Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH net-next] netfilter: conntrack: dccp: try not to drop skb in conntrack
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- iptables-nft: Wrong payload merge of rule filter - "! --sport xx ! --dport xx"
- From: Sriram Rajagopalan <bglsriram@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- Re: [PATCH] ipvs: allow netlink configuration from non-initial user namespace
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net v3] netfilter: Add protection for bmp length out of range
- From: Lena Wang (王娜) <Lena.Wang@xxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- [RFC nftables PATCH]: fix a2x: ERROR: missing --destination-dir: ./doc
- From: Neels Hofmeyr <nhofmeyr@xxxxxxxxxxx>
- [PATCH] ipvs: allow netlink configuration from non-initial user namespace
- From: Michael Weiß <michael.weiss@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nft 2/5] parser_json: move list_add into json_parse_cmd
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 2/5] parser_json: move list_add into json_parse_cmd
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Issues with netdev egress hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- Re: [PATCH nft 2/5] parser_json: move list_add into json_parse_cmd
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- Re: [PATCH nft 2/5] parser_json: move list_add into json_parse_cmd
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft 2/5] parser_json: move list_add into json_parse_cmd
- From: Phil Sutter <phil@xxxxxx>
- [PATCH xtables] extensions: xt_TPROXY: add txlate support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Issues with netdev egress hooks
- From: Daniel Mack <daniel@xxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- [PATCH nft 5/5] tests: shell: add more json-nft dumps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/5] parser_json: defer command allocation to nft_cmd_expand
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/5] parser_json: add and use CMD_ERR helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/5] parser_json: move list_add into json_parse_cmd
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/5] parser_json: fix up transaction ordering
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/5] parser_json: move some code around
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- Re: [PATCH net 1/5] netfilter: nf_tables: disallow anonymous set with timeout flag
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net] netfilter: conntrack: fix ct-state for ICMPv6 Multicast Router Discovery
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb
- From: Jason Xing <kerneljasonxing@xxxxxxxxx>
- [PATCH nf-next 9/9] netfilter: nf_tables: remove gc sequence counter
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 8/9] netfilter: nf_tables: remove expired elements based on key lookup only
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 7/9] netfilter: nf_tables: prepare for key-based deletion from workqueue
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 5/9] netfilter: nf_tables: condense catchall gc
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 6/9] netfilter: nf_tables: add in-kernel only query that will return expired/dead elements
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/9] netfilter: remove nft_trans_gc_catchall_async handling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/9] netfilter: nf_tables: add lockdep assertion for chain use counter
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/9] netfilter: nf_tables: decrement element counters on set removal/flush
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/9] netfilter: nf_tables: warn if set being destroyed is still active
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/9] netfilter: nf_tables: rewrite gc again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: skip netdev hook unregistration if table is dormant
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: skip netdev hook unregistration if table is dormant
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/5] netfilter: nf_conntrack_h323: Add protection for bmp length out of range
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/5] netfilter: nf_tables: mark set as dead when unbinding anonymous set with timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/5] netfilter: nft_ct: fix l3num expectations with inet pseudo family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/5] netfilter: nf_tables: reject constant set with timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/5] netfilter: nf_tables: disallow anonymous set with timeout flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [syzbot] [netfilter?] INFO: rcu detected stall in gc_worker (3)
- From: syzbot <syzbot+eec403943a2a2455adaa@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft,v2] evaluate: translate meter into dynamic set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: translate meter into dynamic set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Issues with netdev egress hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nf_tables: Fix a memory leak in nf_tables_updchain
- From: Quan Tian <tianquan23@xxxxxxxxx>
- Re: [PATCH xtables-nft v2] extensions: xt_socket: add txlate support for socket match
- From: Phil Sutter <phil@xxxxxx>
- Issues with netdev egress hooks
- From: Daniel Mack <daniel@xxxxxxxxxx>
- Re: [PATCH xtables-nft v2] extensions: xt_socket: add txlate support for socket match
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH xtables-nft v2] extensions: xt_socket: add txlate support for socket match
- From: Phil Sutter <phil@xxxxxx>
- Re: [libnftnl PATCH 0/6] Attribute policies for expressions
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net] netfilter: conntrack: fix ct-state for ICMPv6 Multicast Router Discovery
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- [syzbot] [netfilter?] KASAN: slab-use-after-free Read in ip_skb_dst_mtu
- From: syzbot <syzbot+e5167d7144a62715044c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH xtables-nft v2] extensions: xt_socket: add txlate support for socket match
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables-nft] extensions: xt_socket: add txlate support for sk match v3
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH 2/2] xlate: libip6t_mh: Fix and simplify plain '-m mh' match
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/2] xlate: Improve redundant l4proto match avoidance
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] xtables-translate: Leverage stored protocol names
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net v3] netfilter: Add protection for bmp length out of range
- From: Lena Wang (王娜) <Lena.Wang@xxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: remove NETDEV_CHANGENAME from netdev chain event handler
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: skip transaction if update object is not implemented
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: mark set as dead when deactivating anonymous set with timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: mark set as dead when deactivating anonymous set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: mark set as dead when deactivating anonymous set
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: mark set as dead when deactivating anonymous set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools v2 0/3] fix potential memory loss and exit codes
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- Re: [PATCH conntrack-tools v2 0/3] fix potential memory loss and exit codes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools v2 0/3] fix potential memory loss and exit codes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools 2/3] conntrackd: use size_t for element indices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net v2] netfilter: Add protection for bmp length out of range
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools 1/3] conntrackd: prevent memory loss if reallocation fails
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- Re: [PATCH conntrack-tools 2/3] conntrackd: use size_t for element indices
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools v2 3/3] conntrackd: exit with failure status
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools v2 2/3] conntrackd: use size_t for element indices
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools v2 1/3] conntrackd: prevent memory loss if reallocation fails
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools v2 0/3] fix potential memory loss and exit codes
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- Re: [PATCH net v2] netfilter: Add protection for bmp length out of range
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH conntrack-tools 1/3] conntrackd: prevent memory loss if reallocation fails
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH conntrack-tools 2/3] conntrackd: use size_t for element indices
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net v2] netfilter: Add protection for bmp length out of range
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH conntrack-tools 3/3] conntrackd: exit with failure status
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools 2/3] conntrackd: use size_t for element indices
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools 1/3] conntrackd: prevent memory loss if reallocation fails
