Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH nf-next 1/3] netfilter: nf_tables: add generation mask to table objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nf_tables: add generation mask to set objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: IP sets: Suggestion: additional value match
- From: Rudolf_AT <Rudolf_AT.nf@xxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Joe Stringer <joestringer@xxxxxxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Joe Stringer <joestringer@xxxxxxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Joe Stringer <joestringer@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: connlabels: Export setting connlabel length
- From: Joe Stringer <joestringer@xxxxxxxxxx>
- [PATCH nft] src: restore nft list tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_counter: convert it to use per-cpu counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: IP sets: Suggestion: additional value match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Multiple DSCP match by "-m dscp --dscp-multi value,value,..."
- From: Kyeong Yoo <Kyeong.Yoo@xxxxxxxxxxxxxxxxxxx>
- New multiple DSCP match by "-m dscp --dscp-multi value,value,..."
- From: Kyeong Yoo <Kyeong.Yoo@xxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: connlabels: Export setting connlabel length
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: connlabels: Export setting connlabel length
- From: Joe Stringer <joestringer@xxxxxxxxxx>
- [IPTABLES] Module ipt_same
- From: Alex william <alex.william21@xxxxxxxxxxx>
- Re: [PATCH] netfilter: xtables: Add helper macro for xt_match boilerplate
- From: Vaishali Thakkar <vthakkar1994@xxxxxxxxx>
- [PATCH nf-next] netfilter: ip6t_REJECT: Remove debug messages from reject_tg6()
- From: subashab@xxxxxxxxxxxxxx
- Re: [PATCH nf-next v3 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v3 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- IP sets: Suggestion: additional value match
- From: Rudolf_AT <Rudolf_AT.nf@xxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xtables: Add helper macro for xt_match boilerplate
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: IPv4 IPv6 parallel dns lookup in combination with nfqueue is problematic
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: bridge: do not initialize statics to 0 or NULL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ip6t_REJECT: Log reject reason in reject_tg6()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: bridge: reduce nf_bridge_info to 32 bytes again
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_ct_sctp: minimal multihoming support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: ip6t_REJECT: Log reject reason in reject_tg6()
- From: subashab@xxxxxxxxxxxxxx
- [PATCHv3 2/2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Bernhard Thaler <bernhard.thaler@xxxxxxxx>
- [PATCH 1/2 nf] netfilter: bridge: do not initialize statics to 0 or NULL
- From: Bernhard Thaler <bernhard.thaler@xxxxxxxx>
- [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH] netfilter: xtables: Add helper macro for xt_match boilerplate
- From: Vaishali Thakkar <vthakkar1994@xxxxxxxxx>
- Re: [PATCH 00/10] Netfilter/IPVS fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- IPv4 IPv6 parallel dns lookup in combination with nfqueue is problematic
- From: Tarik Demirci <tarik@xxxxxxxxxxxxxxxx>
- Re: [IPTABLES 0/2] iptables-compat fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: bridge: reduce nf_bridge_info to 32 bytes again
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_queue: fix deadlock in nf_queue_nf_hook_drop()
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf-next] netfilter: nf_queue: fix nf_queue_nf_hook_drop()
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH nf] netfilter: nf_conntrack: silence warning on falling back to vmalloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nf_conntrack: falling back to vmalloc.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_queue: fix deadlock in nf_queue_nf_hook_drop()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_queue: fix nf_queue_nf_hook_drop()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/10] netfilter: ctnetlink: put back references to master ct and expect objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/10] netfilter: IDLETIMER: fix lockdep warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/10] Netfilter/IPVS fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/10] ipvs: fix ipv6 route unreach panic
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/10] ipvs: fix crash if scheduler is changed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/10] ipvs: skb_orphan in case of forwarding
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/10] ipvs: call skb_sender_cpu_clear
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/10] ipvs: fix crash with sync protocol v0 and FTP
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/10] netfilter: fix netns dependencies with conntrack templates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/10] netfilter: nf_conntrack: Support expectations in different zones
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/10] ipvs: do not use random local source address for tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: rename local nf_hook_list to hook_list
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf-next 1/2] netfilter: fix possible removal of wrong hook
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf-next] netfilter: nf_queue: fix deadlock in nf_queue_nf_hook_drop()
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf] netfilter: Support expectations in different zones
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- heads up, rebasing nf (was Re: [PATCH nf] netfilter: nf_conntrack: silent warning when adding) extensions to templates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/6] IPVS Fixes for v4.2
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH 0/5] netlink: mmap kernel panic and some issues
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH iptables] libxt_CT: add support for recently introduced zone options
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v3 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v3 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v3 2/3] netfilter: nf_conntrack: add direction support for zones
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v3 0/3] Netfilter zone directions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- ip(6)tables-restore segfault + patch
- From: Felix Bolte <bolte.felix@xxxxxxxxx>
- [PATCH nf] netfilter: Support expectations in different zones
- From: Joe Stringer <joestringer@xxxxxxxxxx>
- [RFC PATCH 5/5] netlink: rx mmap: notify only when NL_MMAP_STATUS_VALID frame exists
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [RFC PATCH 4/5] netlink: mmap: update tx type check
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [RFC PATCH 3/5] netlink: mmap: fix status for not delivered skb
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [RFC PATCH 2/5] netlink: mmap: apply mmaped skb helper functions
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [RFC PATCH 1/5] netlink: mmap: introduce mmaped skb helper functions
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- [RFC PATCH 0/5] netlink: mmap kernel panic and some issues
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- Re: [PATCHv2 net-next] net: #ifdefify sk_classid member of struct sock
- From: David Miller <davem@xxxxxxxxxxxxx>
- [IPTABLES 0/2] iptables-compat fixes
- From: Thomas Woerner <twoerner@xxxxxxxxxx>
- [IPTABLES 2/2] iptables-compat: Increase rule number only for the selected table and chain
- From: Thomas Woerner <twoerner@xxxxxxxxxx>
- [IPTABLES 1/2] iptables-compat: Allow to insert into rule_count+1 position
- From: Thomas Woerner <twoerner@xxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: validate generated netlink instructions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: validate generated netlink instructions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH iptables] fix wrong headername in ipv6header for protocols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: validate generated netlink instructions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: validate generated netlink instructions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH iptables] fix wrong headername in ipv6header for protocols
- From: Andreas Herz <andi@xxxxxxxxxxxxxxx>
- Re: [PATCHv2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: validate generated netlink instructions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] Fix grammar error in manpage
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: fix possible removal of wrong hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: rename local nf_hook_list to hook_list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_queue: fix deadlock in nf_queue_nf_hook_drop()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] Fix grammar error in manpage
- From: Neutron Soutmun <neo.neutron@xxxxxxxxx>
- [PATCH nf] netfilter: nf_conntrack: silent warning when adding extensions to templates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] fix wrong headername in ipv6header for protocols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: Fix memory leak in nf_register_net_hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [netfilter] INFO: task kworker/u2:0:6 blocked for more than 120 seconds.
