Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [nf PATCH 2/5] netfilter: nf_tables: Add locking for NFT_MSG_GETRULE_RESET requests, (continued)
- [PATCH -stable,5.10 00/17] Netfilter stable fixes for 5.10,
Pablo Neira Ayuso
- [PATCH -stable,5.10 03/17] netfilter: nf_tables: GC transaction API to avoid race with control plane, Pablo Neira Ayuso
- [PATCH -stable,5.10 02/17] netfilter: nf_tables: don't skip expired elements during walk, Pablo Neira Ayuso
- [PATCH -stable,5.10 01/17] netfilter: nf_tables: integrate pipapo into commit protocol, Pablo Neira Ayuso
- [PATCH -stable,5.10 11/17] netfilter: nf_tables: use correct lock to protect gc_list, Pablo Neira Ayuso
- [PATCH -stable,5.10 10/17] netfilter: nf_tables: GC transaction race with abort path, Pablo Neira Ayuso
- [PATCH -stable,5.10 09/17] netfilter: nf_tables: GC transaction race with netns dismantle, Pablo Neira Ayuso
- [PATCH -stable,5.10 05/17] netfilter: nft_set_hash: mark set element as dead when deleting from packet path, Pablo Neira Ayuso
- [PATCH -stable,5.10 06/17] netfilter: nf_tables: remove busy mark and gc batch API, Pablo Neira Ayuso
- [PATCH -stable,5.10 04/17] netfilter: nf_tables: adapt set backend to use GC transaction API, Pablo Neira Ayuso
- [PATCH -stable,5.10 08/17] netfilter: nf_tables: fix GC transaction races with netns and netlink event exit path, Pablo Neira Ayuso
- [PATCH -stable,5.10 07/17] netfilter: nf_tables: don't fail inserts if duplicate has expired, Pablo Neira Ayuso
- [PATCH -stable,5.10 12/17] netfilter: nf_tables: defer gc run if previous batch is still pending, Pablo Neira Ayuso
- [PATCH -stable,5.10 14/17] netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention, Pablo Neira Ayuso
- [PATCH -stable,5.10 15/17] netfilter: nft_set_pipapo: stop GC iteration if GC transaction allocation fails, Pablo Neira Ayuso
- [PATCH -stable,5.10 17/17] netfilter: nf_tables: fix memleak when more than 255 elements expired, Pablo Neira Ayuso
- [PATCH -stable,5.10 16/17] netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration, Pablo Neira Ayuso
- [PATCH -stable,5.10 13/17] netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction, Pablo Neira Ayuso
- [PATCH -stable,5.15 00/17] Netfilter stable fixes for 5.15,
Pablo Neira Ayuso
- [PATCH -stable,5.15 03/17] netfilter: nf_tables: adapt set backend to use GC transaction API, Pablo Neira Ayuso
- [PATCH -stable,5.15 12/17] netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction, Pablo Neira Ayuso
- [PATCH -stable,5.15 09/17] netfilter: nf_tables: GC transaction race with abort path, Pablo Neira Ayuso
- [PATCH -stable,5.15 15/17] netfilter: nft_set_pipapo: stop GC iteration if GC transaction allocation fails, Pablo Neira Ayuso
- [PATCH -stable,5.15 11/17] netfilter: nf_tables: defer gc run if previous batch is still pending, Pablo Neira Ayuso
- [PATCH -stable,5.15 06/17] netfilter: nf_tables: don't fail inserts if duplicate has expired, Pablo Neira Ayuso
- [PATCH -stable,5.15 13/17] netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention, Pablo Neira Ayuso
- [PATCH -stable,5.15 01/17] netfilter: nf_tables: don't skip expired elements during walk, Pablo Neira Ayuso
- [PATCH -stable,5.15 04/17] netfilter: nft_set_hash: mark set element as dead when deleting from packet path, Pablo Neira Ayuso
- [PATCH -stable,5.15 16/17] netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration, Pablo Neira Ayuso
- [PATCH -stable,5.15 07/17] netfilter: nf_tables: fix GC transaction races with netns and netlink event exit path, Pablo Neira Ayuso
