Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH nf] netfilter: conntrack: remove GC_MAX_EVICTS break
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 1/1] netfilter: nf_tables: Eliminate duplicated codes in nf_tables_table_enable
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [nf-next:fw 18/18] net/netfilter/nf_conntrack_standalone.c:647:2: error: call to '__compiletime_assert_647' declared with attribute error: BUILD_BUG_ON failed: NFCT_INFOMASK >= ARCH_KMALLOC_MINALIGN
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: refine gc worker heuristics, redux
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH nft] src: Honor obligatory stateless printing of flow tables
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH nf-next v2 1/1] netfilter: nf_tables: Refine the codes to eliminate useless condition checks in nf_tables_api.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipt_CLUSTERIP: fix build error without procfs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Eliminate duplicated codes in nf_tables_table_enable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_meta: deal with PACKET_LOOPBACK in netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: pkttype: unnecessary to check ipv6 multicast address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 4/4] netfilter: merge ctinfo into nfct pointer storage area
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC/PATCH 2/3] netfilter: ctnetlink: Fix regression in CTA_STATUS processing
- From: Doug Anderson <dianders@xxxxxxxxxxxx>
- Re: [RFC/PATCH 3/3] netfilter: ctnetlink: Fix regression in CTA_HELP processing
- From: Doug Anderson <dianders@xxxxxxxxxxxx>
- Re: [RFC/PATCH 1/3] netfilter: ctnetlink: Fix regression in CTA_TIMEOUT processing
- From: Doug Anderson <dianders@xxxxxxxxxxxx>
- Re: [PATCH nft 2/2] tests: py: Use stateless option on tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/2] tests: py: Use stateless option on tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] doc: Include stateless option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 7/7] netfilter: nf_tables: add bitmap set type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 5/7] netfilter: nf_tables: rename struct nft_set_estimate class field
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 6/7] netfilter: nf_tables: add space notation to sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/7] netfilter: nf_tables: rename deactivate_one() to flush()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/7] netfilter: nf_tables: add flush field to struct nft_set_iter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/7] netfilter: nf_tables: pass netns to set->ops->remove()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/7] netfilter: nf_tables: use struct nft_set_iter in set element flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/7] nf_tables set enhancements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix set->nelem leak
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: make more information available in DESTROY events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: make more information available in DESTROY events
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: make more information available in DESTROY events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: make more information available in DESTROY events
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- [PATCH nf-next] netfilter: ctnetlink: make more information available in DESTROY events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: refine gc worker heuristics, redux
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH] iptables-save: Exit with error if unable to open proc file
- Re: [PATCH] iptables-save: Exit with error if unable to open proc file
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] iptables-save: Exit with error if unable to open proc file
- Re: [PATCH] iptables-save: Exit with error if unable to open proc file
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] iptables-save: Exit with error if unable to open proc file
- From: Thomas Habets <thomas@xxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Paul Moore <pmoore@xxxxxxxxxx>
- Re: [PATCH nf v2] netfilter: conntrack: refine gc worker heuristics, redux
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH nf v2] netfilter: conntrack: refine gc worker heuristics, redux
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: tcp state in conntrack destroy events
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: tcp state in conntrack destroy events
- From: Jarno Rajahalme <jarno@xxxxxxx>
- [nft PATCH 0/3] Boolean comparison and exthdr existence match support
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/3] Implement boolean comparison in relational expression
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 3/3] exthdr: Implement exthdr existence check
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/3] exthdr: Add support for exthdr specific flags
- From: Phil Sutter <phil@xxxxxx>
- Re: tcp state in conntrack destroy events
- From: Florian Westphal <fw@xxxxxxxxx>
- [nf-next PATCH] netfilter: nf_tables: exthdr: Add support for existence check
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH] exthdr: Add support for exthdr flags
- From: Phil Sutter <phil@xxxxxx>
- [nf-next PATCH] netfilter: nf_tables: cmp: support boolean operation
- From: Phil Sutter <phil@xxxxxx>
- Re: tcp state in conntrack destroy events
- From: Victor Julien <lists@xxxxxxxxxxxx>
- tcp state in conntrack destroy events
- From: Victor Julien <lists@xxxxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH nft 2/2] tests: py: Use stateless option on tests
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft 1/2] doc: Include stateless option
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: AUDIT_NETFILTER_PKT message format
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: [stable] bridge: netfilter: Fix dropping packets that moving through bridge interface
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: remove GC_MAX_EVICTS break
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [RFC/PATCH 1/3] netfilter: ctnetlink: Fix regression in CTA_TIMEOUT processing
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- [RFC/PATCH 2/3] netfilter: ctnetlink: Fix regression in CTA_STATUS processing
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- AUDIT_NETFILTER_PKT message format
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [RFC/PATCH 0/3] Fix ctnetlink regressions
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- [RFC/PATCH 3/3] netfilter: ctnetlink: Fix regression in CTA_HELP processing
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- Re: [PATCH nft v2] src: Allow to list ruleset without stateful information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2] src: Allow to list ruleset without stateful information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: fix export length and data corruption
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v2] src: Allow to list ruleset without stateful information
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [stable] bridge: netfilter: Fix dropping packets that moving through bridge interface
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [stable] bridge: netfilter: Fix dropping packets that moving through bridge interface
- From: Artur Molchanov <arturmolchanov@xxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: refine gc worker heuristics, redux
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: conntrack: remove GC_MAX_EVICTS break
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] Add a configure flag to link libc statically
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: conntrack: refine gc worker heuristics, redux
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH] Add a configure flag to link libc statically
- From: Keno Fischer <keno@xxxxxxxxxxxxxxxxxx>
- ANNOUNCE: Netdev 2.1 Call For Proposals Opened!
