Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [PATCH 1/1] solve musl build problem, (continued)
- broken packet passed into raw table by nf_defrag_ipv6, Andreas Herz
- [PATCH nf-next] netfilter: nf_conntrack: make nf_ct_zone_dflt built-in,
Daniel Borkmann
- [PATCH nf-next] netfilter: nf_dup{4,6}: fix build error when nf_conntrack disabled,
Daniel Borkmann
- [PATCH libnftnl 3/3] src: add compat header file definitions, Pablo Neira Ayuso
- [PATCH libnftnl 0/3] use nftnl_ prefix,
Pablo Neira Ayuso
- [PATCH nf] netfilter: conntrack: use nf_ct_tmpl_free in CT/synproxy error paths,
Daniel Borkmann
- [PATCH nf 1/1] nft: Fix nlmsg_type in GET operation callbacks,
Vijay Subramanian
- [ANNOUNCE] ipset 6.26 released, Jozsef Kadlecsik
- [PATCH 0/1] ipset patch for nf,
Jozsef Kadlecsik
- [PATCH -next] netfilter: nfnetlink: work around wrong endianess with old nft userspace,
Florian Westphal
- [PATCH -next] netfilter: reduce sparse warnings,
Florian Westphal
- nftables batch abi broken ...,
Florian Westphal
- [conntrackd] allowing DisableExternalCache in alarm mode,
Arturo Borrero Gonzalez
- [PATCH -next] Revert "netfilter: xtables: compute exact size needed for jumpstack",
Florian Westphal
- [PATCHv6 net-next 00/10] OVS conntrack support,
Joe Stringer
- [PATCHv6 net-next 10/10] openvswitch: Allow attaching helpers to ct action, Joe Stringer
- [PATCHv6 net-next 08/10] netfilter: connlabels: Export setting connlabel length, Joe Stringer
- [PATCHv6 net-next 09/10] openvswitch: Allow matching on conntrack label, Joe Stringer
- [PATCHv6 net-next 03/10] ipv6: Export nf_ct_frag6_gather(), Joe Stringer
- [PATCHv6 net-next 06/10] openvswitch: Allow matching on conntrack mark, Joe Stringer
- [PATCHv6 net-next 07/10] netfilter: Always export nf_connlabels_replace(), Joe Stringer
- [PATCHv6 net-next 04/10] dst: Add __skb_dst_copy() variation, Joe Stringer
- [PATCHv6 net-next 05/10] openvswitch: Add conntrack action, Joe Stringer
- [PATCHv6 net-next 02/10] openvswitch: Move MASKED* macros to datapath.h, Joe Stringer
- [PATCHv6 net-next 01/10] openvswitch: Serialize acts with original netlink len, Joe Stringer
- Re: [PATCHv6 net-next 00/10] OVS conntrack support, David Miller
- Re: [PATCHv6 net-next 00/10] OVS conntrack support, Simon Horman
- [conntrack-tools PATCH] tcp: use MSG_NOSIGNAL in sendto() to avoid SIGPIPE,
Arturo Borrero Gonzalez
- How to set connmark on a socket descriptor from userspace?,
David Hinkle
- WARNING at net/ipv4/netfilter/ip_tables.c:530,
Cong Wang
- [PATCH conntrack-tools] conntrack: add zone direction support,
Daniel Borkmann
- [PATCH libnetfilter_conntrack] conntrack: add zone attribute to tuple,
Daniel Borkmann
- [PATCHv5 net-next 00/10] OVS conntrack support,
Joe Stringer
- [PATCHv5 net-next 08/10] netfilter: connlabels: Export setting connlabel length, Joe Stringer
- [PATCHv5 net-next 07/10] netfilter: Always export nf_connlabels_replace(), Joe Stringer
- [PATCHv5 net-next 10/10] openvswitch: Allow attaching helpers to ct action, Joe Stringer
- [PATCHv5 net-next 05/10] openvswitch: Add conntrack action, Joe Stringer
- [PATCHv5 net-next 06/10] openvswitch: Allow matching on conntrack mark, Joe Stringer
- [PATCHv5 net-next 09/10] openvswitch: Allow matching on conntrack label, Joe Stringer
- [PATCHv5 net-next 03/10] ipv6: Export nf_ct_frag6_gather(), Joe Stringer
