo <ap420073@xxxxxxxxx>
- [PATCH libnetfilter_conntrack] src: remove old libnfnetlink parsers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Thanks to netfilter project
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ulogd2] adjust ulogd.logrotate to match ulogd.conf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: bridge: remove unneeded rcu_read_lock
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: Use bool type instead of int as the return value of nf_conntrack_tuple_taken and nf_nat_used_tuple
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nf 1/2] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: validate the expr explicitly after init successfully
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Thanks to netfilter project
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: [PATCH nft v2] src: hash: support of symmetric hash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Use pr_cont where appropriate
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] expr: hash: support of symmetric hash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ulogd2] adjust ulogd.logrotate to match ulogd.conf
- From: Kaarle Ritvanen <kaarle.ritvanen@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: remove redundant check on ret being non-zero
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 2/2] netfilter: nft_hash: support of symmetric hash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next PATCH] nftables: exthdr: Allow checking TCP option presence, too
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nft_hash: rename nft_hash to nft_jhash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] netlink: use nftnl_udata_put_u32()/nftnl_udata_get_u32()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] udata: add nftnl_udata_put_u32() and nftnl_udata_get_u32()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: add nft_set_lookup()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- ANNOUNCE: New talk accepted on IO no Things
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: validate the expr explicitly after init successfully
- From: Liping Zhang <zlpnobody@xxxxxxx>
- ANNOUNCE: New talk accepted on Netfilter Connection Tracking
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nft_set_bitmap: fix memory leak
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf 1/2] netfilter: nft_set_bitmap: fetch the element key based on the set->klen
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: set pktinfo->thoff at AH header if found
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: set pktinfo->thoff at AH header if found
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: set pktinfo->thoff at AH header if found
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: set pktinfo->thoff at AH header if found
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [net] netfilter: nat: sctp: fix ICMP packet to be dropped accidently
- From: Ying Xue <ying.xue@xxxxxxxxxxxxx>
- Re: [PATCH 0/4] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- ANNOUNCE: Netdev 2.1 update Mar 03
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH v2 nf] netfilter: don't track fragmented packets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: remove incorrect debug assert
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCH 1/4] netfilter: use skb_to_full_sk in ip_route_me_harder
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/4] netfilter: nf_conntrack_sip: fix wrong memory initialisation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] netfilter: nf_tables: don't call nfnetlink_set_err() if nfnetlink_send() fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/4] netfilter: nft_set_rbtree: incorrect assumption on lower interval lookups
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nft: ah expression doesn't work for IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: nftables queue target aborts rules processing unconditionally
- From: Andreas Schultz <aschultz@xxxxxxxx>
- Re: nftables queue target aborts rules processing unconditionally
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables queue target aborts rules processing unconditionally
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables queue target aborts rules processing unconditionally
- From: Andreas Schultz <aschultz@xxxxxxxx>
- Re: [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] src: Use nftnl_buf to export XML/JSON rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- nftables queue target aborts rules processing unconditionally
- From: Andreas Schultz <aschultz@xxxxxxxx>
- Re: [PATCH iptables] utils: nfsynproxy: fix build with musl libc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipv6: Preserve link scope traffic original oif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nft: ah expression doesn't work for IPv6
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH] ipv6: Preserve link scope traffic original oif
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_conntrack_sip: fix wrong memory initialisation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: remove incorrect debug assert
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipv6: Preserve link scope traffic original oif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: remove incorrect debug assert
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nat: remove incorrect debug assert
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipv6: Preserve link scope traffic original oif
- From: Alin Năstac <alin.nastac@xxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: nat_masquerade: Check oom when invoke nfct_nat
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: nat_masquerade: Check oom when invoke nfct_nat
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH nf 1/1] netfilter: nat_masquerade: Check oom when invoke nfct_nat
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: nft: ah expression doesn't work for IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nft: ah expression doesn't work for IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: h323,sip: Fix possible dead loop in nat_rtp_rtcp and nf_nat_sdp_media
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- nft: ah expression doesn't work for IPv6
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf,v2] netfilter: nf_tables: don't call nfnetlink_set_err() if nfnetlink_send() fails
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- [PATCH libnftnl] src: Use nftnl_buf to export XML/JSON rules
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH nftables] tests: py: fix some typos in README
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables] tests: py: fix some typos in README
- From: Timothy Redaelli <tredaelli@xxxxxxxxxx>
- ANNOUNCE: Netdev 2.1 New Gold Sponsor
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: h323,sip: Fix possible dead loop in nat_rtp_rtcp and nf_nat_sdp_media
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH nf-next v3 2/2] netfilter: nft_hash: support of symmetric hash
- From: Laura Garcia Liebana <nevola@xxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: don't call nfnetlink_set_err() if nfnetlink_send() fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: h323,sip: Fix possible dead loop in nat_rtp_rtcp and nf_nat_sdp_media
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf 1/1] netfilter: h323,sip: Fix possible dead loop in nat_rtp_rtcp and nf_nat_sdp_media
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf 1/1] netfilter: h323,sip: Fix possible dead loop in nat_rtp_rtcp and nf_nat_sdp_media
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH iptables] utils: nfsynproxy: fix build with musl libc
- From: Baruch Siach <baruch@xxxxxxxxxx>
- About Kernel SynProxy Performance
- From: Tugrul Erdogan <h.tugrul.erdogan@xxxxxxxxx>
- Re: [PATCH nft] mnl: continue monitor if errno is ESRCH
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nf_tables: netlink listener hits ESRCH on socket overrun