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- [PATCH nf-next v2 1/1] netfilter: nf_tables: Refine the codes to eliminate useless condition checks in nf_tables_api.c
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Refine the codes to eliminate useless condition checks in nf_tables_api.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: fix export length and data corruption
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_cthelper] Use __EXPORTED rather than EXPORT_SYMBOL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_cttimeout] Use __EXPORTED rather than EXPORT_SYMBOL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Fix typo in NF_CONNTRACK Kconfig option description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix possible oops when dumping stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: rpfilter: fix incorrect loopback packet judgment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: fix spelling mistakes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] extensions: libxt_rpfilter: add translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] extensions: libxt_connbytes: Add translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] ct: add average bytes per packet counter support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] Add a configure flag to link libc statically
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: conntrack: refine gc worker heuristics, redux
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] examples: Remove the use of nftnl_mnl_batch_put()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] build: add missing backslash to list of CFLAGS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] expr: Add const qualifiers to *2str translation arrays
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: Allow to list ruleset without stateful information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: 4.9 conntrack performance issues
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- Re: 4.9 conntrack performance issues
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: 4.9 conntrack performance issues
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- Re: 4.9 conntrack performance issues
- From: Florian Westphal <fw@xxxxxxxxx>
- 4.9 conntrack performance issues
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- ANNOUNCE: Netdev 2.1 in Montreal
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH v3 1/8] arm: put types.h in uapi
- From: Russell King - ARM Linux <linux@xxxxxxxxxxxxxxx>
- Re: [PATCH v3 4/8] x86: stop exporting msr-index.h to userland
- From: Borislav Petkov <bp@xxxxxxxxx>
- Re: [PATCH v3 1/8] arm: put types.h in uapi
- From: Russell King - ARM Linux <linux@xxxxxxxxxxxxxxx>
- Re: [PATCH v3 4/8] x86: stop exporting msr-index.h to userland
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH v3 1/8] arm: put types.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [no subject]
- From: David Howells <dhowells@xxxxxxxxxx>
- [PATCH] netfilter: ipt_CLUSTERIP: fix build error without procfs
- From: Arnd Bergmann <arnd@xxxxxxxx>
- [no subject]
- From: David Howells <dhowells@xxxxxxxxxx>
- [PATCH nft] src: Allow to list ruleset without stateful information
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft] build: add missing backslash to list of CFLAGS
- From: Tobias Klauser <tklauser@xxxxxxxxxx>
- Re: [PATCH v3 3/8] nios2: put setup.h in uapi
- From: Tobias Klauser <tklauser@xxxxxxxxxx>
- [PATCH v3 1/8] arm: put types.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 6/8] Makefile.headersinst: remove destination-y option
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 0/8] uapi: export all headers under uapi directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH libnftnl] expr: Add const qualifiers to *2str translation arrays
- From: Tobias Klauser <tklauser@xxxxxxxxxx>
- [PATCH v3 8/8] uapi: export all arch specifics directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 7/8] uapi: export all headers under uapi directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 2/8] h8300: put bitsperlong.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 5/8] Makefile.headersinst: cleanup input files
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 3/8] nios2: put setup.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v3 4/8] x86: stop exporting msr-index.h to userland
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Jeff Epler <jepler@xxxxxxxxxxxxxx>
- [PATCH] examples: Remove the use of nftnl_mnl_batch_put()
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Remove the rcu lock for dump functions
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Refine the codes to eliminate useless condition checks in nf_tables_api.c
- From: Gao Feng <fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: nftables conntrack set ops for zone, helper assignment, etc.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables conntrack set ops for zone, helper assignment, etc.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nftables conntrack set ops for zone, helper assignment, etc.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables conntrack set ops for zone, helper assignment, etc.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Refine the codes to eliminate useless condition checks in nf_tables_api.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Remove the rcu lock for dump functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: nf_tables: Remove the rcu lock for dump functions
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Remove the rcu lock for dump functions
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- Re: nftables conntrack set ops for zone, helper assignment, etc.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables conntrack set ops for zone, helper assignment, etc.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Linux-c6x-dev] [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Mark Salter <msalter@xxxxxxxxxx>
- Re: probably serious conntrack/netfilter panic, 4.8.14, timers and intel turbo
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- Re: probably serious conntrack/netfilter panic, 4.8.14, timers and intel turbo
- From: Guillaume Nault <g.nault@xxxxxxxxxxxx>
- Re: [PATCH v2 0/7] uapi: export all headers under uapi directories
- From: Jesper Nilsson <jesper.nilsson@xxxxxxxx>
- nftables conntrack set ops for zone, helper assignment, etc.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: nf_tables: Remove one useless condition check in nf_tables_newobj
- From: Feng Gao <gfree.wind@xxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: nf_tables: Refine the codes to eliminate useless condition checks in nf_tables_api.c
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH nft 2/2] tests: shell: add maps tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] src: sort set elements in netlink_get_setelems()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RFC: nftables: Boolean operation, two alternatives
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next 1/1] netfilter: nf_tables: Eliminate duplicated codes in nf_tables_table_enable
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH] netfilter: Fix typo in NF_CONNTRACK Kconfig option description
- From: William Breathitt Gray <vilhelm.gray@xxxxxxxxx>
- Re: [PATCH v2 2/2] tcp: fix mark propagation with fwmark_reflect enabled
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH v2 2/2] tcp: fix mark propagation with fwmark_reflect enabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/2] netfilter: use fwmark_reflect in nf_send_reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/7] xtables: use dedicated copy_to_user helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Christoph Hellwig <hch@xxxxxxxxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Russell King - ARM Linux <linux@xxxxxxxxxxxxxxx>
