Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- [PATCH net-next 01/19] netfilter: nf_tables: merge nft_rules_old structure and end of ruleblob marker, (continued)
- [PATCH net-next 00/20] Netfilter/IPVS updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 03/20] netfilter: nf_tables: don't store address of last rule on jump, Pablo Neira Ayuso
- [PATCH net-next 13/20] ipvs: Remove {Enter,Leave}Function, Pablo Neira Ayuso
- [PATCH net-next 19/20] netfilter: nf_tables: support for deleting devices in an existing netdev chain, Pablo Neira Ayuso
- [PATCH net-next 12/20] ipvs: Consistently use array_size() in ip_vs_conn_init(), Pablo Neira Ayuso
- [PATCH net-next 18/20] netfilter: nf_tables: support for adding new devices to an existing netdev chain, Pablo Neira Ayuso
- [PATCH net-next 05/20] netfilter: nf_tables: don't write table validation state without mutex, Pablo Neira Ayuso
- [PATCH net-next 01/20] netfilter: nft_exthdr: add boolean DCCP option matching, Pablo Neira Ayuso
- [PATCH net-next 14/20] ipvs: Correct spelling in comments, Pablo Neira Ayuso
- [PATCH net-next 10/20] netfilter: nf_tables: do not store rule in traceinfo structure, Pablo Neira Ayuso
- [PATCH net-next 07/20] netfilter: nf_tables: remove unneeded conditional, Pablo Neira Ayuso
- [PATCH net-next 06/20] netfilter: nf_tables: make validation state per table, Pablo Neira Ayuso
- [PATCH net-next 04/20] netfilter: nf_tables: don't store chain address on jump, Pablo Neira Ayuso
- [PATCH net-next 11/20] ipvs: Update width of source for ip_vs_sync_conn_options, Pablo Neira Ayuso
- [PATCH net-next 17/20] netfilter: nf_tables: rename function to destroy hook list, Pablo Neira Ayuso
- [PATCH net-next 15/20] netfilter: nf_tables: extended netlink error reporting for netdevice, Pablo Neira Ayuso
- [PATCH net-next 08/20] netfilter: nf_tables: do not store pktinfo in traceinfo structure, Pablo Neira Ayuso
- [PATCH net-next 16/20] netfilter: nf_tables: do not send complete notification of deletions, Pablo Neira Ayuso
- [PATCH net-next 20/20] netfilter: nf_tables: allow to create netdev chain without device, Pablo Neira Ayuso
- [PATCH net-next 09/20] netfilter: nf_tables: do not store verdict in traceinfo structure, Pablo Neira Ayuso
- [PATCH net-next 02/20] netfilter: nf_tables: merge nft_rules_old structure and end of ruleblob marker, Pablo Neira Ayuso
- Re: [PATCH net-next 00/20] Netfilter/IPVS updates for net-next, Pablo Neira Ayuso
- [iptables PATCH 0/3] Extract nftnl_rule parsing code,
Phil Sutter
- [PATCH bpf-next v5 0/7] bpf: add netfilter program type,
Florian Westphal
- [iptables PATCH 1/2] utils: nfbpf_compile: Replace pcap_compile_nopcap(),
Phil Sutter
- [PATCH nft] evaluate: bail out if new flowtable does not specify hook and priority,
Pablo Neira Ayuso
- [PATCH nft,v3 1/2] mnl: flowtable support for extended netlink error reporting,
Pablo Neira Ayuso
- [PATCH nf-next,v6 1/7] netfilter: nf_tables: extended netlink error reporting for netdevice,
Pablo Neira Ayuso
- [PATCH nf-next,v6 3/7] netfilter: nf_tables: rename function to destroy hook list, Pablo Neira Ayuso
- [PATCH nf-next,v6 4/7] netfilter: nf_tables: support for adding new devices to an existing netdev chain, Pablo Neira Ayuso
