Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [netfilter-core] [PATCH nft v4] src: Support netdev egress hook, (continued)
- [conntrack-tools PATCH 1/3] tests: introduce new python-based framework for running tests,
Arturo Borrero Gonzalez
- Re: KASAN: use-after-free Read in dump_schedule,
syzbot
- [PATCH nf-next v4 0/5] Netfilter egress hook,
Lukas Wunner
- [PATCH nft] json: icmp: move expected parts to json.output, Florian Westphal
- [PATCH nft] evaluate: disallow ct original {s,d}ddr from concatenations, Pablo Neira Ayuso
- [PATCH nft] exthdr: remove tcp dependency for tcp option matching,
Florian Westphal
- [PATCH nft 0/4] json test case fixups,
Florian Westphal
- [PATCH nf-next v2] netfilter: ctnetlink: remove get_ct indirection,
Florian Westphal
- [conntrack-tools PATCH] conntrackd: introduce yes & no config values,
Arturo Borrero Gonzalez
- [PATCH nf-next] netfilter: ctnetlink: remove get_ct indirection,
Florian Westphal
- [PATCH] ipset: fix print format warning,
Neutron Soutmun
- [PATCH nf] netfilter: nft_dynset: dump expressions when set definition contains no expressions, Pablo Neira Ayuso
- [PATCH nf] netfilter: nft_dynset: add timeout extension to template, Pablo Neira Ayuso
- [PATCH nf] netfilter: nft_dynset: honor stateful expressions in set definition, Pablo Neira Ayuso
- [ANNOUNCE] iptables 1.8.7 release, Phil Sutter
- [ANNOUNCE] nftables 0.9.8 release, Pablo Neira Ayuso
- [iptables PATCH] tests/shell: Fix nft-only/0009-needless-bitwise_0, Phil Sutter
- [ANNOUNCE] libnftnl 1.1.9 release, Pablo Neira Ayuso
- [PATCH nft] evaluate: disallow ct original {s,d}ddr from maps, Pablo Neira Ayuso
- [PATCH conntrack-tools 0/3] preparing support for command batch,
Pablo Neira Ayuso
- KMSAN: uninit-value in nf_conntrack_udplite_packet (2), syzbot
- [PATCH libnetfilter_queue] src: fix header handling in nfq_ip6_set_transport_header, Etan Kissling
- [PATCH libnetfilter_queue] src: fix IPv6 header handling,
Etan Kissling
- [PATCH libnetfilter_queue] src: add pkt_buff function for ICMP,
Etan Kissling
- [PATCH ghak90 v11 00/11] audit: implement container identifier,
Richard Guy Briggs
- [PATCH ghak90 v11 01/11] audit: collect audit task parameters, Richard Guy Briggs
- [PATCH ghak90 v11 02/11] audit: add container id, Richard Guy Briggs
- [PATCH ghak90 v11 03/11] audit: log container info of syscalls, Richard Guy Briggs
- [PATCH ghak90 v11 04/11] audit: add contid support for signalling the audit daemon, Richard Guy Briggs
- [PATCH ghak90 v11 05/11] audit: add support for non-syscall auxiliary records, Richard Guy Briggs
- [PATCH ghak90 v11 06/11] audit: add containerid support for user records, Richard Guy Briggs
- [PATCH ghak90 v11 07/11] audit: add containerid filtering, Richard Guy Briggs
- [PATCH ghak90 v11 09/11] audit: contid check descendancy and nesting, Richard Guy Briggs
- [PATCH ghak90 v11 10/11] audit: track container nesting, Richard Guy Briggs
- [PATCH ghak90 v11 11/11] audit: add capcontid to set contid outside init_user_ns, Richard Guy Briggs
- [PATCH ghak90 v11 08/11] audit: add support for containerid to network namespaces, Richard Guy Briggs
- [PATCH AUTOSEL 5.10 08/51] netfilter: ipset: fixes possible oops in mtype_resize, Sasha Levin