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_set_rbtree: incorrect assumption on lower interval lookups
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Parse ICMPv6 redirects
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: netfilter: conntrack: refine gc worker heuristics, redux
- From: Florian Westphal <fw@xxxxxxxxx>
- netfilter: conntrack: refine gc worker heuristics, redux
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 09/14] netfilter: conntrack: refine gc worker heuristics, redux
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] mnl: continue monitor if errno is ESRCH
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- [PATCH] netfilter: nf_conntrack_sip: fix wrong memory initialisation
- From: Christophe Leroy <christophe.leroy@xxxxxx>
- Re: [PATCH nft] mnl: continue monitor if errno is ESRCH
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 09/14] netfilter: conntrack: refine gc worker heuristics, redux
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH] netfilter: Parse ICMPv6 redirects
- From: Alin Nastac <alin.nastac@xxxxxxxxx>
- [PATCH] ipv6: Preserve link scope traffic original oif
- From: Alin Nastac <alin.nastac@xxxxxxxxx>
- [PATCH] ipv6: Preserve link scope traffic original oif
- From: Alin Nastac <alin.nastac@xxxxxxxxx>
- Re: [PATCH nf-next v2 2/2] netfilter: nft_hash: support of symmetric hash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] mnl: continue monitor if errno is ESRCH
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] mnl: continue monitor if errno is ESRCH
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nft authentication
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nft authentication
- From: Fabian Franz <s1410239008@xxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 2/2] netfilter: nft_hash: support of symmetric hash
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: nft authentication
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: Use pr_cont where appropriate
- From: Joe Perches <joe@xxxxxxxxxxx>
- Re: [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- Re: [PATCH V3] audit: normalize NETFILTER_PKT
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- nft authentication
- From: Fabian Franz <s1410239008@xxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft v2] src: hash: support of symmetric hash
- From: Laura Garcia Liebana <nevola@xxxxxxxxx>
- [PATCH nf-next v2 2/2] netfilter: nft_hash: support of symmetric hash
- From: Laura Garcia Liebana <nevola@xxxxxxxxx>
- ANNOUNCE: Netdev 2.1 update Feb 28
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH v3] libiptc: don't set_changed() when checking rules with module jumps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [4.9.10] ip_route_me_harder() reading off-slab
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] libiptc: don't set_changed() when checking rules with module jumps
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- Re: [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] libiptc: don't set_changed() when checking rules with module jumps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: remove redundant check on ret being non-zero
- From: Colin King <colin.king@xxxxxxxxxxxxx>
- Re: [PATCH 0/7] nftables: add ct helper set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] extensions: libxt_hashlimit: Add translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables 1/2] xshared: do not lock again and again if "-w" option is not specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables V2 2/2] xshared: using the blocking file lock request when we wait indefinitely
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH lnfct 1/2] conntrack: fix missing break
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH lnfct 0/2] fix - src: add support for IPv6 NAT
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [PATCH lnfct 2/2] conntrack: revert getobjopt_is_nat condition
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [PATCH lnfct 1/2] conntrack: fix missing break
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [PATCH nft 3/4] src: support zone set statement with optional direction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/4] src: add conntrack zone support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 4/4] tests: add test entries for conntrack zones
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/4] ct: refactor print function so it can be re-used for ct statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] xtables: Remove unused macro
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH nft 4/4] src: store byteorder for set data
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/4] evaluate: set byteorder as lhs expression context in stmt_evaluate_arg()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/4] netlink: rework NFTNL_SET_USERDATA to accomodate new attributes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/4] src: rename set_keytype_alloc() to set_datatype_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: per flow stats collection using libnetfilter_conntrack
- From: Tarun Khanna <tkhanna@xxxxxxxxxx>
- Re: per flow stats collection using libnetfilter_conntrack
- From: Florian Westphal <fw@xxxxxxxxx>
- per flow stats collection using libnetfilter_conntrack
- From: Tarun Khanna <tkhanna@xxxxxxxxxx>
- [PATCH iptables] xtables: Remove unused macro
- From: Subash Abhinov Kasiviswanathan <subashab@xxxxxxxxxxxxxx>
- [PATCH iptables] extensions: libxt_hashlimit: Add translation to nft
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft 3/7] netlink: BUG when object type is unknown
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 6/7] src: allow listing all ct helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnftnl 1/2] object: don't set NFTNL_OBJ_TYPE unless obj->ops is non-null
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 1/2] object: don't set NFTNL_OBJ_TYPE unless obj->ops is non-null
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnftnl 2/2] object: fix crash when object ops is null
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 5/7] evaluate: refactor CMD_OBJ_QUOTA/COUNTER handling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 0/2] object: fix crashes with out-of-tree nft
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/7] src: add initial ct helper support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 7/7] src: implement add/create/delete for ct helper objects
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 2/2] object: fix crash when object ops is null
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 0/7] nftables: add ct helper set support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 2/7] src: ct helper support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl 1/7] object: extend set/get api for u8/u16 types
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [4.9.10] ip_route_me_harder() reading off-slab
- From: Daniel J Blueman <daniel@xxxxxxxxx>
- Re: [PATCH 0/6] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- ANNOUNCE: Netdev 2.1 update Feb 27
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH 2/6] uapi: stop including linux/sysctl.h in uapi/linux/netfilter.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] netfilter: nft_set_bitmap: incorrect bitmap size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] netfilter: nf_ct_expect: Change __nf_ct_expect_check() return value.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] netfilter: nf_ct_expect: nf_ct_expect_related_report(): Return zero on success.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/6] uapi: fix linux/netfilter/xt_hashlimit.h userspace compilation error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] netfilter: nft_ct: fix random validation errors for zone set support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nft] mnl: continue monitor if errno is ESRCH
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH V3] audit: normalize NETFILTER_PKT
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]