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- [PATCH conntrack-tools 0/3] fix potential memory loss and exit codes
- From: Donald Yandt <donald.yandt@xxxxxxxxx>
- Re: [PATCH net v2] netfilter: Add protection for bmp length out of range
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- [PATCH net v2] netfilter: Add protection for bmp length out of range
- From: Lena Wang (王娜) <Lena.Wang@xxxxxxxxxxxx>
- [PATCH nft 3/3] tests: add test case for named ct objects
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/3] parser: allow to define maps that contain ct helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] parser: allow to define maps that contain timeouts and expectations
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/3] parser: allow to define maps that contain ct objects
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf v2] netfilter: nft_ct: fix l3num expectations with inet pseudo family
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_ct: fix l3num expectations with inet pseudo family
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf,v2 2/2] netfilter: nf_tables: reject constant set with timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2 1/2] netfilter: nf_tables: disallow anonymous set with timeout flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nf_tables: reject constant set with timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nf_tables: disallow anonymous set with NFT_SET_{TIMEOUT,EVAL} flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipvs: generic netlink multicast event group
- From: Terin Stock <terin@xxxxxxxxxxxxxx>
- Re: [PATCH] ipvs: generic netlink multicast event group
- From: Julian Anastasov <ja@xxxxxx>
- [iptables PATCH] xtables-translate: Leverage stored protocol names
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] ipvs: generic netlink multicast event group
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] rule: fix ASAN errors in priority to string conversion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 3/3] selftests: netfilter: add bridge conntrack + multicast test case
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- [PATCH nft 3/3] tests: maps: add a test case for "limit" objref map
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/3] parser: allow typeof in objref maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/3] netlink: allow typeof keywords with objref maps during listing
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/3] nftables: add typeof support for objref maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 2/3] netfilter: bridge: confirm multicast packets before passing them up the stack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] selftests: netfilter: add bridge conntrack + multicast test case
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Fix for broken recover_rule_compat()
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] Add protection for bmp length out of range
- From: Lena Wang (王娜) <Lena.Wang@xxxxxxxxxxxx>
- Re: [PATCH] Add protection for bmp length out of range
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] nft: Fix for broken recover_rule_compat()
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v2 nf] netfilter: bridge: confirm multicast packets before passing them up the stack
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ulogd2 Mysql KO
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser: compact type/typeof set rules
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] parser: compact interval typeof rules
- From: Florian Westphal <fw@xxxxxxxxx>
- Ulogd2 Mysql KO
- From: Yves Metivier <yves@xxxxxxxxxxx>
- [PATCH libnftnl 3/3] utils: remove unused code
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 2/3] udata: incorrect userdata buffer size validation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 1/3] expr: immediate: check for chain attribute to release chain name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netlink: validate length of NLA_{BE16,BE32} types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netlink: validate length of NLA_{BE16,BE32} types
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nf 2/2] selftests: netfilter: add bridge conntrack + multicast test case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] netfilter: bridge: confirm multicast packets before passing them up the stack
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 0/2] netfilter: bridge_netfilter:
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netlink: validate length of NLA_{BE16,BE32} types
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net] netlink: validate length of NLA_{BE16,BE32} types
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- [PATCH nft] parser_json: allow 0 offsets again
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net] netlink: validate length of NLA_{BE16,BE32} types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] nftables 0.9.8 -stable backports
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] netfilter: xtables: fix IP6_NF_IPTABLES_LEGACY typo
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] netfilter: xtables: fix IP6_NF_IPTABLES_LEGACY typo
- From: Arnd Bergmann <arnd@xxxxxxxxxx>
- Re: [PATCH net-next 01/12] netfilter: expect: Simplify the allocation of slab caches in nf_conntrack_expect_init
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v3] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Ignat Korchagin <ignat@xxxxxxxxxxxxxx>
- Re: [PATCH v3] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v3] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Ignat Korchagin <ignat@xxxxxxxxxxxxxx>
- Re: [PATCH net 1/5] netfilter: nf_tables: set dormant flag on hook register failure
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Ignat Korchagin <ignat@xxxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/5] netfilter: nf_tables: use kzalloc for hook allocation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/5] netfilter: nf_tables: set dormant flag on hook register failure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/5] netfilter: nf_tables: register hooks last when adding new chain/flowtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/5] netfilter: nft_flow_offload: release dst in case direct xmit path is used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/5] netfilter: nft_flow_offload: reset dst in route object after setting up flow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/5] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: use kzalloc for hook allocation
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: register hooks last when adding new chain/flowtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_flow_offload: reset dst in route object after setting up flow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nft_flow_offload: release dst in case direct xmit path is used
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] src: improve error reporting for destroy command
- From: 谢致邦 (XIE Zhibang) <Yeking@xxxxxxxxx>
- Re: [syzbot] [netfilter?] KMSAN: uninit-value in __nla_validate_parse (3)
- From: xingwei lee <xrivendell7@xxxxxxxxx>
- [PATCH net-next 12/12] netfilter: x_tables: Use unsafe_memcpy() for 0-sized destination
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 11/12] netfilter: move nf_reinject into nfnetlink_queue modules
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 10/12] netfilter: nft_set_pipapo: use GFP_KERNEL for insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 05/12] netfilter: xtables: fix up kconfig dependencies
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 09/12] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 08/12] netfilter: nft_set_pipapo: shrink data structures
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 07/12] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 04/12] netfilter: nft_osf: simplify init path
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 06/12] netfilter: nft_set_pipapo: constify lookup fn args where possible
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 03/12] netfilter: nf_log: validate nf_logger_find_get()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 01/12] netfilter: expect: Simplify the allocation of slab caches in nf_conntrack_expect_init
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 00/12] netfilter updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 02/12] netfilter: nf_log: consolidate check for NULL logger in lookup function
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v5.4.y] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Ignat Korchagin <ignat@xxxxxxxxxxxxxx>
- [syzbot] [netfilter?] KMSAN: uninit-value in __nla_validate_parse (3)
- From: syzbot <syzbot+3f497b07aa3baf2fb4d0@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [RFC] nftables 0.9.8 -stable backports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] nftables 0.9.8 -stable backports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] obj: ct_timeout: setter checks for timeout array boundaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] Add protection for bmp length out of range
- From: Lena Wang (王娜) <Lena.Wang@xxxxxxxxxxxx>
- Re: [RFC nf-next v5 0/2] netfilter: bpf: support prog update
- From: "D. Wythe" <alibuda@xxxxxxxxxxxxxxxxx>
- Re: [RFC nf-next v5 0/2] netfilter: bpf: support prog update
- From: "D. Wythe" <alibuda@xxxxxxxxxxxxxxxxx>
- CFS for Netdev Conf 0x18 open!
