Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- [PATCH nftables] evaluate: don't crash on set definition with incorrect datatype, Pablo Neira Ayuso
- [PATCH nftables 2/2] src: add set element catch-all support, Pablo Neira Ayuso
- [PATCH nftables 1/2] parser_bison: add set_elem_key_expr rule,
Pablo Neira Ayuso
- [PATCH nf-next] nft_set_pipapo_avx2: Skip LDMXCSR, we don't need a valid MXCSR state,
Stefano Brivio
- [PATCH nf] nft_set_pipapo_avx2: Add irq_fpu_usable() check, fallback to non-AVX2 version,
Stefano Brivio
- [PATCH net 0/8] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 2/8] netfilter: arptables: use pernet ops struct during unregister, Pablo Neira Ayuso
- [PATCH net 1/8] netfilter: xt_SECMARK: add new revision to fix structure layout, Pablo Neira Ayuso
- [PATCH net 3/8] netfilter: nfnetlink: add a missing rcu_read_unlock(), Pablo Neira Ayuso
- [PATCH net 4/8] netfilter: nfnetlink_osf: Fix a missing skb_header_pointer() NULL check, Pablo Neira Ayuso
- [PATCH net 5/8] netfilter: remove BUG_ON() after skb_header_pointer(), Pablo Neira Ayuso
- [PATCH net 6/8] netfilter: nftables: Fix a memleak from userdata error path in new objects, Pablo Neira Ayuso
- [PATCH net 7/8] netfilter: nftables: avoid overflows in nft_hash_buckets(), Pablo Neira Ayuso
- [PATCH net 8/8] netfilter: nftables: avoid potential overflows on 32bit arches, Pablo Neira Ayuso
- <Possible follow-ups>
- [PATCH net 0/8] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/8] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/8] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/8] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/8] Netfilter fixes for net, Pablo Neira Ayuso
- nft_pipapo_avx2_lookup backtrace in linux 5.10,
Arturo Borrero Gonzalez
- [PATCH net 2/2] netfilter: nf_tables: avoid potential overflows on 32bit arches,
Eric Dumazet
- [PATCH net 1/2] netfilter: nf_tables: avoid overflows in nft_hash_buckets(),
Eric Dumazet
- [nft PATCH] doc: Reduce size of NAT statement synopsis, Phil Sutter
- [PATCH nft 0/2] Fix display of < 64 bits IPv6 masks in concatenated elements,
Stefano Brivio
- [PATCH nf,v2] netfilter: remove BUG_ON() after skb_header_pointer(), Pablo Neira Ayuso
- [PATCH nf] netfilter: nftables: Fix a memleak from userdata error path in new objects, Pablo Neira Ayuso
- [PATCH nf] netfilter: remove BUG_ON() after skb_header_pointer(), Pablo Neira Ayuso
- [PATCH nf] netfilter: nfnetlink_osf: Fix a missing skb_header_pointer() NULL check, Pablo Neira Ayuso
- [PATCH] ipv6: netfilter.c: fix missing line after declaration,
Pallavi Prabhu
- [PATCH net] netfilter: nfnetlink: add a missing rcu_read_unlock(),
Eric Dumazet
- [iptables PATCH 1/2] extensions: sctp: Fix nftables translation,
Phil Sutter
- [nft PATCH 1/3] scanner: sctp: Move to own scope,
Phil Sutter
- [net-next PATCH] net: netfilter: nft_exthdr: Support SCTP chunks,
Phil Sutter
- [PATCH nf] netfilter: conntrack: unregister ipv4 sockopts on error unwind, Florian Westphal
- [PATCH RFC libnetfilter_queue 0/1] Eliminate packet copy when constructing struct pkt_buff,
Duncan Roe
- Re: conntrackd inverted NAT address, endianness issue?, Pablo Neira Ayuso
- [PATCH conntrack-tools] conntrack: release options after parsing, Pablo Neira Ayuso
- [syzbot] bpf test error: WARNING in __nf_unregister_net_hook,
syzbot
- [syzbot] net test error: WARNING in __nf_unregister_net_hook,
syzbot
