Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- [PATCH 03/12] nft: allow stacking vlan header on top of ethernet, (continued)
- [PATCH 03/12] nft: allow stacking vlan header on top of ethernet, Florian Westphal
- [PATCH 06/12] src: netlink: don't truncate set key lengths, Florian Westphal
- [PATCH 07/12] nft: fill in doff and fix ihl/version template entries, Florian Westphal
- [PATCH 10/12] nft: support listing expressions that use non-byte header fields, Florian Westphal
- [PATCH 12/13] vlan: make != tests work, Florian Westphal
- [PATCH 11/12] tests: vlan tests, Florian Westphal
- [PATCH 08/12] netlink: cmp: shift rhs constant if lhs offset doesn't start on byte boundary, Florian Westphal
- [PATCH 09/12] tests: add tests for ip version/hdrlength/tcp doff, Florian Westphal
- [PATCH 05/12] src: netlink_linearize: handle sub-byte lengths, Florian Westphal
- [PATCH 04/12] payload: disable payload merge if offsets are not on byte boundary, Florian Westphal
- Re: [PATCH nft 0/12] add support for VLAN header filtering in bridge family, Florian Westphal
- Re: [PATCH nft 0/12] add support for VLAN header filtering in bridge family, Florian Westphal
- [PATCH] configure: fix 3rd arg w/AC_ARG_ENABLE,
Mike Frysinger
- [PATCH nf-next v5 0/2] Netfilter zone directions,
Daniel Borkmann
- ipset triggering kasan warnings.,
Dave Jones
- nftables: precondition validation fails on map construct,
Andreas Schultz
- [PATCH] netfilter: Remove the duplicated word "see" in the comment when set the IPS_ASSURED_BIT in tcp_packet,
Feng Gao
- [PATCHv4 nf-next] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n,
Bernhard Thaler
- [PATCH nft 1/2] evaluate: display error on unexisting chain when listing,
Pablo Neira Ayuso
- [PATCH] netfilter: nf_tables: Use 32 bit addressing register from nft_type_to_reg(), Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH 1/5] netfilter: nf_conntrack: silence warning on falling back to vmalloc(), Pablo Neira Ayuso
- [PATCH 2/5] netfilter: nf_conntrack: checking for IS_ERR() instead of NULL, Pablo Neira Ayuso
- [PATCH 3/5] netfilter: conntrack: Use flags in nf_ct_tmpl_alloc(), Pablo Neira Ayuso
- [PATCH 4/5] netfilter: ip6t_SYNPROXY: fix NULL pointer dereference, Pablo Neira Ayuso
- [PATCH 5/5] netfilter: SYNPROXY: fix sending window update to client, Pablo Neira Ayuso
- Re: [PATCH 0/5] Netfilter fixes for net, David Miller
- <Possible follow-ups>
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- Re: IPv6 and private net with masquerading not working correctly,
Cong Wang
- nft: parser problem, can use mark as datatype in sets and maps,
Andreas Schultz
- [PATCH nft v5 00/14] cache consolidation,
Pablo Neira Ayuso
- [PATCH nft v5 01/14] src: add cache infrastructure and use it for table objects, Pablo Neira Ayuso
- [PATCH nft v5 03/14] rule: add reference counter to the table object, Pablo Neira Ayuso
- [PATCH nft v5 04/14] src: add table declaration to cache, Pablo Neira Ayuso
- [PATCH nft v5 02/14] src: add cmd_evaluate_list(), Pablo Neira Ayuso
- [PATCH nft v5 05/14] src: use cache infrastructure for set objects, Pablo Neira Ayuso
- [PATCH nft v5 06/14] src: add set declaration to cache, Pablo Neira Ayuso
- [PATCH nft v5 07/14] src: early allocation of the set ID, Pablo Neira Ayuso