- Re: [PATCH v2 1/7] arm: put types.h in uapi
- From: Russell King - ARM Linux <linux@xxxxxxxxxxxxxxx>
- Re: [PATCH v2 0/7] uapi: export all headers under uapi directories
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH v2 3/7] nios2: put setup.h in uapi
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH v2 1/7] arm: put types.h in uapi
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Daniel Vetter <daniel@xxxxxxxx>
- net_device features
- From: Peter Skvarka <pet3243@xxxxxxxxx>
- [PATCH iptables] extensions: libxt_rpfilter: add translation to nft
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_meta: deal with PACKET_LOOPBACK in netdev family
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf-next 1/2] netfilter: pkttype: unnecessary to check ipv6 multicast address
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix possible oops when dumping stateful objects
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf] netfilter: rpfilter: fix incorrect loopback packet judgment
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH] treewide: fix semicolon.cocci warnings
- From: Michal Hocko <mhocko@xxxxxxxxxx>
- [PATCH] treewide: fix semicolon.cocci warnings
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- [PATCH nft 2/2] tests: shell: add maps tests
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft 1/2] src: sort set elements in netlink_get_setelems()
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH v2 4/7] x86: put msr-index.h in uapi
- From: Andy Shevchenko <andy.shevchenko@xxxxxxxxx>
- [PATCH v2 2/2] tcp: fix mark propagation with fwmark_reflect enabled
- From: Pau Espin Pedrol <pau.espin@xxxxxxxxxxxx>
- [PATCH v2 1/2] netfilter: use fwmark_reflect in nf_send_reset
- From: Pau Espin Pedrol <pau.espin@xxxxxxxxxxxx>
- Re: [PATCH v2 4/7] x86: put msr-index.h in uapi
- From: Borislav Petkov <bp@xxxxxxxxx>
- [PATCH v2 7/7] uapi: export all headers under uapi directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 6/7] Makefile.headersinst: remove destination-y option
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 2/7] h8300: put bitsperlong.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 3/7] nios2: put setup.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 4/7] x86: put msr-index.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 5/7] Makefile.headersinst: cleanup input files
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 1/7] arm: put types.h in uapi
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH v2 0/7] uapi: export all headers under uapi directories
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: nf_tables: Remove one useless condition check in nf_tables_newobj
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH V2 conntrack-tools] conntrackd: cthelper: ssdp: Track UPnP eventing
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- [PATCH V2 conntrack-tools] conntrackd: cthelper: ssdp: Track UPnP eventing
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: Remove cache_update() in cmd_evaluate_flush()
- From: Anatole Denis <anatole@xxxxxxxxx>
- [PATCH nft] evaluate: Remove cache_update() in cmd_evaluate_flush()
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH 0/6] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: Use strlcpy to copy dev name instead of strncpy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nf_tables: Make sure the uniform style of condition blocks in nf_tables_newrule
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nf_tables: Check chain's use count before alloc new handle in nf_tables_newrule
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_connlimit: use rb_entry()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] nf_conntrack: validate crc32c on SCTP packets hitting PREROUTING hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 3/4] netfilter: reduce direct skb->nfct usage
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 1/4] netfilter: conntrack: no need to pass ctinfo to error handler
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 2/4] netfilter: reset netfilter state when duplicating packet
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 0/4] netfilter: skbuff: merge nfctinfo bits and nfct pointer
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 4/4] netfilter: merge ctinfo into nfct pointer storage area
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [-stable 4.8.y] Revert NAT conversion to rhashtable
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH iptables] iptables 1.6.1 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] netfilter: ipt_CLUSTERIP: check duplicate config when initializing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/6] netfilter: nf_tables: fix oob access
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] bridge: netfilter: Fix dropping packets that moving through bridge interface
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] netfilter: nft_payload: mangle ckecksum if NFT_PAYLOAD_L4CSUM_PSEUDOHDR is set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] netfilter: nft_queue: use raw_smp_processor_id()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] netfilter: nft_quota: reset quota after dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: use fwmark_reflect in nf_send_reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [-stable 4.8.y] Revert NAT conversion to rhashtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 4/4] netfilter: merge ctinfo into nfct pointer storage area
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH] net/bridge: Fix dropping packets that moving through bridge interface
- From: Artur Molchanov <arturmolchanov@xxxxxxxxx>
- Re: [PATCH nf-next 4/4] netfilter: merge ctinfo into nfct pointer storage area
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH libnetfilter_cthelper] Use __EXPORTED rather than EXPORT_SYMBOL
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- [PATCH libnetfilter_cttimeout] Use __EXPORTED rather than EXPORT_SYMBOL
- From: Kevin Cernekee <cernekee@xxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: fix spelling mistakes
- From: Alexander Alemayhu <alexander@xxxxxxxxxxxx>
- Re: [-stable 4.8.y] Revert NAT conversion to rhashtable
- From: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH nf-next 2/4] netfilter: reset netfilter state when duplicating packet
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: merge ctinfo into nfct pointer storage area
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/4] netfilter: reduce direct skb->nfct usage
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/4] netfilter: conntrack: no need to pass ctinfo to error handler
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/4] netfilter: skbuff: merge nfctinfo bits and nfct pointer
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] uapi: use wildcards to list files
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: build failure if --with-xtables [WAS: nftables 0.7 release]
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: [PATCH xtables-addons] build: support for Linux 4.10
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH net-next 5/8] bridge: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- [PATCH net-next] nfnetlink/queue: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- Re: build failure if --with-xtables [WAS: nftables 0.7 release]
- From: Robby Workman <robby@xxxxxxxxxxxxx>
- Re: [PATCH] uapi: use wildcards to list files
- From: Arnd Bergmann <arnd@xxxxxxxx>
- [PATCH net-next v2 13/27] bridge: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- [PATCH net-next v2 16/27] nfnetlink/queue: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- Re: [PATCH] uapi: use wildcards to list files
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH] uapi: use wildcards to list files
