Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [PATCH libnetfilter_queue v3 3/6] build: doc: Avoid having to special-case `make distcheck`, (continued)
- libnetfilter_queue: automake portability warning,
Jeremy Sowden
- [PATCH libnetfilter_log] build: remove broken code from autogen.sh.,
Jeremy Sowden
- [PATCH nf 0/3] netfilter: conntrack: switch to siphash,
Florian Westphal
- [PATCH nft] netlink_delinearize: incorrect meta protocol dependency kill,
Pablo Neira Ayuso
- [Bug] Reverse translation skips "leading" meta protocol match,
Tom Yan
- [PATCH libnetfilter_queue v2 1/5] build: doc: Fix man pages,
Duncan Roe
- [PATCH nft] cache: provide a empty list for flowtables and objects when request fails, Pablo Neira Ayuso
- [PATCH libnetfilter_queue] build: doc: Fix man pages, Duncan Roe
- Request for a backport to Linux v5.4,
Gianluca Anzolin
- [PATCH nft] cache: skip set element netlink dump for add/delete element command, Pablo Neira Ayuso
- [PATCH] netfilter: x_tables: handle xt_register_template() returning an error value,
Lukas Bulwahn
- Suspicious pattern for use of function xt_register_template(),
Lukas Bulwahn
- [PATCH 0/2] Reusing nfct handle for bulk ct loads,
Mikhail Sennikovsky
- Seemingly random crashes with CONFIG_HARDENED_USERCOPY=y on ppc64be, Stijn Tintel
- [PATCH xtables-addons 0/8] xt_condition: per-net improvements,
Jeremy Sowden
- Old good cBPF and program size, alexandre.ferrieux
- [PATCH libnetfilter_queue v4 1/4] build: doc: Fix NAME entry in man pages,
Duncan Roe
- [PATCH] Add DWARF object files to .gitignore.,
Jeremy Sowden
- Re: [PATCH net-next v4] net: ipvs: add sysctl_run_estimation to support disable estimation,
Julian Anastasov
- [PATCH libnetfilter_queue v3 1/3] build: doc: Fix NAME entry in man pages,
Duncan Roe
- [PATCH] xtables-addons 3.18 condition - Improved network namespace support,
Grzegorz Kuczyński
- [PATCH nftables] src: Optimize prefix match only if is big-endian,
Xiao Liang
- [PATCH nft,v3] src: queue: consolidate queue statement syntax, Pablo Neira Ayuso
- [PATCH nft,v2] src: queue: consolidate queue statement syntax, Pablo Neira Ayuso
- [PATCH nft] tests: shell: add nft-f/0022variables_0 dump file, Pablo Neira Ayuso
- [PATCH nft] src: queue: consolidate queue statement syntax, Pablo Neira Ayuso
- [PATCH nft] parser_bison: restore variable expression in queue statement, Pablo Neira Ayuso
- [ANNOUNCE] nftables 1.0.0 release,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: ctnetlink: missing counters and timestamp in nfnetlink_{log,queue}, Pablo Neira Ayuso
- [PATCH v2 40/63] netfilter: conntrack: Use memset_startat() to zero struct nf_conn, Kees Cook
- [PATCH v2 iptables] iptables-nft: allow removal of empty builtin chains, Florian Westphal
- [PATCH v7 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows,
Ryoga Saito
- [PATCH v6 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows,
Ryoga Saito
- [PATCH AUTOSEL 5.4 3/5] netfilter: conntrack: collect all entries in one cycle, Sasha Levin
- [PATCH AUTOSEL 4.19 3/4] netfilter: conntrack: collect all entries in one cycle, Sasha Levin
- [PATCH AUTOSEL 5.10 5/9] netfilter: conntrack: collect all entries in one cycle, Sasha Levin
- [PATCH AUTOSEL 5.13 07/12] netfilter: conntrack: collect all entries in one cycle, Sasha Levin
- [PATCH AUTOSEL 5.13 06/12] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete, Sasha Levin
- [PATCH nf-next 0/5] netfilter: ecache: simplify event registration,
Florian Westphal
- [PATCH nft] netlink_delinearize: skip flags / mask notation for singleton bitmask again, Pablo Neira Ayuso
- [PATCH iptabes-nft] iptables-nft: allow removal of empty builtin chains,
Florian Westphal