- [PATCH nf-next,v6 7/7] netfilter: nf_tables: remove artificial cap on maximum number of netdevices, Pablo Neira Ayuso
- [PATCH nf-next,v6 6/7] netfilter: nf_tables: allow to create netdev chain without device, Pablo Neira Ayuso
- [PATCH nf-next,v6 5/7] netfilter: nf_tables: support for deleting devices in an existing netdev chain, Pablo Neira Ayuso
- [PATCH nf-next,v6 2/7] netfilter: nf_tables: do not send complete notification of deletions, Pablo Neira Ayuso
- [libmnl, PATCH] examples: add rtnl-link-can, Dario Binacchi
- [PATCH nf-next,v5 1/7] netfilter: nf_tables: extended netlink error reporting for netdevice,
Pablo Neira Ayuso
- [PATCH nf-next,v5 5/7] netfilter: nf_tables: support for deleting devices in an existing netdev chain, Pablo Neira Ayuso
- [PATCH nf-next,v5 3/7] netfilter: nf_tables: rename function to destroy hook list, Pablo Neira Ayuso
- [PATCH nf-next,v5 6/7] netfilter: nf_tables: allow to create netdev chain without device, Pablo Neira Ayuso
- [PATCH nf-next,v5 7/7] netfilter: nf_tables: remove artificial cap on maximum number of netdevices, Pablo Neira Ayuso
- [PATCH nf-next,v5 2/7] netfilter: nf_tables: do not send complete notification of deletions, Pablo Neira Ayuso
- [PATCH nf-next,v5 4/7] netfilter: nf_tables: support for adding new devices to an existing netdev chain, Pablo Neira Ayuso
- [nft PATCH] tests: shell: Fix for unstable sets/0043concatenated_ranges_0,
Phil Sutter
- [PATCH bpf-next v4 0/7] bpf: add netfilter program type,
Florian Westphal
- [PATCH nft 1/2] mnl: flowtable support for extended netlink error reporting,
Pablo Neira Ayuso
- [PATCH nf-next,v4 1/7] netfilter: nf_tables: extended netlink error reporting for netdevice,
Pablo Neira Ayuso
- [PATCH nf-next,v4 3/7] netfilter: nf_tables: rename function to destroy hook list, Pablo Neira Ayuso
- [PATCH nf-next,v4 6/7] netfilter: nf_tables: allow to create netdev chain without device, Pablo Neira Ayuso
- [PATCH nf-next,v4 7/7] netfilter: nf_tables: remove artificial cap on maximum number of netdevices, Pablo Neira Ayuso
- [PATCH nf-next,v4 5/7] netfilter: nf_tables: support for deleting devices in an existing netdev chain, Pablo Neira Ayuso
- [PATCH nf-next,v4 4/7] netfilter: nf_tables: support for adding new devices to an existing netdev chain, Pablo Neira Ayuso
- [PATCH nf-next,v4 2/7] netfilter: nf_tables: do not send complete notification of deletions, Pablo Neira Ayuso
- [PATCH nf-next,v3 1/5] netfilter: nf_tables: do not send complete notification of deletions,
Pablo Neira Ayuso
- [PATCH v3] netfilter: conntrack: fix wrong ct->timeout value,
Tzung-Bi Shih
- [PATCH nf] netfilter: conntrack: restore IPS_CONFIRMED out of nf_conntrack_hash_check_insert(),
Pablo Neira Ayuso
- [PATCH bpf-next v3 0/6] bpf: add netfilter program type,
Florian Westphal
- [PATCH nft] mnl: set SO_SNDBUF before SO_SNDBUFFORCE, Pablo Neira Ayuso
- [PATCH nf,v2] netfilter: nf_tables: tighten netlink attribute requirements for catch-all elements, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: tighten netlink attribute requirements for catch-all elements, Pablo Neira Ayuso
- [PATCH nf,v2] netfilter: nf_tables: validate catch-all set elements, Pablo Neira Ayuso
- [PATCH nf-next v3 0/4] ipvs: Cleanups for v6.4,
Simon Horman
