Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- [iptables PATCH v2] iptables/nft-shared.c: kill add_*() invflags parameter,
Arturo Borrero Gonzalez
- [PATCH] netfilter: nft_redir: fix sparse warnings: cast to restricted __be32,
Arturo Borrero Gonzalez
- [PATCH nf-next 1/2] netfilter: fix unmet dependencies in NETFILTER_XT_TARGET_REDIRECT,
Pablo Neira Ayuso
- [GIT PULL nf] Second Round of IPVS Fixes for v3.18,
Simon Horman
- [iptables PATCH] iptables/nft-shared.c: kill add_*() invflags parameter,
Arturo Borrero Gonzalez
- [PATCH 1/3] netfilter: nft_compat: relax chain type validation,
Pablo Neira Ayuso
- [PATCH] arptables: remove dead dynamic hooks code,
Gustavo Zacarias
- [PATCH -next 0/2] seq: Convert seq_puts and seq_putc to return void,
Joe Perches
- [PATCH 0/1] autotools conversion: added autotools support for the 'files' subdir.,
Giorgio Dal Molin
- [PATCH 0/1] autotools conversion: added autotools support for the 'doc' subdir.,
Giorgio Dal Molin
- [PATCH libnftnl 1/3] expr: nat: use 'nat_type' instead of 'type' in the parser,
Pablo Neira Ayuso
- [PATCH libnftnl] src: consolidate XML/JSON exportation,
Pablo Neira Ayuso
- [PATCH] From fryasu: Trim kernel struct to allow deletion for TEE targets,
Loganaden Velvindron
- How to debug libiptc and mechanism for exchanging information between user space and kernel space, Nguyen Duong Tuan
- [ebtables-compat-experimental3 PATCH 1/2] nft-bridge: fix inversion of matches,
Arturo Borrero Gonzalez
- [iptables PATCH] nft-arp: fix inversion of matches,
Arturo Borrero Gonzalez
- [PATCH] arptables: disable dlfcn.h include,
Gustavo Zacarias
- [PATCH] netfilter: nft_compat: use current net namespace, Pablo Neira Ayuso
- [PATCH -nf] nft: masq: fix uninitialized range in nft_masq_{ipv4,ipv6}_eval,
Daniel Borkmann
- [nft PATCH 1/3] tests/regression: masquerade: fix invalid syntax,
Arturo Borrero Gonzalez
- [patch -mainline] netfilter: ipset: small potential read beyond the end of buffer,
Dan Carpenter
- [PATCH nft 0/5] autotools conversion,
Pablo Neira Ayuso
- [PATCH nf] netfilter: conntrack: fix race in __nf_conntrack_confirm against get_next_corpse,
Jesper Dangaard Brouer
- [PATCH 1/3] netfilter: nfnetlink_log: remove unnecessary error messages,
Pablo Neira Ayuso
- [nft PATCH v2] nft: don't resolve hostnames by default,
Arturo Borrero Gonzalez
- [PATCH 4/8] netfilter: Remove checks of seq_printf() return values, Steven Rostedt
- [PATCH 2/8] netfilter: Remove return values for print_conntrack callbacks, Steven Rostedt
- [PATCH 3/8] netfilter: Convert print_tuple functions to return void,
Steven Rostedt
- [PATCH] iptables-compat: homogenize error messages with 'R' option,
Ana Rey
- [PATCH] Make use of pr_fmt where applicable, Marcelo Ricardo Leitner
- [PATCH nft] utils: indicate file and line on memory allocation errors, Pablo Neira Ayuso
- [Repost] Fix userspace compilation of ip_tables.h/ip6_tables.h in C++ mode,
Matthew Weber
- [libnftnf PATCH] expr: meta: Add cgroup support,
Ana Rey
- recent module,
Pietro Paolini
- [PATCH] netfilter: nft_reject_bridge: fix missing declaration of csum_ipv6_magic, Jeff Mahoney
- [PATCH] netfilter: nft_reject_bridge: Fix powerpc build error,
Guenter Roeck
- iptables/ipset "-m set" alignment problem 64bit kernel 32bit userspace,
Sven-Haegar Koch
- bug report: use after free bug leading to kernel panic,
eric gisse
- [PATCH] netfilter: nf_log: fix sparse warning in nf_logger_find_get(), Pablo Neira Ayuso
- [PATCH] extensions: devgroup: fix showing and saving of dst-group,
Ana Rey
- [PATCH] iptables-compat: homogenize error messages,
Ana Rey
- [PATCH net-next] netfilter: fix spelling errors,
Stephen Hemminger
- [RFA][PATCH 2/8] netfilter: Remove return values for print_conntrack callbacks,