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [PATCH] netfilter: x_tables: Use unsafe_memcpy() for 0-sized destination
- From: Simon Horman <horms@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: set dormant flag on hook register failure
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue 1/1] Convert libnetfilter_queue to use entirely libmnl functions
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [RFC] nftables 0.9.8 -stable backports
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [RFC] nftables 0.9.8 -stable backports
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [linux-next:master] BUILD REGRESSION d37e1e4c52bc60578969f391fb81f947c3e83118
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH] netfilter: x_tables: Use unsafe_memcpy() for 0-sized destination
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Matthieu Baerts <matttbe@xxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue 1/1] Convert libnetfilter_queue to use entirely libmnl functions
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix bidirectional offload regression
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 1/3] netfilter: nft_set_pipapo: fix missing : in kdoc
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v2 nf-next 2/4] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_set_pipapo: use GFP_KERNEL for insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/3] netfilter: nat: restore default DNAT behavior
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nf_tables: fix bidirectional offload regression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/3] netfilter: nft_set_pipapo: fix missing : in kdoc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nf-next v5 0/2] netfilter: bpf: support prog update
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nf-next v5 0/2] netfilter: bpf: support prog update
- From: Quentin Deslandes <qde@xxxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix bidirectional offload regression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nf_tables: fix bidirectional offload regression
- From: Felix Fietkau <nbd@xxxxxxxx>
- [PATCH nf-next] netfilter: move nf_reinject into nfnetlink_queue modules
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue 1/1] Convert libnetfilter_queue to use entirely libmnl functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_byteorder: remove multi-register support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [syzbot] [netfilter?] WARNING: ODEBUG bug in ip_set_free
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH libnetfilter_queue 0/1] Convert libnetfilter_queue to use entirely libmnl functions
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue 1/1] Convert libnetfilter_queue to use entirely libmnl functions
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [syzbot] [netfilter?] WARNING: ODEBUG bug in ip_set_free
- From: syzbot <syzbot+ebbab3e04c88fa141e6b@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft] expression: missing line in describe command with invalid expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 nf-next 0/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH v2 nf-next 4/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 3/4] netfilter: nft_set_pipapo: shrink data structures
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 2/4] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 1/4] netfilter: nft_set_pipapo: constify lookup fn args where possible
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nf-next 0/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 4/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 4/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next 3/4] netfilter: nft_set_pipapo: shrink data structures
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next 2/4] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] cache: Always set NFT_CACHE_TERSE for list cmd with --terse
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 2/4] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next 1/4] netfilter: nft_set_pipapo: constify lookup fn args where possible
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Jordan Griege <jgriege@xxxxxxxxxxxxxx>
- [ANNOUNCE] ipset 7.21 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/4] netfilter: nft_set_pipapo: shrink data structures
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/4] netfilter: nft_set_pipapo: constify lookup fn args where possible
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/4] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/4] netfilter: nft_set_pipapo: speed up bulk element insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/1] tests/shell: no longer support unprettified ".json-nft" files
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Ignat Korchagin <ignat@xxxxxxxxxxxxxx>
- Re: [PATCH 1/1] tests: use common shebang in "packetpath/flowtables" test
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate()
- From: Ignat Korchagin <ignat@xxxxxxxxxxxxxx>
- [PATCH 1/1] tests: use common shebang in "packetpath/flowtables" test
- From: Thomas Haller <thaller@xxxxxxxxxx>
- [PATCH 1/1] tests/shell: no longer support unprettified ".json-nft" files
- From: Thomas Haller <thaller@xxxxxxxxxx>
- [syzbot] Monthly netfilter report (Feb 2024)
- From: syzbot <syzbot+list54bd6dcf58b0a6cd42fd@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [netfilter-nf:testing 5/13] net/netfilter/ipset/ip_set_hash_gen.h:435:19: sparse: sparse: incorrect type in assignment (different address spaces)
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH v3] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- [netfilter-nf:testing 8/13] net/netfilter/nft_set_pipapo.c:518: warning: Function parameter or struct member 'tstamp' not described in 'pipapo_get'
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH nft 2/2 v2] tests/shell: have .json-nft dumps prettified to wrap lines
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 01/13] netfilter: nft_compat: narrow down revision to unsigned 8-bits
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- [nft PATCH] cache: Always set NFT_CACHE_TERSE for list cmd with --terse
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft 2/2] netlink_linearize: add assertion to catch for buggy byteorder
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH,v2 nft 1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 01/13] netfilter: nft_compat: narrow down revision to unsigned 8-bits
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net 13/13] netfilter: nft_set_pipapo: remove scratch_aligned pointer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 12/13] netfilter: nft_set_pipapo: add helper to release pcpu scratch area
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 11/13] netfilter: nft_set_pipapo: store index in scratch maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 08/13] netfilter: nf_tables: use timestamp to check for set element timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 10/13] netfilter: nft_set_rbtree: skip end interval element from gc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 09/13] netfilter: nfnetlink_queue: un-break NF_REPEAT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 06/13] netfilter: ctnetlink: fix filtering for zone 0
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 07/13] netfilter: nft_ct: reject direction for ct id