- [PATCH AUTOSEL 5.4 05/28] netfilter: ipset: fixes possible oops in mtype_resize, Sasha Levin
- [PATCH] netfilter: Fix memleak in nf_nat_init,
Dinghao Liu
- [PATCH net] netfilter: conntrack: fix reading nf_conntrack_buckets,
Jesper Dangaard Brouer
- [PATCH] netfilter: Reverse nft_set_lookup_byid list traversal,
Jan-Philipp Litza
- Re: [PATCH v6] ipvs: add weighted random twos choice algorithm,
Julian Anastasov
- [PATCH nft] segtree: honor set element expiration, Pablo Neira Ayuso
- [PATCH nft 0/2] libedit support followup,
Pablo Neira Ayuso
- [PATCH nft 0/2] follow up work on the libedit support,
Pablo Neira Ayuso
- [PATCH net 0/3] net: fix netfilter defrag/ip tunnel pmtu blackhole,
Florian Westphal
- [PATCH nft] cli: add libedit support, Pablo Neira Ayuso
- [PATCH nft] src: set on flags to request multi-statement support, Pablo Neira Ayuso
- Potential licensing issue with libreadline,
Arturo Borrero Gonzalez
- [PATCH net 0/3] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 1/3] netfilter: xt_RATEEST: reject non-null terminated string from userspace, Pablo Neira Ayuso
- [PATCH net 2/3] netfilter: nft_dynset: report EOPNOTSUPP on missing set feature, Pablo Neira Ayuso
- [PATCH net 3/3] netfilter: nftables: add set expression flags, Pablo Neira Ayuso
- Re: [PATCH net 0/3] Netfilter fixes for net, Jakub Kicinski
- <Possible follow-ups>
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] netfilter fixes for net, Florian Westphal
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Florian Westphal
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] netfilter fixes for net, Florian Westphal
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/3] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH libnetfilter_conntrack] examples: check return value of nfct_nlmsg_build(),
Eyal Birger
- WARNING: suspicious RCU usage in xt_obj_to_user, syzbot
- Announcing Netdev 0x15, Jamal Hadi Salim
- [PATCH nf 1/2] netfilter: nft_dynset: report EOPNOTSUPP on missing set feature,
Pablo Neira Ayuso
- stack corruption with EBT_ENTRY_ITERATE, sharathv
- [PATCH conntrack-tools] conntrackd: add ip netns test script,
Pablo Neira Ayuso
- kernel BUG at lib/string.c:LINE! (6),
syzbot
- [PATCH ghak90 v10 00/11] audit: implement container identifier,
Richard Guy Briggs
- [PATCH ghak90 v10 01/11] audit: collect audit task parameters, Richard Guy Briggs
- [PATCH ghak90 v10 02/11] audit: add container id, Richard Guy Briggs
- [PATCH ghak90 v10 03/11] audit: log container info of syscalls, Richard Guy Briggs
- [PATCH ghak90 v10 04/11] audit: add contid support for signalling the audit daemon, Richard Guy Briggs
- [PATCH ghak90 v10 06/11] audit: add containerid support for user records, Richard Guy Briggs
- [PATCH ghak90 v10 05/11] audit: add support for non-syscall auxiliary records, Richard Guy Briggs
- [PATCH ghak90 v10 07/11] audit: add containerid filtering, Richard Guy Briggs
- [PATCH ghak90 v10 08/11] audit: add support for containerid to network namespaces, Richard Guy Briggs
- [PATCH ghak90 v10 09/11] audit: contid check descendancy and nesting, Richard Guy Briggs
- [PATCH ghak90 v10 10/11] audit: track container nesting, Richard Guy Briggs
- [PATCH ghak90 v10 11/11] audit: add capcontid to set contid outside init_user_ns, Richard Guy Briggs