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH libnftnl] src: ct: add average bytes per packet counter support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_ct: add average bytes per packet support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nf_tables: add missing descriptions in nft_ct_keys
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next 0/2] netfilter: merge udp and udplite trackers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] scanner: fix search_in_include_path test
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 0/2] segtree: move huge arrays to heap
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 7/7] xtables: extend matches and targets with .usersize
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 5/7] ebtables: use match, target and data copy_to_user helpers
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 6/7] xtables: use match, target and data copy_to_user helpers in compat
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 4/7] arptables: use match, target and data copy_to_user helpers
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 3/7] ip6tables: use match, target and data copy_to_user helpers
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 2/7] iptables: use match, target and data copy_to_user helpers
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 1/7] xtables: add xt_match, xt_target and data copy_to_user functions
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next 0/7] xtables: use dedicated copy_to_user helpers
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH v2 0/2] segtree: move huge arrays to heap
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- [PATCH v2 1/2] utils: provide array allocation wrapper
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- [PATCH v2 2/2] segtree: allocate memory for arrays on heap
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: select LIBCRC32C together with SCTP conntrack
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- [PATCH 1/2] utils: provide array allocation wrapper
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- [PATCH 2/2] segtree: allocate memory for arrays on heap
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- [PATCH 0/2] segtree: move huge arrays to heap
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- [PATCH nft] scanner: fix search_in_include_path test
- From: Anatole Denis <anatole@xxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: conntrack: validate SCTP crc32c in PREROUTING
- From: Davide Caratti <dcaratti@xxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: select LIBCRC32C together with SCTP conntrack
- From: Davide Caratti <dcaratti@xxxxxxxxxx>
- [PATCH nf-next 0/2] nf_conntrack: validate crc32c on SCTP packets hitting PREROUTING hook
- From: Davide Caratti <dcaratti@xxxxxxxxxx>
- nft segfaults listing huge sets
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- Re: nft segfaults listing huge sets
- From: Oleksandr Natalenko <oleksandr@xxxxxxxxxxxxxx>
- Re: [PATCH] net/bridge: Fix dropping packets that moving through bridge interface
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net/bridge: Fix dropping packets that moving through bridge interface
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] net/bridge: Fix dropping packets that moving through bridge interface
- From: Artur Molchanov <arturmolchanov@xxxxxxxxx>
- [PATCH] Add a configure flag to link libc statically
- From: Keno Fischer <keno@xxxxxxxxxxxxxxxxxx>
- [PATCH] Fix two compile errors during out-of-tree build
- From: Keno Fischer <keno@xxxxxxxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nf_tables: Make sure the uniform style of condition blocks in nf_tables_newrule
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH nf-next 1/2] netfilter: nf_tables: Check chain's use count before alloc new handle in nf_tables_newrule
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- Re: [PATCH] netfilter: use fwmark_reflect in nf_send_reset
- From: Pau Espin Pedrol <pespin.shar@xxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: Use strlcpy to copy dev name instead of strncpy
- From: fgao@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
- [PATCH xtables-addons] build: support for Linux 4.10
- From: Ralph Sennhauser <ralph.sennhauser@xxxxxxxxx>
- [PATCH xtables-addons] build: support for Linux 4.9
- From: Ralph Sennhauser <ralph.sennhauser@xxxxxxxxx>
- [PATCH iptables] extensions: libxt_connbytes: Add translation to nft
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nft] ct: add average bytes per packet counter support
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH libnftnl] src: ct: add average bytes per packet counter support
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_ct: add average bytes per packet support
- From: Liping Zhang <zlpnobody@xxxxxxx>
- [PATCH nf-next 1/2] netfilter: nf_tables: add missing descriptions in nft_ct_keys
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH] netfilter: conntrack: Fix ifdef checks for CONFIG_NF_CONNTRACK_MARK
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools] conntrack: send mark filter to kernel iff set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 10/10] src: support for stateful object monitoring
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 07/10] parser_bison: allow RESET token from rhs
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 02/10] src: remove SET_F_* flag definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 05/10] src: add/create/delete stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 08/10] src: add stateful object reference expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 09/10] src: add support for stateful object maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 06/10] src: reset internal stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 03/10] src: add used quota support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 04/10] src: listing of stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 01/10] include: fetch nf_tables.h updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: use fwmark_reflect in nf_send_reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nftables: masquerade sets wrong source address
- From: Tom Hacohen <tom@xxxxxxxxx>
- Re: nftables: masquerade sets wrong source address
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables: masquerade sets wrong source address
- From: Tom Hacohen <tom@xxxxxxxxx>
- BUG/panic in ctnetlink_conntrack_event in 4.8.11
- From: Chris Boot <bootc@xxxxxxxxx>
- Re: libmnl compile failure.
- From: Florian Westphal <fw@xxxxxxxxx>
- RE: libmnl compile failure.
- From: maowenan <maowenan@xxxxxxxxxx>
- Re: nftables: masquerade sets wrong source address
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [PATCH v2 nf-next 2/2] netfilter: nat: merge udp and udplite helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 1/2] netfilter: merge udp and udplite conntrack helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 0/2] netfilter: merge udp and udplite trackers
- From: Florian Westphal <fw@xxxxxxxxx>
- [ANNOUNCE] nftables 0.7 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] expression: Show the base which pre-defined constants are displayed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: RFC: nft.8 review
- From: mark diener <rpzrpzrpz@xxxxxxxxx>
- Re: RFC: nft.8 review
- From: Phil Sutter <phil@xxxxxx>
- Re: RFC: nft.8 review
- From: mark diener <rpzrpzrpz@xxxxxxxxx>
- Re: nftables: masquerade sets wrong source address
- From: Tom Hacohen <tom@xxxxxxxxx>
- [PATCH] netfilter: xt_connlimit: use rb_entry()
- From: Geliang Tang <geliangtang@xxxxxxxxx>
- [PATCH libnftnl] src: get rid of aliases and compat
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] xt: use NFTNL_* definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Feature request: Load u32 value into packet mark
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- How to leverage IP & UDP checksum offloading from iptables kernel module?