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 02/13] netfilter: nft_compat: reject unused compat flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 04/13] netfilter: nft_set_pipapo: remove static in nft_pipapo_get()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 03/13] netfilter: nft_compat: restrict match/target protocol to u16
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 01/13] netfilter: nft_compat: narrow down revision to unsigned 8-bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net,v2 00/13] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] cache: Reduce caching when terse listing a table
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 13/13] netfilter: nft_set_pipapo: remove scratch_aligned pointer
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH net 11/13] netfilter: nft_set_pipapo: store index in scratch maps
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH net 08/13] netfilter: nf_tables: use timestamp to check for set element timeout
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH net 04/13] netfilter: nft_set_pipapo: remove static in nft_pipapo_get()
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: linux-next: Fixes tag needs some work in the netfilter tree
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Thorsten Leemhuis <regressions@xxxxxxxxxxxxx>
- linux-next: Fixes tag needs some work in the netfilter tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xtables: fix up kconfig dependencies
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: skip byteorder conversion for selector smaller than 2 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 13/13] netfilter: nft_set_pipapo: remove scratch_aligned pointer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 11/13] netfilter: nft_set_pipapo: store index in scratch maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 12/13] netfilter: nft_set_pipapo: add helper to release pcpu scratch area
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 09/13] netfilter: nfnetlink_queue: un-break NF_REPEAT
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 10/13] netfilter: nft_set_rbtree: skip end interval element from gc
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 08/13] netfilter: nf_tables: use timestamp to check for set element timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 06/13] netfilter: ctnetlink: fix filtering for zone 0
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 07/13] netfilter: nft_ct: reject direction for ct id
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 05/13] netfilter: ipset: Missing gc cancellations fixed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 03/13] netfilter: nft_compat: restrict match/target protocol to u16
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 04/13] netfilter: nft_set_pipapo: remove static in nft_pipapo_get()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 00/13] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 02/13] netfilter: nft_compat: reject unused compat flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 01/13] netfilter: nft_compat: narrow down revision to unsigned 8-bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH v2 1/1] netfilter: nat: restore default DNAT behavior
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.4 6/7] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.10 09/16] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.15 12/23] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 6.1 15/29] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 6.6 21/38] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 6.7 23/44] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nf v2 3/3] netfilter: nft_set_pipapo: remove scratch_aligned pointer
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf v2 2/3] netfilter: nft_set_pipapo: add helper to release pcpu scratch area
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf v2 1/3] netfilter: nft_set_pipapo: store index in scratch maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf v2 0/3] netfilter: nft_set_pipapo: nft_set_pipapo: map_index must be per set
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 1/3] netfilter: nft_set_pipapo: store index in scratch maps
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] cache: Optimize caching for 'list tables' command
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 3/3] netfilter: nft_set_pipapo: remove scratch_aligned pointer
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 2/3] netfilter: nft_set_pipapo: add helper to release pcpu scratch area
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 1/3] netfilter: nft_set_pipapo: store index in scratch maps
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] Makefile.am: don't silence -Wimplicit-function-declaration
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v3] evaluate: fix check for unknown in cmd_op_to_name
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] ipvs: generic netlink multicast event group
- From: Julian Anastasov <ja@xxxxxx>
- [nft PATCH] cache: Optimize caching for 'list tables' command
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH conntrack] conntrack: don't print [USERSPACE] information in case of XML output
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 1/3] netfilter: nft_set_pipapo: store index in scratch maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH v3] evaluate: fix check for unknown in cmd_op_to_name
- From: 谢致邦 (XIE Zhibang) <Yeking@xxxxxxxxx>
- [PATCH conntrack] conntrack: don't print [USERSPACE] information in case of XML output
- From: Ignacy Gawędzki <ignacy.gawedzki@xxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf 1/3] netfilter: nft_set_pipapo: store index in scratch maps
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [nft PATCH v2] evaluate: fix check for unknown in cmd_op_to_name
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2] evaluate: fix check for unknown in cmd_op_to_name
- From: 谢致邦 (XIE Zhibang) <Yeking@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: use timestamp to check for set element timeout
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- 0x18: Dates And Location for upcoming conference
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Matthieu Baerts <matttbe@xxxxxxxxxx>
- Re: [PATCH 1/1] netfilter: ipset: Missing gc cancellations fixed
- From: "Linux regression tracking (Thorsten Leemhuis)" <regressions@xxxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [syzbot] [netfilter?] WARNING: ODEBUG bug in hash_netiface4_destroy
- From: syzbot <syzbot+52bbc0ad036f6f0d4a25@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH] Makefile.am: don't silence -Wimplicit-function-declaration
- From: Sam James <sam@xxxxxxxxxx>
- Re: [iptables PATCH v2 0/3] iptables-save: Avoid /etc/protocols lookups
- From: Phil Sutter <phil@xxxxxx>
- Re: [syzbot] [netfilter?] WARNING: suspicious RCU usage in hash_netportnet6_destroy
- From: syzbot <syzbot+bcd44ebc3cd2db18f26c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [iptables PATCH 00/12] Range value related fixes/improvements
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 0/7] A number of ASAN-identified fixes
- From: Phil Sutter <phil@xxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Matthieu Baerts <matttbe@xxxxxxxxxx>