- [syzbot] memory leak in nf_hook_entries_grow (2),
syzbot
- [syzbot] upstream test error: WARNING in __nf_unregister_net_hook,
syzbot
- [PATCH nf] netfilter: arptables: use pernet ops struct during unregister,
Florian Westphal
- [syzbot] bpf-next test error: WARNING in __nf_unregister_net_hook,
syzbot
- [syzbot] linux-next test error: WARNING in __nf_unregister_net_hook,
syzbot
- [iptables PATCH v2] extensions: SECMARK: Implement revision 1, Phil Sutter
- [net-next PATCH v2] netfilter: xt_SECMARK: add new revision to fix structure layout,
Phil Sutter
- [PATCH] Avoid potentially erroneos RST drop.,
Ali Abdallah
- [PATCH] netfilter: Remove redundant assignment to ret,
Yang Li
- [PATCH nft 00/18] cache updates,v2,
Pablo Neira Ayuso
- [PATCH nft 01/18] tests: shell: remove missing modules, Pablo Neira Ayuso
- [PATCH nft 02/18] src: unbreak deletion by table handle, Pablo Neira Ayuso
- [PATCH nft 03/18] rule: skip fuzzy lookup for unexisting 64-bit handle, Pablo Neira Ayuso
- [PATCH nft 04/18] src: pass chain name to chain_cache_find(), Pablo Neira Ayuso
- [PATCH nft 05/18] src: consolidate nft_cache infrastructure, Pablo Neira Ayuso
- [PATCH nft 06/18] src: consolidate object cache infrastructure, Pablo Neira Ayuso
- [PATCH nft 09/18] cache: add set_cache_del() and use it, Pablo Neira Ayuso
- [PATCH nft 07/18] cache: add hashtable cache for object, Pablo Neira Ayuso
- [PATCH nft 08/18] cache: add hashtable cache for flowtable, Pablo Neira Ayuso
- [PATCH nft 10/18] evaluate: add set to the cache, Pablo Neira Ayuso
- [PATCH nft 11/18] evaluate: add flowtable to the cache, Pablo Neira Ayuso
- [PATCH nft 12/18] cache: missing table cache for several policy objects, Pablo Neira Ayuso
- [PATCH nft 13/18] evaluate: add object to the cache, Pablo Neira Ayuso
- [PATCH nft 14/18] cache: add hashtable cache for table, Pablo Neira Ayuso
- [PATCH nft 15/18] evaluate: remove chain from cache on delete chain command, Pablo Neira Ayuso
- [PATCH nft 17/18] evaluate: remove flowtable from cache on delete flowtable command, Pablo Neira Ayuso
- [PATCH nft 16/18] evaluate: remove set from cache on delete set command, Pablo Neira Ayuso
- [PATCH nft 18/18] evaluate: remove object from cache on delete object command, Pablo Neira Ayuso
- [PATCH net-next] netfilter: x_tables: improve limit_mt scalability,
Jason Baron
- [iptables PATCH] extensions: SECMARK: Implement revision 1, Phil Sutter
- [net-next PATCH] netfilter: xt_SECMARK: add new revision to fix structure layout,
Phil Sutter
- [iptables PATCH] extensions: sctp: Explain match types in man page, Phil Sutter
- [iptables PATCH 0/5] Merge some common code,
Phil Sutter
- [PATCH] Avoid potentially erroneos RST check,
Ali Abdallah
- [PATCH] Don't drop out of segments RST if tcp_be_liberal is set, Ali Abdallah
- [PATCH net-next 0/7] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH 1/2] netfilter: nft_socket: fix an unused variable warning,
Arnd Bergmann
- [PATCH nf-next 1/5, v2] netfilter: nftables: rename set element data activation/deactivation functions,
Pablo Neira Ayuso
- [iptables PATCH 0/2] Drop use of some obsolete functions,
Phil Sutter
- [PATCH net-next 00/22] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 01/22] netfilter: nat: move nf_xfrm_me_harder to where it is used, Pablo Neira Ayuso
- [PATCH net-next 02/22] netfilter: nft_socket: add support for cgroupsv2, Pablo Neira Ayuso