- From: Fengguang Wu <fengguang.wu@xxxxxxxxx>
- [PATCHv2 net-next] net: #ifdefify sk_classid member of struct sock
- From: Mathias Krause <minipli@xxxxxxxxxxxxxx>
- Re: [PATCH net-next] net: #ifdefify sk_classid member of struct sock
- From: Mathias Krause <minipli@xxxxxxxxxxxxxx>
- Re: [PATCH net-next] net: #ifdefify sk_classid member of struct sock
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH net-next] net: #ifdefify sk_classid member of struct sock
- From: Mathias Krause <minipli@xxxxxxxxxxxxxx>
- Re: [PATCHv2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Bernhard Thaler <bernhard.thaler@xxxxxxxx>
- Re: nf_conntrack: falling back to vmalloc.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nf_conntrack: falling back to vmalloc.
- From: Toralf Förster <toralf.foerster@xxxxxx>
- [PATCH nf-next v2] netfilter: nf_ct_sctp: minimal multihoming support
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: nf_conntrack: falling back to vmalloc.
- From: Florian Westphal <fw@xxxxxxxxx>
- nf_conntrack: falling back to vmalloc.
- From: Toralf Förster <toralf.foerster@xxxxxx>
- [PATCH nft] tests: validate generated netlink instructions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nft: meta l4proto range printing broken on 32bit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nft: meta l4proto range printing broken on 32bit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nft: meta l4proto range printing broken on 32bit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH iptables] fix wrong headername in ipv6header for protocols
- From: Andreas Herz <andi@xxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: nft: meta l4proto range printing broken on 32bit
- From: Florian Westphal <fw@xxxxxxxxx>
- nft: meta l4proto range printing broken on 32bit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCHv2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH -next 0/6] Per network namespace netfilter chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 0/6] IPVS Fixes for v4.2
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf 2/6] ipvs: do not use random local source address for tunnels
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf 1/6] ipvs: fix ipv6 route unreach panic
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf 4/6] ipvs: skb_orphan in case of forwarding
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf 3/6] ipvs: fix crash if scheduler is changed
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf 5/6] ipvs: fix crash with sync protocol v0 and FTP
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH nf 6/6] ipvs: call skb_sender_cpu_clear
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCHv2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Bernhard Thaler <bernhard.thaler@xxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH -next 5/6] netfilter: Per network namespace netfilter hooks.
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf,v2] netfilter: fix netns dependencies with conntrack templates
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH -next 0/6] Per network namespace netfilter chains
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH -next 5/6] netfilter: Per network namespace netfilter hooks.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH -next v2 0/6] netfilter: xtables: improve jumpstack handling
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC PATCH nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH -next 0/6] Per network namespace netfilter chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH -next v2 0/6] netfilter: xtables: improve jumpstack handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next] net-ipvs: Delete an unnecessary check before the function call "module_put"
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] extensions: libxt_socket: update man pages and tests for --restore-skmark
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: fix netns dependencies with conntrack templates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2] build: resolve build error involving libnftnl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Q] iptables AH module api mismatch between -master and 1.4.7
- From: Cyrill Gorcunov <gorcunov@xxxxxxxxx>
- Re: [Q] iptables AH module api mismatch between -master and 1.4.7
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 1/2] build: resolve build error involving libnftnl
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH 2/2] extensions: restore matching any SPI id by default
- From: Jan Engelhardt <jengelh@xxxxxxx>
- iptables: AH/ESP init fix, and a build fix
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [Q] iptables AH module api mismatch between -master and 1.4.7
- From: Cyrill Gorcunov <gorcunov@xxxxxxxxx>
- Re: [PATCH] netfilter: nf_nat: Fix possible null dereference
- From: subashab@xxxxxxxxxxxxxx
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Akemi Yagi <amyagi@xxxxxxxxx>
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Michal Kubecek <mkubecek@xxxxxxx>
- [PATCH -next v2 6/6] netfilter: xtables: add upper limit on call chain depth
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next v2 2/6] netfilter: move tee_active to core
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next v2 3/6] netfilter: xtables: don't save/restore jumpstack offset
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next v2 1/6] netfilter: xtables: compute exact size needed for jumpstack
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next v2 0/6] netfilter: xtables: improve jumpstack handling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next 5/6] netfilter: xtables: remove __pure annotation
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next 4/6] netfilter: add and use jump label for xt_tee
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support
- From: Michal Kubecek <mkubecek@xxxxxxx>
- Re: [PATCH nf RFC] netfilter: fix netns dependencies with conntrack templates
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Alan Bartlett <ajb@xxxxxxxxxx>
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Cong Wang <cwang@xxxxxxxxxxxxxxxx>
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Akemi Yagi <amyagi@xxxxxxxxx>
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH iptables] extensions: libxt_socket: update man pages and tests for --restore-skmark
- From: Harout Hedeshian <harouth@xxxxxxxxxxxxxx>
- Re: [PATCH nf RFC] netfilter: fix netns dependencies with conntrack templates
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: nf_nat: Fix possible null dereference
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] nf: IDLETIMER: fix lockdep warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] nf: IDLETIMER: fix lockdep warning
- From: Dmitry Torokhov <dtor@xxxxxxxxxx>
- Re: [PATCH] nf: IDLETIMER: fix lockdep warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf RFC] netfilter: fix netns dependencies with conntrack templates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 0/3] Netfilter zone directions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v2 2/3] netfilter: nf_conntrack: add direction support for zones
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v2 3/3] netfilter: nf_conntrack: add efficient mark to zone mapping
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf-next v2 1/3] netfilter: nf_conntrack: push zone object into functions
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH iptables] libxt_CT: add support for recently introduced zone options
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH -next 6/6] netfilter: nftables: Only run the nftables chains in the proper netns
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH -next 5/6] netfilter: Per network namespace netfilter hooks.
