Hi Dave, these patches contain some netfilter fixes for 2.6.25, fixing undersized skb allocation and incorrect EPERM errors in nfnetlink_queue and nfnetlink_log, an xt_time bug that causes mismatches on Sundays, a missing newline in a conntrack message and the "horrible hack" in ct_extend. Please apply, thanks. include/linux/netfilter/nfnetlink_compat.h | 2 +- include/net/netfilter/nf_conntrack_extend.h | 1 - net/netfilter/nf_conntrack_expect.c | 2 +- net/netfilter/nf_conntrack_extend.c | 19 ++------------- net/netfilter/nf_queue.c | 2 +- net/netfilter/nfnetlink_log.c | 32 ++++++++++++++------------ net/netfilter/nfnetlink_queue.c | 17 ++++---------- net/netfilter/xt_time.c | 7 ++++- 8 files changed, 33 insertions(+), 49 deletions(-) Alexey Dobriyan (1): [NETFILTER]: nf_conntrack: add \n to "expectation table full" message Andrew Schulman (1): [NETFILTER]: xt_time: fix failure to match on Sundays Eric Leblond (2): [NETFILTER]: nfnetlink_queue: fix computation of allocated size for netlink skb. [NETFILTER]: nfnetlink_log: fix computation of netlink skb size Patrick McHardy (4): [NETFILTER]: nfnetlink: fix ifdef in nfnetlink_compat.h [NETFILTER]; nfnetlink_log: fix EPERM when binding/unbinding and instance 0 exists [NETFILTER]: nfnetlink_queue: fix EPERM when binding/unbinding and instance 0 exists [NETFILTER]: nf_queue: don't return error when unregistering a non-existant handler Pekka Enberg (1): [NETFILTER]: nf_conntrack: replace horrible hack with ksize() -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html