- [PATCH net-next 03/22] netfilter: disable defrag once its no longer needed, Pablo Neira Ayuso
- [PATCH net-next 04/22] netfilter: ebtables: remove the 3 ebtables pointers from struct net, Pablo Neira Ayuso
- [PATCH net-next 05/22] netfilter: x_tables: remove ipt_unregister_table, Pablo Neira Ayuso
- [PATCH net-next 06/22] netfilter: x_tables: add xt_find_table, Pablo Neira Ayuso
- [PATCH net-next 07/22] netfilter: iptables: unregister the tables by name, Pablo Neira Ayuso
- [PATCH net-next 08/22] netfilter: ip6tables: unregister the tables by name, Pablo Neira Ayuso
- [PATCH net-next 09/22] netfilter: arptables: unregister the tables by name, Pablo Neira Ayuso
- [PATCH net-next 10/22] netfilter: x_tables: remove paranoia tests, Pablo Neira Ayuso
- [PATCH net-next 11/22] netfilter: xt_nat: pass table to hookfn, Pablo Neira Ayuso
- [PATCH net-next 21/22] netfilter: nfnetlink: consolidate callback types, Pablo Neira Ayuso
- [PATCH net-next 22/22] netfilter: allow to turn off xtables compat layer, Pablo Neira Ayuso
- [PATCH net-next 12/22] netfilter: ip_tables: pass table pointer via nf_hook_ops, Pablo Neira Ayuso
- [PATCH net-next 13/22] netfilter: arp_tables: pass table pointer via nf_hook_ops, Pablo Neira Ayuso
- [PATCH net-next 15/22] netfilter: remove all xt_table anchors from struct net, Pablo Neira Ayuso
- [PATCH net-next 16/22] netfilter: nf_log_syslog: Unset bridge logger in pernet exit, Pablo Neira Ayuso
- [PATCH net-next 14/22] netfilter: ip6_tables: pass table pointer via nf_hook_ops, Pablo Neira Ayuso
- [PATCH net-next 17/22] netfilter: nftables: add nft_pernet() helper function, Pablo Neira Ayuso
- [PATCH net-next 18/22] netfilter: nfnetlink: add struct nfnl_info and pass it to callbacks, Pablo Neira Ayuso
- [PATCH net-next 19/22] netfilter: nfnetlink: pass struct nfnl_info to rcu callbacks, Pablo Neira Ayuso
- [PATCH net-next 20/22] netfilter: nfnetlink: pass struct nfnl_info to batch callbacks, Pablo Neira Ayuso
- [nf-next:for-net-next 25/25] net/netfilter/nf_tables_api.c:4448:22: warning: variable 'ext' set but not used, kernel test robot
- [PATCH nf-next] netfilter: allow to turn off xtables compat layer,
Florian Westphal
- [PATCH nf-next 1/4] netfilter: nftables: rename set element data activation/deactivation functions,
Pablo Neira Ayuso
- [PATCH nf-next,v2] netfilter: nftables: add catch-all set element support, Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nftables: add catch-all set element support, Pablo Neira Ayuso
- RSTs being marked as invalid because of wrong td_maxack value,
Ali Abdallah
- [PATCH nf-next 0/5] nfnetlink housekeeping,
Pablo Neira Ayuso
- [PATCH] net: netfilter: Add RFC-7597 Section 5.1 PSID support,
Cole Dishington
[PATCH] netfilter: nf_log_syslog: Unset bridge logger in pernet exit,
Phil Sutter
[PATCH nf-next v2 00/12] netfilter: x_tables: remove ipt_unregister_table,
Florian Westphal
- [PATCH nf-next v2 01/12] netfilter: ebtables: remove the 3 ebtables pointers from struct net, Florian Westphal
- [PATCH nf-next v2 02/12] netfilter: x_tables: remove ipt_unregister_table, Florian Westphal
- [PATCH nf-next v2 03/12] netfilter: add xt_find_table, Florian Westphal
- [PATCH nf-next v2 04/12] netfilter: iptables: unregister the tables by name, Florian Westphal
- [PATCH nf-next v2 05/12] netfilter: ip6tables: unregister the tables by name, Florian Westphal