- [PATCH nft v5 09/14] src: use cache infrastructure for chain objects, Pablo Neira Ayuso
- [PATCH nft v5 10/14] evaluate: add cmd_evaluate_rename(), Pablo Neira Ayuso
- [PATCH nft v5 08/14] rule: add chain reference counter, Pablo Neira Ayuso
- [PATCH nft v5 12/14] src: use cache infrastructure for rule objects, Pablo Neira Ayuso
- [PATCH nft v5 11/14] src: add chain declarations to cache, Pablo Neira Ayuso
- [PATCH nft v5 13/14] src: use cache infrastructure for set element objects, Pablo Neira Ayuso
- [PATCH nft v5 14/14] src: get rid of EINTR handling for nft_netlink(), Pablo Neira Ayuso
- [lnf-log RFC PATCH 0/2] introduce new functions to use without nflog_handle,
Ken-ichirou MATSUZAWA
- [lnf-log PATCH] build: fix typo,
Ken-ichirou MATSUZAWA
- [PATCH nf-next v4 0/3] Netfilter zone directions,
Daniel Borkmann
- [PATCH] netfilter: per network namespace nfacct,
Andreas Schultz
- [PATCH nf-next 1/6] netfilter: nft_limit: rename to nft_limit_pkts,
Pablo Neira Ayuso
- [PATCH libnftnl] src: fix memory leaks at nft_[object]_nlmsg_parse,
Carlos Falgueras García
- [PATCH net] netfilter: conntrack: Use flags in nf_ct_tmpl_alloc(),
Joe Stringer
- Re: [PATCH] netfilter: ipt_SYNPROXY: fix sending window update to client,
Pablo Neira Ayuso
- IPv6 support for GRE helper(nf_conntrack_proto_gre),
Aju L Francis
- nfacct is not namespace aware,
Andreas Schultz
- [PATCH nf-next 1/3] netfilter: xt_TEE: get rid of WITH_CONNTRACK definition,
Pablo Neira Ayuso
- [PATCH nf-next 1/3] netfilter: nf_tables: add generation mask to table objects,
Pablo Neira Ayuso
- [PATCH nft] src: restore nft list tables, Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nft_counter: convert it to use per-cpu counters, Pablo Neira Ayuso
- Multiple DSCP match by "-m dscp --dscp-multi value,value,...", Kyeong Yoo
- New multiple DSCP match by "-m dscp --dscp-multi value,value,...",
Kyeong Yoo
- [PATCH nf-next] netfilter: connlabels: Export setting connlabel length,
Joe Stringer
- [IPTABLES] Module ipt_same,
Alex william
- [PATCH nf-next] netfilter: ip6t_REJECT: Remove debug messages from reject_tg6(),
subashab
- IP sets: Suggestion: additional value match,
Rudolf_AT
- [PATCH nf-next] netfilter: ip6t_REJECT: Log reject reason in reject_tg6(),
subashab
- [PATCHv3 2/2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n,
Bernhard Thaler
- [PATCH 1/2 nf] netfilter: bridge: do not initialize statics to 0 or NULL,
Bernhard Thaler
- [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL,
Dan Carpenter
- [PATCH] netfilter: xtables: Add helper macro for xt_match boilerplate,
Vaishali Thakkar
- IPv4 IPv6 parallel dns lookup in combination with nfqueue is problematic,
Tarik Demirci
- [PATCH nf-next] netfilter: bridge: reduce nf_bridge_info to 32 bytes again,
Florian Westphal
- [PATCH nf] netfilter: nf_conntrack: silence warning on falling back to vmalloc(), Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nf_queue: fix nf_queue_nf_hook_drop(),
Pablo Neira Ayuso
- [PATCH 00/10] Netfilter/IPVS fixes for net,
Pablo Neira Ayuso
- [PATCH 04/10] ipvs: do not use random local source address for tunnels, Pablo Neira Ayuso
- [PATCH 10/10] netfilter: nf_conntrack: Support expectations in different zones, Pablo Neira Ayuso
- [PATCH 09/10] netfilter: fix netns dependencies with conntrack templates, Pablo Neira Ayuso