- [PATCH -stable,5.15 02/17] netfilter: nf_tables: GC transaction API to avoid race with control plane, Pablo Neira Ayuso
- [PATCH -stable,5.15 10/17] netfilter: nf_tables: use correct lock to protect gc_list, Pablo Neira Ayuso
- [PATCH -stable,5.15 14/17] netfilter: nft_set_pipapo: call nft_trans_gc_queue_sync() in catchall GC, Pablo Neira Ayuso
- [PATCH -stable,5.15 08/17] netfilter: nf_tables: GC transaction race with netns dismantle, Pablo Neira Ayuso
- [PATCH -stable,5.15 05/17] netfilter: nf_tables: remove busy mark and gc batch API, Pablo Neira Ayuso
- [PATCH -stable,5.15 17/17] netfilter: nf_tables: fix memleak when more than 255 elements expired, Pablo Neira Ayuso
- [PATCH -stable,6.1 00/17] Netfilter stable fixes for 6.1,
Pablo Neira Ayuso
- [-stable,6.1 01/17] netfilter: nf_tables: don't skip expired elements during walk, Pablo Neira Ayuso
- [-stable,6.1 02/17] netfilter: nf_tables: GC transaction API to avoid race with control plane, Pablo Neira Ayuso
- [-stable,6.1 04/17] netfilter: nft_set_hash: mark set element as dead when deleting from packet path, Pablo Neira Ayuso
- [-stable,6.1 03/17] netfilter: nf_tables: adapt set backend to use GC transaction API, Pablo Neira Ayuso
- [-stable,6.1 05/17] netfilter: nf_tables: remove busy mark and gc batch API, Pablo Neira Ayuso
- [-stable,6.1 06/17] netfilter: nf_tables: don't fail inserts if duplicate has expired, Pablo Neira Ayuso
- [-stable,6.1 07/17] netfilter: nf_tables: fix GC transaction races with netns and netlink event exit path, Pablo Neira Ayuso
- [-stable,6.1 14/17] netfilter: nft_set_pipapo: call nft_trans_gc_queue_sync() in catchall GC, Pablo Neira Ayuso
- [-stable,6.1 08/17] netfilter: nf_tables: GC transaction race with netns dismantle, Pablo Neira Ayuso
- [-stable,6.1 13/17] netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention, Pablo Neira Ayuso
- [-stable,6.1 12/17] netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction, Pablo Neira Ayuso
- [-stable,6.1 11/17] netfilter: nf_tables: defer gc run if previous batch is still pending, Pablo Neira Ayuso
- [-stable,6.1 16/17] netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration, Pablo Neira Ayuso
- [-stable,6.1 15/17] netfilter: nft_set_pipapo: stop GC iteration if GC transaction allocation fails, Pablo Neira Ayuso
- [-stable,6.1 10/17] netfilter: nf_tables: use correct lock to protect gc_list, Pablo Neira Ayuso
- [-stable,6.1 17/17] netfilter: nf_tables: fix memleak when more than 255 elements expired, Pablo Neira Ayuso
- [-stable,6.1 09/17] netfilter: nf_tables: GC transaction race with abort path, Pablo Neira Ayuso
- [PATCH -stable,6.5 0/5] Netfilter stable fixes for 6.5,
Pablo Neira Ayuso
- [PATCH -stable,6.5 1/5] netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention, Pablo Neira Ayuso
- [PATCH -stable,6.5 2/5] netfilter: nft_set_pipapo: call nft_trans_gc_queue_sync() in catchall GC, Pablo Neira Ayuso
- [PATCH -stable,6.5 4/5] netfilter: nft_set_hash: try later when GC hits EAGAIN on iteration, Pablo Neira Ayuso
- [PATCH -stable,6.5 3/5] netfilter: nft_set_pipapo: stop GC iteration if GC transaction allocation fails, Pablo Neira Ayuso
- [PATCH -stable,6.5 5/5] netfilter: nf_tables: fix memleak when more than 255 elements expired, Pablo Neira Ayuso
- Re: [PATCH -stable,6.5 0/5] Netfilter stable fixes for 6.5, Sasha Levin
- [PATCH nft] tests: shell: skip flowtable-uaf if we lack table owner support, Florian Westphal
- [ANNOUNCE] ipset 7.19 released, Jozsef Kadlecsik