- [PATCH nf-next v2 06/12] netfilter: arptables: unregister the tables by name, Florian Westphal
- [PATCH nf-next v2 08/12] netfilter: xt_nat: pass table to hookfn, Florian Westphal
- [PATCH nf-next v2 07/12] netfilter: x_tables: remove paranoia tests, Florian Westphal
- [PATCH nf-next v2 10/12] netfilter: arp_tables: pass table pointer via nf_hook_ops, Florian Westphal
- [PATCH nf-next v2 09/12] netfilter: ip_tables: pass table pointer via nf_hook_ops, Florian Westphal
- [PATCH nf-next v2 12/12] netfilter: remove all xt_table anchors from struct net, Florian Westphal
- [PATCH nf-next v2 11/12] netfilter: ip6_tables: pass table pointer via nf_hook_ops, Florian Westphal
- Re: [PATCH nf-next v2 00/12] netfilter: x_tables: remove ipt_unregister_table, Pablo Neira Ayuso
[PATCH v2 nf-next] netfilter: disable defrag once its no longer needed,
Florian Westphal
[PATCH nft] src: add cgroupsv2 support, Pablo Neira Ayuso
[PATCH libnftnl] expr: socket: add cgroups v2 support, Pablo Neira Ayuso
[PATCH nf-next] netfilter: nft_socket: add support for cgroupsv2, Pablo Neira Ayuso
[PATCH nf-next] netfilter: disable defrag once its no longer needed,
Florian Westphal
[PATCH nf-next 00/12] netfilter: remove xtables pointers from struct net,
Florian Westphal
- [PATCH nf-next 01/12] netfilter: ebtables: remove the 3 ebtables pointers from struct net, Florian Westphal
- [PATCH nf-next 02/12] netfilter: x_tables: remove ipt_unregister_table, Florian Westphal
- [PATCH nf-next 03/12] netfilter: add xt_find_table, Florian Westphal
- [PATCH nf-next 04/12] netfilter: iptables: unregister the tables by name, Florian Westphal
- [PATCH nf-next 05/12] netfilter: ip6tables: unregister the tables by name, Florian Westphal
- [PATCH nf-next 06/12] netfilter: arptables: unregister the tables by name, Florian Westphal
- [PATCH nf-next 07/12] netfilter: x_tables: remove paranoia tests, Florian Westphal
- [PATCH nf-next 08/12] netfilter: xt_nat: pass table to hookfn, Florian Westphal
- [PATCH nf-next 09/12] netfilter: ip_tables: pass table pointer via nf_hook_ops, Florian Westphal
- [PATCH nf-next 10/12] netfilter: arp_tables: pass table pointer via nf_hook_ops, Florian Westphal
- [PATCH nf-next 11/12] netfilter: ip6_tables: pass table pointer via nf_hook_ops, Florian Westphal
- [PATCH nf-next 12/12] netfilter: remove all xt_table anchors from struct net, Florian Westphal
[PATCH] netfilter: conntrack: Reset the max ACK flag on SYN in ignore state,
Ali Abdallah
Error when using clone option in iptables,
Mohan Das
Now have make distcheck passing with doxygen enabled,
Duncan Roe
[PATCH nf-next] netfilter: nat: move nf_xfrm_me_harder to where it is used,
Florian Westphal
[PATCH nft] parser_bison: missing relational operation on flag list, Pablo Neira Ayuso
[PATCH net-next 00/14] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 01/14] netfilter: flowtable: add vlan match offload support, Pablo Neira Ayuso
- [PATCH net-next 02/14] netfilter: flowtable: add vlan pop action offload support, Pablo Neira Ayuso
- [PATCH net-next 03/14] netfilter: conntrack: move autoassign warning member to net_generic data, Pablo Neira Ayuso
- [PATCH net-next 04/14] netfilter: conntrack: move autoassign_helper sysctl to net_generic data, Pablo Neira Ayuso
- [PATCH net-next 05/14] netfilter: conntrack: move expect counter to net_generic data, Pablo Neira Ayuso
- [PATCH net-next 07/14] netfilter: conntrack: convert sysctls to u8, Pablo Neira Ayuso