- [PATCH nf] netfilter: nf_tables: validate catch-all set elements, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: fix ifdef to also consider nf_tables=m,
Florian Westphal
- [PATCH v5 3/3] Replace invocation of weak PRNG,
david . keisarschm
- [PATCH nf-next 0/4] netfilter: nf_tables: shrink stack usage a bit more,
Florian Westphal
- [PATCH nf-next 0/2] netfilter: nf_tables: move ruleset validation state to table,
Florian Westphal
- [PATCH bpf-next v2 0/6] bpf: add netfilter program type,
Florian Westphal
- [PATCH] ipvs: change ip_vs_conn_tab_bits range to [8,31],
Abhijeet Rastogi via B4 Relay
- [PATCH nftables v2] exthdr: add boolean DCCP option matching,
Jeremy Sowden
- [PATCH nf-next v2] netfilter: nft_exthdr: add boolean DCCP option matching, Jeremy Sowden
- [PATCH nf-next 0/3] netfilter: nf_tables: shrink jump stack size,
Florian Westphal
- [PATCH nf-next v2 0/4] ipvs: Cleanups for v6.4,
Simon Horman
- [PATCH nf-next 0/4] ipvs: Cleanups for v6.4,
Simon Horman
- [PATCH v2] netfilter: conntrack: fix wrong ct->timeout value, Tzung-Bi Shih
- [PATCH] netfilter: conntrack: fix wrong ct->timeout value,
Tzung-Bi Shih
- [PATCH nft] main: Error out when combining -i/--interactive and -f/--file, Pablo Neira Ayuso
- [PATCH] src: try SO_SNDBUF before SO_SNDBUFFORCE,
Dave Pifke
- [PATCH net,v2] uapi: linux: restore IPPROTO_MAX to 256 and add IPPROTO_UAPI_MAX,
Pablo Neira Ayuso
- [PATCH] netfilter: nf_tables: Modify nla_memdup's flag to GFP_KERNEL_ACCOUNT,
Chen Aotian
- [PATCH bpf-next 0/6] bpf: add netfilter program type,
Florian Westphal
- [PATCH nft,v2 4/4] optimize: support for redirect and masquerade,
Pablo Neira Ayuso
- [iptables PATCH] tests: shell: Test for false-positive rule check,
Phil Sutter
- [PATCH nft 0/4] revisit NAT redirect support,
Pablo Neira Ayuso
- [PATCH iptables 1/2] include: update nf_tables uapi header,
Florian Westphal
- [PATCH iptables] ip6tables: Fix checking existence of rule,
Markus Boehme
- [PATCH nf] netfilter: br_netfilter: fix recent physdev match breakage,
Florian Westphal
- [PATCH iptables v2] build: use pkg-config for libpcap,
Alyssa Ross
- [PATCH] udp:nat:vxlan tx after nat should recsum if vxlan tx offload on,
Fei Cheng
- [PATCH iptables] build: use pkg-config for libpcap,
Alyssa Ross
- [PATCH net-next 0/4] netfilter updates for net-next,
Florian Westphal
- [RFC PATCH v2] nft: autocomplete for libreadline, Sriram Yagnaraman
- [RFC PATCH] nft: autocomplete for libreadline,
Sriram Yagnaraman
- [PATCH nf-next] netfilter: Correct documentation errors in nf_tables.h, Matthieu De Beule
- [PATCH nf-next] netfilter: nfnetlink_log: remove rcu_bh usage, Florian Westphal
- [nft PATCH] xt: Fix translation error path,
Phil Sutter
- RE: iptables patch,
Kevin Peeters
- [PATCH v5] netfilter: nfnetlink_queue: enable classid socket info retrieval, Eric Sage
- [PATCH nft] intervals: use expression location when translating to intervals, Pablo Neira Ayuso
- [lvc-project] [PATCH] netfilter: nfnetlink: NULL-check skb->dev in __build_packet_message(),
Igor Artemiev
- [PATCH v4] netfilter: nfnetlink_queue: enable classid socket info retrieval,
Eric Sage
- [PATCH nf-next v3 0/4] Support for shifted port-ranges in NAT,
Jeremy Sowden
- [PATCH v3] netfilter: nfnetlink_queue: enable classid socket info retrieval,