- [PATCH 0/3] nftables: add feature probes for sctp and multistmt set support,
Florian Westphal
- [RFC nf] netfilter: nf_tables: nft_set_rbtree: invalidate greater range element on removal,
Florian Westphal
- [PATCH libnetfilter_queue v2] doc: make the HTML main page available as `man 7 libnetfilter_queue`,
Duncan Roe
- [nft PATCH 0/9] Misc JSON parser fixes,
Phil Sutter
- [nft PATCH 7/9] parser_json: Wrong check in json_parse_ct_timeout_policy(), Phil Sutter
- [nft PATCH 1/9] parser_json: Catch wrong "reset" payload, Phil Sutter
- [nft PATCH 6/9] parser_json: Fix synproxy object mss/wscale parsing, Phil Sutter
- [nft PATCH 5/9] parser_json: Fix limit object burst value parsing, Phil Sutter
- [nft PATCH 8/9] parser_json: Catch nonsense ops in match statement, Phil Sutter
- [nft PATCH 4/9] parser_json: Fix flowtable prio value parsing, Phil Sutter
- [nft PATCH 9/9] parser_json: Default meter size to zero, Phil Sutter
- [nft PATCH 3/9] parser_json: Proper ct expectation attribute parsing, Phil Sutter
- [nft PATCH 2/9] parser_json: Fix typo in json_parse_cmd_add_object(), Phil Sutter
- Re: [nft PATCH 0/9] Misc JSON parser fixes, Phil Sutter
- [PATCH nft] datatype: return const pointer from datatype_get(),
Thomas Haller
- [PATCH nft v2] icmpv6: Allow matching target address in NS/NA, redirect and MLD, Nicolas Cavallari
- [PATCH nft 0/9] various cleanups related to enums and struct datatype,
Thomas Haller
- [PATCH] build: Fix double-prefix w/ pkgconfig,
Sam James
- [PATCH nft 0/4] remove xfree() and add free_const()+nft_gmp_free(),
Thomas Haller
- [PATCH 4.19 046/273] netfilter: nft_flow_offload: fix underflow in flowtable reference counter, Greg Kroah-Hartman
- [PATCH 4.19 047/273] netfilter: nf_tables: missing NFT_TRANS_PREPARE_ERROR in flowtable deactivatation, Greg Kroah-Hartman
- [PATCH v12 00/12] Network support for Landlock,
Konstantin Meskhidze
- [PATCH v12 05/12] landlock: Move and rename layer helpers, Konstantin Meskhidze
- [PATCH v12 04/12] landlock: Refactor merge/inherit_ruleset functions, Konstantin Meskhidze
- [PATCH v12 06/12] landlock: Refactor layer helpers, Konstantin Meskhidze
- [PATCH v12 10/12] selftests/landlock: Add 7 new test variants dedicated to network, Konstantin Meskhidze
- [PATCH v12 12/12] landlock: Document Landlock's network support, Konstantin Meskhidze
- [PATCH v12 07/12] landlock: Refactor landlock_add_rule() syscall, Konstantin Meskhidze
- [PATCH v12 08/12] landlock: Add network rules and TCP hooks support, Konstantin Meskhidze
- [PATCH v12 01/12] landlock: Make ruleset's access masks more generic, Konstantin Meskhidze
- [PATCH v12 02/12] landlock: Allow filesystem layout changes for domains without such rule type, Konstantin Meskhidze
- [PATCH v12 09/12] selftests/landlock: Share enforce_ruleset(), Konstantin Meskhidze
- [PATCH v12 11/12] samples/landlock: Add network demo, Konstantin Meskhidze
- [PATCH v12 03/12] landlock: Refactor landlock_find_rule/insert_rule, Konstantin Meskhidze
- [PATCH net 0/3] netfilter updates for net,
Florian Westphal
- [ANNOUNCE] ipset 7.18 released,
Jozsef Kadlecsik
- [PATCH 0/1] ipset patch for nf tree,
Jozsef Kadlecsik
- [PATCH nft] datatype: initialize TYPE_CT_EVENTBIT slot in datatype array, Pablo Neira Ayuso
- [PATCH nft] datatype: initialize TYPE_CT_LABEL slot in datatype array, Pablo Neira Ayuso
- [PATCH nft,v2] limit: display default burst when listing ruleset, Pablo Neira Ayuso