- From: Llorente Santos Jesus <jesus.llorente.santos@xxxxxxxx>
- Feature request: Load u32 value into packet mark
- From: Llorente Santos Jesus <jesus.llorente.santos@xxxxxxxx>
- [PATCHv2 net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [PATCH net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] mnl: add mnl_nft_setelem_batch_flush() and use it from netlink_flush_setelems()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: RFC: nft.8 review
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2] libxtables: xtables: Use getnameinfo()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2] libxtables: xtables: remove unnecessary debug code
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] libnftnl 1.0.7 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] expression: Show the base which pre-defined constants are displayed
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH libnftnl] build: update LIBVERSION to prepare a new release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [-stable 4.8.y] Revert NAT conversion to rhashtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: Fix ifdef checks for CONFIG_NF_CONNTRACK_MARK
- From: Joseph Conley <joseph.j.conley@xxxxxxxxx>
- RE: libmnl compile failure.
- From: maowenan <maowenan@xxxxxxxxxx>
- Re: libmnl compile failure.
- From: Phil Sutter <phil@xxxxxx>
- Re: nftables: masquerade sets wrong source address
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: [PATCH net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH 0/2] GTP tunneling fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: Easy way to set NOTRACK for INPUT, FORWARD and OUTPUT independently
- Re: nftables: masquerade sets wrong source address
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- Re: Easy way to set NOTRACK for INPUT, FORWARD and OUTPUT independently
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: use fwmark_reflect in nf_send_reset
- From: Pau Espin Pedrol <pau.espin@xxxxxxxxxxxx>
- libmnl compile failure.
- From: maowenan <maowenan@xxxxxxxxxx>
- Re: Adding element to interval map consumes entire memory
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Adding element to interval map consumes entire memory
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/2] GTP tunneling fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/2] GTP tunneling fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2] gtp: Fix initialization of Flags octet in GTPv1 header
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/2] gtp: gtp_check_src_ms_ipv4() always return success
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: Fix ifdef checks for CONFIG_NF_CONNTRACK_MARK
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: use fwmark_reflect in nf_send_reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: use fwmark_reflect in nf_send_reset
- From: Pau Espin Pedrol <pau.espin@xxxxxxxxxxxx>
- [PATCH net] netfilter: check duplicate config when initializing in ipt_CLUSTERIP
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: Adding element to interval map consumes entire memory
- From: Richard Mörbitz <richard.moerbitz@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_payload: mangle ckecksum if NFT_PAYLOAD_L4CSUM_PSEUDOHDR is set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: conntrack: Fix ifdef checks for CONFIG_NF_CONNTRACK_MARK
- From: joseph.j.conley@xxxxxxxxx
- Re: [PATCH net-next 13/27] bridge: use __vlan_hwaccel helpers
- From: Toshiaki Makita <makita.toshiaki@xxxxxxxxxxxxx>
- [PATCH nft] netlink_linearize: fix IPv6 layer 4 checksum mangling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: py: update quota and payload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] mnl: don't send empty set elements netlink message to kernel
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix oob access
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] ARM: add cmpxchg64 helper for ARMv7-M
- From: Russell King - ARM Linux <linux@xxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix oob access
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 13/27] bridge: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- Re: [PATCH net-next 13/27] bridge: use __vlan_hwaccel helpers
- From: Sergei Shtylyov <sergei.shtylyov@xxxxxxxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix oob access
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Adding element to interval map consumes entire memory
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] segtree: wrong prefix expression length on interval_map_decompose()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] segtree: don't trigger error on exact overlaps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 13/27] bridge: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- [PATCH net-next 16/27] nfnetlink/queue: use __vlan_hwaccel helpers
- From: Michał Mirosław <mirq-linux@xxxxxxxxxxxx>
- [PATCH 2/2] libxtables: xtables: Use getnameinfo()
- From: Shyam Saini <mayhs11saini@xxxxxxxxx>
- [PATCH 1/2] libxtables: xtables: remove unnecessary debug code
- From: Shyam Saini <mayhs11saini@xxxxxxxxx>
- Re: [PATCH] libxtables: xtables.c: Use getnameinfo()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libxtables: xtables.c: Use getnameinfo()
- From: Shivani Bhardwaj <shivanib134@xxxxxxxxx>
- Re: [PATCH] libxtables: xtables.c: Use getnameinfo()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libxtables: xtables.c: Use getnameinfo()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH next] iptables: on revision mismatch, do not call print/save
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_queue: use raw_smp_processor_id()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] datatype: Display pre-defined inet_service values in decimal base
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Adding element to interval map consumes entire memory
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_quota: reset quota after dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Arnd Bergmann <arnd@xxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: David Miller <davem@xxxxxxxxxxxxx>
- Adding element to interval map consumes entire memory
- From: Richard Mörbitz <richard.moerbitz@xxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] datatype: Display pre-defined inet_service values in decimal base
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next] netfilter: nft_counter: rework atomic dump and reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3] datatype: Display pre-defined inet_service values in host byte order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] extensions: libxt_bpf: support ebpf pinned objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ARM: add cmpxchg64 helper for ARMv7-M
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 37/50] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] ARM: add cmpxchg64 helper for ARMv7-M
- From: Arnd Bergmann <arnd@xxxxxxxx>
- RFC: nft.8 review
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft v3] datatype: Display pre-defined inet_service values in host byte order
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Question on match pid owner
- From: Christos <christos@xxxxxxxxxxx>
- Re: [PATCH 37/50] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH 37/50] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH libnftnl 7/7] quota: support for consumed bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 3/7] expr: add stateful object reference expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 2/7] src: support for stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 6/7] expr: objref: add support for stateful object maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 5/7] set_elem: add NFTNL_SET_ELEM_OBJREF attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 1/7] include: fetch stateful object updates for nf_tables.h cache copy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 4/7] set: add NFTNL_SET_OBJ_TYPE attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] libxtables: xtables.c: Use getnameinfo()
- From: Shyam Saini <mayhs11saini@xxxxxxxxx>
- Re: [PATCH 37/50] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 37/50] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Paul Gortmaker <paul.gortmaker@xxxxxxxxxxxxx>
- [PATCH next] iptables: on revision mismatch, do not call print/save
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH] extensions: libxt_bpf: support ebpf pinned objects
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [PATCH nft v2] datatype: Display pre-defined inet_service values in host byte order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2] datatype: Display pre-defined inet_service values in host byte order
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [nf-next:master 36/49] ERROR: "__cmpxchg_u64" [net/netfilter/nft_counter.ko] undefined!