Eric Sage
- [PATCH nft] payload: set byteorder when completing expression,
Pablo Neira Ayuso
- [PATCH v2] netfilter: nfnetlink_queue: enable classid socket info retrieval,
Eric Sage
- [PATCH nft,v3 00/12] mark statement support for non-constant expression,
Pablo Neira Ayuso
- [PATCH nft,v3 01/12] netlink_delinearize: correct type and byte-order of shifts, Pablo Neira Ayuso
- [PATCH nft,v3 03/12] evaluate: don't eval unary arguments, Pablo Neira Ayuso
- [PATCH nft,v3 05/12] evaluate: set up integer type to shift expression, Pablo Neira Ayuso
- [PATCH nft,v3 06/12] evaluate: honor statement length in integer evaluation, Pablo Neira Ayuso
- [PATCH nft,v3 08/12] netlink_delinerize: incorrect byteorder in mark statement listing, Pablo Neira Ayuso
- [PATCH nft,v3 02/12] evaluate: support shifts larger than the width of the left operand, Pablo Neira Ayuso
- [PATCH nft,v3 07/12] evaluate: honor statement length in bitwise evaluation, Pablo Neira Ayuso
- [PATCH nft,v3 10/12] tests: shell: rename and move bitwise test-cases, Pablo Neira Ayuso
- [PATCH nft,v3 04/12] evaluate: relax type-checking for integer arguments in mark statements, Pablo Neira Ayuso
- [PATCH nft,v3 09/12] tests: py: add test-cases for ct and packet mark payload expressions, Pablo Neira Ayuso
- [PATCH nft,v3 12/12] tests: py: extend test-cases for mark statements with bitwise expressions, Pablo Neira Ayuso
- [PATCH nft,v3 11/12] tests: shell: add test-cases for ct and packet mark payload expressions, Pablo Neira Ayuso
- [PATCH v10 00/13] Network support for Landlock,
Konstantin Meskhidze
- [PATCH v10 01/13] landlock: Make ruleset's access masks more generic, Konstantin Meskhidze
- [PATCH v10 02/13] landlock: Allow filesystem layout changes for domains without such rule type, Konstantin Meskhidze
- [PATCH v10 04/13] landlock: Refactor landlock_find_rule/insert_rule, Konstantin Meskhidze
- [PATCH v10 03/13] landlock: Remove unnecessary inlining, Konstantin Meskhidze
- [PATCH v10 05/13] landlock: Refactor merge/inherit_ruleset functions, Konstantin Meskhidze
- [PATCH v10 06/13] landlock: Move and rename layer helpers, Konstantin Meskhidze
- [PATCH v10 07/13] landlock: Refactor layer helpers, Konstantin Meskhidze
- [PATCH v10 08/13] landlock: Refactor landlock_add_rule() syscall, Konstantin Meskhidze
- [PATCH v10 10/13] selftests/landlock: Share enforce_ruleset(), Konstantin Meskhidze
- [PATCH v10 12/13] samples/landlock: Add network demo, Konstantin Meskhidze
- [PATCH v10 09/13] landlock: Add network rules and TCP hooks support, Konstantin Meskhidze
- [PATCH v10 11/13] selftests/landlock: Add 10 new test suites dedicated to network, Konstantin Meskhidze
- [PATCH v10 13/13] landlock: Document Landlock's network support, Konstantin Meskhidze
- [PATCH] netfilter: nfnetlink_queue: enable classid socket info retrieval,
eric_sage
- [PATCH nft,v2 0/8] mark statement support for non-constant expression,
Pablo Neira Ayuso
- [PATCH nft,v2 3/8] evaluate: don't eval unary arguments, Pablo Neira Ayuso
- [PATCH nft,v2 4/8] evaluate: get length from statement instead of lhs expression, Pablo Neira Ayuso
- [PATCH nft,v2 2/8] evaluate: support shifts larger than the width of the left operand, Pablo Neira Ayuso