- [PATCH 07/10] ipvs: fix crash with sync protocol v0 and FTP, Pablo Neira Ayuso
- [PATCH 08/10] ipvs: call skb_sender_cpu_clear, Pablo Neira Ayuso
- [PATCH 06/10] ipvs: skb_orphan in case of forwarding, Pablo Neira Ayuso
- [PATCH 05/10] ipvs: fix crash if scheduler is changed, Pablo Neira Ayuso
- [PATCH 03/10] ipvs: fix ipv6 route unreach panic, Pablo Neira Ayuso
- [PATCH 02/10] netfilter: IDLETIMER: fix lockdep warning, Pablo Neira Ayuso
- [PATCH 01/10] netfilter: ctnetlink: put back references to master ct and expect objects, Pablo Neira Ayuso
- Re: [PATCH 00/10] Netfilter/IPVS fixes for net, David Miller
- <Possible follow-ups>
- [PATCH 00/10] Netfilter/IPVS fixes for net, Pablo Neira Ayuso
- [PATCH 04/10] ipvs: do not schedule icmp errors from tunnels, Pablo Neira Ayuso
- [PATCH 05/10] netfilter: ctnetlink: don't use conntrack/expect object addresses as id, Pablo Neira Ayuso
- [PATCH 02/10] netfilter: conntrack: don't set related state for different outer address, Pablo Neira Ayuso
- [PATCH 10/10] netfilter: fix nf_l4proto_log_invalid to log invalid packets, Pablo Neira Ayuso
- [PATCH 06/10] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook(), Pablo Neira Ayuso
- [PATCH 09/10] netfilter: never get/set skb->tstamp, Pablo Neira Ayuso
- [PATCH 07/10] netfilter: nat: fix icmp id randomization, Pablo Neira Ayuso
- [PATCH 03/10] netfilter: conntrack: initialize ct->timeout, Pablo Neira Ayuso
- [PATCH 01/10] selftests: netfilter: check icmp pkttoobig errors are set as related, Pablo Neira Ayuso
- [PATCH 08/10] netfilter: ebtables: CONFIG_COMPAT: drop a bogus WARN_ON, Pablo Neira Ayuso
- Re: [PATCH 00/10] Netfilter/IPVS fixes for net, David Miller
- [PATCH nf-next v3 0/3] Netfilter zone directions,
Daniel Borkmann
- ip(6)tables-restore segfault + patch, Felix Bolte
- [PATCH nf] netfilter: Support expectations in different zones,
Joe Stringer
- [RFC PATCH 0/5] netlink: mmap kernel panic and some issues,
Ken-ichirou MATSUZAWA
- [IPTABLES 0/2] iptables-compat fixes,
Thomas Woerner
- [PATCH nf-next 1/2] netfilter: fix possible removal of wrong hook,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nf_queue: fix deadlock in nf_queue_nf_hook_drop(),
Pablo Neira Ayuso
- [PATCH] Fix grammar error in manpage,
Neutron Soutmun
- [PATCH nf] netfilter: nf_conntrack: silent warning when adding extensions to templates,
Pablo Neira Ayuso
- Re: [PATCH] netfilter: Fix memory leak in nf_register_net_hook, Pablo Neira Ayuso
- [netfilter] INFO: task kworker/u2:0:6 blocked for more than 120 seconds., Fengguang Wu
- [PATCHv2 net-next] net: #ifdefify sk_classid member of struct sock,
Mathias Krause
- [PATCH net-next] net: #ifdefify sk_classid member of struct sock,
Mathias Krause
- [PATCH nf-next v2] netfilter: nf_ct_sctp: minimal multihoming support,
Michal Kubecek
- nf_conntrack: falling back to vmalloc.,
Toralf Förster
- [PATCH nft] tests: validate generated netlink instructions,
Florian Westphal
- [PATCH iptables] fix wrong headername in ipv6header for protocols,
Andreas Herz
- nft: meta l4proto range printing broken on 32bit,
Florian Westphal
- [PATCH nf 0/6] IPVS Fixes for v4.2,
Simon Horman
- [PATCH nf,v2] netfilter: fix netns dependencies with conntrack templates,
Pablo Neira Ayuso
- iptables: AH/ESP init fix, and a build fix,
Jan Engelhardt