- [PATCH nft] limit: display default burst when listing ruleset, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: fix memory leak when more than 255 elements expired,
Florian Westphal
- [PATCH nft 1/2] libnftables: drop gmp_init() and mp_set_memory_functions(),
Thomas Haller
- [PATCH nft 1/1] datatype: explicitly set missing datatypes for TYPE_CT_LABEL,TYPE_CT_EVENTBIT,
Thomas Haller
- [PATCH libnetfilter_queue] doc: generate libnetfilter_queue.7 man page from HTML mainpage, Duncan Roe
- [PATCH nft,v2] evaluate: update mark datatype compatibility check from maps, Pablo Neira Ayuso
- [PATCH nft 1/1] tests/shell: honor NFT_TEST_FAIL_ON_SKIP variable to fail on any skipped tests, Thomas Haller
- [PATCH nft 1/3] tests/shell: fix preserving ruleset diff after test,
Thomas Haller
- [PATCH nft 0/3] tests/shell: minor improvements to "run-tests.sh",
Thomas Haller
- [PATCH nft] evaluate: update mark datatype compatibility check from maps,
Pablo Neira Ayuso
- [PATCH nft,v2] evaluate: expand sets and maps before evaluation, Pablo Neira Ayuso
- [PATCH nft 00/14] tests/shell: fix tests to skip on lacking feature support,
Thomas Haller
- [PATCH nft 07/14] tests/shell: skip inet ingress tests if kernel lacks support, Thomas Haller
- [PATCH nft 02/14] tests/shell: skip netdev_chain_0 if kernel requires netdev device, Thomas Haller
- [PATCH nft 04/14] tests/shell: skip inner matching tests if unsupported, Thomas Haller
- [PATCH nft 06/14] tests/shell: skip some tests if kernel lacks netdev egress support, Thomas Haller
- [PATCH nft 03/14] tests/shell: skip map query if kernel lacks support, Thomas Haller
- [PATCH nft 09/14] tests/shell: skip catchall tests if kernel lacks support, Thomas Haller
- [PATCH nft 08/14] tests/shell: skip destroy tests if kernel lacks support, Thomas Haller
- [PATCH nft 11/14] tests/shell: skip test cases if ct expectation and/or timeout lacks support, Thomas Haller
- [PATCH nft 10/14] tests/shell: skip test cases involving osf match if kernel lacks support, Thomas Haller
- [PATCH nft 14/14] tests/shell: check diff in "maps/typeof_maps_0" and "sets/typeof_sets_0" test, Thomas Haller
- [PATCH nft 05/14] tests/shell: skip bitshift tests if kernel lacks support, Thomas Haller
- [PATCH nft 12/14] tests/shell: skip reset tests if kernel lacks support, Thomas Haller
- [PATCH nft 13/14] tests/shell: implement NFT_TEST_HAVE_json feature detection as script, Thomas Haller
- [PATCH nft 01/14] tests/shell: add and use chain binding feature probe, Thomas Haller
- [PATCH nft] evaluate: expand sets and maps before evaluation, Pablo Neira Ayuso
- [PATCH nft] evaluate: fix memleak in prefix evaluation with wildcard interface name, Pablo Neira Ayuso
- [PATCH nft 0/3] shell/tests: cleanups and skip tests on Fedora 38,
Thomas Haller
- [PATCH nft 0/2] tests/shell: add feature probing via "features/*.nft" files,
Thomas Haller
- [PATCH nft] tests: add test for dormant on/off/on bug, Florian Westphal
- [PATCH nf] netfilter: nf_tables: disable toggling dormant table state more than once, Florian Westphal
- [PATCH nft 1/1] netlink: fix leaking typeof_expr_data/typeof_expr_key in netlink_delinearize_set(),
Thomas Haller
- [PATCH nft 1/1] tests/shell: honor CLICOLOR_FORCE to force coloring in run-tests.sh, Thomas Haller
- [PATCH nft 1/1] tests/build: capture more output from "tests/build/run-tests.sh" script, Thomas Haller
- [RFC nft] icmpv6: Allow matching target address in NS/NA, redirect and MLD, Nicolas Cavallari
- [PATCH v2 libnetfilter_conntrack 1/2] Adding NFCT_FILTER_DUMP_TUPLE in filter_dump_attr, using kernel CTA_FILTER API,