- [PATCH nft,v2 1/8] netlink_delinearize: correct type and byte-order of shifts, Pablo Neira Ayuso
- [PATCH nft,v2 5/8] evaluate: relax type-checking for integer arguments in mark statements, Pablo Neira Ayuso
- [PATCH nft,v2 8/8] tests: shell: add test-cases for ct and packet mark payload expressions, Pablo Neira Ayuso
- [PATCH nft,v2 6/8] tests: py: add test-cases for ct and packet mark payload expressions, Pablo Neira Ayuso
- [PATCH nft,v2 7/8] tests: shell: rename and move bitwise test-cases, Pablo Neira Ayuso
- [PATCH nf-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion,
Paul Blakey
- [PATCH] net : netfilter: Keep conntrack reference until IPsecv6 policy checks are done, Madhu Koriginja
- [PATCH net-next 1/1] netfilter: ctnetlink: Support offloaded conntrack entry deletion,
Paul Blakey
- [nft PATCH 1/2] Reduce signature of do_list_table(),
Phil Sutter
- [PATCH v5] netfilter: nf_flow_table: count offloaded flows,
Sven Auhagen
- [PATCH nft 0/9] mark statement support for non-constant expression,
Pablo Neira Ayuso
- [PATCH nf-next] xtables: move icmp/icmpv6 logic to xt_tcpudp, Florian Westphal
- [PATCH nf-next] netfilter: xtables: disable 32bit compat interface by default, Florian Westphal
- [PATCH ulogd2 v3 0/2] pcap: prevent crashes when output `FILE *` is null,
Jeremy Sowden
- Re: [PATCH net-next] net: netfilter: Keep conntrack reference until IPsecv6 policy checks are done, Florian Westphal
- [PATCH nf-next v2 0/2] NF NAT deduplication refactoring,
Jeremy Sowden
- [PATCH nft] meta: don't crash if meta key isn't known, Florian Westphal
- [PATCH nft,v3] parser_bison: simplify reset syntax,
Pablo Neira Ayuso
- [PATCH nft,v2] parser_bison: simplify reset syntax,
Pablo Neira Ayuso
- [PATCH nft] parser_bison: simplify reset syntax,
Pablo Neira Ayuso
- [PATCH] Correct documentation errors in nf_tables.h,
Matthieu De Beule
- [PATCH nft] Revert "evaluate: relax type-checking for integer arguments in mark statements", Pablo Neira Ayuso
- [ANNOUNCE] nftables 1.0.7 release, Pablo Neira Ayuso
- [PATCH nf-next 0/3] NF NAT deduplication refactoring,
Jeremy Sowden
- [PATCH nftables] src: fix a couple of typo's in comments, Jeremy Sowden
- [PATCH nf-next] netfilter: nft_exthdr: add boolean DCCP option matching,
Jeremy Sowden
- [PATCH nftables] exthdr: add boolean DCCP option matching,
Jeremy Sowden
- [PATCH nft] cmd: move command functions to src/cmd.c, Pablo Neira Ayuso
- [PATCH nft] src: improve error reporting for unsupported chain type,
Pablo Neira Ayuso
- [ipset PATCH] tests: hash:ip,port.t: Replace VRRP by GRE protocol,
Phil Sutter
- [nft PATCH v2] Reject invalid chain priority values in user space,
Phil Sutter
- [nft PATCH] Reject invalid chain priority values in user space,
Phil Sutter
- [ANNOUNCE] libnftnl 1.2.5 release,
Pablo Neira Ayuso
- [nft PATCH] doc: nft.8: Document lower priority limit for nat type chains,
Phil Sutter
- [nft PATCH] xt: Fix fallback printing for extensions matching keywords,
Phil Sutter
- [PATCH v2] ulogd2: Avoid use after free in unregister on global ulogd_fds linked list,
Kyuwon Shim
- [PATCH nf-next v2 0/9] Support for shifted port-ranges in NAT,
Jeremy Sowden
- [PATCH nf-next v2 2/9] netfilter: nat: fix indentation of function arguments, Jeremy Sowden
