Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [PATCH net-next,v3 0/9] netfilter: flowtable bridge and vlan enhancements, (continued)
- [PATCH net v4] ipv6/netfilter: Discard first fragment not including all headers,
Georg Kohmann
- [iptables PATCH] tests/shell: Add test for bitwise avoidance fixes, Phil Sutter
- [nft PATCH] proto: Fix ARP header field ordering, Phil Sutter
- Re: [PATCH v22 06/23] LSM: Use lsmblob in security_secid_to_secctx, James Morris
- Re: [PATCH v22 05/23] LSM: Use lsmblob in security_secctx_to_secid, James Morris
- Re: [net-next] netfiler: conntrack: Add the option to set ct tcp flag - BE_LIBERAL per-ct basis.,
Jakub Kicinski
- [PATCH v2 0/4] conntrack: accept commands from file + tests,
Mikhail Sennikovsky
- [PATCH] tests: py: remove duplicate payloads.,
Jeremy Sowden
- [PATCH net v3] ipv6/netfilter: Discard first fragment not including all headers,
Georg Kohmann
- [PATCH] MAINTAINERS: rectify file patterns for NETFILTER,
Lukas Bulwahn
- [PATCH] netfilter: conntrack: fix -Wformat,
Nick Desaulniers
- [PATCH] netfilter: nf_nat: Support fullcone NAT,
Paul Menzel
- [PATCH net v2] ipv6/netfilter: Discard first fragment not including all headers,
Georg Kohmann
- [PATCH] netfilter: remove unused macro DUMP_INIT to tame gcc, Alex Shi
- [PATCH] netfilter: Remove unnecessary conversion to bool,
xiakaixu1987
- [PATCH net] vrf: Fix fast path output packet handling with async Netfilter rules,
Martin Willi
- [PATCH nft 0/7] rework tcp option handling,
Florian Westphal
- [PATCH v22 16/23] LSM: security_secid_to_secctx in netlink netfilter,
Casey Schaufler
- [PATCH net-next 0/8] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 3/8] netfilter: nft_reject: add reject verdict support for netdev, Pablo Neira Ayuso
- [PATCH net-next 7/8] netfilter: nftables: Add __printf() attribute, Pablo Neira Ayuso
- [PATCH net-next 4/8] netfilter: ipset: Support the -exist flag with the destroy command, Pablo Neira Ayuso
- [PATCH net-next 5/8] netfilter: ipset: Add bucketsize parameter to all hash types, Pablo Neira Ayuso
- [PATCH net-next 8/8] netfilter: nft_reject_inet: allow to use reject from inet ingress, Pablo Neira Ayuso
- [PATCH net-next 6/8] netfilter: ipset: Expose the initval hash parameter to userspace, Pablo Neira Ayuso
- [PATCH net-next 1/8] netfilter: nf_reject: add reject skbuff creation helpers, Pablo Neira Ayuso
- [PATCH net-next 2/8] netfilter: nft_reject: unify reject init and dump into nft_reject, Pablo Neira Ayuso
- Re: [PATCH net-next 0/8] Netfilter updates for net-next, Jakub Kicinski
- <Possible follow-ups>
- [PATCH net-next 0/8] Netfilter updates for net-next, Pablo Neira Ayuso
- [PATCH net-next 0/8] Netfilter updates for net-next, Pablo Neira Ayuso
- [PATCH net] ipv6/netfilter: Discard first fragment not including all headers,
Georg Kohmann
- [PATCH nf 0/2] fixes for nftables offload,
Pablo Neira Ayuso
- [PATCH nft 0/3] json: resolve multiple test case failures,
Florian Westphal
- [PATCH conntrack] conntrack: do not allow to update offload status bits,
Pablo Neira Ayuso
- ipset 7.7 modules fail to build on kernel 4.19.152,
Oskar Berggren
- [PATCH] doc: correct chain name in example of adding a rule.,
Jeremy Sowden
- [PATCH nf-next,v2] netfilter: nft_reject_inet: allow to use reject from inet ingress,
Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH net 1/5] netfilter: nftables: fix netlink report logic in flowtable and genid, Pablo Neira Ayuso
- [PATCH net 2/5] wireguard: selftests: check that route_me_harder packets use the right sk, Pablo Neira Ayuso
- [PATCH net 3/5] netfilter: use actual socket sk rather than skb sk when routing harder, Pablo Neira Ayuso
- [PATCH net 5/5] netfilter: ipset: Update byte and packet counters regardless of whether they match, Pablo Neira Ayuso
- [PATCH net 4/5] netfilter: nf_tables: missing validation from the abort path, Pablo Neira Ayuso
- Re: [PATCH net 0/5] Netfilter fixes for net, Jakub Kicinski
- <Possible follow-ups>
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH net 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [ANNOUNCE] iptables 1.8.6 release, Phil Sutter
- [PATCH nf-next] netfilter: nft_reject_inet: allow to use reject from inet ingress, Pablo Neira Ayuso
- [PATCH RFC] ipvs: add genetlink cmd to dump all services and destinations,
Cezar Sa Espinola
- [PATCH nft] tests: shell: exercise validate with nft -c, Pablo Neira Ayuso
- Re: [PATCH] raw2packet: fix comma instead of semicolon, Pablo Neira Ayuso
- [iptables PATCH v2 1/2] nft: Optimize class-based IP prefix matches,
Phil Sutter
- [PATCH nf] netfilter: nf_tables: missing validation from the abort path, Pablo Neira Ayuso
- [nft PATCH] tests/shell: Improve fix in sets/0036add_set_element_expiration_0, Phil Sutter
- [PATCH v2 0/2] conntrack: save output format,
Mikhail Sennikovsky
- [PATCH libnetfilter_conntrack] conntrack: add flush filter command,
Pablo Neira Ayuso
- [PATCH conntrack-tools] conntrack: allow to flush per family, Pablo Neira Ayuso
- [PATCH nf 0/2] route_me_harder routing loop with tunnels,
Jason A. Donenfeld
- [nft PATCH] tests/shell: Restore testcases/sets/0036add_set_element_expiration_0,
Phil Sutter
- [PATCH conntrack] conntrack: allow to filter event by family,
Pablo Neira Ayuso
- [nft PATCH 0/2] src: Optimize prefix matches on byte-boundaries,
Phil Sutter
- [PATCH conntrack] conntrack: default to unspec family for dualstack setups, Pablo Neira Ayuso
- [ANNOUNCE] nftables 0.9.7 release, Pablo Neira Ayuso
- [ANNOUNCE] libnftnl 1.1.8 release, Pablo Neira Ayuso
- [UPDATES] Renewing Netfilter coreteam PGP keys, Pablo Neira Ayuso
- [iptables PATCH] tests: shell: Improve concurrent noflush restore test a bit, Phil Sutter
- Re: [PATCH v3 1/1] uapi: Move constants from <linux/kernel.h> to <linux/const.h>, Petr Vorel
- [PATCH xtables-addons] pnock: pknlusr: mention the group ID command-line paramater in the man-page.,
Jeremy Sowden
- [PATCH xtables-addons v2 00/13] pknlusr improvements,
Jeremy Sowden
- [PATCH xtables-addons v2 01/13] pknock: pknlusr: ensure man-page is included by `make dist`., Jeremy Sowden
- [PATCH xtables-addons v2 00/13] pknlusr improvements, Jeremy Sowden
- [PATCH xtables-addons v2 04/13] pknock: pknlusr: tidy up initialization of local address., Jeremy Sowden
- [PATCH xtables-addons v2 06/13] pknock: pknlusr: use macro to define inet_ntop buffer size., Jeremy Sowden
- [PATCH xtables-addons v2 05/13] pknock: pknlusr: use NLMSG macros and proper types, rather than arithmetic on char pointers., Jeremy Sowden
- [PATCH xtables-addons v2 07/13] pknock: pknlusr: don't treat recv return value of zero as an error., Jeremy Sowden