- [ANNOUNCE] ipset 7.10 released, Jozsef Kadlecsik
- Re: INFO: rcu detected stall in tipc_release,
syzbot
- [PATCH nft] tests: shell: set element multistatement support, Pablo Neira Ayuso
- [PATCH nft 1/2,v2] src: add support for multi-statement in dynamic sets and maps,
Pablo Neira Ayuso
- [PATCH nft,v2] src: disallow burst 0 in ratelimits, Pablo Neira Ayuso
- [PATCH 1/3 libnftnl,v2] src: add NFTNL_SET_ELEM_EXPRESSIONS,
Pablo Neira Ayuso
- [PATCH v2] netfilter: ipset: fix shift-out-of-bounds in htable_bits(),
Vasily Averin
- [PATCH nf] parser_bison: disallow burst 0 in ratelimits, Pablo Neira Ayuso
- [PATCH nft 0/2] multi-statement support for set elements,
Pablo Neira Ayuso
- [PATCH] netfilter: ipset: fixes possible oops in mtype_resize,
Vasily Averin
- [PATCH nf] netfilter: x_tables: Update remaining dereference to RCU,
Subash Abhinov Kasiviswanathan
- [PATCH conntrack-tools] conntrack: pretty-print the portid, Florian Westphal
- UBSAN: shift-out-of-bounds in hash_ipmark_create, syzbot
- WARNING: suspicious RCU usage in nf_ct_iterate_cleanup, syzbot
- [nft PATCH] tests: py: Fix for changed concatenated ranges output, Phil Sutter
- [PATCH][next] netfilter: nftables: fix incorrect increment of loop counter,
Colin King
- [libnftnl PATCH 1/2] set_elem: Use nftnl_data_reg_snprintf(),
Phil Sutter
- [PATCH nft] json: don't leave dangling pointers on hlist, Florian Westphal
- UBSAN: shift-out-of-bounds in hash_mac_create, syzbot
- [PATCH net-next 00/10] Netfilter/IPVS updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 04/10] netfilter: nfnl_acct: remove data from struct net, Pablo Neira Ayuso
- [PATCH net-next 09/10] netfilter: nftables: generalize set extension to support for several expressions, Pablo Neira Ayuso
- [PATCH net-next 06/10] netfilter: ctnetlink: add timeout and protoinfo to destroy events, Pablo Neira Ayuso
- [PATCH net-next 10/10] netfilter: nftables: netlink support for several set element expressions, Pablo Neira Ayuso
- [PATCH net-next 07/10] netfilter: nftables: generalize set expressions support, Pablo Neira Ayuso
- [PATCH net-next 05/10] netfilter: use actual socket sk for REJECT action, Pablo Neira Ayuso
- [PATCH net-next 08/10] netfilter: nftables: move nft_expr before nft_set, Pablo Neira Ayuso
- [PATCH net-next 01/10] netfilter: nft_reject_bridge: fix build errors due to code movement, Pablo Neira Ayuso
- [PATCH net-next 03/10] netfilter: Remove unnecessary conversion to bool, Pablo Neira Ayuso
- [PATCH net-next 02/10] ipvs: replace atomic_add_return(), Pablo Neira Ayuso
- Re: [PATCH net-next 00/10] Netfilter/IPVS updates for net-next, Jakub Kicinski
- [PATCH libnftnl 1/3] src: add NFTNL_SET_ELEM_EXPRESSIONS,
Pablo Neira Ayuso
- [PATCH nft] nft: trace: print packet unconditionally,
Florian Westphal
- [PATCH xtables-nft 0/3] xt-monitor fixes,
Florian Westphal
- [PATCH nf-next,v4 1/4] netfilter: nftables: generalize set expressions support,
Pablo Neira Ayuso
- [PATCH nf-next,v3] netfilter: ctnetlink: add timeout and protoinfo to destroy events, Pablo Neira Ayuso
- [PATCH nf-next,v3 1/4] netfilter: nftables: generalize set expressions support,
Pablo Neira Ayuso
- [PATCH nf-next v2 1/1] netfilter: ctnetlink: add timeout and protoinfo to destroy events,