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH -next 4/6] netfilter: Factor out the hook list selection from nf_register_hook
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH -next 3/6] netfilter: Simply the tests for enabling and disabling the ingress queue hook
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH -next 2/6] netfilter: kill nf_hooks_active
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH -next 1/6] netfilter: nf_queue: Don't recompute the hook_list head
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH -next 0/6] Per network namespace netfilter chains
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH nf-next] net-ipvs: Delete an unnecessary check before the function call "module_put"
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [GIT PULL nf-next] IPVS for v4.3
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH] nf: IDLETIMER: fix lockdep warning
- From: Dmitry Torokhov <dtor@xxxxxxxxxx>
- Re: [PATCH] netfilter: nf_nat: Fix possible null dereference
- From: subashab@xxxxxxxxxxxxxx
- Re: [PATCH] netfilter: nf_nat: Fix possible null dereference
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: ctnetlink: put back references to master ct and expect objects
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH -next 3/4] netfilter: xtables: don't save/restore jumpstack offset
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH -next 3/4] netfilter: xtables: don't save/restore jumpstack offset
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH -next 3/4] netfilter: xtables: don't save/restore jumpstack offset
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH 0/7] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH COLO-Frame v7 00/34] COarse-grain LOck-stepping(COLO) Virtual Machines for Non-stop Service (FT)
- From: zhanghailiang <zhang.zhanghailiang@xxxxxxxxxx>
- Re: [PATCH] net-ipvs: Delete an unnecessary check before the function call "module_put"
- From: Simon Horman <horms@xxxxxxxxxxxx>
- [PATCH] netfilter: nf_nat: Fix possible null dereference
- From: subashab@xxxxxxxxxxxxxx
- Re: [PATCH -next 3/4] netfilter: xtables: don't save/restore jumpstack offset
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH -next 3/4] netfilter: xtables: don't save/restore jumpstack offset
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH RFC -next 4/4] netfilter: xtables: add upper limit on call chain depth
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next 3/4] netfilter: xtables: don't save/restore jumpstack offset
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next 2/4] netfilter: move tee_active to core
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next 1/4] xtables: compute exact size needed for jumpstack
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH -next 0/4] netfilter: xtables: improve jumpstack handling
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 2/7] netfilter: bridge: fix CONFIG_NF_DEFRAG_IPV4/6 related warnings/errors
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/7] netfilter: bridge: don't leak skb in error paths
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/7] netfilter: bridge: Use __in6_dev_get rather than in6_dev_get in br_validate_ipv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/7] MAINTAINER: add bridge netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/7] netfilter: nf_queue: Don't recompute the hook_list head
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/7] netfilter: nfnetlink: keep going batch handling on missing modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/7] netfilter: arptables: use percpu jumpstack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/7] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/3 nft] configure: fix --enable-debug
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/3 nft] src: fix do_list_tables() with family filtering
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/3 nft] src: get rid of EINTR handling in nft_netlink()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] net/bridge: Use __in6_dev_get rather than in6_dev_get in br_validate_ipv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] net/bridge: Use __in6_dev_get rather than in6_dev_get in br_validate_ipv6
- From: Stephen Hemminger <stephen@xxxxxxxxxxxxxxxxxx>
- [PATCH v2] net/bridge: Use __in6_dev_get rather than in6_dev_get in br_validate_ipv6
- From: Julien Grall <julien.grall@xxxxxxxxxx>
- Re: [PATCH lnf-ct] conntrack: fix stop timestamp assignment
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH lnf-ct] conntrack: fix stop timestamp assignment
- From: Ken-ichirou MATSUZAWA <chamaken@xxxxxxxxx>
- Re: [RFC PATCH nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC PATCH nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Bernhard Thaler <bernhard.thaler@xxxxxxxx>
- [PATCH nf] MAINTAINER: add bridge netfilter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 16/16] src: consolidate set element cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 15/16] rule: consolidate rule cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 14/16] src: add chain declarations to cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 13/16] evaluate: add cmd_evaluate_rename()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 12/16] src: consolidate chain cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 06/16] src: add set declaration to cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 10/16] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 11/16] rule: add chain reference counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 09/16] rule: use netlink_add_setelems() when creating literal sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 08/16] segtree: pass element expression as parameter to set_to_intervals()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 05/16] src: consolidate set cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 07/16] src: early allocation of the set ID
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 04/16] src: add table declaration to cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 01/16] src: consolidate table cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 00/16] cache consolidation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 03/16] rule: add reference counter to the table object
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v4 02/16] src: add cmd_evaluate_list()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/3] src: set chain->hookstr from delinearization
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] rule: missing family when listing of tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/3] rule: add do_list_tables()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: Kernel 4.1.0 broke the TARPIT & DELUGE targets in xtables-addons-2.6
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [Q RFC nft] how to add bridge vlan header match support?