Steven Rostedt
- [RFA][PATCH 3/8] netfilter: Convert print_tuple functions to return void,
Steven Rostedt
- [RFA][PATCH 4/8] netfilter: Remove checks of seq_printf() return values,
Steven Rostedt
- [ebtables-compat PATCH] extensions: libebt_log,
Giuseppe Longo
[ebtables-compat PATCH] build ebtables extensions,
Giuseppe Longo
[PATCH v4 1/3] netfilter: log: protect nf_log_register against double registering,
Marcelo Ricardo Leitner
[PATCH v2] Introduce nft_log_dereference() macro,
Marcelo Ricardo Leitner
[PATCH v3 1/3] netfilter: log: protect nf_log_register against double registering,
Marcelo Ricardo Leitner
nftables in network name spaces breaks networking,
Ed Tomlinson
[PATCH] Make_global.am: Don't include host headers,
Baruch Siach
[ebtables-compat PATCH 1/2] nft-shared: rework inversion of matches,
Arturo Borrero Gonzalez
[PATCH 0/5] bridge reject fixes,
Pablo Neira Ayuso
netfilter: nf_conntrack: there maybe a bug in __nf_conntrack_confirm, when it race against get_next_corpse,
billbonaparte
[GIT PULL nf] IPVS Fixes for v3.18,
Simon Horman
[GIT PULL nf-next] IPVS Updates for v3.19,
Simon Horman
[nf_tables PATCH] netfilter: nft_compat: fix wrong target lookup in nft_target_select_ops(),
Arturo Borrero Gonzalez
[Kernel Bug 86261] Ipset add/restore slowed to a crawl in kernel 3.17 (and 3.17.1),
Kim N
iptables doesn't match udp rule, Ralf Schwarzmaier
[PATCH] add missing ipset_parse_tcp_udp_port to libipset.map,
Thomas Backlund
[PATCH 1/3] Introduce nft_log_dereference() macro,
Marcelo Ricardo Leitner
Re: [PATCH 1/3] Introduce nft_log_dereference() macro, Pablo Neira Ayuso
[PATCH] libipset: Bump lib version and update map file,
Neutron Soutmun
[RFC PATCH netfilter] Fix Unknown symbols in nf_reject_ipvX modules,
Li Zhong
netfilter: NAT: do the optimization for getting curr_tuple in function nf_nat_setup_info, billbonaparte
[nft PATCH 1/2 v2] evaluate: reject: check the context in reject without reason for bridge and inet tables,
Alvaro Neira Ayuso
[nft PATCH 1/2] evaluate: reject: check the context in reject without reason for bridge and inet tables,
Alvaro Neira Ayuso
[nftables PATCH] meta: Add support for datatype devgroup,
Ana Rey
[PATCH] iptables-compat: fix empty chains after first invocation of iptables-compat -L, Pablo Neira Ayuso
[PATCH 1/3] iptables-compat: fix chain policy reset with iptables -L -n,
Pablo Neira Ayuso
[PATCH 0/3] netfilter: nf_log: nlmsg size fixes,
Florian Westphal
Xtables Getting Started Question, Daniel Martin
[nft PATCH 1/2 v3] evaluate: reject: accept a reject reason with incorrect network context,
Alvaro Neira Ayuso
Re: [PATCH] netfilter: xt_hashlimit: Enhance the xt_hashlimit to avoid duplicated codes,
Pablo Neira Ayuso
[nft PATCH 1/4 v2] evaluate: refactor function to check the reject family in inet and bridge,
Alvaro Neira Ayuso
[RFC nft PATCH] src: add import operation,
Arturo Borrero Gonzalez
[nft PATCH] mnl: delete useless parameter nf_sock in batch functions,
Arturo Borrero Gonzalez
[PATCH nf] netfilter: nf_tables: check for NULL in nf_tables_newchain pcpu stats allocation,
Sabrina Dubroca
[patch] netfilter: ipset: off by one in ip_set_nfnl_get_byindex(),
Dan Carpenter
[PATCH] netfilter: Fix wastful cleanup check for unconfirmed conn in get_next_corpse,
Feng Gao
[nft PATCH 1/4] evaluate: refactor function to check the reject family in inet and bridge,
Alvaro Neira Ayuso
[PATCH] netfilter: log: protect nf_log_register against double registering,
Marcelo Ricardo Leitner
TCP LAST ACK incorrectly treated as invalid,
vDev
[libnftnl PATCH] ruleset: deconstify _get interface,
Arturo Borrero Gonzalez
[nft PATCH v3] evaluate: fix a crash if we specify ether type or meta nfproto in reject,
Alvaro Neira Ayuso