Florian Westphal
- [iptables PATCH v3 0/9] nft: Sorted chain listing et al.,
Phil Sutter
- [iptables PATCH v3 7/9] nft: cache: Sort custom chains by name, Phil Sutter
- [iptables PATCH v3 2/9] nft: cache: Introduce nft_cache_add_chain(), Phil Sutter
- [iptables PATCH v3 6/9] nft: Introduce a dedicated base chain array, Phil Sutter
- [iptables PATCH v3 8/9] tests: shell: Drop any dump sorting in place, Phil Sutter
- [iptables PATCH v3 4/9] nft: cache: Move nft_chain_find() over, Phil Sutter
- [iptables PATCH v3 3/9] nft: Implement nft_chain_foreach(), Phil Sutter
- [iptables PATCH v3 5/9] nft: Introduce struct nft_chain, Phil Sutter
- [iptables PATCH v3 1/9] nft: Fix selective chain compatibility checks, Phil Sutter
- [iptables PATCH v3 9/9] nft: Avoid pointless table/chain creation, Phil Sutter
- Re: [iptables PATCH v3 0/9] nft: Sorted chain listing et al., Phil Sutter
- [PATCH nf-next] netfilter: ctnetlink: always include remaining timeout,
Florian Westphal
- [PATCH nft 0/10] nft: add automatic icmp/icmpv6 dependencies,
Florian Westphal
- [PATCH nft 01/10] exthdr: remove unused proto_key member from struct, Florian Westphal
- [PATCH nft 03/10] src: add auto-dependencies for ipv4 icmp, Florian Westphal
- [PATCH nft 04/10] tests: fix exepcted payload of icmp expressions, Florian Westphal
- [PATCH nft 05/10] src: add auto-dependencies for ipv6 icmp6, Florian Westphal
- [PATCH nft 07/10] payload: auto-remove simple icmp/icmpv6 dependency expressions, Florian Westphal
- [PATCH nft 02/10] proto: reduce size of proto_desc structure, Florian Westphal
- [PATCH nft 06/10] tests: fix exepcted payload of icmpv6 expressions, Florian Westphal
- [PATCH nft 08/10] tests: icmp, icmpv6: avoid remaining warnings, Florian Westphal
- [PATCH nft 10/10] tests: icmp, icmpv6: check we don't add second dependency, Florian Westphal
- [PATCH nft 09/10] tests: ip: add one test case to cover both id and sequence, Florian Westphal
- Re: [PATCH nft 0/10] nft: add automatic icmp/icmpv6 dependencies, Phil Sutter
- [PATCH 5/5 nf-next,v2] netfilter: nftables: netlink support for several set element expressions, Pablo Neira Ayuso
- [PATCH nf] netfilter: nft_ct: Remove confirmation check for NFT_CT_ID,
Brett Mastbergen
- [PATCH net] net: sched: incorrect Kconfig dependencies on Netfilter modules,
Pablo Neira Ayuso
- [PATCH nf,v4] netfilter: nft_dynset: fix timeouts later than 23 days,
Pablo Neira Ayuso
- [PATCH nft] tests: shell: timeouts later than 23 days,
Pablo Neira Ayuso
- [PATCH nf,v3] netfilter: nft_dynset: fix timeouts later than 23 days, Pablo Neira Ayuso
- [PATCH nf,v2] netfilter: nft_dynset: fix timeouts later than 23 days, Pablo Neira Ayuso
- [PATCH nf] netfilter: nftables: comment indirect serialization of commit_mutex with rtnl_mutex,
Pablo Neira Ayuso
- [PATCH nf] netfilter: nft_dynset: fix timeouts layer than 23 days,
Pablo Neira Ayuso
- [PATCH nf] netfilter: nftables: fix incorrect element timeout,
Pablo Neira Ayuso
- [PATCH nft] parser_bison: double close_scope() call for implicit chains, Pablo Neira Ayuso
- [PATCH] Remove IP_NF_IPTABLES dependency for NET_ACT_CONNMARK,
Andreas Sundstrom
- [PATCH nf-next 0/5] support for several expression in set elements,