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [RFC PATCH nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC PATCH nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n
- From: Bernhard Thaler <bernhard.thaler@xxxxxxxx>
- Re: Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Guenter Roeck <linux@xxxxxxxxxxxx>
- Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c
- From: Vinson Lee <vlee@xxxxxxxxxxxxxxxx>
- [RFC PATCH v2] netfilter: nf_conntrack: fix endless loop on netns deletion
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH v2] conntrack: made the protocol option value case insensitive
- From: pfeiffer.szilard@xxxxxxxxxx
- Re: [PATCH] conntrack: made the protocol option value case insensitive
- From: Szilárd Pfeiffer <pfeiffer.szilard@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: bridge: don't leak skb in error paths
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 7/7] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 6/7] rule: use netlink_add_setelems() when creating literal sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 5/7] segtree: pass element expression as parameter to set_to_intervals()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 4/7] src: early allocation of the set ID
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 3/7] src: consolidate set cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 2/7] src: add table declaration to cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 1/7] src: consolidate table cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3 0/7] cache consolidation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] conntrack: made the protocol option value case insensitive
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [Q RFC nft] how to add bridge vlan header match support?
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] net-ipvs: Delete an unnecessary check before the function call "module_put"
- From: SF Markus Elfring <elfring@xxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: bridge: don't leak skb in error paths
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_conntrack: fix endless loop on netns deletion
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_conntrack: fix endless loop on netns deletion
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_conntrack: fix endless loop on netns deletion
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- [PATCH nf,v2] netfilter: nfnetlink: keep going batch handling on missing modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH -stable] netfilter: nft_rbtree: fix locking
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] COLO Proxy Module
- From: Wen Congyang <wency@xxxxxxxxxxxxxx>
- Re: [PATCH COLO-Frame v6 00/31] COarse-grain LOck-stepping(COLO) Virtual Machines for Non-stop Service
- From: zhanghailiang <zhang.zhanghailiang@xxxxxxxxxx>
- [PATCH nf] netfilter: bridge: don't leak skb in error paths
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: arptables: use percpu jumpstack
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH COLO-Frame v6 00/31] COarse-grain LOck-stepping(COLO) Virtual Machines for Non-stop Service
- From: "Dr. David Alan Gilbert" <dgilbert@xxxxxxxxxx>
- RE: [PATCH iptables] xt_socket: add --restore-skmark option
- From: "Harout Hedeshian" <harouth@xxxxxxxxxxxxxx>
- Re: [PATCH] libmnl: security context retrieval in nf-queue example
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] xt_socket: add --restore-skmark option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 3/7] src: consolidate set cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/7] src: consolidate table cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC] COLO Proxy Module
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft] datatype: avoid crash in debug mode when printing integers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] redir: fix snprintf to return the number of bytes printed
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] payload: reorder case in a switch for consistency
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables 2/3] erec: fix logic when reading from file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables 1/3] erec: fix buffer overflow
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Extending nftables user-space utility for custom filters
- From: Juergen Brendel <juergen@xxxxxxxxxxx>
- Re: [PATCH -stable] netfilter: nft_rbtree: fix locking
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- Re: nftables: parser conflict between tokens & symbols
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: nftables: parser conflict between tokens & symbols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nftables: parser conflict between tokens & symbols
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/7] rule: use netlink_add_setelems() when creating literal sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/7] src: early allocation of the set ID
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/7] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/7] segtree: pass element expression as parameter to set_to_intervals()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/7] src: consolidate table cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/7] src: consolidate set cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/7] src: always allocate table object with no table block
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/7 nft] cache consolidation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nftables: parser conflict between tokens & symbols
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: IPSet target SET subnet options
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- IPSet target SET subnet options
- From: WaaX <waax@xxxxxxxxx>
- nftables: parser conflict between tokens & symbols
- From: Balazs Scheidler <balazs.scheidler@xxxxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Bjørnar Ness <bjornar.ness@xxxxxxxxx>
- [PATCH] redir: fix snprintf to return the number of bytes printed
- From: balazs.scheidler@xxxxxxxxxxx
- [PATCH nft] payload: reorder case in a switch for consistency
- From: Eric Leblond <eric@xxxxxxxxx>
- Re: [PATCH nft] payload: fix transport matching with no network layer info in bridge family
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [nftables] payload: gen l4proto dependency on bridge
- From: Eric Leblond <eric@xxxxxxxxx>
- [PATCH nft] datatype: avoid crash in debug mode when printing integers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] payload: fix transport matching with no network layer info in bridge family
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_queue: restrict queueing to supported families
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] conntrack: made the manual page and help consistent in case of proto option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables 1/4] Sync with ethernetdb.h from ebtables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: expectation entry creation with conntrack
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/5] netlink: delinarize chain policy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 nf] netfilter: nft_queue: restrict queueing to supported families
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [PATCH 2/2 nf] netfilter: nfnetlink: keep going batch handling on missing modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/2 nf] netfilter: nft_queue: restrict queueing to supported families