- [PATCHv5 net-next 02/10] openvswitch: Move MASKED* macros to datapath.h, Joe Stringer
- [PATCHv5 net-next 04/10] dst: Add __skb_dst_copy() variation, Joe Stringer
- [PATCHv5 net-next 01/10] openvswitch: Serialize acts with original netlink len, Joe Stringer
- [PATCH nf-next 0/2] netfilter: nfnetlink_log attach conntrack,
Ken-ichirou MATSUZAWA
- [PATCH iptables v2] libxt_CT: add support for recently introduced zone options,
Daniel Borkmann
- [PATCH 1/2 nf-next] netfilter: nf_dup: fix sparse warnings,
Pablo Neira Ayuso
- [PATCH v2 net-next] netfilter: ipset: Fixing unnamed union init,
Elad Raz
- [PATCH] netfilter: nf_ct_tcp: Remove the duplicated word in comment,
Feng Gao
- [PATCH conntrack-tools] nfct: Update syntax to specify command before subsystem, Pablo Neira Ayuso
- [GIT PULL nf-next] Second Round of IPVS Updates for v4.3,
Simon Horman
- [PATCH net-next] netfilter: ipset: Fixing unnamed union init, Elad Raz
- [PATCH v2 iptables] added missing icmpv6 codes in REJECT,
Andreas Herz
- [PATCH v2 nf-next] added missing icmpv6 codes in REJECT,
Andreas Herz
- [PATCH nf-next] add missing icmpv6 codes (rfc4443) in REJECT,
Andreas Herz
- [PATCH iptables] add missing icmpv6 codes (rfc4443) in REJECT, Andreas Herz
- [conntrack-tools PATCH] nfct: don't link against libnetfilter_conntrack,
Arturo Borrero Gonzalez
- [conntrack-tools PATCH] nfct.8: reword some sentences, Arturo Borrero Gonzalez
- [conntrack-tools PATCH] doc/debian.conntrackd.init.d: drop file,
Arturo Borrero Gonzalez
- [conntrack-tools PATCH] list: fix prefetch dummy,
Arturo Borrero Gonzalez
- [PATCH] iptables: update gitignore list,
Mike Frysinger
- [PATCH] libiptc: fix fortify errors in debug code,
Mike Frysinger
- [PATCH 1/1] added missing icmpv6 dest-unreach codes,
Andreas Herz
- ICMPv6 Type 1 Code 5 and 6 missing in iptables REJECT target and icmpv6 match,
Andreas Herz
- [PATCH] build: add finer module blacklisting,
Mike Frysinger
- [PATCH] build: use _DEFAULT_SOURCE for newer glibc,
Mike Frysinger
- [PATCH conntrackd 0/8] unsorted fixes,
Pablo Neira Ayuso
- [PATCH nft 1/2] tests: sets: don't include listing in payload tests,
Pablo Neira Ayuso
- [PATCH libnftnl] expr: immediate: fix leak in expression destroy path, Pablo Neira Ayuso
- [nft] merged next-4.2 and lastest cache consolidation patches, Pablo Neira Ayuso
- [PATCH -next] nftables: nft_payload: work around vlan header stripping,
Florian Westphal
- [PATCH libnftnl 1/3] expr: add dup expression support,
Pablo Neira Ayuso
- [PATCH nft 0/12] add support for VLAN header filtering in bridge family,
Florian Westphal
- [PATCH 02/12] tests: add 'awkward' prefix match expression, Florian Westphal
- [PATCH 01/12] tests: use the src/nft binary instead of $PATH one, Florian Westphal
- [PATCH 03/12] nft: allow stacking vlan header on top of ethernet, Florian Westphal
- [PATCH 06/12] src: netlink: don't truncate set key lengths, Florian Westphal
- [PATCH 07/12] nft: fill in doff and fix ihl/version template entries, Florian Westphal
- [PATCH 10/12] nft: support listing expressions that use non-byte header fields, Florian Westphal
- [PATCH 12/13] vlan: make != tests work, Florian Westphal
- [PATCH 11/12] tests: vlan tests, Florian Westphal
- [PATCH 08/12] netlink: cmp: shift rhs constant if lhs offset doesn't start on byte boundary, Florian Westphal