- [PATCH nf] netfilter: nfnetlink_queue: un-break NF_REPEAT
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: iptables: considers incomplete rule in -C and finds an erroneous match
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: xtables: fix up kconfig dependencies
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 3/3] netfilter: nft_set_pipapo: remove scratch_aligned pointer
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/3] netfilter: nft_set_pipapo: store index in scratch maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/3] netfilter: nft_set_pipapo: add helper to release pcpu scratch area
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/3] netfilter: nft_set_pipapo: map_index must be per set
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [netfilter-core] [PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH] evaluate: fix check for unknown in cmd_op_to_name
- From: 谢致邦 (XIE Zhibang) <Yeking@xxxxxxxxx>
- [syzbot] [netfilter?] WARNING: suspicious RCU usage in hash_netportnet6_destroy
- From: syzbot <syzbot+bcd44ebc3cd2db18f26c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH] ipvs: generic netlink multicast event group
- From: Terin Stock <terin@xxxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_ct: reject direction for ct id
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Viktor Malik <vmalik@xxxxxxxxxx>
- Re: [PATCH net-next v2] net: ctnetlink: support filtering by zone
- From: Felix Huettner <felix.huettner@mail.schwarz>
- [PATCH net] net: ctnetlink: fix filtering for zone 0
- From: Felix Huettner <felix.huettner@mail.schwarz>
- [PATCH v5.4.y] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Ajay Kaher <ajay.kaher@xxxxxxxxxxxx>
- [PATCH v4.19.y] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Ajay Kaher <ajay.kaher@xxxxxxxxxxxx>
- libnetfilter_queue patch ping
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v4 3/3] bpf: treewide: Annotate BPF kfuncs in BTF
- From: kernel test robot <oliver.sang@xxxxxxxxx>
- Re: iptables: considers incomplete rule in -C and finds an erroneous match
- From: Roman Mamedov <rm@xxxxxxxxxxx>
- iptables: considers incomplete rule in -C and finds an erroneous match
- From: Roman Mamedov <rm@xxxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: Missing gc cancellations fixed
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Manu Bretelle <chantr4@xxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Jiri Olsa <olsajiri@xxxxxxxxx>
- Re: [syzbot] [netfilter?] WARNING: ODEBUG bug in hash_netiface4_destroy
- From: syzbot <syzbot+52bbc0ad036f6f0d4a25@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Manu Bretelle <chantr4@xxxxxxxxx>
- [iptables PATCH 08/12] extensions: esp: Save/xlate inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 02/12] libxtables: xtoptions: Assert ranges are monotonic increasing
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 10/12] nft: Do not omit full ranges if inverted
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 00/12] Range value related fixes/improvements
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 04/12] extensions: ah: Save/xlate inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 05/12] extensions: frag: Save/xlate inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 03/12] libxtables: Reject negative port ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 01/12] extensions: *.t/*.txlate: Test range corner-cases
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 07/12] extensions: rt: Save/xlate inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 06/12] extensions: mh: Save/xlate inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 12/12] libxtables: xtoptions: Respect min/max values when completing ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 09/12] extensions: ipcomp: Save inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 11/12] extensions: tcp/udp: Save/xlate inverted full ranges
- From: Phil Sutter <phil@xxxxxx>
- [syzbot] [netfilter?] WARNING: ODEBUG bug in hash_netiface4_destroy
- From: syzbot <syzbot+52bbc0ad036f6f0d4a25@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next v2] net: ctnetlink: support filtering by zone
- From: Felix Huettner <felix.huettner@mail.schwarz>
- [PATCH nf] netfilter: nft_compat: reject unused compat flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_compat: restrict match/target protocol to u16
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_compat: narrow down revision to unsigned 8-bits
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_byteorder: length must be multiple of size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next v2] net: ctnetlink: support filtering by zone
- From: Ilya Maximets <i.maximets@xxxxxxx>
- Re: [PATCH net-next v2] net: ctnetlink: support filtering by zone
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_set_pipapo: remove static in nft_pipapo_get()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v5.10.y] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
- From: Ajay Kaher <ajay.kaher@xxxxxxxxxxxx>
- Re: [PATCH net 1/6] netfilter: conntrack: correct window scaling with retransmitted SYN
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [iptables PATCH 4/7] xtables-eb: Eliminate 'opts' define
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/7] nft: ruleparse: Add missing braces around ternary
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 5/7] xshared: Fix for memleak in option merging with ebtables
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/7] A number of ASAN-identified fixes
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 7/7] ebtables: Fix for memleak with change counters command
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/7] tests: iptables-test: Increase non-fast mode strictness
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 6/7] xshared: Introduce xtables_clear_args()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/7] libxtables: Fix memleak of matches' udata
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net 4/6] netfilter: ipset: fix performance regression in swap operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/6] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/6] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/6] netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/6] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/6] netfilter: conntrack: correct window scaling with retransmitted SYN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [nft PATCH] json: Support sets' auto-merge option
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] json: Support sets' auto-merge option
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] json: Support sets' auto-merge option
- From: Phil Sutter <phil@xxxxxx>
- [ANNOUNCE] ipset 7.20 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/9] netfilter: uapi: Document NFT_TABLE_F_OWNER flag
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: linux-next: Tree for Jan 30 (netfilter, xtables)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 0/9] netfilter updates for -next
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Jiri Olsa <olsajiri@xxxxxxxxx>
- Re: [PATCH bpf-next v4 3/3] bpf: treewide: Annotate BPF kfuncs in BTF
- From: Benjamin Tissoires <bentiss@xxxxxxxxxx>
- Re: [PATCH nf-next 0/9] netfilter updates for -next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/9] netfilter updates for -next