- [PATCH xtables-addons v2 08/13] pknock: pknlusr: always close socket., Jeremy Sowden
- [PATCH xtables-addons v2 03/13] pknock: pknlusr: tighten up variable scopes., Jeremy Sowden
- [PATCH xtables-addons v2 02/13] pknock: pknlusr: remove dest_addr and rename src_addr., Jeremy Sowden
- [PATCH xtables-addons v2 12/13] pknock: xt_pknock: use `pr_err`., Jeremy Sowden
- [PATCH xtables-addons v2 13/13] pknock: xt_pknock: remove DEBUG definition and disable debug output., Jeremy Sowden
- [PATCH xtables-addons v2 11/13] pknock: xt_pknock: use kzalloc., Jeremy Sowden
- [PATCH xtables-addons v2 10/13] pknock: xt_pknock: use IS_ENABLED., Jeremy Sowden
- [PATCH xtables-addons v2 09/13] pknock: pknlusr: fix hard-coded netlink multicast group ID., Jeremy Sowden
- Re: [PATCH xtables-addons v2 00/13] pknlusr improvements, Jan Engelhardt
- [PATCH nft] Revert "monitor: do not print generation ID with --echo", Pablo Neira Ayuso
- [PATCH nf] netfilter: nftables: fix netlink report logic in flowtable and genid, Pablo Neira Ayuso
- [PATCH 0/5] add support for reject verdict in netdev,
Jose M. Guisado Gomez
- [PATCH xtables-addons 0/3] pknlusr improvements,
Jeremy Sowden
- [PATCH nf,v3] netfilter: nf_fwd_netdev: clear timestamp in forwarding path, Pablo Neira Ayuso
- [PATCH nf,v2] netfilter: nf_dup_netdev: clear timestamp in forwarding path, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_dup_netdev: clear timestamp in forwarding path, Pablo Neira Ayuso
- [PATCH nft] monitor: do not print generation ID with --echo, Pablo Neira Ayuso
- Network namespace, ipvlan and IPVS source NAT,
Damien Claisse
- [PATCH linux-5.9 1/1] net: netfilter: fix KASAN: slab-out-of-bounds Read in nft_flow_rule_create,
saeed . mirzamohammadi
- [PATCH nft 1/2] rule: larger number of error locations,
Pablo Neira Ayuso
- [PATCH libnftnl] expr: add nftnl_rule_del_expr(), Pablo Neira Ayuso
- [PATCH] conntrack: fix zone sync issue,
yang_y_yi
- [PATCH AUTOSEL 5.8 086/101] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH AUTOSEL 5.4 69/80] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH AUTOSEL 4.19 50/56] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH AUTOSEL 4.14 46/52] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH AUTOSEL 4.4 29/33] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH AUTOSEL 4.9 37/41] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH AUTOSEL 5.9 092/111] ipvs: Fix uninit-value in do_ip_vs_set_ctl(), Sasha Levin
- [PATCH] docs: nf_flowtable: fix typo.,
Jeremy Sowden
- [PATCH libnfnl] expr: expose nftnl_expr_build_payload(), Pablo Neira Ayuso
- [bugreport] [5.10] warning at net/netfilter/nf_tables_api.c:622,
Mikhail Gavrilov
- [nft] Bug 1444 - Segfault, Gopal Yadav
- Re: bpf-next test error: BUG: program execution failed: executor 0: exit status 67,
Dmitry Vyukov
- [PATCH net-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements,
Pablo Neira Ayuso
- [PATCH net-next,v2 0/9] netfilter: flowtable bridge and vlan enhancements,
Pablo Neira Ayuso
- [PATCH net-next,v2 1/9] netfilter: flowtable: add xmit path types, Pablo Neira Ayuso
- [PATCH net-next,v2 3/9] net: 8021q: resolve forwarding path for vlan devices, Pablo Neira Ayuso
- [PATCH net-next,v2 2/9] net: resolve forwarding path from virtual netdevice and HW destination address, Pablo Neira Ayuso