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: bridge: fix CONFIG_NF_DEFRAG_IPV4/6 related warnings/errors
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] conntrack: made the protocol option value case insensitive
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 4/5] trace: implement commands action
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 5/5] trace: add log for packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2] conntrack: fix expectation entry creation
- From: pfeiffer.szilard@xxxxxxxxxx
- [PATCH 1/2] conntrack: refactor handling of address options
- From: pfeiffer.szilard@xxxxxxxxxx
- expectation entry creation with conntrack
- From: pfeiffer.szilard@xxxxxxxxxx
- [PATCH] conntrack: made the protocol option value case insensitive
- From: pfeiffer.szilard@xxxxxxxxxx
- [PATCH] conntrack: made the manual page and help consistent in case of proto option
- From: pfeiffer.szilard@xxxxxxxxxx
- [PATCH] conntrack: made the manual page and help consistent in case of proto option
- From: pfeiffer.szilard@xxxxxxxxxx
- [ANNOUNCE] ipset 6.25.1 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: net/netfilter/ipset: work around gcc-4.4.4 initializer bug (was: Re: linux-next: Tree for Jun 25)
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- Re: net/netfilter/ipset: work around gcc-4.4.4 initializer bug (was: Re: linux-next: Tree for Jun 25)
- From: Geert Uytterhoeven <geert@xxxxxxxxxxxxxx>
- Re: [RESEND PATCH V2] Add element count to hash headers
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxxxxxx>
- [ulogd2 PATCHv3] Use stdint types everywhere
- From: Felix Janda <felix.janda@xxxxxxxxx>
- merge window freeze
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [nftables 3/3] mnl: improve select timeout logic
- From: Eric Leblond <eric@xxxxxxxxx>
- [nftables 3/3] mnl: improve select timeout logic
- From: Eric Leblond <eric@xxxxxxxxx>
- [nftables 2/3] erec: fix logic when reading from file
- From: Eric Leblond <eric@xxxxxxxxx>
- [nftables 1/3] erec: fix buffer overflow
- From: Eric Leblond <eric@xxxxxxxxx>
- [nftables 0/3] misc fixes
- From: Eric Leblond <eric@xxxxxxxxx>
- Re: [ulogd2 PATCHv2] Use stdint types everywhere
- From: Eric Leblond <eric@xxxxxxxxx>
- [ulogd2 PATCHv2] Use stdint types everywhere
- From: Felix Janda <felix.janda@xxxxxxxxx>
- Re: [ulogd2 PATCH 2/4] Use stdint types everywhere
- From: Felix Janda <felix.janda@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nftables: Do not run chains in the wrong network namespace
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [ulogd2 PATCH 2/4] Use stdint types everywhere
- From: Eric Leblond <eric@xxxxxxxxx>
- RE: Kernel 4.1.0 broke the TARPIT & DELUGE targets in xtables-addons-2.6
- From: Alexander Petrenas <zeracles@xxxxxxxxxxxxxxx>
- RE: Kernel 4.1.0 broke the TARPIT & DELUGE targets in xtables-addons-2.6
- From: Alexander Petrenas <zeracles@xxxxxxxxxxxxxxx>
- Re: Kernel 4.1.0 broke the TARPIT & DELUGE targets in xtables-addons-2.6
- From: Florian Westphal <fw@xxxxxxxxx>
- Kernel 4.1.0 broke the TARPIT & DELUGE targets in xtables-addons-2.6
- From: Alexander Petrenas <zeracles@xxxxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH 03/12] netfilter: x_tables: align per cpu xt_counter
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- RE: [PATCH 03/12] netfilter: x_tables: align per cpu xt_counter
- From: David Laight <David.Laight@xxxxxxxxxx>
- Re: [PATCH 00/12] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 00/32] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH 00/32] Netfilter updates for net-next
- From: Jakub Kiciński <moorray3@xxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nf_queue: Don't recompute the hook_list head
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nftables: Do not run chains in the wrong network namespace
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/12] netfilter: bridge: rename br_netfilter.c to br_netfilter_hooks.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/12] netfilter: Kill unused copies of RCV_SKB_FAIL
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/12] netfilter: bridge: split ipv6 code into separated file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/12] netfilter: xt_socket: add XT_SOCKET_RESTORESKMARK flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/12] netfilter: use forward declaration instead of including linux/proc_fs.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/12] net: include missing headers in net/net_namespace.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/12] net: sched: Simplify em_ipset_match
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/12] netfilter: x_tables: align per cpu xt_counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/12] netfilter: Remove spurios included of netfilter.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/12] netfilter: xtables: fix warnings on 32bit platforms
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/12] netfilter: don't pull include/linux/netfilter.h from netns headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/12] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/12] netfilter: nfnetlink_queue: add security context information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nftables: Do not run chains in the wrong network namespace
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nft] src: add tee statement
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nf-next, v4] netfilter: nft_counter: convert it to use per-cpu counters
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Marcelo Ricardo Leitner <marcelo.leitner@xxxxxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Patrick Schaaf <netdev@xxxxxx>
- Re: [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [PATCH nft 3/3] rule: fix use of intervals in set declarations
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/3] segtree: pass element expression as parameter to set_to_intervals()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] rule: use netlink_add_setelems() when creating literal sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] src: add tee statement
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [PATCH nf-next, v4] netfilter: nft_counter: convert it to use per-cpu counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next, v3] netfilter: nft_counter: convert it to use per-cpu counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: add tee statement
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] expr: add new nft_tee expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] libnetfilter_queue.h: Include <sys/time.h> for struct timeval
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_counter: add per-cpu support
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_counter: add per-cpu support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_counter: add per-cpu support
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH] net: fix search limit handling in skb_find_text()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/43] Simplify netfilter and network namespaces (take 2)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH -next] netfilter: xtables: fix warnings on 32bit platforms
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] x_table: align per cpu xt_counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH iptables] xt_socket: add --restore-skmark option
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] nfnetlink_queue: add security context information