- [PATCH] libxt_ACCOUNT_cl: correct LDFLAGS variable name.,
Jeremy Sowden
- nfnetlink_queue -- why linear lookup ?,
alexandre.ferrieux
- [PATCH libnetfilter_queue v3 0/1] src: doc: Insert SYNOPSIS sections for man pages,
Duncan Roe
- [PATCH nft] evaluate: expand variable containing set into multiple mappings, Pablo Neira Ayuso
- [PATCH libnetfilter_queue v2 0/1] Insert SYNOPSIS sections for man pages,
Duncan Roe
- [nft PATCH 1/3] tests: json_echo: Print errors to stderr,
Phil Sutter
- [iptables PATCH] iptables-test: Make netns spawning more robust, Phil Sutter
- [PATCH nft] evaluate: element key cannot in map cannot be a set, Pablo Neira Ayuso
- [PATCH nft] tcpopt: bogus assertion on undefined options, Pablo Neira Ayuso
- Netdevconf 0x15 slides and papers up,
Jamal Hadi Salim
- [PATCH libnetfilter_queue] include: deprecate libnetfilter_queue/linux_nfnetlink_queue.h,
Pablo Neira Ayuso
- [nft PATCH] tests/py: Make netns spawning more robust, Phil Sutter
- [PATCH] netfiler: protect nft_ct_pcpu_template_refcnt with mutex,
Pavel Skripkin
- [ANNOUNCE] ipset 7.15 released, Jozsef Kadlecsik
- [PATCH libnetfilter_queue v2] build: doc: Fix NAME entry in man pages,
Duncan Roe
- [PATCH 1/3] extensions: libtxt_NFLOG: use nft built-in logging instead of xt_NFLOG,
Kyle Bowman
- [iptables PATCH] extensions: hashlimit: Fix tests with HZ=100, Phil Sutter
- [syzbot] WARNING in destroy_conntrack,
syzbot
- [syzbot] KASAN: use-after-free Read in nf_tables_dump_sets,
syzbot
- [nft PATCH RFC] scanner: nat: Move to own scope,
Phil Sutter
- [PATCH libnetfilter_queue] src: doc: Insert SYNOPSIS sections for man pages, Duncan Roe
- [PATCH libnetfilter_queue] build: doc: Fix NAME entry in man pages,
Duncan Roe
- [PATCH v5 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows,
proelbtn
- [PATCH libmnl] src: doc: Fix messed-up Netlink message batch diagram,
Duncan Roe
- [syzbot] KASAN: use-after-free Write in nft_ct_tmpl_put_pcpu,
syzbot
- [PATCH libnetfilter_queue v2] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure,
Duncan Roe
- [PATCH libmnl] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure,
Duncan Roe
- [PATCH] netfilter: remove duplicate code,
Kangmin Park
- [PATCH net 0/9,v2] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 1/9] netfilter: ipset: Limit the maximal range of consecutive elements to add/delete, Pablo Neira Ayuso
- [PATCH net 2/9] netfilter: nf_conntrack_bridge: Fix memory leak when error, Pablo Neira Ayuso
- [PATCH net 3/9] netfilter: conntrack: collect all entries in one cycle, Pablo Neira Ayuso
- [PATCH net 4/9] netfilter: nfnetlink_hook: strip off module name from hookfn, Pablo Neira Ayuso
- [PATCH net 5/9] netfilter: nfnetlink_hook: missing chain family, Pablo Neira Ayuso
- [PATCH net 8/9] netfilter: conntrack: remove offload_pickup sysctl again, Pablo Neira Ayuso
- [PATCH net 6/9] netfilter: nfnetlink_hook: use the sequence number of the request message, Pablo Neira Ayuso
- [PATCH net 7/9] netfilter: nfnetlink_hook: Use same family as request message, Pablo Neira Ayuso
- [PATCH net 9/9] netfilter: nfnetlink_hook: translate inet ingress to netdev, Pablo Neira Ayuso
- Re: [PATCH net 0/9,v2] Netfilter fixes for net, Jakub Kicinski
- [PATCH nf] netfilter: nfnetlink_hook: translate inet ingress to netdev, Pablo Neira Ayuso
- [PATCH libnetfilter_queue] build: If doxygen is not available, be sure to report "doxygen: no" to ./configure,
Duncan Roe
- [PATCH libnetfilter_queue v2] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h,
Duncan Roe
- [PATCH nf-next v2] netfilter: nf_queue: move hookfn registration out of struct net,
Florian Westphal
- [PATCH nf-next] netfilter: nf_queue: move hookfn registration out of struct net, Florian Westphal