- [PATCH net-next 06/14] netfilter: conntrack: move ct counter to net_generic data, Pablo Neira Ayuso
- [PATCH net-next 08/14] netfilter: flowtable: Add FLOW_OFFLOAD_XMIT_UNSPEC xmit type, Pablo Neira Ayuso
- [PATCH net-next 09/14] netfilter: nft_payload: fix C-VLAN offload support, Pablo Neira Ayuso
- [PATCH net-next 10/14] netfilter: nftables_offload: VLAN id needs host byteorder in flow dissector, Pablo Neira Ayuso
- [PATCH net-next 12/14] netfilter: Dissect flow after packet mangling, Pablo Neira Ayuso
- [PATCH net-next 11/14] netfilter: nftables_offload: special ethertype handling for VLAN, Pablo Neira Ayuso
- [PATCH net-next 13/14] selftests: fib_tests: Add test cases for interaction with mangling, Pablo Neira Ayuso
- [PATCH net-next 14/14] netfilter: nftables: counter hardware offload support, Pablo Neira Ayuso
- <Possible follow-ups>
- [PATCH net-next 00/14] Netfilter updates for net-next, Pablo Neira Ayuso
- [PATCH net-next 02/14] netfilter: nfqueue: enable to get skb->priority, Pablo Neira Ayuso
- [PATCH net-next 01/14] netfilter: conntrack: mark UDP zero checksum as CHECKSUM_UNNECESSARY, Pablo Neira Ayuso
- [PATCH net-next 03/14] netfilter: conntrack: make all extensions 8-byte alignned, Pablo Neira Ayuso
- [PATCH net-next 06/14] netfilter: conntrack: remove extension register api, Pablo Neira Ayuso
- [PATCH net-next 05/14] netfilter: conntrack: handle ->destroy hook via nat_ops instead, Pablo Neira Ayuso
- [PATCH net-next 04/14] netfilter: conntrack: move extension sizes into core, Pablo Neira Ayuso
- [PATCH net-next 07/14] netfilter: conntrack: pptp: use single option structure, Pablo Neira Ayuso
- [PATCH net-next 08/14] netfilter: exthdr: add support for tcp option removal, Pablo Neira Ayuso
- [PATCH net-next 10/14] netfilter: ecache: don't use nf_conn spinlock, Pablo Neira Ayuso
- [PATCH net-next 09/14] netfilter: nft_compat: suppress comment match, Pablo Neira Ayuso
- [PATCH net-next 13/14] nfqueue: enable to set skb->priority, Pablo Neira Ayuso
- [PATCH net-next 12/14] netfilter: nft_cmp: optimize comparison for 16-bytes, Pablo Neira Ayuso
- [PATCH net-next 11/14] netfilter: cttimeout: use option structure, Pablo Neira Ayuso
- [PATCH net-next 14/14] netfilter: ctnetlink: use dump structure instead of raw args, Pablo Neira Ayuso
- [PATCH net-next 00/14] Netfilter updates for net-next, Pablo Neira Ayuso
- [PATCH net-next 03/14] netfilter: nf_tables: add nft_trans_commit_list_add_elem helper, Pablo Neira Ayuso
- [PATCH net-next 01/14] netfilter: nfnetlink: Report extack policy errors for batched ops, Pablo Neira Ayuso
- [PATCH net-next 02/14] netfilter: bpf: Pass string literal as format argument of request_module(), Pablo Neira Ayuso
- [PATCH net-next 05/14] netfilter: nf_tables: prepare nft audit for set element compaction, Pablo Neira Ayuso
- [PATCH net-next 04/14] netfilter: nf_tables: prepare for multiple elements in nft_trans_elem structure, Pablo Neira Ayuso
- [PATCH net-next 10/14] netfilter: rpfilter: Convert rpfilter_mt() to dscp_t., Pablo Neira Ayuso
- [PATCH net-next 08/14] netfilter: ipv4: Convert ip_route_me_harder() to dscp_t., Pablo Neira Ayuso
- [PATCH net-next 09/14] netfilter: flow_offload: Convert nft_flow_route() to dscp_t., Pablo Neira Ayuso
- [PATCH net-next 07/14] netfilter: nf_tables: allocate element update information dynamically, Pablo Neira Ayuso