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- Re: [PATCH 00/50] Netfilter/IPVS updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 00/50] Netfilter/IPVS updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/50] netfilter: nfnetlink_log: add "nf-logger-5-1" module alias name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/50] netfilter: built-in NAT support for UDPlite
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/50] netfilter: nf_conntrack_tuple_common.h: fix #include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/50] netfilter: conntrack: built-in support for SCTP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/50] netfilter: add and use nf_ct_netns_get/put
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 24/50] netfilter: x_tables: pass xt_counters struct to counter allocator
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/50] netfilter: conntrack: built-in support for UDPlite
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/50] netfilter: nat: add dependencies on conntrack module
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/50] netfilter: nf_tables: add conntrack dependencies for nat/masq/redir expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/50] netfilter: conntrack: add nf_conntrack_default_on sysctl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/50] netfilter: convert while loops to for loops
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 27/50] netfilter: nft_fib_ipv4: initialize *dest to zero
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 26/50] netfilter: nft_fib: convert htonl to ntohl properly
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 29/50] netfilter: xt_multiport: Fix wrong unmatch result with multiple ports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 28/50] netfilter: nft_payload: layer 4 checksum adjustment for pseudoheader fields
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 23/50] netfilter: x_tables: pass xt_counters struct instead of packet counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/50] netfilter: defrag: only register defrag functionality if needed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 30/50] netfilter: ingress: translate 0 nf_hook_slow retval to -1
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 25/50] netfilter: x_tables: pack percpu counter allocations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 31/50] netfilter: add and use nf_fwd_netdev_egress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/50] netfilter: introduce accessor functions for hook entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 32/50] netfilter: nf_tables: add stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 34/50] netfilter: nft_quota: add stateful object type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 38/50] netfilter: nf_tables: notify internal updates of stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 39/50] netfilter: nft_quota: add depleted flag for objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 40/50] netfilter: nf_tables: add stateful object reference to set elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 41/50] netfilter: nft_objref: support for stateful object maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/50] netfilter: decouple nf_hook_entry and nf_hook_ops
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/50] netfilter: conntrack: register hooks in netns when needed by ruleset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 36/50] netfilter: nft_quota: dump consumed quota
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 43/50] netfilter: rpfilter: bypass ipv4 lbcast packets with zeronet source
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 33/50] netfilter: nft_counter: add stateful object type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 42/50] netfilter: nf_tables: allow to filter stateful object dumps by type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 46/50] netfilter: nft_set: introduce nft_{hash, rbtree}_deactivate_one()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 44/50] netfilter: nat: skip checksum on offload SCTP packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 45/50] netfilter: nf_tables: constify struct nft_ctx * parameter in nft_trans_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 37/50] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 49/50] netfilter: xt_bpf: support ebpf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 48/50] netfilter: x_tables: avoid warn and OOM killer on vmalloc call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 50/50] netfilter: nft_quota: allow to restore consumed quota
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 47/50] netfilter: nf_tables: support for set flushing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 35/50] netfilter: nf_tables: add stateful object reference expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/50] netfilter: conntrack: remove unused init_net hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/50] netfilter: conntrack: built-in support for DCCP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/50] netfilter: built-in NAT support for SCTP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/50] netfilter: built-in NAT support for DCCP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/50] netfilter: nf_log: do not assume ethernet header in netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/50] netfilter: update Arturo Borrero Gonzalez email address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/50] ipvs: Decrement ttl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/50] ipvs: Use IS_ERR_OR_NULL(svc) instead of IS_ERR(svc) || svc == NULL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v2] datatype: Display pre-defined inet_service values in host byte order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v2] datatype: Display pre-defined inet_service values in host byte order
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [nf-next:master 36/48] net/netfilter/nft_counter.c:131:9: error: implicit declaration of function 'cmpxchg64'
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_quota: allow to restore consumed quota
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: xt_bpf: support ebpf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nft_counter: use cmpxchg64 instead of xchg
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- [PATCH nf-next v2] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Rebasing nf-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_tables: silence gcc warning with stateful object maps
- From: kbuild test robot <lkp@xxxxxxxxx>
- [nf-next:master 37/48] net/netfilter/nft_counter.c:125:21: error: call to '__xchg_wrong_size' declared with attribute error: Bad argument size for xchg
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- [nf-next:master 18/48] net/ipv6/netfilter/nf_defrag_ipv6_hooks.c:94:9: error: 'struct net' has no member named 'ct'
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- [PATCH nf-next] netfilter: add list element test to br_netfilter_hooks
- From: Aaron Conole <aconole@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_quota: don't read quota twice on reset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nf_tables: restore check for NFTA_SET_ELEM_LIST_ELEMENTS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_counter: move counter reset into separated function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [bug report] netfilter: convert while loops to for loops
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [nf-next:master 37/48] net/netfilter/nft_counter.c:128:18: warning: 'packets' may be used uninitialized in this function
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- Re: [bug report] netfilter: nft_payload: layer 4 checksum adjustment for pseudoheader fields