- [PATCH 09/12] tests: add tests for ip version/hdrlength/tcp doff, Florian Westphal
- [PATCH 05/12] src: netlink_linearize: handle sub-byte lengths, Florian Westphal
- [PATCH 04/12] payload: disable payload merge if offsets are not on byte boundary, Florian Westphal
- Re: [PATCH nft 0/12] add support for VLAN header filtering in bridge family, Florian Westphal
- Re: [PATCH nft 0/12] add support for VLAN header filtering in bridge family, Florian Westphal
- [PATCH] configure: fix 3rd arg w/AC_ARG_ENABLE,
Mike Frysinger
- [PATCH nf-next v5 0/2] Netfilter zone directions,
Daniel Borkmann
- ipset triggering kasan warnings.,
Dave Jones
- nftables: precondition validation fails on map construct,
Andreas Schultz
- [PATCH] netfilter: Remove the duplicated word "see" in the comment when set the IPS_ASSURED_BIT in tcp_packet,
Feng Gao
- [PATCHv4 nf-next] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n,
Bernhard Thaler
- [PATCH nft 1/2] evaluate: display error on unexisting chain when listing,
Pablo Neira Ayuso
- [PATCH] netfilter: nf_tables: Use 32 bit addressing register from nft_type_to_reg(), Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH 1/5] netfilter: nf_conntrack: silence warning on falling back to vmalloc(), Pablo Neira Ayuso
- [PATCH 2/5] netfilter: nf_conntrack: checking for IS_ERR() instead of NULL, Pablo Neira Ayuso
- [PATCH 3/5] netfilter: conntrack: Use flags in nf_ct_tmpl_alloc(), Pablo Neira Ayuso
- [PATCH 4/5] netfilter: ip6t_SYNPROXY: fix NULL pointer dereference, Pablo Neira Ayuso
- [PATCH 5/5] netfilter: SYNPROXY: fix sending window update to client, Pablo Neira Ayuso
- Re: [PATCH 0/5] Netfilter fixes for net, David Miller
- <Possible follow-ups>
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- [PATCH 0/5] Netfilter fixes for net, Pablo Neira Ayuso
- Re: IPv6 and private net with masquerading not working correctly,
Cong Wang
- nft: parser problem, can use mark as datatype in sets and maps,
Andreas Schultz
- [PATCH nft v5 00/14] cache consolidation,
Pablo Neira Ayuso
- [PATCH nft v5 01/14] src: add cache infrastructure and use it for table objects, Pablo Neira Ayuso
- [PATCH nft v5 03/14] rule: add reference counter to the table object, Pablo Neira Ayuso
- [PATCH nft v5 04/14] src: add table declaration to cache, Pablo Neira Ayuso
- [PATCH nft v5 02/14] src: add cmd_evaluate_list(), Pablo Neira Ayuso
- [PATCH nft v5 05/14] src: use cache infrastructure for set objects, Pablo Neira Ayuso
- [PATCH nft v5 06/14] src: add set declaration to cache, Pablo Neira Ayuso
- [PATCH nft v5 07/14] src: early allocation of the set ID, Pablo Neira Ayuso
- [PATCH nft v5 09/14] src: use cache infrastructure for chain objects, Pablo Neira Ayuso
- [PATCH nft v5 10/14] evaluate: add cmd_evaluate_rename(), Pablo Neira Ayuso
- [PATCH nft v5 08/14] rule: add chain reference counter, Pablo Neira Ayuso
- [PATCH nft v5 12/14] src: use cache infrastructure for rule objects, Pablo Neira Ayuso
- [PATCH nft v5 11/14] src: add chain declarations to cache, Pablo Neira Ayuso
- [PATCH nft v5 13/14] src: use cache infrastructure for set element objects, Pablo Neira Ayuso
- [PATCH nft v5 14/14] src: get rid of EINTR handling for nft_netlink(), Pablo Neira Ayuso
- [lnf-log RFC PATCH 0/2] introduce new functions to use without nflog_handle,
Ken-ichirou MATSUZAWA