- [PATCH net-next 06/14] netfilter: nf_tables: switch trans_elem to real flex array, Pablo Neira Ayuso
- [PATCH net-next 12/14] netfilter: nf_dup4: Convert nf_dup_ipv4_route() to dscp_t., Pablo Neira Ayuso
- [PATCH net-next 11/14] netfilter: nft_fib: Convert nft_fib4_eval() to dscp_t., Pablo Neira Ayuso
- [PATCH net-next 13/14] netfilter: bitwise: rename some boolean operation functions, Pablo Neira Ayuso
- [PATCH net-next 14/14] netfilter: bitwise: add support for doing AND, OR and XOR directly, Pablo Neira Ayuso
- [PATCH net-next 00/14] Netfilter updates for net-next, Pablo Neira Ayuso
- [PATCH net-next 01/14] netfilter: nf_tables: fix set size with rbtree backend, Pablo Neira Ayuso
- [PATCH net-next 02/14] netfilter: br_netfilter: remove unused conditional and dead code, Pablo Neira Ayuso
- [PATCH net-next 04/14] netfilter: nf_tables: Store user-defined hook ifname, Pablo Neira Ayuso
- [PATCH net-next 03/14] netfilter: nf_tables: Flowtable hook's pf value never varies, Pablo Neira Ayuso
- [PATCH net-next 08/14] netfilter: nf_tables: Simplify chain netdev notifier, Pablo Neira Ayuso
- [PATCH net-next 06/14] netfilter: nf_tables: Compare netdev hooks based on stored name, Pablo Neira Ayuso
- [PATCH net-next 09/14] netfilter: nft_flow_offload: clear tcp MAXACK flag before moving to slowpath, Pablo Neira Ayuso
- [PATCH net-next 07/14] netfilter: nf_tables: Tolerate chains with no remaining hooks, Pablo Neira Ayuso
- [PATCH net-next 10/14] netfilter: nft_flow_offload: update tcp state flags under lock, Pablo Neira Ayuso
- [PATCH net-next 05/14] netfilter: nf_tables: Use stored ifname in netdev hook dumps, Pablo Neira Ayuso
- [PATCH net-next 13/14] netfilter: flowtable: teardown flow if cached mtu is stale, Pablo Neira Ayuso
- [PATCH net-next 14/14] netfilter: flowtable: add CLOSING state, Pablo Neira Ayuso
- [PATCH net-next 11/14] netfilter: conntrack: remove skb argument from nf_ct_refresh, Pablo Neira Ayuso
- [PATCH net-next 12/14] netfilter: conntrack: rework offload nf_conn timeout extension logic, Pablo Neira Ayuso
[PATCH 3/3,v4] netfilter: nftables_offload: special ethertype handling for VLAN, Pablo Neira Ayuso
[PATCH v2 0/2] Two fixes related to '--concurrent',
Firo Yang
[PATCH nf-next] netfilter: nftables: counter hardware offload support, Pablo Neira Ayuso
[PATCH nft 0/10] cache updates,
Pablo Neira Ayuso
- [PATCH nft 01/10] cache: add hashtable cache for object, Pablo Neira Ayuso
- [PATCH nft 02/10] cache: add hashtable cache for flowtable, Pablo Neira Ayuso
- [PATCH nft 03/10] cache: add set_cache_del() and use it, Pablo Neira Ayuso
- [PATCH nft 04/10] evaluate: add set to the cache, Pablo Neira Ayuso
- [PATCH nft 05/10] evaluate: add flowtable to the cache, Pablo Neira Ayuso
- [PATCH nft 07/10] evaluate: add object to the cache, Pablo Neira Ayuso
- [PATCH nft 06/10] cache: missing table cache for several policy objects, Pablo Neira Ayuso
- [PATCH nft 08/10] cache: move struct nft_cache declaration to cache.h, Pablo Neira Ayuso
- [PATCH nft 09/10] cache: add hashtable cache for table, Pablo Neira Ayuso
- [PATCH nft 10/10] evaluate: remove table_lookup_global(), Pablo Neira Ayuso
[nft PATCH] mnl: Increase BATCH_PAGE_SIZE to support huge rulesets, Phil Sutter
[PATCH nf-next v2 0/2] netfilter: Dissect flow after packet mangling,
Ido Schimmel
[PATCH] netfilter: nf_conntrack: Add conntrack helper for ESP/IPsec,
Cole Dishington