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: linux-next: Tree for Jan 30 (netfilter, xtables)
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_ct: bail out if helper is not found for NFPROTO_{IPV4,IPV6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [RFC PATCH v2 1/1] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- [RFC PATCH v2 0/1] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- Re: [RFC PATCH 1/1] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- [PATCH nf-next] netfilter: nft_osf: simplify init path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nf_log: validate nf_logger_find_get()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nf_log: consolidate check for NULL logger in lookup function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_ct: bail out if helper is not found for NFPROTO_{IPV4,IPV6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 9/9] netfilter: ebtables: allow xtables-nft only builds
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 8/9] netfilter: xtables: allow xtables-nft only builds
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 7/9] netfilter: arptables: allow xtables-nft only builds
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 5/9] netfilter: nf_conncount: Use KMEM_CACHE instead of kmem_cache_create()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 6/9] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 2/9] netfilter: nf_tables: Introduce NFT_TABLE_F_PERSIST
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/9] netfilter: uapi: Document NFT_TABLE_F_OWNER flag
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 4/9] netfilter: nf_tables: pass flags to set backend selection routine
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 3/9] netfilter: nf_tables: Implement table adoption support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/9] netfilter updates for -next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] datatype: display 0s time datatype
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/1] ipset performance regression in swap fix
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: fix performance regression in swap operation
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [RFC PATCH 1/1] netfilter: nat: restore default DNAT behavior
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH bpf-next v4 3/3] bpf: treewide: Annotate BPF kfuncs in BTF
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH bpf-next v4 0/3] Annotate kfuncs in .BTF_ids section
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_conncount: Use KMEM_CACHE() instead of kmem_cache_create()
- From: Markus Elfring <Markus.Elfring@xxxxxx>
- Re: [RFC PATCH 1/1] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- Re: [RFC PATCH 1/1] netfilter: nat: restore default DNAT behavior
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC PATCH 1/1] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- [RFC PATCH 0/1] netfilter: nat: restore default DNAT behavior
- From: Kyle Swenson <kyle.swenson@xxxxxxxx>
- Re: [PATCH nf] netfilter: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
- From: Xin Long <lucien.xin@xxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Phil Sutter <phil@xxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/6] netfilter: nf_tables: cleanup documentation
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH libnetfilter_conntrack 1/2] dump: support filtering by zone
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [netfilter-core] [ANN] net-next is OPEN
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/6] netfilter: nf_tables: cleanup documentation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/6] netfilter: nf_tables: validate NFPROTO_* family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/6] netfilter: nf_tables: reject QUEUE/DROP verdict parameters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/6] netfilter: nf_tables: restrict anonymous set and map names to 16 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/6] netfilter: nft_limit: reject configurations that cause integer overflow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/6] netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [ANN] net-next is OPEN
- From: Matthieu Baerts <matttbe@xxxxxxxxxx>
- [PATCH nf,v3] netfilter: nf_tables: validate NFPROTO_* family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ANN] net-next is OPEN
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] iptables: Add missing error codes
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next] netfilter: arptables: allow arptables-nft only builds
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next 2/2] netfilter: ebtables: add _LEGACY kconfig symbol
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: xtables: add _LEGACY kconfig symbol
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: expect: Simplify the allocation of slab caches in nf_conntrack_expect_init
- From: Kunwu Chan <chentao@xxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: "David Wang" <00107082@xxxxxxx>
- Re: [PATCH 64/82] netfilter: Refactor intentional wrap-around test
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_tables: Add a null pointer check in two functions
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH iptables] extensions: libebt_stp: fix range checking
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] iptables: Add missing error codes
- From: Jacek Tomasiak <jacek.tomasiak@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: arptables: allow arptables-nft only builds
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: netfilter: nf_tables: Add a null pointer check in two functions
- From: Markus Elfring <Markus.Elfring@xxxxxx>
- Re: [PATCH] netfilter: nf_tables: Add a null pointer check in two functions
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] netfilter: nf_tables: Add a null pointer check in two functions
- From: Markus Elfring <Markus.Elfring@xxxxxx>
- Re: [iptables PATCH] iptables: Add missing error codes
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] iptables: Add missing error codes
- From: Jacek Tomasiak <jacek.tomasiak@xxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH] tests: shell: add test to cover ct offload by using nft flowtables To cover kernel patch ("netfilter: nf_tables: set transport offset from mac header for netdev/egress").
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] tests: shell: add test to cover ct offload by using nft flowtables To cover kernel patch ("netfilter: nf_tables: set transport offset from mac header for netdev/egress").
- From: Yi Chen <yiche@xxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_conncount: Use KMEM_CACHE instead of kmem_cache_create()
- From: Kunwu Chan <chentao@xxxxxxxxxx>
- [PATCH 64/82] netfilter: Refactor intentional wrap-around test
- From: Kees Cook <keescook@xxxxxxxxxxxx>
- Re: [PATCH] tests: shell: add test to cover ct offload by using nft flowtables To cover kernel patch ("netfilter: nf_tables: set transport offset from mac header for netdev/egress").
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] tests: shell: add test to cover ct offload by using nft flowtables To cover kernel patch ("netfilter: nf_tables: set transport offset from mac header for netdev/egress").