- [lnf-log PATCH] build: fix typo,
Ken-ichirou MATSUZAWA
- [PATCH nf-next v4 0/3] Netfilter zone directions,
Daniel Borkmann
- [PATCH] netfilter: per network namespace nfacct,
Andreas Schultz
- [PATCH nf-next 1/6] netfilter: nft_limit: rename to nft_limit_pkts,
Pablo Neira Ayuso
- [PATCH libnftnl] src: fix memory leaks at nft_[object]_nlmsg_parse,
Carlos Falgueras García
- [PATCH net] netfilter: conntrack: Use flags in nf_ct_tmpl_alloc(),
Joe Stringer
- Re: [PATCH] netfilter: ipt_SYNPROXY: fix sending window update to client,
Pablo Neira Ayuso
- IPv6 support for GRE helper(nf_conntrack_proto_gre),
Aju L Francis
- nfacct is not namespace aware,
Andreas Schultz
- [PATCH nf-next 1/3] netfilter: xt_TEE: get rid of WITH_CONNTRACK definition,
Pablo Neira Ayuso
- [PATCH nf-next 1/3] netfilter: nf_tables: add generation mask to table objects,
Pablo Neira Ayuso
- [PATCH nft] src: restore nft list tables, Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nft_counter: convert it to use per-cpu counters, Pablo Neira Ayuso
- Multiple DSCP match by "-m dscp --dscp-multi value,value,...", Kyeong Yoo
- New multiple DSCP match by "-m dscp --dscp-multi value,value,...",
Kyeong Yoo
- [PATCH nf-next] netfilter: connlabels: Export setting connlabel length,
Joe Stringer
- [IPTABLES] Module ipt_same,
Alex william
- [PATCH nf-next] netfilter: ip6t_REJECT: Remove debug messages from reject_tg6(),
subashab
- IP sets: Suggestion: additional value match,
Rudolf_AT
- [PATCH nf-next] netfilter: ip6t_REJECT: Log reject reason in reject_tg6(),
subashab
- [PATCHv3 2/2 nf] netfilter: bridge: fix IPv6 packets not being bridged with CONFIG_IPV6=n,
Bernhard Thaler
- [PATCH 1/2 nf] netfilter: bridge: do not initialize statics to 0 or NULL,
Bernhard Thaler
- [patch -master] netfilter: xt_CT: checking for IS_ERR() instead of NULL,
Dan Carpenter
- [PATCH] netfilter: xtables: Add helper macro for xt_match boilerplate,
Vaishali Thakkar
- IPv4 IPv6 parallel dns lookup in combination with nfqueue is problematic,
Tarik Demirci
- [PATCH nf-next] netfilter: bridge: reduce nf_bridge_info to 32 bytes again,
Florian Westphal
- [PATCH nf] netfilter: nf_conntrack: silence warning on falling back to vmalloc(), Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nf_queue: fix nf_queue_nf_hook_drop(),
Pablo Neira Ayuso
- [PATCH 00/10] Netfilter/IPVS fixes for net,
Pablo Neira Ayuso
- [PATCH 04/10] ipvs: do not use random local source address for tunnels, Pablo Neira Ayuso
- [PATCH 10/10] netfilter: nf_conntrack: Support expectations in different zones, Pablo Neira Ayuso
- [PATCH 09/10] netfilter: fix netns dependencies with conntrack templates, Pablo Neira Ayuso
- [PATCH 07/10] ipvs: fix crash with sync protocol v0 and FTP, Pablo Neira Ayuso
- [PATCH 08/10] ipvs: call skb_sender_cpu_clear, Pablo Neira Ayuso
- [PATCH 06/10] ipvs: skb_orphan in case of forwarding, Pablo Neira Ayuso
- [PATCH 05/10] ipvs: fix crash if scheduler is changed, Pablo Neira Ayuso
- [PATCH 03/10] ipvs: fix ipv6 route unreach panic, Pablo Neira Ayuso
- [PATCH 02/10] netfilter: IDLETIMER: fix lockdep warning, Pablo Neira Ayuso
- [PATCH 01/10] netfilter: ctnetlink: put back references to master ct and expect objects, Pablo Neira Ayuso
- Re: [PATCH 00/10] Netfilter/IPVS fixes for net, David Miller
- <Possible follow-ups>