- [PATCH net-next,v2 4/9] bridge: resolve forwarding path for bridge devices, Pablo Neira Ayuso
- [PATCH net-next,v2 8/9] netfilter: flowtable: bridge port support, Pablo Neira Ayuso
- [PATCH net-next,v2 9/9] netfilter: flowtable: add vlan support, Pablo Neira Ayuso
- [PATCH net-next,v2 5/9] netfilter: flowtable: use dev_fill_forward_path() to obtain ingress device, Pablo Neira Ayuso
- [PATCH net-next,v2 6/9] netfilter: flowtable: use dev_fill_forward_path() to obtain egress device, Pablo Neira Ayuso
- [PATCH net-next,v2 7/9] netfilter: flowtable: add direct xmit path, Pablo Neira Ayuso
- Re: [PATCH net-next,v2 0/9] netfilter: flowtable bridge and vlan enhancements, Jakub Kicinski
- [PATCH nf-next] netfilter: nftables: allow re-computing sctp CRC-32C in 'payload' statements,
Florian Westphal
- [PATCH nft] segtree: copy expr data to closing element, Florian Westphal
- [PATCH] netfilter: conntrack: Fix kmemleak false positive reports,
Kavana Ravindra
- [PATCH net-next 0/9] netfilter: flowtable bridge and vlan enhancements,
Pablo Neira Ayuso
- [PATCH net-next] netfilter: restore NF_INET_NUMHOOKS,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: restore NF_INET_NUMHOOKS,
Pablo Neira Ayuso
- iptables userspace API broken due to added value in nf_inet_hooks,
Jason A. Donenfeld
- [PATCH] Fixes dropping of small packets in bridge nat,
timothee.cocault
- selftests: netfilter: nft_nat.sh: /dev/stdin:2:9-15: Error: syntax error, unexpected counter,
Naresh Kamboju
- Bug: ebtables snat drops small packets,
timothee.cocault
- WARNING: at net/netfilter/nf_tables_api.c:622 lockdep_nfnl_nft_mutex_not_held+0x28/0x38 [nf_tables],
Naresh Kamboju
- [PATCH net V2] netfilter: Drop fragmented ndisc packets assembled in netfilter,
Georg Kohmann
- [PATCH nft] src: ingress inet support,
Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_log: missing vlan offload tag and proto,
Pablo Neira Ayuso
- [PATCH v21 16/23] LSM: security_secid_to_secctx in netlink netfilter, Casey Schaufler
- Re: [PATCH net] netfilter: Drop fragmented ndisc packets assembled in netfilter,
Pablo Neira Ayuso
- [PATCH 0/6] Netfilter/IPVS updates for net-next,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: flowtable: reduce calls to pskb_may_pull(), Pablo Neira Ayuso
- [PATCH nft 0/3] tests: py: fixes for failing JSON tests,
Jeremy Sowden
- [ulogd2] Problem while running, Amiq Nahas
- [PATCH net] ipvs: clear skb->tstamp in forwarding path,
Julian Anastasov
- 0x14: Videos posted, Jamal Hadi Salim
- [PATCH nf v2] selftests: netfilter: extend nfqueue test case,
Florian Westphal
- [PATCH] netfilter: nf_conntrack_sip: Fix inconsistent of format with argument type in nf_nat_sip.,
Ye Bin
- [nft PATCH] json: Fix memleak in set_dtype_json(),
Phil Sutter
- [PATCH nf] selftests: netfilter: extend nfqueue test case,
Florian Westphal
- [iptables PATCH] libiptc: Avoid gcc-10 zero-length array warning,
Phil Sutter
- [PATCH nf-next 0/4] Add nf_tables ingress hook for the inet family,
Pablo Neira Ayuso
- [PATCH nf v2] netfilter: conntrack: connection timeout after re-register,
Francesco Ruggeri
- [PATCH v2] Solves Bug 1462 - `nft -j list set` does not show counters,
Gopal Yadav
- [iptables PATCH] extensions: libipt_icmp: Fix translation of type 'any',
Phil Sutter