- [PATCH nf-next v2 6/9] netfilter: nft_masq: add support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next v2 9/9] netfilter: nft_redir: add support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next v2 5/9] netfilter: nft_masq: deduplicate eval call-backs, Jeremy Sowden
- [PATCH nf-next v2 8/9] netfilter: nft_redir: deduplicate eval call-backs, Jeremy Sowden
- [PATCH nf-next v2 3/9] netfilter: nat: extend core support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next v2 4/9] netfilter: nft_nat: add support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next v2 7/9] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API, Jeremy Sowden
- [PATCH nf-next v2 1/9] netfilter: conntrack: fix typo, Jeremy Sowden
- Re: [PATCH nf-next v2 0/9] Support for shifted port-ranges in NAT, Florian Westphal
- [PATCH nf 0/4] NAT fixes,
Jeremy Sowden
- [PATCHv2 nf-next 0/6] netfilter: handle ipv6 jumbo packets properly for bridge ovs and tc,
Xin Long
- [ipset PATCH 0/4] Some testsuite improvements,
Phil Sutter
- [PATCH net] netfilter: conntrack:,
Eric Dumazet
- [PATCH nf-next 00/13] Support for shifted port-ranges in NAT,
Jeremy Sowden
- [PATCH nf-next 06/13] netfilter: nft_masq: correct length for loading protocol registers, Jeremy Sowden
- [PATCH nf-next 03/13] netfilter: nat: extend core support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next 07/13] netfilter: nft_masq: deduplicate eval call-backs, Jeremy Sowden
- [PATCH nf-next 02/13] netfilter: nat: fix indentation of function arguments, Jeremy Sowden
- [PATCH nf-next 09/13] netfilter: nft_redir: correct value of inet type `.maxattrs`, Jeremy Sowden
- [PATCH nf-next 04/13] netfilter: nft_nat: correct length for loading protocol registers, Jeremy Sowden
- [PATCH nf-next 01/13] netfilter: conntrack: fix typo, Jeremy Sowden
- [PATCH nf-next 08/13] netfilter: nft_masq: add support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next 05/13] netfilter: nft_nat: add support for shifted port-ranges, Jeremy Sowden
- [PATCH nf-next 12/13] netfilter: nft_redir: deduplicate eval call-backs, Jeremy Sowden
- [PATCH nf-next 10/13] netfilter: nf_nat_redirect: use `struct nf_nat_range2` in ipv4 API, Jeremy Sowden
- [PATCH nf-next 11/13] netfilter: nft_redir: correct length for loading protocol registers, Jeremy Sowden
- [PATCH nf-next 13/13] netfilter: nft_redir: add support for shifted port-ranges, Jeremy Sowden
- Re: [PATCH nf-next 00/13] Support for shifted port-ranges in NAT, Florian Westphal
- [PATCH libnftnl 0/3] Support for shifted port-ranges in NAT,
Jeremy Sowden
- [PATCH nftables 0/8] Support for shifted port-ranges in NAT,
Jeremy Sowden
- [PATCH nf-next 0/6] netfilter: handle ipv6 jumbo packets properly for bridge ovs and tc,
Xin Long
- [PATCH nf] netfilter: tproxy: fix deadlock due to missing BH disable,
Florian Westphal
- [PATCH v2] netfilter: ctnetlink: revert to dumping mark regardless of event type,
Ivan Delalande
- [PATCH RFC v2 bpf-next 0/3] bpf: add netfilter program type,
Florian Westphal
- CPU soft lockup in a spin lock using tproxy and nfqueue,
Major Dávid
- Re: Bug report DNAT destination not work,
Florian Westphal
- [PATCH] netfilter: ctnetlink: revert to dumping mark regardless of event type,
Ivan Delalande
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]