- [Q] iptables AH module api mismatch between -master and 1.4.7,
Cyrill Gorcunov
- [PATCH -next v2 0/6] netfilter: xtables: improve jumpstack handling,
Florian Westphal
- [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support,
Michal Kubecek
- [PATCH iptables] extensions: libxt_socket: update man pages and tests for --restore-skmark,
Harout Hedeshian
- [PATCH nf RFC] netfilter: fix netns dependencies with conntrack templates,
Pablo Neira Ayuso
- [PATCH nf-next v2 0/3] Netfilter zone directions,
Daniel Borkmann
- [PATCH iptables] libxt_CT: add support for recently introduced zone options,
Daniel Borkmann
- [GIT PULL nf-next] IPVS for v4.3,
Simon Horman
- [PATCH] nf: IDLETIMER: fix lockdep warning,
Dmitry Torokhov
- [PATCH nf] netfilter: ctnetlink: put back references to master ct and expect objects, Pablo Neira Ayuso
- [PATCH COLO-Frame v7 00/34] COarse-grain LOck-stepping(COLO) Virtual Machines for Non-stop Service (FT), zhanghailiang
- [PATCH] netfilter: nf_nat: Fix possible null dereference,
subashab
- [PATCH -next 0/4] netfilter: xtables: improve jumpstack handling,
Florian Westphal
- [PATCH 1/3 nft] src: get rid of EINTR handling in nft_netlink(),
Pablo Neira Ayuso
- [PATCH v2] net/bridge: Use __in6_dev_get rather than in6_dev_get in br_validate_ipv6,
Julien Grall
- [PATCH lnf-ct] conntrack: fix stop timestamp assignment,
Ken-ichirou MATSUZAWA
- [PATCH nf] MAINTAINER: add bridge netfilter, Pablo Neira Ayuso
- [PATCH nft,v4 00/16] cache consolidation,
Pablo Neira Ayuso
- [PATCH nft,v4 02/16] src: add cmd_evaluate_list(), Pablo Neira Ayuso
- [PATCH nft,v4 03/16] rule: add reference counter to the table object, Pablo Neira Ayuso
- [PATCH nft,v4 01/16] src: consolidate table cache, Pablo Neira Ayuso
- [PATCH nft,v4 04/16] src: add table declaration to cache, Pablo Neira Ayuso
- [PATCH nft,v4 07/16] src: early allocation of the set ID, Pablo Neira Ayuso
- [PATCH nft,v4 05/16] src: consolidate set cache, Pablo Neira Ayuso
- [PATCH nft,v4 08/16] segtree: pass element expression as parameter to set_to_intervals(), Pablo Neira Ayuso
- [PATCH nft,v4 09/16] rule: use netlink_add_setelems() when creating literal sets, Pablo Neira Ayuso
- [PATCH nft,v4 11/16] rule: add chain reference counter, Pablo Neira Ayuso
- [PATCH nft,v4 10/16] rule: fix use of intervals in set declarations, Pablo Neira Ayuso
- [PATCH nft,v4 06/16] src: add set declaration to cache, Pablo Neira Ayuso
- [PATCH nft,v4 12/16] src: consolidate chain cache, Pablo Neira Ayuso
- [PATCH nft,v4 13/16] evaluate: add cmd_evaluate_rename(), Pablo Neira Ayuso
- [PATCH nft,v4 14/16] src: add chain declarations to cache, Pablo Neira Ayuso
- [PATCH nft,v4 15/16] rule: consolidate rule cache, Pablo Neira Ayuso
- [PATCH nft,v4 16/16] src: consolidate set element cache, Pablo Neira Ayuso
- [PATCH nft 1/3] rule: missing family when listing of tables,
Pablo Neira Ayuso
- [RFC PATCH nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n,
Bernhard Thaler
- Linux 4.2 build error in net/netfilter/ipset/ip_set_hash_netnet.c,
Vinson Lee
[RFC PATCH v2] netfilter: nf_conntrack: fix endless loop on netns deletion, Daniel Borkmann
[PATCH v2] conntrack: made the protocol option value case insensitive, pfeiffer . szilard
[PATCH nft,v3 0/7] cache consolidation,
Pablo Neira Ayuso
- [PATCH nft,v3 1/7] src: consolidate table cache, Pablo Neira Ayuso