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] tests: shell: add test to cover ct offload by using nft flowtables To cover kernel patch ("netfilter: nf_tables: set transport offset from mac header for netdev/egress").
- Re: [PATCH net] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Kunwu Chan <chentao@xxxxxxxxxx>
- [PATCH] netfilter: conntrack: correct window scaling with retransmitted SYN
- From: Ryan Schaefer <ryanschf@xxxxxxxxxx>
- Re: PROBLEM: nf_conntrack tcp SYN reuse results in incorrect window scaling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: reject QUEUE/DROP verdict parameters
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: PROBLEM: nf_conntrack tcp SYN reuse results in incorrect window scaling
- From: "Schaefer, Ryan" <ryanschf@xxxxxxxxxx>
- PROBLEM: nf_conntrack tcp SYN reuse results in incorrect window scaling
- From: "Schaefer, Ryan" <ryanschf@xxxxxxxxxx>
- Re: [PATCH net] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Simon Horman <horms@xxxxxxxxxx>
- [PATCH nft 2/2] evaluate: permit use of host-endian constant values in set lookup keys
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/2] fix host-endian constant values in set lookup keys
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] netlink_delinearize: move concat and value postprocessing to helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: restrict anonymous set and map names to 16 bytes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_limit: reject configurations that cause integer overflow
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 01/13] netfilter: nf_tables: reject invalid set policy
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net 13/13] ipvs: avoid stat macros calls from preemptible context
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 06/13] netfilter: nf_queue: remove excess nf_bridge variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 12/13] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 08/13] netfilter: bridge: replace physindev with physinif in nf_bridge_info
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 10/13] netfilter: nf_tables: do not allow mismatch field size and set key length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 11/13] netfilter: nf_tables: skip dead set elements in netlink dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 07/13] netfilter: propagate net to nf_bridge_get_physindev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 09/13] netfilter: nf_tables: check if catch-all set element is active in next generation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 05/13] netfilter: nfnetlink_log: use proper helper for fetching physinif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 04/13] netfilter: nft_limit: do not ignore unsupported flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 03/13] netfilter: nf_tables: bail out if stateful expression provides no .clone
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 01/13] netfilter: nf_tables: reject invalid set policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 02/13] netfilter: nf_tables: validate .maxattr at expression registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net,v2 00/13] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH nft] tests: py: remove huge-limit test cases
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Kunwu Chan <chentao@xxxxxxxxxx>
- [syzbot] [netfilter?] WARNING in nf_hook_entry_head
- From: syzbot <syzbot+ea8f0147cde55bfa62e9@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [PATCH net 13/14] ipvs: avoid stat macros calls from preemptible context
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 14/14] netfilter: ipset: fix performance regression in swap operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 11/14] netfilter: nf_tables: skip dead set elements in netlink dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 12/14] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 08/14] netfilter: bridge: replace physindev with physinif in nf_bridge_info
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 07/14] netfilter: propagate net to nf_bridge_get_physindev
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 10/14] netfilter: nf_tables: do not allow mismatch field size and set key length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 09/14] netfilter: nf_tables: check if catch-all set element is active in next generation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 05/14] netfilter: nfnetlink_log: use proper helper for fetching physinif
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 06/14] netfilter: nf_queue: remove excess nf_bridge variable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 04/14] netfilter: nft_limit: do not ignore unsupported flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 03/14] netfilter: nf_tables: bail out if stateful expression provides no .clone
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 02/14] netfilter: nf_tables: validate .maxattr at expression registration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 01/14] netfilter: nf_tables: reject invalid set policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 00/14] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 0/4] netlink: bridge: fix nf_bridge->physindev use after free
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCHv2 RFC net-next 08/14] ipvs: use resizable hash table for services
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH 1/1] netfilter: ipset: fix performance regression in swap operation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] net: ipvs: avoid stat macros calls from preemptible context
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 0/4] netlink: bridge: fix nf_bridge->physindev use after free
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 RFC net-next 08/14] ipvs: use resizable hash table for services
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [PATCH net] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [PATCH net] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Denis Kirjanov <dkirjanov@xxxxxxx>
- [PATCH net] ipvs: Simplify the allocation of ip_vs_conn slab caches
- From: Kunwu Chan <chentao@xxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: fix performance regression in swap operation
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 0/1] ipset performance regression in swap fix
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH net] net: ipvs: avoid stat macros calls from preemptible context
- From: Simon Horman <horms@xxxxxxxxxx>
- [PATCH nft] evaluate: don't assert on net/transport header conflict
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC nf-next v5 0/2] netfilter: bpf: support prog update
- From: "D. Wythe" <alibuda@xxxxxxxxxxxxxxxxx>
- Re: [PATCH net] net: ipvs: avoid stat macros calls from preemptible context
- From: Julian Anastasov <ja@xxxxxx>
- Re: Performance regression in ip_set_swap on 6.7.0
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: netfilter ipv6 flow offloading seemingly causing hangs - how to debug?