- [syzbot] WARNING: proc registration bug in clusterip_tg_check (3),
syzbot
- [PATCH iptables] ip6tables: masquerade: use fully-random so that nft can understand the rule,
Pavel Tikhomirov
- [PATCH v2 nf] netfilter: conntrack: remove offload_pickup sysctl again,
Florian Westphal
- [PATCH nf] netfilter: conntrack: remove offload_pickup sysctl again,
Florian Westphal
- [PATCH] netfilter: ipset: fix uninitialized variable bug,
Dan Carpenter
- [PATCH nf 1/2] netfilter: nfnetlink_hook: use the sequence number of the request message,
Pablo Neira Ayuso
- [PATCH nft,v3] mnl: revisit hook listing, Pablo Neira Ayuso
- [PATCH] netfilter: ipset: Fix maximal range check in hash_ipportnet4_uadt(),
Nathan Chancellor
- [PATCH nf-next] x_tables: never register tables by default,
Florian Westphal
- [iptables PATCH] tests/shell: Assert non-verbose mode is silent, Phil Sutter
- [iptables PATCH] nft: Fix for non-verbose check command, Phil Sutter
- [PATCH nft,v2] mnl: revisit hook listing, Pablo Neira Ayuso
- [PATCH nf 1/2] netfilter: nfnetlink_hook: strip off module name from hookfn,
Pablo Neira Ayuso
- [PATCH nft] mnl: revisit hook listing, Pablo Neira Ayuso
- [PATCH v4 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows,
proelbtn
- [PATCH] conntrack-tools: support conntrack dump status filtering,
Florian Westphal
- [PATCH nf-next 0/2] netfilter: ctnetlink: allow to filter dumps via ct->status,
Florian Westphal
- [iptables PATCH] ebtables: Dump atomic waste,
Phil Sutter
- [PATCH v3 0/2] netfilter: add netfilter hooks to track SRv6-encapsulated flows,
Ryoga Saito
- [PATCH v2 0/2] net: add netfilter hooks to track SRv6-encapsulated flows,
Ryoga Saito
- [PATCH v3] netfilter: nf_conntrack_bridge: Fix memory leak when error,
Yajun Deng
- [PATCH v2] netfilter: nf_conntrack_bridge: Fix memory leak when error,
Yajun Deng
- [iptables PATCH] doc: ebtables-nft.8: Adjust for missing atomic-options,
Phil Sutter
- [PATCH 0/1] ipset patch for the nf tree v2,
Jozsef Kadlecsik
- [ANNOUNCE] ipset 7.14 released, Jozsef Kadlecsik
- [PATCH nft] tests: py: check more flag match transformations to compact syntax, Pablo Neira Ayuso
- [PATCH] net: netfilter: Fix port selection of FTP for NF_NAT_RANGE_PROTO_SPECIFIED,
Cole Dishington
- [PATCH nft,v2 1/3] tests: py: idempotent tcp flags & syn != 0 to tcp flag syn,
Pablo Neira Ayuso
- [PATCH nft 1/2] tests: py: idempotent tcp flags & syn != 0 to tcp flag syn,
Pablo Neira Ayuso
- [PATCH] netfilter: xt_NFLOG: allow 128 character log prefixes,
Kyle Bowman
- [PATCH nft 1/3] expression: missing != in flagcmp expression print function,
Pablo Neira Ayuso
- [nft] Regarding `tcp flags` (and a potential bug),
Tom Yan
- [ANNOUNCE] ipset 7.13 released,
Jozsef Kadlecsik
- [PATCH nf] netfilter: conntrack: collect all entries in one cycle,
Florian Westphal
- [PATCH nft] evaluate: error reporting for missing statements in set/map declaration, Pablo Neira Ayuso
- [PATCH nft] src: promote 'reject with icmp CODE' syntax, Pablo Neira Ayuso
- [PATCH nft] parser_bison: parse number as reject icmp code, Pablo Neira Ayuso
- [nft PATCH] tests: shell: Fix bogus testsuite failure with 100Hz,
Phil Sutter
- [PATCH nft] parser_bison: stateful statement support in map, Pablo Neira Ayuso
- [PATCH] netfilter: nf_conntrack_bridge: Fix not free when error,
Yajun Deng
- Nf_nat_h323 module not working with Panasonic VCs,
Akshat Kakkar
- [PATCH nft 1/2] src: fix nft_ctx_clear_include_paths in libnftables.map,
Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 3/6] netfilter: nft_last: avoid possible false sharing, Pablo Neira Ayuso
- [PATCH net 1/6] netfilter: nf_tables: fix audit memory leak in nf_tables_commit, Pablo Neira Ayuso