- [PATCH nft,v3 2/7] src: add table declaration to cache, Pablo Neira Ayuso
- [PATCH nft,v3 3/7] src: consolidate set cache, Pablo Neira Ayuso
- [PATCH nft,v3 4/7] src: early allocation of the set ID, Pablo Neira Ayuso
- [PATCH nft,v3 5/7] segtree: pass element expression as parameter to set_to_intervals(), Pablo Neira Ayuso
- [PATCH nft,v3 6/7] rule: use netlink_add_setelems() when creating literal sets, Pablo Neira Ayuso
- [PATCH nft,v3 7/7] rule: fix use of intervals in set declarations, Pablo Neira Ayuso
[Q RFC nft] how to add bridge vlan header match support?,
Florian Westphal
[PATCH nf] netfilter: nf_conntrack: fix endless loop on netns deletion,
Daniel Borkmann
[PATCH nf,v2] netfilter: nfnetlink: keep going batch handling on missing modules, Pablo Neira Ayuso
[PATCH nf] netfilter: bridge: don't leak skb in error paths,
Florian Westphal
[PATCH nf] netfilter: arptables: use percpu jumpstack,
Florian Westphal
Extending nftables user-space utility for custom filters, Juergen Brendel
[PATCH 0/7 nft] cache consolidation,
Pablo Neira Ayuso
IPSet target SET subnet options,
WaaX
nftables: parser conflict between tokens & symbols,
Balazs Scheidler
[PATCH] redir: fix snprintf to return the number of bytes printed,
balazs . scheidler
[nftables] payload: gen l4proto dependency on bridge, Eric Leblond
[PATCH nft] datatype: avoid crash in debug mode when printing integers,
Florian Westphal
[PATCH nft] payload: fix transport matching with no network layer info in bridge family,
Pablo Neira Ayuso
[PATCH 1/2 nf] netfilter: nft_queue: restrict queueing to supported families,
Pablo Neira Ayuso
[PATCH nf] netfilter: bridge: fix CONFIG_NF_DEFRAG_IPV4/6 related warnings/errors, Pablo Neira Ayuso
expectation entry creation with conntrack,
pfeiffer . szilard
[PATCH] conntrack: made the protocol option value case insensitive,
pfeiffer . szilard
[PATCH] conntrack: made the manual page and help consistent in case of proto option,
pfeiffer . szilard
[ANNOUNCE] ipset 6.25.1 released, Jozsef Kadlecsik
Re: net/netfilter/ipset: work around gcc-4.4.4 initializer bug (was: Re: linux-next: Tree for Jun 25),
Geert Uytterhoeven
[ulogd2 PATCHv3] Use stdint types everywhere, Felix Janda
merge window freeze, David Miller
[nftables 0/3] misc fixes,
Eric Leblond
[ulogd2 PATCHv2] Use stdint types everywhere,
Felix Janda
Kernel 4.1.0 broke the TARPIT & DELUGE targets in xtables-addons-2.6,
Alexander Petrenas
[PATCH net] netfilter: nf_queue: Don't recompute the hook_list head,
Eric W. Biederman
Re: [PATCH net] netfilter: nf_qeueue: Drop queue entries on nf_unregister_hook,
Eric W. Biederman
[PATCH net] netfilter: nftables: Do not run chains in the wrong network namespace,
Eric W. Biederman
[PATCH nft 1/3] rule: use netlink_add_setelems() when creating literal sets,
Pablo Neira Ayuso
[PATCH nf-next, v4] netfilter: nft_counter: convert it to use per-cpu counters,
Pablo Neira Ayuso
[PATCH nf-next, v3] netfilter: nft_counter: convert it to use per-cpu counters, Pablo Neira Ayuso
[PATCH nft] src: add tee statement,
Pablo Neira Ayuso
[PATCH libnftnl] expr: add new nft_tee expression, Pablo Neira Ayuso
[PATCH nf-next,v2] netfilter: nft_counter: convert it to use per-cpu counters,
Pablo Neira Ayuso
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]