Florian Westphal
- [PATCH nft 1/2] libnftables: refuse to open onput files other than named pipes or regular files,
Florian Westphal
- [iptables PATCH] tests: shell: Fix for ineffective 0007-mid-restore-flush_0,
Phil Sutter
- [iptables PATCH] extensions: Fix checking of conntrack --ctproto 0,
Phil Sutter
- Issue with counter and interval map,
Jann Haber
- [PATCH nft 1/2] tests/shell: exit 77 from "run-tests.sh" if all tests were skipped,
Thomas Haller
- [PATCH nft 0/6] adjust nft dump files and add check-tree script,
Thomas Haller
- [ANNOUNCE] nftlb 1.0.9 release, Laura García Liébana
- [nf PATCH v3 0/2] nf_tables: follow-up on audit fix, add selftest,
Phil Sutter
- [PATCH nft 0/3] add NFT_TEST_RANDOM_SEED and shuffle tests,
Thomas Haller
- [PATCH nft 1/2] tests/shell: kill running child processes when aborting "run-tests.sh",
Thomas Haller
- [iproute2] xfrm: add udp standalone encapsulation mode, Pablo Neira Ayuso
- [PATCH nf] netfilter: conntrack: fix extension size table,
Florian Westphal
- [PATCH nft v2] datatype: fix leak and cleanup reference counting for struct datatype, Thomas Haller
- Regression: Commit "netfilter: nf_tables: disallow rule addition to bound chain via NFTA_RULE_CHAIN_ID" breaks ruleset loading in linux-stable,
Timo Sigurdsson
- [nft PATCH] datatype: fix leak and cleanup reference counting for struct datatype,
Thomas Haller
- [PATCH RFC libnetfilter_queue] doc: Get rid of DEPRECATED tag (Work In Progress),
Duncan Roe
- [PATCH libmnl] nlmsg, attr: fix false positives when validating buffer sizes,
Jeremy Sowden
- [PATCH nf] netfilter: nf_tables: disallow element removal on anonymous sets, Pablo Neira Ayuso
- [PATCH AUTOSEL 5.10 11/14] netfilter: ebtables: fix fortify warnings in size_entry_mwt(), Sasha Levin
- [PATCH AUTOSEL 6.4 30/41] netfilter: ebtables: fix fortify warnings in size_entry_mwt(), Sasha Levin
- [PATCH AUTOSEL 5.15 12/15] netfilter: ebtables: fix fortify warnings in size_entry_mwt(), Sasha Levin
- [PATCH AUTOSEL 4.14 6/8] netfilter: ebtables: fix fortify warnings in size_entry_mwt(),
Sasha Levin
- [PATCH AUTOSEL 6.1 20/26] netfilter: ebtables: fix fortify warnings in size_entry_mwt(), Sasha Levin
- [PATCH AUTOSEL 6.5 33/45] netfilter: ebtables: fix fortify warnings in size_entry_mwt(), Sasha Levin
- [PATCH nft 1/1] datatype: rename "dtype_clone()" to datatype_clone(), Thomas Haller
- [PATCH nft 1/2] parser_bison: include <nft.h> for base C environment to "parser_bison.y",
Thomas Haller
- [PATCH nft 1/1] cache: avoid accessing uninitialized varible in implicit_chain_cache(), Thomas Haller
- [PATCH nft 0/2] tests/shell: add mechanism for skipping (for no JSON and slow),
Thomas Haller
- [PATCH nft 1/1] tests/shell: set valgrind's "--vgdb-prefix=" to orignal TMPDIR, Thomas Haller
- [PATCH nft 1/1] tests/shell: print number of completed tests to show progress, Thomas Haller
- [PATCH nft v2 0/4] tests/shell: add missing .nft and .nodump files,
Thomas Haller
- [nf PATCH v2] netfilter: nf_tables: Fix entries val in rule reset audit log,
Phil Sutter
- [PATCH nf 1/4] netfilter: nft_set_rbtree: use read spinlock to avoid datapath contention,
Pablo Neira Ayuso
- [PATCH nf,v2] netfilter: nf_tables: disallow rule removal from chain binding, Pablo Neira Ayuso
- [nf PATCH 0/2] nf_tables: follow-up on audit fix, propose kselftest,
Phil Sutter
- [PATCH nft 00/11] tests/shell: colorize output, fix VALGRIND mode,
Thomas Haller
- [PATCH nft 01/11] tests/shell: cleanup result handling in "test-wrapper.sh", Thomas Haller