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nft_counter: split out counters from nft_counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_counter: add per-cpu support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- =?y?q?=5BPATCH=20nf-next=2C=20v2=202/3=5D=20netfilter=3A=20move=20generic=20TEE=20code=20from=20xtables=20to=20nf=5Ftee=5Fipv=7B4=2C6=7D=20modules?=
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next, v2 3/3] netfilter: nf_tables: add nft_tee expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next, v2 1/3] netfilter: xt_TEE: always allocate private area
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Kedves Email felhasználói;
- From: "rendszer Administrator®" <fizik@xxxxxxxxxxxxxx>
- Re: [PATCH net-next 00/43] Simplify netfilter and network namespaces (take 2)
- From: Andreas Schultz <aschultz@xxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net-next] x_table: align per cpu xt_counter
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next] x_table: align per cpu xt_counter
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH] net: fix search limit handling in skb_find_text()
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH COLO-Frame v6 00/31] COarse-grain LOck-stepping(COLO) Virtual Machines for Non-stop Service
- From: zhanghailiang <zhang.zhanghailiang@xxxxxxxxxx>
- [RFC] COLO Proxy Module
- From: Li Zhijian <lizhijian@xxxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH -next] netfilter: xtables: fix warnings on 32bit platforms
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net-next 43/43] netfilter: Skip unnecessary calls to synchronize_net
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH 0/5] nft trace
- From: Markus Koetter <koetter@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 4/5] trace: implement commands action
- From: Markus Koetter <koetter@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 5/5] trace: add log for packets
- From: Markus Koetter <koetter@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 3/5] rule: make cache creation a function
- From: Markus Koetter <koetter@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/5] parser: add trace command
- From: Markus Koetter <koetter@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 2/5] netlink: delinarize chain policy
- From: Markus Koetter <koetter@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH net-next 43/43] netfilter: Skip unnecessary calls to synchronize_net
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH net-next] x_table: align per cpu xt_counter
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 28/43] x_tables: Where possible convert to the new hook registration method
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 23/43] netfilter: Add a struct net parameter to nf_unregister_hook[s]
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 19/43] ipvs: Read hooknum from state rather than ops->hooknum
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 14/43] ipv4: Pass struct net into ip_defrag and ip_check_defrag
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 13/43] nf_conntrack: Add a struct net parameter to l4_pkt_to_tuple
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 38/43] netfilter: synproxy: Register netfilter hooks in all network namespaces
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 42/43] netfilter bridge: Make the sysctl knobs per network namespace
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 25/43] netfilter: Make nf_hook_ops just a parameter structure
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 24/43] netfilter: Make the netfilter hooks per network namespace
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 17/43] netfilter: use forward declaration instead of including linux/proc_fs.h
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 29/43] x_tables: Kill xt_[un]hook_link
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 16/43] net: include missing headers in net/net_namespace.h
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 35/43] ipvs: Register netfilter hooks in all network namespaces
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 40/43] smack: adapt it to pernet hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 20/43] netfilter: Pass priv instead of nf_hook_ops to netfilter hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 31/43] netfilter: nf_tables: adapt it to pernet hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 22/43] netfilter: Add a struct net parameter to nf_register_hook[s]
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 12/43] nf_tables: Use pkt->net instead of computing net from the passed net_devices
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 39/43] selinux: adapt it to pernet hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 30/43] x_tables: Update ip?table_nat to register their hooks in all network namespaces
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 41/43] netfilter: Remove the network namespace Kconfig conflict
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 43/43] netfilter: Skip unnecessary calls to synchronize_net
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 27/43] x_tables: Add magical hook registration in the common case
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 37/43] netfilter: nf_defrag: Register netfilter hooks in all network namespaces
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 36/43] netfilter: nf_conntract: Register netfilter hooks in all network namespaces
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 26/43] netfitler: Remove spurios included of netfilter.h
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 11/43] nftables: Pass struct net in nft_pktinfo
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 18/43] netfilter: don't pull include/linux/netfilter.h from netns headers
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 15/43] ipv6: Pass struct net into nf_ct_frag6_gather
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 33/43] netfilter: ebtables: adapt the filter and nat table to pernet hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 32/43] netfilter: ipt_CLUSTERIP: adapt it to support pernet hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 34/43] netfilter: bridge: adapt it to pernet hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 21/43] netfilter: Add a network namespace Kconfig conflict
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 02/43] netfilter: Pass struct net into the netfilter hooks
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 08/43] tc: Simplify em_ipset_match
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 04/43] ebtables: Simplify the arguments to ebt_do_table
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 07/43] nftables: kill nft_pktinfo.ops
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 10/43] x_tables: Use par->net instead of computing from the passed net devices
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 09/43] x_tables: Pass struct net in xt_action_param
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 06/43] inet netfilter: Prefer state->hook to ops->hooknum
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 05/43] inet netfilter: Remove hook from ip6t_do_table, arp_do_table, ipt_do_table
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 03/43] netfilter: Use nf_hook_state.net
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 01/43] netfilter: Kill unused copies of RCV_SKB_FAIL