- [PATCH 00/10] Netfilter/IPVS fixes for net, Pablo Neira Ayuso
- [PATCH 04/10] ipvs: do not schedule icmp errors from tunnels, Pablo Neira Ayuso
- [PATCH 05/10] netfilter: ctnetlink: don't use conntrack/expect object addresses as id, Pablo Neira Ayuso
- [PATCH 02/10] netfilter: conntrack: don't set related state for different outer address, Pablo Neira Ayuso
- [PATCH 10/10] netfilter: fix nf_l4proto_log_invalid to log invalid packets, Pablo Neira Ayuso
- [PATCH 06/10] netfilter: nf_tables: prevent shift wrap in nft_chain_parse_hook(), Pablo Neira Ayuso
- [PATCH 09/10] netfilter: never get/set skb->tstamp, Pablo Neira Ayuso
- [PATCH 07/10] netfilter: nat: fix icmp id randomization, Pablo Neira Ayuso
- [PATCH 03/10] netfilter: conntrack: initialize ct->timeout, Pablo Neira Ayuso
- [PATCH 01/10] selftests: netfilter: check icmp pkttoobig errors are set as related, Pablo Neira Ayuso
- [PATCH 08/10] netfilter: ebtables: CONFIG_COMPAT: drop a bogus WARN_ON, Pablo Neira Ayuso
- Re: [PATCH 00/10] Netfilter/IPVS fixes for net, David Miller
- [PATCH nf-next v3 0/3] Netfilter zone directions,
Daniel Borkmann
- ip(6)tables-restore segfault + patch, Felix Bolte
- [PATCH nf] netfilter: Support expectations in different zones,
Joe Stringer
- [RFC PATCH 0/5] netlink: mmap kernel panic and some issues,
Ken-ichirou MATSUZAWA
- [IPTABLES 0/2] iptables-compat fixes,
Thomas Woerner
- [PATCH nf-next 1/2] netfilter: fix possible removal of wrong hook,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nf_queue: fix deadlock in nf_queue_nf_hook_drop(),
Pablo Neira Ayuso
- [PATCH] Fix grammar error in manpage,
Neutron Soutmun
- [PATCH nf] netfilter: nf_conntrack: silent warning when adding extensions to templates,
Pablo Neira Ayuso
- Re: [PATCH] netfilter: Fix memory leak in nf_register_net_hook, Pablo Neira Ayuso
- [netfilter] INFO: task kworker/u2:0:6 blocked for more than 120 seconds., Fengguang Wu
- [PATCHv2 net-next] net: #ifdefify sk_classid member of struct sock,
Mathias Krause
- [PATCH net-next] net: #ifdefify sk_classid member of struct sock,
Mathias Krause
- [PATCH nf-next v2] netfilter: nf_ct_sctp: minimal multihoming support,
Michal Kubecek
- nf_conntrack: falling back to vmalloc.,
Toralf Förster
- [PATCH nft] tests: validate generated netlink instructions,
Florian Westphal
- [PATCH iptables] fix wrong headername in ipv6header for protocols,
Andreas Herz
- nft: meta l4proto range printing broken on 32bit,
Florian Westphal
- [PATCH nf 0/6] IPVS Fixes for v4.2,
Simon Horman
- [PATCH nf,v2] netfilter: fix netns dependencies with conntrack templates,
Pablo Neira Ayuso
- iptables: AH/ESP init fix, and a build fix,
Jan Engelhardt
- [Q] iptables AH module api mismatch between -master and 1.4.7,
Cyrill Gorcunov
- [PATCH -next v2 0/6] netfilter: xtables: improve jumpstack handling,
Florian Westphal
- [PATCH nf-next] netfilter: nf_ct_sctp: minimal multihoming support,
Michal Kubecek
- [PATCH iptables] extensions: libxt_socket: update man pages and tests for --restore-skmark,
Harout Hedeshian
- [PATCH nf RFC] netfilter: fix netns dependencies with conntrack templates,
Pablo Neira Ayuso
- [PATCH nf-next v2 0/3] Netfilter zone directions,
Daniel Borkmann
- [PATCH iptables] libxt_CT: add support for recently introduced zone options,
Daniel Borkmann
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]