- [PATCH] Solves Bug 1462 - `nft -j list set` does not show counters, Gopal Yadav
- Re: WARNING in ieee80211_check_rate_mask, syzbot
- INFO: task hung in hub_port_init,
syzbot
- INFO: task hung in usb_get_descriptor,
syzbot
- [PATCH nf] netfilter: conntrack: connection timeout after re-register, Francesco Ruggeri
- [PATCH v8 net-next] ipvs: inspect reply packets from DR/TUN real servers,
Julian Anastasov
- [iptables PATCH 0/3] nft: Fix transaction refreshing,
Phil Sutter
- [PATCH 00/11] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH 03/11] ipvs: Remove unused macros, Pablo Neira Ayuso
- [PATCH 04/11] netfilter: nf_tables: fix userdata memleak, Pablo Neira Ayuso
- [PATCH 07/11] netfilter: nf_tables_offload: Remove unused macro FLOW_SETUP_BLOCK, Pablo Neira Ayuso
- [PATCH 08/11] netfilter: ipset: enable memory accounting for ipset allocations, Pablo Neira Ayuso
- [PATCH 06/11] netfilter: nf_tables: add userdata attributes to nft_chain, Pablo Neira Ayuso
- [PATCH 05/11] netfilter: nf_tables: use nla_memdup to copy udata, Pablo Neira Ayuso
- [PATCH 01/11] netfilter: conntrack: proc: rename stat column, Pablo Neira Ayuso
- [PATCH 02/11] netfilter: nf_tables: Remove ununsed function nft_data_debug, Pablo Neira Ayuso
- [PATCH 11/11] netfilter: nf_tables: Implement fast bitwise expression, Pablo Neira Ayuso
- [PATCH 09/11] netfilter: nfnetlink: place subsys mutexes in distinct lockdep classes, Pablo Neira Ayuso
- [PATCH 10/11] netfilter: nf_tables: Enable fast nft_cmp for inverted matches, Pablo Neira Ayuso
- Re: [PATCH 00/11] Netfilter updates for net-next, David Miller
- [PATCH 1/1] Solves Bug 1462 - `nft -j list set` does not show counters,
Gopal Yadav
- [PATCH nf-next] netfilter: nfnetlink: place subsys mutexes in distinct lockdep classes,
Florian Westphal
- [iptables PATCH] iptables-nft: fix basechain policy configuration,
Arturo Borrero Gonzalez
- [iptables PATCH] nft: Optimize class-based IP prefix matches,
Phil Sutter
- [net-next PATCH 0/2] netfilter: Improve inverted IP prefix matches,
Phil Sutter
- [PATCH] nft: migrate man page examples with `meter` directive to sets,
Devin Bayer
- iptables-nft-restore issue,
Arturo Borrero Gonzalez
- [PATCH libnetfilter_queue] doc: build: Reduce size of doxygen.cfg and doxygen build o/p, Duncan Roe
- [PATCH libnetfilter_queue] src: doc: Fix doxygen warning, Duncan Roe
- nftables bug?? Maybe, Evgeniy Yakubov
- [PATCH] ipvs: Add traffic statistic up even it is VS/DR or VS/TUN mode,
longguang.yue
- Re: general protection fault in strncasecmp, syzbot
- [iptables PATCH] nft: Fix for broken address mask match detection,
Phil Sutter
- [PATCH v4 nf-next] netfilter: nf_tables: add userdata attributes to nft_chain,
Jose M. Guisado Gomez
- [PATCH nf-next] netfilter: nf_tables: use nla_memdup to copy udata,
Jose M. Guisado Gomez
- KASAN: use-after-free Read in tcf_action_init,
syzbot
- [nftables] counter not working on kernel 5.6,
Gopal Yadav
- [PATCH v4] ipvs: adjust the debug info in function set_tcp_state,
longguang.yue
- [PATCH nf-next] netfilter: nf_tables: fix userdata memleak,
Jose M. Guisado Gomez
- BUG: unable to handle kernel paging request in dqput,
syzbot
- [PATCH 0/8] Fast bulk transfers of large sets of ct entries,
Mikhail Sennikovsky
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]