- [PATCH net 5/6] netfilter: nft_nat: allow to specify layer 4 protocol NAT only, Pablo Neira Ayuso
- [PATCH net 6/6] netfilter: nfnl_hook: fix unused variable warning, Pablo Neira Ayuso
- [PATCH net 2/6] netfilter: flowtable: avoid possible false sharing, Pablo Neira Ayuso
- [PATCH net 4/6] netfilter: conntrack: adjust stop timestamp to real expiry value, Pablo Neira Ayuso
- <Possible follow-ups>
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/6] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH nf-next] netfilter: ebtables: do not hook tables by default,
Florian Westphal
- [PATCH nft 1/2] parser_bison: missing initialization of ct timeout policy list,
Pablo Neira Ayuso
- [PATCH nf-next 0/3] netfilter: clusterip: don't register hook in all netns,
Florian Westphal
- [PATCH v28 18/25] LSM: security_secid_to_secctx in netlink netfilter, Casey Schaufler
- [PATCH v28 16/25] LSM: Use lsmcontext in security_secid_to_secctx, Casey Schaufler
- [PATCH v28 15/25] LSM: Ensure the correct LSM context releaser, Casey Schaufler
- [PATCH v28 08/25] LSM: Use lsmblob in security_secid_to_secctx, Casey Schaufler
- [PATCH v28 07/25] LSM: Use lsmblob in security_secctx_to_secid, Casey Schaufler
- [PATCH] netfilter: nfnl_hook: fix unused variable warning,
Arnd Bergmann
- [PATCH nf] netfilter: nft_nat: allow to specify layer 4 protocol NAT only, Pablo Neira Ayuso
- [PATCH nft] evaluate: fix inet nat with no layer 3 info, Pablo Neira Ayuso
- [PATCH nft] src: add --define key=value, Pablo Neira Ayuso
- [PATCH nf-next,v2] netfilter: flowtable: remove nf_ct_l4proto_find() call, Pablo Neira Ayuso
- [PATCH nf] netfilter: conntrack: adjust stop timestamp to real expiry value,
Florian Westphal
- [PATCH libnetfilter_queue] src: Stop users from accidentally using legacy linux_nfnetlink_queue.h,
Duncan Roe
- [PATCH libnetfilter_queue] build: doc: get rid of the need for manual updating of Makefile, Duncan Roe
- [PATCH libmnl] build: doc: get rid of the need for manual updating of Makefile,
Duncan Roe
- [PATCH nf 1/2] netfilter: flowtable: avoid possible false sharing,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: flowtable: remove nf_ct_l4proto_find() call, Pablo Neira Ayuso
- [PATCH nf 1/2] netfilter: nft_last: avoid possible false sharing,
Pablo Neira Ayuso
- [syzbot] general protection fault in nf_tables_dump_flowtable, syzbot
- [PATCH nf-next,v2] netfilter: nft_compat: use nfnetlink_unicast(), Pablo Neira Ayuso
- [PATCH v3] audit: fix memory leak in nf_tables_commit,
Dongliang Mu
- [PATCH] xtables: Call init_extensions6() for static builds,
Erik Wilson
- [PATCH nftables,v3 1/3] src: remove STMT_NAT_F_INTERVAL flags and interval keyword,
Pablo Neira Ayuso
- [PATCH nf] netfilter: nft_compat: use nfnetlink_unicast(), Pablo Neira Ayuso
- [PATCH v2] audit: fix memory leak in nf_tables_commit,
Dongliang Mu
- [PATCH nftables,v2 1/2] src: infer interval from set,
Pablo Neira Ayuso
- [issue] conntrack: lack of lock during nat, ze wang
- [PATCH] audit: fix memory leak in nf_tables_commit,
Dongliang Mu
- [PATCH v2] net: Use nlmsg_unicast() instead of netlink_unicast(),
Yajun Deng
- [PATCH nftables] src: support for nat with interval concatenation, Pablo Neira Ayuso
- [PATCH nftables] netlink_delinearize: stmt and expr error path memleaks, Pablo Neira Ayuso
- [PATCH] net: Use nlmsg_unicast() instead of netlink_unicast(),
Yajun Deng
- [PATCH net 00/11] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 01/11] selftest: netfilter: add test case for unreplied tcp connections, Pablo Neira Ayuso
- [PATCH net 02/11] netfilter: conntrack: do not renew entry stuck in tcp SYN_SENT state, Pablo Neira Ayuso