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] net: ipvs: avoid stat macros calls from preemptible context
- From: Fedor Pchelkin <pchelkin@xxxxxxxxx>
- Re: Performance regression in ip_set_swap on 6.7.0
- From: Ale Crismani <ale.crismani@xxxxxxxxxxxxxx>
- [PATCH nft] rule: fix sym refcount assertion
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] evaluate: error out when store needs more than one 128bit register of align fixup
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: skip dead set elements in netlink dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: do not allow mismatch field size and set key length
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 3/4] netfilter: propagate net to nf_bridge_get_physindev
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [PATCH v3 2/4] netfilter: nf_queue: remove excess nf_bridge variable
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [PATCH v3 1/4] netfilter: nfnetlink_log: use proper helper for fetching physinif
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: Performance regression in ip_set_swap on 6.7.0
- From: Ale Crismani <ale.crismani@xxxxxxxxxxxxxx>
- Re:Performance regression in ip_set_swap on 6.7.0
- From: "David Wang" <00107082@xxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Annotate kfuncs in .BTF_ids section
- From: Jiri Olsa <olsajiri@xxxxxxxxx>
- Re:Performance regression in ip_set_swap on 6.7.0
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Annotate kfuncs in .BTF_ids section
- From: Daniel Xu <dxu@xxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Annotate kfuncs in .BTF_ids section
- From: Jiri Olsa <olsajiri@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: check if catch-all set element is active in next generation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Annotate kfuncs in .BTF_ids section
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH libnftnl,v3] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Annotate kfuncs in .BTF_ids section
- From: Jiri Olsa <olsajiri@xxxxxxxxx>
- Re: [PATCH libnftnl] set: buffer overflow in NFTNL_SET_DESC_CONCAT setter
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft] rule: do not crash if to-be-printed flowtable lacks priority
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 1/2] parser: reject raw payload expressions with 0 length
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft v3] src: do not merge a set with a erroneous one
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnftnl] set: buffer overflow in NFTNL_SET_DESC_CONCAT setter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] set: buffer overflow in NFTNL_SET_DESC_CONCAT setter
- From: Phil Sutter <phil@xxxxxx>
- [PATCH libnftnl] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] set: buffer overflow in NFTNL_SET_DESC_CONCAT setter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] evaluate: release mpz type in expr_evaluate_list() error path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/2] memleak fixes for tests/shell/testcases/bogons/nft-f/
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] evaluate: release key expression in error path of implicit map with unknown datatype
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2] evaluate: bail out if anonymous concat set defines a non concat expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v2 2/2] evaluate: add missing range checks for dup,fwd and payload statements
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] evaluate: tproxy: move range error checks after arg evaluation
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/2] evaluate: add more checks for '... set 1-3'
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Re: [PATCH v14 10/12] selftests/landlock: Add network tests
- From: Mickaël Salaün <mic@xxxxxxxxxxx>
- Re: [PATCH nft] evaluate: disable ct set with ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] evaluate: error out when expression has no datatype
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v3 4/4] netfilter: bridge: replace physindev with physinif in nf_bridge_info
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- [PATCH v3 3/4] netfilter: propagate net to nf_bridge_get_physindev
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- [PATCH v3 2/4] netfilter: nf_queue: remove excess nf_bridge variable
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- [PATCH v3 1/4] netfilter: nfnetlink_log: use proper helper for fetching physinif
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- [PATCH v3 0/4] netlink: bridge: fix nf_bridge->physindev use after free
- From: Pavel Tikhomirov <ptikhomirov@xxxxxxxxxxxxx>
- Re:Performance regression in ip_set_swap on 6.7.0
- From: David Wang <00107082@xxxxxxx>
- Re: [PATCH nft] evaluate: disable ct set with ranges
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] evaluate: disable ct set with ranges
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] payload: only assert if l2 header base has no length
- From: Florian Westphal <fw@xxxxxxxxx>
- Re:Re: Performance regression in ip_set_swap on 6.1.69
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re:Re: Performance regression in ip_set_swap on 6.1.69
- From: "David Wang" <00107082@xxxxxxx>
- Re: [PATCH nft 4/4] Revert "datatype: do not assert when value exceeds expected width"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Performance regression in ip_set_swap on 6.1.69
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nft 4/4] Revert "datatype: do not assert when value exceeds expected width"
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH v2 0/3] iptables-save: Avoid /etc/protocols lookups
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 1/3] Revert "xshared: Print protocol numbers if --numeric was given"
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 2/3] libxtables: Add dccp and ipcomp to xtables_chain_protos
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH v2 3/3] iptables-save: Avoid /etc/protocols lookups
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH v2] ebtables: Default to extrapositioned negations
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nft 4/4] Revert "datatype: do not assert when value exceeds expected width"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/4] assorted fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/4] evaluate: bail out if anonymous concat set defines a non concat expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/4] evaluate: skip anonymous set optimization for concatenations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/4] evaluate: do not fetch next expression on runaway number of concatenation components
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Performance regression in ip_set_swap on 6.1.69
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nftables] doc: clarify reject is supported at prerouting stage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 00/23] Guided option parser for ebtables
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/2] Revert "xshared: Print protocol numbers if --numeric was given"
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/2] iptables-save: Avoid /etc/protocols lookups
- From: Phil Sutter <phil@xxxxxx>
- Re: Performance regression in ip_set_swap on 6.1.69
- From: "David Wang" <00107082@xxxxxxx>
- Re: Performance regression in ip_set_swap on 6.1.69
- From: "David Wang" <00107082@xxxxxxx>
- Re: Performance regression in ip_set_swap on 6.1.69
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Performance regression in ip_set_swap on 6.1.69
- From: David Wang <00107082@xxxxxxx>
- Re: [PATCH v2 nft 3/3] evaluate: don't assert if set->data is NULL
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nft 3/3] evaluate: don't assert if set->data is NULL
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nft 2/3] src: do not merge a set with a erroneous one
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nft 1/3] intervals: allow low-level interval code to return errors
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 nft 0/3] set related parser fixes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nftables] doc: clarify reject is supported at prerouting stage
- From: Quan Tian <tianquan23@xxxxxxxxx>
- Re: [nf-next PATCH v2 0/3] netfilter: nf_tables: Introduce NFT_TABLE_F_PERSIST
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] doc: incorrect datatype description for icmpv6_type and icmpvx_code
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v3 0/3] Annotate kfuncs in .BTF_ids section
- From: Daniel Xu <dxu@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: bail out if stateful expression provides no .clone
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]