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 00/43] Simplify netfilter and network namespaces (take 2)
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH nf-next 0/3] netfilter: socket lookup function refactoring, cgroup match fixes
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: socket lookup function refactoring, cgroup match fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables nftables compat weirdness
- From: Andreas Schultz <aschultz@xxxxxxxx>
- Re: [PATCH nft] parser_bison: allow to use mark as datatype for maps and sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables nftables compat weirdness
- From: Andreas Schultz <aschultz@xxxxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: socket lookup function refactoring, cgroup match fixes
- From: Daniel Mack <daniel@xxxxxxxxxx>
- Re: [PATCH nft] parser_bison: allow to use mark as datatype for maps and sets
- From: Miroslav Kratochvil <exa.exa@xxxxxxxxx>
- Re: [PATCH nft,next-4.2,v2] src: add netdev family support
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nf-next 3/4] netfilter: move generic TEE code from xtables to nf_tee_ipv{4,6} modules
- From: Patrick McHardy <kaber@xxxxxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: socket lookup function refactoring, cgroup match fixes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: factor out helpers from xt_socket into separate modules
- From: Daniel Mack <daniel@xxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: x_tables: fix cgroup's NF_INET_LOCAL_IN sk lookups
- From: Daniel Mack <daniel@xxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nft_meta: fix cgroup socket lookups
- From: Daniel Mack <daniel@xxxxxxxxxx>
- [PATCH nf-next 0/3] netfilter: socket lookup function refactoring, cgroup match fixes
- From: Daniel Mack <daniel@xxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [musl] [PATCH iptables RFC 4/4] libxt_TCPOPTSTRIP: Use local copy of TCPOPTS constants
- From: Rich Felker <dalias@xxxxxxxx>
- Re: [patch] ipvs: prevent some underflows
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH iptables RFC 4/4] libxt_TCPOPTSTRIP: Use local copy of TCPOPTS constants
- From: Felix Janda <felix.janda@xxxxxxxxx>
- [PATCH iptables 3/4] ip*_tables.h: Sync with upstream
- From: Felix Janda <felix.janda@xxxxxxxxx>
- [PATCH iptables 2/4] xtables.h: Use <stdint.h> types
- From: Felix Janda <felix.janda@xxxxxxxxx>
- [PATCH iptables 1/4] Sync with ethernetdb.h from ebtables
- From: Felix Janda <felix.janda@xxxxxxxxx>
- [PATCH nft-sync] event.c: Include <signal.h> for signal names
- From: Felix Janda <felix.janda@xxxxxxxxx>
- [PATCH libnetfilter_queue] libnetfilter_queue.h: Include <sys/time.h> for struct timeval
- From: Felix Janda <felix.janda@xxxxxxxxx>
- Re: [libnetfilter_log PATCH 2/3] Convert kernel to stdint types
- From: Felix Janda <felix.janda@xxxxxxxxx>
- Re: [libnetfilter_log PATCH 2/3] Convert kernel to stdint types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/4] netfilter: move generic TEE code from xtables to nf_tee_ipv{4,6} modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/4] netfilter: move generic TEE code from xtables to nf_tee_ipv{4,6} modules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,next-4.2,v2] src: add netdev family support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libmnl: security context retrieval in nf-queue example
- From: Roman Kubiak <r.kubiak@xxxxxxxxxxx>
- [PATCH nft] netlink: fix use-after-free netlink_events_cache_deltable()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: iptables nftables compat weirdness
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft,next-4.2] src: add netdev family support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: allow to use mark as datatype for maps and sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: allow to use mark as datatype for maps and sets
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [PATCH nft] parser_bison: allow to use mark as datatype for maps and sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft,next-4.2] src: add netdev family support
- From: Patrick McHardy <kaber@xxxxxxxxx>
- [PATCH nft,next-4.2] src: add netdev family support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnfnl] chain: add netdev family support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libmnl: security context retrieval in nf-queue example
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] datatype: fix packet mark type name
- From: Miroslav Kratochvil <exa.exa@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_RESTORESKMARK flag
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Matching MLD with ip6tables
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- RE: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_RESTORESKMARK flag
- From: "Harout Hedeshian" <harouth@xxxxxxxxxxxxxx>
- Re: [PATCH] libmnl: security context retrieval in nf-queue example
- From: Roman Kubiak <r.kubiak@xxxxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: bridge: split ipv6 code out of the core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] libmnl: security context retrieval in nf-queue example
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: bridge: split ipv6 code out of the core
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: bridge: rename br_netfilter.c to br_netfilter_hooks.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] libmnl: security context retrieval in nf-queue example
- From: Roman Kubiak <r.kubiak@xxxxxxxxxxx>
- Re: [PATCH] net: fix search limit handling in skb_find_text()
- From: Roman Khimov <khimov@xxxxxxxxx>
- Re: [PATCH] net: fix search limit handling in skb_find_text()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Matching MLD with ip6tables
- From: Jan Engelhardt <jengelh@xxxxxxx>
- Re: Matching MLD with ip6tables
- From: Linus Lüssing <linus.luessing@xxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH net-next] x_table: align per cpu xt_counter
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH RFC 04/15] netfilter: add pernet hook support
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- RE: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_MATCHSOCKMARK flag and mark fields
- From: "Harout Hedeshian" <harouth@xxxxxxxxxxxxxx>
- [PATCH iptables] xt_socket: add --restore-skmark option
- From: Harout Hedeshian <harouth@xxxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_RESTORESKMARK flag
- From: Harout Hedeshian <harouth@xxxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH 00/32] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 16/32] netfilter: ipset: Permit CIDR equal to the host address CIDR in IPv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/32] net: ip_fragment: remove BRIDGE_NETFILTER mtu special handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/32] netfilter: ipset: Use SET_WITH_*() helpers to test set extensions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/32] netfilter: ipset: Use MSEC_PER_SEC consistently
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/32] netfilter: xtables: use percpu rule counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/32] netfilter: xtables: avoid percpu ruleset duplication
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/32] netfilter: ipset: Check extensions attributes before getting extensions.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/32] netfilter: ipset: Check CIDR value only when attribute is given