- [PATCH nft 04/11] tests/shell: fix handling failures with VALGRIND=y, Thomas Haller
- [PATCH nft 03/11] tests/shell: colorize terminal output with test result, Thomas Haller
- [PATCH nft 02/11] tests/shell: cleanup print_test_result() and show TAINTED error code, Thomas Haller
- [PATCH nft 06/11] tests/shell: don't redirect error/warning messages to stderr, Thomas Haller
- [PATCH nft 07/11] tests/shell: redirect output of test script to file too, Thomas Haller
- [PATCH nft 05/11] tests/shell: print the NFT setting with the VALGRIND=y wrapper, Thomas Haller
- [PATCH nft 09/11] tests/shell: no longer enable verbose output when selecting a test, Thomas Haller
- [PATCH nft 11/11] tests/shell: set NFT_TEST_JOBS based on $(nproc), Thomas Haller
- [PATCH nft 08/11] tests/shell: print "kernel is tainted" separate from test result, Thomas Haller
- [PATCH nft 10/11] tests/shell: record wall time of test run in result data, Thomas Haller
- [PATCH nft] tests/shell: return 77/skip for tests that fail to create dummy device, Thomas Haller
- [PATCH nft 1/2] tests/shell: honor .nodump file for tests without nft dumps,
Thomas Haller
- [PATCH nf] netfilter: nf_tables: disallow rule removal from chain binding, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: skip deactivation of deleted rules in bound chain, Pablo Neira Ayuso
- [iptables PATCH] include: linux: Update kernel.h,
Phil Sutter
- [iptables PATCH] nft: Fix for useless meta expressions in rule,
Phil Sutter
- [PATCH nft v5 00/19] tests/shell: allow running tests as non-root,
Thomas Haller
- [PATCH nft v5 01/19] tests/shell: rework command line parsing in "run-tests.sh", Thomas Haller
- [PATCH nft v5 02/19] tests/shell: rework finding tests and add "--list-tests" option, Thomas Haller
- [PATCH nft v5 04/19] tests/shell: export NFT_TEST_BASEDIR and NFT_TEST_TMPDIR for tests, Thomas Haller
- [PATCH nft v5 03/19] tests/shell: check test names before start and support directories, Thomas Haller
- [PATCH nft v5 09/19] tests/shell: support --keep-logs option (NFT_TEST_KEEP_LOGS=y) to preserve test output, Thomas Haller
- [PATCH nft v5 07/19] tests/shell: run each test in separate namespace and allow rootless, Thomas Haller
- [PATCH nft v5 05/19] tests/shell: normalize boolean configuration in environment variables, Thomas Haller
- [PATCH nft v5 10/19] tests/shell: move the dump diff handling inside "test-wrapper.sh", Thomas Haller
- [PATCH nft v5 11/19] tests/shell: rework printing of test results, Thomas Haller
- [PATCH nft v5 08/19] tests/shell: interpret an exit code of 77 from scripts as "skipped", Thomas Haller
- [PATCH nft v5 06/19] tests/shell: print test configuration, Thomas Haller
- [PATCH nft v5 13/19] tests/shell: move valgrind wrapper script to separate script, Thomas Haller
- [PATCH nft v5 16/19] tests/shell: skip test in rootless that hit socket buffer size limit, Thomas Haller
- [PATCH nft v5 17/19] tests/shell: record the test duration (wall time) in the result data, Thomas Haller
- [PATCH nft v5 12/19] tests/shell: move taint check to "test-wrapper.sh", Thomas Haller
- [PATCH nft v5 14/19] tests/shell: support running tests in parallel, Thomas Haller
- [PATCH nft v5 19/19] tests/shell: set TMPDIR for tests in "test-wrapper.sh", Thomas Haller
- [PATCH nft v5 15/19] tests/shell: bind mount private /var/run/netns in test container, Thomas Haller
- [PATCH nft v5 18/19] tests/shell: fix "0003includepath_0" for different TMPDIR, Thomas Haller
- Re: [PATCH nft v5 00/19] tests/shell: allow running tests as non-root, Florian Westphal