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nf_tables: silence gcc warning with stateful object maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: silence gcc warning with stateful object maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [bug report] netfilter: nft_payload: layer 4 checksum adjustment for pseudoheader fields
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH v2] netfilter: avoid warn and OOM killer on vmalloc call
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nf-next:master 41/48] net/netfilter/nf_tables_api.c:3003:15: warning: 'objtype' may be used uninitialized in this function
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- Re: [bug report] netfilter: nft_payload: layer 4 checksum adjustment for pseudoheader fields
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [bug report] netfilter: nft_payload: layer 4 checksum adjustment for pseudoheader fields
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH nft] src: add support to flush sets
- From: Anatole Denis <anatole@xxxxxxxxx>
- Re: [PATCH nft] src: add support to flush sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] NAT: skip checksum on offload SCTP packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: conntrack: merge udp and udplite helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: rpfilter: bypass ipv4 lbcast packets with zeronet source
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: conntrack: merge udp and udplite helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ingress: translate 0 nf_hook_slow retval to -EINPROGRESS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_payload: restrict l4 checksum updates to l3 header mangling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: fix build failure with CONNTRACK=n NF_DEFRAG=y
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] datatype: Display pre-defined inet_service values in host byte order
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Easy way to set NOTRACK for INPUT, FORWARD and OUTPUT independently
- Re: Easy way to set NOTRACK for INPUT, FORWARD and OUTPUT independently
- [PATCH nft] datatype: Display pre-defined inet_service values in host byte order
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemb@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: add support to flush sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] set_elem: nftnl_set_elems_nlmsg_build_payload_iter()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nf_tables: support for set flushing
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: nft_set: introduce nft_{hash,rbtree}_deactivate_one()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_tables: constify struct nft_ctx * parameter in nft_trans_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser: Add glob support to include directive
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Kernel panic in netfilter 4.8.10 probably on conntrack -L
- From: Denys Fedoryshchenko <nuclearcat@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH nf-next] netfilter: xt_bpf: support ebpf
- From: Willem de Bruijn <willemdebruijn.kernel@xxxxxxxxx>
- Re: [PATCH v3 net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH nf-next] NAT: skip checksum on offload SCTP packets
- From: Davide Caratti <dcaratti@xxxxxxxxxx>
- [PATCH nft] parser: Add glob support to include directive
- From: Kohei Suzuki <eagletmt@xxxxxxxxx>
- linux-next: build warnings after merge of the netfilter-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: fix build failure with CONNTRACK=n NF_DEFRAG=y
- From: Florian Westphal <fw@xxxxxxxxx>
- [nf-next:master 18/28] net/ipv4/netfilter/nf_defrag_ipv4.c:110:9: error: 'struct net' has no member named 'ct'
- From: kbuild test robot <fengguang.wu@xxxxxxxxx>
- Re: [conntrack-tools PATCH] config: drop old/obsolete/deprecated conntrackd.conf config options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH] systemd: fix missing log.h include
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: shell: add test case for inserting element into verdict map
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [GIT PULL nf-next 0/2] IPVS Updates for v4.10
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_fib_ipv4: initialize *dest to zero
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_fib: convert htonl to ntohl properly
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 1/1] netfilter: xt_multiport: Fix wrong unmatch result with multiple ports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v4 nf-next] netfilter: allow disabling conntrack-on-by-default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/3] Additional nf_hook_entry compaction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nf-next 0/3] netfilter: x_tables: pack percpu counter allocations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/3] netfilter: built-in NAT support for DCCP, SCTP, UDPlite
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nfnetlink_log: add "nf-logger-5-1" module alias name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_log: do not assume ethernet header in netdev family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/4] netfilter: built-in conntrack support for DCCP, SCTP, UDPlite
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v3 net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCN v2 net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCN net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: rpfilter: bypass ipv4 lbcast packets with zeronet source
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCN v2 net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: kbuild test robot <lkp@xxxxxxxxx>
- Re: [PATCN net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCN net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCN v2 net-next] net_sched: gen_estimator: complete rewrite of rate estimators
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH nf-next] netfilter: rpfilter: bypass ipv4 lbcast packets with zeronet source
- From: Liping Zhang <zlpnobody@xxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: conntrack: merge udp and udplite helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: conntrack: merge udp and udplite helpers
- From: kbuild test robot <lkp@xxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nat: merge udp and udplite helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: conntrack: merge udp and udplite helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: merge udp and udplite helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2,nf-next 09/11] netfilter: nf_tables: add stateful object reference to set elements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 01/11] netfilter: nf_tables: add stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 04/11] netfilter: nf_tables: add stateful object reference expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 07/11] netfilter: nft_quota: dump consumed quota
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 02/11] netfilter: nft_counter: add stateful object type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 11/11] netfilter: nf_tables: allow to filter stateful object dumps by type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 08/11] netfilter: nft_quota: add depleted flag for objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 10/11] netfilter: nft_objref: support for stateful object maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 06/11] netfilter: nf_tables: notify internal updates of stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 05/11] netfilter: nf_tables: atomic dump and reset for stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 03/11] netfilter: nft_quota: add stateful object type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2,nf-next 00/11] nf_tables: add stateful objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH] config: drop old/obsolete/deprecated conntrackd.conf config options
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- [conntrack-tools PATCH] systemd: fix missing log.h include
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- [PATCH v2] netfilter: avoid warn and OOM killer on vmalloc call