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/32] netfilter: ipset: Make sure we always return line number on batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/32] netfilter: bridge: restore vlan tag when refragmenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/32] netfilter: ipset: Fix cidr handling for hash:*net* types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/32] netfilter: bridge: re-order check_hbh_len()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/32] netfilter: ipset: Fix parallel resizing and listing of the same set
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/32] netfilter: ipset: Make sure listing doesn't grab a set which is just being destroyed.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 27/32] netfilter: ipset: Fix coding styles reported by checkpatch.pl
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 31/32] netfilter: nf_tables: add nft_register_basechain() and nft_unregister_basechain()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 32/32] netfilter: nf_tables_netdev: unregister hooks on net_device removal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 23/32] netfilter: ipset: Prepare the ipset core to use RCU at set level
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/32] netfilter:ipset Remove rbtree from hash:net,iface
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 30/32] netfilter: nf_tables: attach net_device to basechain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 25/32] netfilter: ipset: Introduce RCU locking in hash:* types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 29/32] netfilter: x_tables: remove XT_TABLE_INFO_SZ and a dereference.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 28/32] netfilter: Kconfig: get rid of parens around depends on
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 24/32] netfilter: ipset: Introduce RCU locking in bitmap:* types
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 26/32] netfilter: ipset: Introduce RCU locking in list type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/32] netfilter: bridge: forward IPv6 fragmented packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/32] netfilter: bridge: refactor frag_max_size
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/32] netfilter: bridge: rename br_parse_ip_options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/32] netfilter: bridge: refactor clearing BRNF_NF_BRIDGE_PREROUTING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/32] netfilter: bridge: detect NAT66 correctly and change MAC address
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/32] netfilter: bridge: re-order br_nf_pre_routing_finish_ipv6()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/32] netfilter: conntrack: warn the user if there is a better helper to use
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/32] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] x_tables: remove XT_TABLE_INFO_SZ and a dereference.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_MATCHSOCKMARK flag and mark fields
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] net: fix search limit handling in skb_find_text()
- From: Roman Khimov <khimov@xxxxxxxxx>
- RE: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_MATCHSOCKMARK flag and mark fields
- From: "Harout Hedeshian" <harouth@xxxxxxxxxxxxxx>
- Re: [PATCH 00/15] ipset patches for nf-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- RE: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_MATCHSOCKMARK flag and mark fields
- From: "Harout Hedeshian" <harouth@xxxxxxxxxxxxxx>
- Re: [PATCH] net: fix search limit handling in skb_find_text()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] x_tables: remove XT_TABLE_INFO_SZ and a dereference.
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: xt_socket: add XT_SOCKET_MATCHSOCKMARK flag and mark fields
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 15/15] netfilter: bridge: adapt it to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 14/15] security: adapt it to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 13/15] netfilter: nf_tables: adapt it to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 07/15] netfilter: x_tables: adapt tables to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 12/15] netfilter: ebtables: adapt the filter and nat table to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 11/15] ipvs: adapt it to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 10/15] netfilter: defrag: add pernet hook support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 09/15] netfilter: synproxy: adapt IPv4 and IPv6 targets to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 08/15] netfilter: nf_conntrack: adapt IPv4 and IPv6 trackers to pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 03/15] netfilter: don't pull include/linux/netfilter.h from netns headers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 06/15] netfilter: x_tables: adapt xt_hook_link() to support pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 04/15] netfilter: add pernet hook support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 05/15] netfilter: ipt_CLUSTERIP: adapt it to support pernet hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 02/15] netfilter: use forward declaration instead of including linux/proc_fs.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 01/15] net: include missing headers in net/net_namespace.h
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH RFC 00/15] Netfilter pernet hook support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: ebiederm@xxxxxxxxxxxx (Eric W. Biederman)
- [PATCH nf-next 3/3] netfilter: nf_tables_netdev: unregister hooks on net_device removal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: nf_tables: add nft_register_basechain() and nft_unregister_basechain()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3, v2] netfilter: nf_tables: attach net_device to basechain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] net: fix search limit handling in skb_find_text()
- From: Roman I Khimov <khimov@xxxxxxxxx>
- Re: [PATCH net-next 00/15] Simplify netfilter and network namespaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 14/15] ipv4: Pass struct net into ip_defrag and ip_check_defrag
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 11/15] nftables: Pass struct net in nft_pktinfo
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 12/15] nf_tables: Use pkt->net instead of computing net from the passed net_devices
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 13/15] nf_conntrack: Add a struct net parameter to l4_pkt_to_tuple
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 15/15] ipv6: Pass struct net into nf_ct_frag6_gather
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 09/15] x_tables: Pass struct net in xt_action_param
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 10/15] x_tables: Use par->net instead of computing from the passed net devices
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 08/15] tc: Simplify em_ipset_match
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 07/15] nftables: kill nft_pktinfo.ops
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 06/15] inet netfilter: Prefer state->hook to ops->hooknum
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
- [PATCH net-next 05/15] inet netfilter: Remove hook from ip6t_do_table, arp_do_table, ipt_do_table
- From: "Eric W. Biederman" <ebiederm@xxxxxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]