- [PATCH nf] netfilter: nf_tables: Unbreak audit log reset,
Pablo Neira Ayuso
- [PATCH nft] evaluate: fix get element for concatenated set,
Florian Westphal
- [PATCH nft v4 00/17] tests/shell: allow running tests as,
Thomas Haller
- [PATCH nft v4 17/17] tests/shell: set TMPDIR for tests in "test-wrapper.sh", Thomas Haller
- [PATCH nft v4 09/17] tests/shell: support --keep-logs option (NFT_TEST_KEEP_LOGS=y) to preserve test output, Thomas Haller
- [PATCH nft v4 01/17] tests/shell: rework command line parsing in "run-tests.sh", Thomas Haller
- [PATCH nft v4 05/17] tests/shell: normalize boolean configuration in environment variables, Thomas Haller
- [PATCH nft v4 16/17] tests/shell: record the test duration for investigation, Thomas Haller
- [PATCH nft v4 08/17] tests/shell: interpret an exit code of 77 from scripts as "skipped", Thomas Haller
- [PATCH nft v4 13/17] tests/shell: support running tests in parallel, Thomas Haller
- [PATCH nft v4 03/17] tests/shell: check test names before start and support directories, Thomas Haller
- [PATCH nft v4 10/17] tests/shell: move the dump diff handling inside "test-wrapper.sh", Thomas Haller
- [PATCH nft v4 11/17] tests/shell: rework printing of test results, Thomas Haller
- [PATCH nft v4 04/17] tests/shell: export NFT_TEST_BASEDIR and NFT_TEST_TMPDIR for tests, Thomas Haller
- [PATCH nft v4 06/17] tests/shell: print test configuration, Thomas Haller
- [PATCH nft v4 15/17] tests/shell: skip test in rootless that hit socket buffer size limit, Thomas Haller
- [PATCH nft v4 12/17] tests/shell: move taint check to "test-wrapper.sh", Thomas Haller
- [PATCH nft v4 14/17] tests/shell: bind mount private /var/run/netns in test container, Thomas Haller
- [PATCH nft v4 02/17] tests/shell: rework finding tests and add "--list-tests" option, Thomas Haller
- [PATCH nft v4 07/17] tests/shell: run each test in separate namespace and allow rootless, Thomas Haller
- [PATCH nft] tests: shell: 0043concatenated_ranges_0: re-enable all tests, Florian Westphal
- Race between IPSET_CMD_CREATE and IPSET_CMD_SWAP,
Kyle Zeng
- [PATCH nft v3 00/11] tests/shell: allow running tests as,
Thomas Haller
- [PATCH nft v3 04/11] tests/shell: export NFT_TEST_BASEDIR and NFT_TEST_TMPDIR for tests, Thomas Haller
- [PATCH nft v3 01/11] tests/shell: rework command line parsing in "run-tests.sh", Thomas Haller
- [PATCH nft v3 02/11] tests/shell: rework finding tests and add "--list-tests" option, Thomas Haller
- [PATCH nft v3 03/11] tests/shell: check test names before start and support directories, Thomas Haller
- [PATCH nft v3 06/11] tests/shell: interpret an exit code of 77 from scripts as "skipped", Thomas Haller
- [PATCH nft v3 09/11] tests/shell: rework printing of test results, Thomas Haller
- [PATCH nft v3 08/11] tests/shell: move the dump diff handling inside "test-wrapper.sh", Thomas Haller
- [PATCH nft v3 07/11] tests/shell: support --keep-logs option (NFT_TEST_KEEP_LOGS=y) to preserve test output, Thomas Haller
- [PATCH nft v3 10/11] tests/shell: move taint check to "test-wrapper.sh", Thomas Haller
- [PATCH nft v3 05/11] tests/shell: run each test in separate namespace and allow rootless, Thomas Haller
- [PATCH nft v3 11/11] tests/shell: support running tests in parallel, Thomas Haller
- Re: [PATCH nft v3 00/11] tests/shell: allow running tests as, Florian Westphal
- [PATCH] uapi/netfilter: Change netfilter hook verdict code definition from macro to enum,
David Wang