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH] netfilter: avoid warn and OOM on vmalloc call
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 00/11] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: [conntrack-tools PATCH] src: add log message when resync is requested by other node
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/2] evaluate: Update cache on flush ruleset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] rule: Introduce helper function cache_flush
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: return ctx->table from table_lookup_global()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Vadim Kochan <vadim4j@xxxxxxxxx>
- [PATCH nft 2/2] evaluate: Update cache on flush ruleset
- From: Anatole Denis <anatole@xxxxxxxxx>
- [PATCH nft 1/2] rule: Introduce helper function cache_flush
- From: Anatole Denis <anatole@xxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH] src: add log message when resync is requested by other node
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- Re: [PATCH] netfilter: avoid warn and OOM on vmalloc call
- From: Andrey Konovalov <andreyknvl@xxxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Arturo Borrero Gonzalez <arturo@xxxxxxxxxx>
- [PATCH nft] datatype: honor -nn option from inet_service_type_print()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/11] netfilter: nf_tables: fix inconsistent element expiration calculation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/11] netfilter: nat: fix cmp return value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/11] netfilter: nft_range: add the missing NULL pointer check
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/11] netfilter: nft_hash: validate maximum value of u32 netlink hash attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/11] netfilter: ipv6: nf_defrag: drop mangled skb on ream error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/11] netfilter: nat: switch to new rhlist interface
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/11] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/11] netfilter: nat: fix crash when conntrack entry is re-used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/11] netfilter: Update nf_send_reset6 to consider L3 domain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/11] netfilter: fix nf_conntrack_helper documentation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/11] netfilter: Update ip_route_me_harder to consider L3 domain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/11] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] tests: py: Test TCP flags match with parentheses
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] tests: py: Test TCP flags match with parentheses
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] netfilter: avoid warn and OOM on vmalloc call
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH] bison: remove old log level tokens
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] bison: remove old log level tokens
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH nft v4] datatype: Replace getnameinfo() by internal lookup table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nftables RFC] build: honor Scrooge McDuck in our release names
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_fib: store loopback interface to dreg when rt is local
- From: Liping Zhang <zlpnobody@xxxxxxxxx>
- [RFC nft PATCH] tests: shell: add a basic scapy test
- From: Arturo Borrero Gonzalez <arturo.borrero.glez@xxxxxxxxx>
- [PATCH] netfilter: arp_tables: fix invoking 32bit "iptable -P INPUT ACCEPT" failed in 64bit kernel
- From: Hongxu Jia <hongxu.jia@xxxxxxxxxxxxx>
- [PATCH nft v4] datatype: Replace getnameinfo() by internal lookup table
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: [PATCH iptables] extensions: LOG: add log flags translation to nft
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] tcp_xlate: Enclose LH flag values in parentheses
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft_ipv{4,6}_xlate: Respect prefix lengths
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] xtables-translate: Support setting standard chain policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] xtables-translate: Fix chain type when translating nat table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] extensions: libip6t_ah: Fix translation of plain '-m ah'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Re : [PATCH nft 1/7] Interpret OP_NEQ against a set as OP_LOOKUP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 2/2] tests: shell: add testcase for different defines usage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 1/2] tests: shell: add a testcase for many defines
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_bison: Allow parens on RHS of relational_expr
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/7] tests/py/{arp,any}: Unmask negative set lookup
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/7] Interpret OP_NEQ against a set as OP_LOOKUP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 3/3] Revert "evaluate: check for NULL datatype in rhs in lookup expr"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 2/3] tests: Add regression test for malformed sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/3] evaluate: Add set to cache only when well-formed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] expr: call expr->ops->snprintf only if defined
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ipv6: nf_defrag: drop mangled skb on ream error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 1/2] datatype: Replace getnameinfo() by internal lookup table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] tcp_xlate: Enclose LH flag values in parentheses
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft v3 2/2] datatype: Implement binary search in symbolic_constant_print()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v3 2/2] datatype: Implement binary search in symbolic_constant_print()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ipv6: nf_defrag: drop mangled skb on ream error
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- [PATCH nf] netfilter: ipv6: nf_defrag: drop mangled skb on ream error
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v3 2/2] datatype: Implement binary search in symbolic_constant_print()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v3 2/2] datatype: Implement binary search in symbolic_constant_print()
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- [PATCH nft v3 1/2] datatype: Replace getnameinfo() by internal lookup table
- From: Elise Lennion <elise.lennion@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- [nft PATCH] parser_bison: Allow parens on RHS of relational_expr
- From: Phil Sutter <phil@xxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re : [PATCH nft 1/7] Interpret OP_NEQ against a set as OP_LOOKUP
- From: Anatole Denis <anatole@xxxxxxxxx>
- [PATCH nft 3/3] Revert "evaluate: check for NULL datatype in rhs in lookup expr"
- From: Anatole Denis <anatole@xxxxxxxxx>
- [PATCH nft 2/3] tests: Add regression test for malformed sets
- From: Anatole Denis <anatole@xxxxxxxxx>
- [PATCH nft 1/3] evaluate: Add set to cache only when well-formed
- From: Anatole Denis <anatole@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Andrey Konovalov <andreyknvl@xxxxxxxxxx>
- Re: net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Neil Horman <nhorman@xxxxxxxxxxxxx>
- net/sctp: vmalloc allocation failure in sctp_setsockopt/xt_alloc_table_info
- From: Andrey Konovalov <andreyknvl@xxxxxxxxxx>
- [nft PATCH 2/2] tests: shell: add testcase for different defines usage
- From: Arturo Borrero Gonzalez <arturo.borrero.glez@xxxxxxxxx>
- [nft PATCH 1/2] tests: shell: add a testcase for many defines
- From: Arturo Borrero Gonzalez <arturo.borrero.glez@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_fib: store loopback interface to dreg when rt is local
- From: Florian Westphal <fw@xxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]