[PATCH nf-next,v3 1/3] netfilter: nft_payload: fix C-VLAN offload support,
Pablo Neira Ayuso
[PATCH nft] parser: allow to load stateful ct connlimit elements in sets,
nevola
[PATCH net 0/7] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 1/7] netfilter: flowtable: fix NAT IPv6 offload mangling, Pablo Neira Ayuso
- [PATCH net 2/7] netfilter: conntrack: do not print icmpv6 as unknown via /proc, Pablo Neira Ayuso
- [PATCH net 3/7] netfilter: nft_limit: avoid possible divide error in nft_limit_init, Pablo Neira Ayuso
- [PATCH net 4/7] netfilter: bridge: add pre_exit hooks for ebtable unregistration, Pablo Neira Ayuso
- [PATCH net 5/7] netfilter: arp_tables: add pre_exit hook for table unregister, Pablo Neira Ayuso
- [PATCH net 6/7] netfilter: x_tables: fix compat match/target pad out-of-bound write, Pablo Neira Ayuso
- [PATCH net 7/7] netfilter: nftables: clone set element expression template, Pablo Neira Ayuso
- <Possible follow-ups>
- [PATCH net 0/7] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/7] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/7] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/7] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/7] Netfilter fixes for net, Pablo Neira Ayuso
[PATCH nf-next v2 0/5] netfilter: conntrack: shrink size of netns_ct,
Florian Westphal
[PATCH nf-next,v2 1/3] netfilter: nft_payload: fix C-VLAN offload support,
Pablo Neira Ayuso
[PATCH nf-next 1/3] netfilter: nft_payload: fix C-VLAN offload support,
Pablo Neira Ayuso
linux-next: build failure after merge of the net-next tree,
Stephen Rothwell
[PATCH nf-next] netfilter: Dissect flow after packet mangling,
Ido Schimmel
[PATCH nf,v4] netfilter: nftables: clone set element expression template, Pablo Neira Ayuso
[PATCH nf,v3] netfilter: nftables: clone set element expression template, Pablo Neira Ayuso
[syzbot] WARNING in __nf_unregister_net_hook (4),
syzbot
[PATCH net] netfilter: nft_limit: avoid possible divide error in nft_limit_init,
Eric Dumazet
[PATCH nf-next 0/5] netfilter: conntrack: shrink size of netns_ct,
Florian Westphal
[PATCH] net/mlx5e: fix ingress_ifindex check in mlx5e_flower_parse_meta,
wenxu
[PATCH nf v2] netfilter: nft_payload: fix the h_vlan_encapsulated_proto flow_dissector vlaue,
wenxu
[PATCH nf] netfilter: nftables: clone set element expression template, Pablo Neira Ayuso
[PATCH] conntrack_tcp: Reset the max ACK flag on SYN in ignore state,
Ali Abdallah
[PATCH nf 0/2] arp,ebtables: add pre_exit hooks for arp/ebtable hook unregister,
Florian Westphal
[PATCH nf] netfilter: x_tables: fix compat match/target pad out-of-bound write,
Florian Westphal
[PATCH nft] evaluate: check if nat statement map specifies a transport header expr, Florian Westphal
LPC 2021 Networking and BPF Track CFP,
Daniel Borkmann
[PATCH net-next 00/28] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 01/28] netfilter: nf_log_ipv4: rename to nf_log_syslog, Pablo Neira Ayuso
- [PATCH net-next 02/28] netfilter: nf_log_arp: merge with nf_log_syslog, Pablo Neira Ayuso
- [PATCH net-next 03/28] netfilter: nf_log_ipv6: merge with nf_log_syslog, Pablo Neira Ayuso
- [PATCH net-next 04/28] netfilter: nf_log_netdev: merge with nf_log_syslog, Pablo Neira Ayuso
- [PATCH net-next 05/28] netfilter: nf_log_bridge: merge with nf_log_syslog, Pablo Neira Ayuso
- [PATCH net-next 07/28] netfilter: nf_log: add module softdeps, Pablo Neira Ayuso