- [PATCH nft 0/5] tests: shell: add and use feature probing,
Florian Westphal
- [PATCH nf] netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction, Pablo Neira Ayuso
- [PATCH libnetfilter_log] libipulog: remove debugging printfs,
Jeremy Sowden
- [PATCH libnetfilter_conntrack 1/2] Ignore `configure~`,
Jeremy Sowden
- [PATCH nft] doc: describe behaviour of {ip,ip6} length, Pablo Neira Ayuso
- [PATCH nft,v2] evaluate: revisit anonymous set with single element optimization, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: ensure audit reset access to table under rcu read side lock, Pablo Neira Ayuso
- [PATCH nft] evaluate: revisit anonymous set with single element optimization, Pablo Neira Ayuso
- [PATCH nft v2 0/3] tests/shell: allow running tests as non-root,
Thomas Haller
- [PATH nf v3] netfilter/osf: avoid OOB read,
Wander Lairson Costa
- [nf-next PATCH] netfilter: nf_tables: Utilize NLA_POLICY_NESTED_ARRAY, Phil Sutter
- [nf PATCH] netfilter: nf_tables: uapi: Describe NFTA_RULE_CHAIN_ID, Phil Sutter
- [PATCH 0/2] Prevent potential write out of bounds,
joao
- [RFC] netfilter: nf_tables: ignore -EOPNOTSUPP on flowtable device offload setup,
Felix Fietkau
- [PATCH RFC] tests: add feature probing,
Florian Westphal
- [PATCH nf v2] netfilter/osf: avoid OOB read,
Wander Lairson Costa
- MASQ leak?,
Ian Kumlien
- [PATCH nf] netfilter/osf: avoid OOB read,
Wander Lairson Costa
- [PATCH nft] tests/shell: allow running tests as non-root users,
Thomas Haller
- [PATCH nft 1/2] src: use internal_location for unspecified location at allocation time,
Pablo Neira Ayuso
- [PATCH nft 1/2] src: simplify chain_alloc(),
Pablo Neira Ayuso
- [GIT PULL] sysctl changes for v6.6-rc1,
Luis Chamberlain
- [PATCH nft 0/5] fix compiler warnings with clang and "-Wextra",
Thomas Haller
- [PATCH nft 1/2] proto: use hexadecimal to display ip frag-off field,
Pablo Neira Ayuso
- [nf PATCH 1/2] netfilter: nf_tables: Audit log setelem reset,
Phil Sutter
- [PATCH nft] evaluate: do not remove anonymous set with protocol flags and single element, Pablo Neira Ayuso
- [nft PATCH 1/4] tests: monitor: Fix monitor JSON output for insert command,
Phil Sutter
- [PATCH] doc: fix example of xt_cpu,
Victor Julien
- [PATCH nft v2 0/8] fix compiler warnings with clang,
Thomas Haller
- [syzbot] Monthly netfilter report (Aug 2023), syzbot
- [syzbot] [netfilter?] INFO: rcu detected stall in tcp_setsockopt, syzbot
- [PATCH nf] netfilter/xt_sctp: validate the flag_info count,
Wander Lairson Costa
- [nft PATCH] evaluate: place byteorder conversion after numgen for IP address datatypes,
Jorge Ortiz
- [PATCH nft 0/8] fix compiler warnings with clang,
Thomas Haller
- [PATCH nf] netfilter/xt_u32: validate user space input,
Wander Lairson Costa
- [syzbot] [arm?] [netfilter?] KASAN: slab-out-of-bounds Read in do_csum,
syzbot
- Fwd: Since 6.1: flow_dissector.c __skb_flow_dissect+0xa91/0x1cd0 raises WARNING in specific circumstances, Bagas Sanjaya
- Re: [Networking] ERSPAN decapsulation drops DHCP unicast packets,
Bagas Sanjaya
- [PATCH conntrack-tools 0/4] Fixes for yacc parser compilation warnings,
Jeremy Sowden
- [PATCH v4.19.y] netfilter: nf_queue: fix socket leak, Vamsi Krishna Brahmajosyula
- [PATCH nft 0/4] add operation cache for timestamp,
Thomas Haller
- [nft PATCH] evaluate: Drop dead code from expr_evaluate_mapping(),
Phil Sutter
- [PATCH nft v2 0/6] cleanup base includes and add <nft.h> header,
Thomas Haller
- [PATCH nft 0/6] no recursive make,
Thomas Haller
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]