- [PATCH net 03/11] netfilter: nf_tables: Fix dereference of null pointer flow, Pablo Neira Ayuso
- [PATCH net 04/11] netfilter: conntrack: nf_ct_gre_keymap_flush() removal, Pablo Neira Ayuso
- [PATCH net 05/11] netfilter: ctnetlink: suspicious RCU usage in ctnetlink_dump_helpinfo, Pablo Neira Ayuso
- [PATCH net 07/11] netfilter: conntrack: add new sysctl to disable RST check, Pablo Neira Ayuso
- [PATCH net 06/11] netfilter: conntrack: improve RST handling when tuple is re-used, Pablo Neira Ayuso
- [PATCH net 08/11] netfilter: conntrack: Mark access for KCSAN, Pablo Neira Ayuso
- [PATCH net 09/11] netfilter: nft_last: honor NFTA_LAST_SET on restoration, Pablo Neira Ayuso
- [PATCH net 10/11] netfilter: nft_last: incorrect arithmetics when restoring last used, Pablo Neira Ayuso
- [PATCH net 11/11] netfilter: uapi: refer to nfnetlink_conntrack.h, not nf_conntrack_netlink.h, Pablo Neira Ayuso
- <Possible follow-ups>
- [PATCH net 00/11] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 01/11] selftests: netfilter: add a vrf+conntrack testcase, Pablo Neira Ayuso
- [PATCH net 02/11] selftests: netfilter: extend nfqueue tests to cover vrf device, Pablo Neira Ayuso
- [PATCH net 04/11] selftests: nft_nat: Improve port shadow test stability, Pablo Neira Ayuso
- [PATCH net 06/11] netfilter: ctnetlink: fix filtering with CTA_TUPLE_REPLY, Pablo Neira Ayuso
- [PATCH net 07/11] netfilter: ctnetlink: do not erase error code with EINVAL, Pablo Neira Ayuso
- [PATCH net 03/11] netfilter: nft_payload: Remove duplicated include in nft_payload.c, Pablo Neira Ayuso
- [PATCH net 08/11] netfilter: ipvs: Fix reuse connection if RS weight is 0, Pablo Neira Ayuso
- [PATCH net 05/11] selftests: nft_nat: Simplify port shadow notrack test, Pablo Neira Ayuso
- [PATCH net 10/11] netfilter: flowtable: fix IPv6 tunnel addr match, Pablo Neira Ayuso
- [PATCH net 09/11] netfilter: xt_IDLETIMER: replace snprintf in show functions with sysfs_emit, Pablo Neira Ayuso
- [PATCH net 11/11] selftests: nft_nat: switch port shadow test cases to socat, Pablo Neira Ayuso
- Netdevconf 0x15 update, Jamal Hadi Salim
- Re: netfilter: Use netlink_ns_capable to verify the permisions of netlink messages,
Pablo Neira Ayuso
- [PATCH] net: Add netfilter hooks to track SRv6-encapsulated flows,
Ryoga Saito
[PATCH nftables] src: add last statement, Pablo Neira Ayuso
[PATCH libnftnl] expr: last: add NFTNL_EXPR_LAST_SET, Pablo Neira Ayuso
[PATCH nf 1/2] netfilter: nft_last: honor NFTA_LAST_SET on restoration,
Pablo Neira Ayuso
[PATCH nf-next] include: fix header file name in 3 comments,
Duncan Roe
[PATCH nftables] build: get `make distcheck` to pass again,
Duncan Roe
[PATCH libnetfilter_queue] src: annotation: Correctly identify item for which header is needed,
Duncan Roe
[PATCH NETFILTER v2] netfilter: nfnetlink: suspicious RCU usage in ctnetlink_dump_helpinfo,
Vasily Averin
[PATCH NETFILTER v2] netfilter: gre: nf_ct_gre_keymap_flush() removal,
Vasily Averin
Re: [PATCH NETFILTER] netfilter: gre: nf_ct_gre_keymap_flush() removal, Florian Westphal
Re: [PATCH NETFILTER] netfilter: nfnetlink: suspicious RCU usage in ctnetlink_dump_helpinfo,
Florian Westphal
[PATCH nft] cmd: incorrect error reporting when table declaration exists, Pablo Neira Ayuso
[PATCH nftables] cmd: incorrect table location in error reporting, Pablo Neira Ayuso
Netfilter rules to replicate, consume ingress packet locally and forward clone packet., rakesh goyal
Re: Reload IPtables,
Neal P. Murphy
Re: Reload IPtables, slow_speed
[PATCH] extensions: masquerade: Add RFC-7597 section 5.1 PSID support,
Cole Dishington
[PATCH 0/2] Fixes for KCSAN findings,
Manfred Spraul
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]