- [PATCH net-next 06/28] netfilter: nf_log_common: merge with nf_log_syslog, Pablo Neira Ayuso
- [PATCH net-next 12/28] netfilter: nftables: remove unnecessary spin_lock_init(), Pablo Neira Ayuso
- [PATCH net-next 08/28] netfilter: nft_log: perform module load from nf_tables, Pablo Neira Ayuso
- [PATCH net-next 10/28] netfilter: ipset: Remove duplicate declaration, Pablo Neira Ayuso
- [PATCH net-next 09/28] audit: log nftables configuration change events once per table, Pablo Neira Ayuso
- [PATCH net-next 13/28] netfilter: nftables: add helper function to set the base sequence number, Pablo Neira Ayuso
- [PATCH net-next 16/28] netfilter: nftables: fix a warning message in nf_tables_commit_audit_collect(), Pablo Neira Ayuso
- [PATCH net-next 20/28] netfilter: cttimeout: use net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 22/28] netfilter: nf_defrag_ipv4: use net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 18/28] netfilter: nfnetlink: add and use nfnetlink_broadcast, Pablo Neira Ayuso
- [PATCH net-next 17/28] netfilter: nftables: remove documentation on static functions, Pablo Neira Ayuso
- [PATCH net-next 15/28] netfilter: ipvs: do not printk on netns creation, Pablo Neira Ayuso
- [PATCH net-next 14/28] netfilter: add helper function to set up the nfnetlink header and use it, Pablo Neira Ayuso
- [PATCH net-next 11/28] netfilter: flowtable: dst_check() from garbage collector path, Pablo Neira Ayuso
- [PATCH net-next 23/28] netfilter: ebtables: use net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 19/28] netfilter: nfnetlink: use net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 24/28] netfilter: nf_tables: use net_generic infra for transaction data, Pablo Neira Ayuso
- [PATCH net-next 21/28] netfilter: nf_defrag_ipv6: use net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 25/28] netfilter: x_tables: move known table lists to net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 26/28] netfilter: conntrack: move sysctl pointer to net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 27/28] netfilter: conntrack: move ecache dwork to net_generic infra, Pablo Neira Ayuso
- [PATCH net-next 28/28] net: remove obsolete members from struct net, Pablo Neira Ayuso
[PATCH v4 0/5] conntrack: save output format,
Mikhail Sennikovsky
[iptables PATCH v2] nft: Increase BATCH_PAGE_SIZE to support huge rulesets, Phil Sutter
Unused macro,
Alejandro Colomar (man-pages)
[PATCH nf-next v2 1/2] netfilter: flowtable: add vlan match offload support,
wenxu
[syzbot] WARNING: suspicious RCU usage in find_inlist_lock,
syzbot
[PATCH iptables] fix build for missing ETH_ALEN definition, Maciej Żenczykowski
[PATCH netfilter] netfilter: xt_IDLETIMER: fix idletimer_tg_helper non-kosher casts,
Maciej Żenczykowski
[PATCH nft 1/2] cache: add hashtable cache for sets,
Pablo Neira Ayuso
[PATCH] netfilter: nftables: fix a warning message in nf_tables_commit_audit_collect(),
Dan Carpenter
[PATCH nf] netfilter: nft_payload: fix vlan_tpid get from h_vlan_proto,
wenxu
[PATCH nft] cache: check for NULL chain in cache_init(), Pablo Neira Ayuso
[PATCH nft 1/4] cache: rename chain_htable to cache_chain_ht,
Pablo Neira Ayuso
[iptables PATCH v5 1/2] extensions: libxt_conntrack: print xlate state as set,
Alexander Mikhalitsyn
[iptables PATCH v5 PATCH 1/2] extensions: libxt_conntrack: print xlate state as set,
Alexander Mikhalitsyn
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]