Pablo Neira Ayuso
- [PATCH v2] xfrm: interface: Don't hide plain packets from netfilter,
Phil Sutter
- [PATCH] xfrm: interface: Don't hide plain packets from netfilter,
Phil Sutter
- [PATCH nftables 1/2] monitor: add assignment check for json_echo,
Jose M. Guisado Gomez
- [iptables PATCH] tests/shell: Test for fixed extension registration, Phil Sutter
- [conntrack-tools PATCH v2 1/2] .gitignore: add nano swap file,
Arturo Borrero Gonzalez
- [conntrack-tools PATCH 1/2] .gitignore: add nano swap file,
Arturo Borrero Gonzalez
- [PATCH nft] src: report EPERM for non-root users,
Pablo Neira Ayuso
- [PATCH nft] mnl: reply netlink error message might be larger than MNL_SOCKET_BUFFER_SIZE, Pablo Neira Ayuso
- [iptables PATCH v3] extensions: dccp: Fix for DCCP type 'INVALID', Phil Sutter
- [nft PATCH] json: Fix seqnum_to_json() functionality,
Phil Sutter
- [nft PATCH] doc: Document 'dccp type' match, Phil Sutter
- [iptables PATCH v2] extensions: dccp: Fix for DCCP type 'INVALID', Phil Sutter
- [PATCH nft] parser_bison: allow to restore limit from dynamic set, Pablo Neira Ayuso
- [iptables PATCH] extensions: dccp: Fix translation of --dccp-type, Phil Sutter
- System crash on Ubuntu 18, in netlink code when using iptables / netfilter,
Yuri Lipnesh
- [PATCH libnetfilter_conntrack 1/2] build: use the right automake variables,
Jan Engelhardt
- [PATCH libnetfilter_queue 1/2] build: choose right automake variables,
Jan Engelhardt
- [PATCH libnetfilter_log] build: choose right automake variables,
Jan Engelhardt
- [PATCH libnetfilter_log 0/2] build: a couple of `-lnfnetlink` fixes.,
Jeremy Sowden
- WARNING: suspicious RCU usage in get_counters, syzbot
- [FYI] summary of Netfilter workshop 2020 virtual, Arturo Borrero Gonzalez
- [PATCH] netfilter: remove trailing semicolon in macro definition, trix
- [PATCH libftnl,RFC] src: add infrastructure to infer byteorder from keys,
Pablo Neira Ayuso
- [HEADS UP] Rebasing nf tree, Pablo Neira Ayuso
- [PATCH nf v2] netfilter: x_tables: Switch synchronization to RCU,
Subash Abhinov Kasiviswanathan
- XFRM interface and NF_INET_LOCAL_OUT hook,
Phil Sutter
- [PATCH net v3] ipvs: fix possible memory leak in ip_vs_control_net_init,
Wang Hai
- [PATCH net-next] netfilter: bridge: reset skb->pkt_type after NF_INET_POST_ROUTING traversal,
Antoine Tenart
- [PATCH nf] netfilter: x_tables: Switch synchronization to RCU,
Subash Abhinov Kasiviswanathan
- [PATCH xtables-addons 0/4] geoip: script fixes,
Jeremy Sowden
- [RFC] MAINTAINERS tag for cleanup robot,
trix
- [PATCH net 0/4] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 2/4] netfilter: nftables_offload: build mask based from the matching bytes, Pablo Neira Ayuso
- [PATCH net 1/4] netfilter: nftables_offload: set address type in control dissector, Pablo Neira Ayuso
- [PATCH net 4/4] netfilter: nf_tables: avoid false-postive lockdep splat, Pablo Neira Ayuso
- [PATCH net 3/4] netfilter: ipset: prevent uninit-value in hash_ip6_add, Pablo Neira Ayuso
- <Possible follow-ups>
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/4] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH] netfilter: use actual socket sk for REJECT action,
Jan Engelhardt
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]