[libnftnl PATCH v3] utils: fix arp family number,
Arturo Borrero Gonzalez
[libnftnl PATCH v2] utils: fix arp family number,
Arturo Borrero Gonzalez
[libnftnl PATCH] utils: fix arp family number,
Arturo Borrero Gonzalez
[nft PATCH] nft: don't resolve hostnames by default, Arturo Borrero Gonzalez
[nft PATCH 4/4 v3] test: update and add the reject tests for ip, ip6, bridge and inet., Alvaro Neira Ayuso
[nft PATCH 1/4 v2] evaluate: fix a crash if we specify ether type or meta nfproto in reject,
Alvaro Neira Ayuso
[libnftnl PATCH v3] src: add support for nft_redir expression,
Arturo Borrero Gonzalez
[nf_tables PATCH v3 1/2] netfilter: refactor NAT redirect IPv6 code to use it from nf_tables,
Arturo Borrero Gonzalez
[PATCH] libipset: Add missing ipset_parse_uint16 to map file,
Neutron Soutmun
[PATCH] ipset: Adjust the maximum timeout jiffies of set timeout extension,
Neutron Soutmun
NAT dropping FIN ACK from remote server,
vDev
[iptables-compat PATCH 1/3] ebtables-compat: fix print_header,
Giuseppe Longo
[PATCH nf 1/3] netfilter: nft_nat: insufficient attribute validation,
Pablo Neira Ayuso
[nft PATCH v2] src: add redirect support,
Arturo Borrero Gonzalez
[libnftnl PATCH v2] src: add support for nft_redir expression,
Arturo Borrero Gonzalez
[nf_tables PATCH v2 1/3] netfilter: refactor NAT redirect IPv4 to use it from nf_tables,
Arturo Borrero Gonzalez
[nft PATCH] tests: add tests for masquerade,
Arturo Borrero Gonzalez
[nft PATCH] src: add redirect support,
Arturo Borrero Gonzalez
[libnftnl PATCH 1/2] src: add support for nft_redir expression,
Arturo Borrero Gonzalez
[nf_tables PATCH 1/3] netfilter: refactor NAT's redirect IPv4 code,
Arturo Borrero Gonzalez
[PATCH 1/2 nf] netfilter: nft_compat: fix hook validation for non-base chains,
Pablo Neira Ayuso
[PATCH v2] netfilter: release skbuf when nlmsg put fail,
Houcheng Lin
[PATCH nf] netfilter: nf_tables: restrict nat/masq expressions to nat chain type, Pablo Neira Ayuso
[PATCH] netfilter: release skbuf when nlmsg put fail,
Houcheng Lin
[nft PATCH 1/3] evaluate: fix a crash if we specify ether type or meta nfproto in reject,
Alvaro Neira Ayuso
[libnftnl PATCH] src: cleanup in mxml and jansson regarding set_id parsing,
Arturo Borrero Gonzalez
[nft PATCH] build: remove unnecessary libintl.h check,
Steven Barth
Re: nf_reject_ipv4: module license 'unspecified' taints kernel,
Pablo Neira Ayuso
ipset: bad timeout assignments,
Vitezslav Samel
[PATCH 0/2] Netfilter fixes for net-next,
Pablo Neira Ayuso
More work on ebtables-compat, Pablo Neira Ayuso
[PATCH arptables-compat] arptables-compat: remove save code, Pablo Neira Ayuso
[PATCH xtables-compat] arptables-compat: get output in sync with arptables -L -n --line-numbers, Pablo Neira Ayuso
[PATCH xtables-compat 1/4] iptables-compat: nft: fix user chain addition, deletion and rename,
Pablo Neira Ayuso
[PATCH] tests: regression: Delete all reference to wlan0 in test files.,
Ana Rey
[PATCH 2/2] netfilter: fix wrong arithmetics regarding NFT_REJECT_ICMPX_MAX, Pablo Neira Ayuso
[PATCH 1/2] netfilter: kill nf_send_reset6() from include/net/netfilter/ipv6/nf_reject.h,
Pablo Neira Ayuso
re: netfilter: nft_reject: introduce icmp code abstraction for inet and bridge, Dan Carpenter
net-next is CLOSED..., David Miller
[nft PATCH v2] src: add masquerade support,
Arturo Borrero Gonzalez
[PATCH nft 1/2] src: interpret the event type from the evaluation step,
Pablo Neira Ayuso
queuing to userspace for the bridge family, using nftables,
stéphane bryant
[PATCH nf next 0/3] bridge: netfilter: fix handling of ipv4 packets w. options,
Florian Westphal
[libnftnl PATCH 1/2] ruleset: add the set_id to the parsed sets,
Alvaro Neira Ayuso
[PATCH 0/9] Netfilter/IPVS updates for net-next,
Pablo Neira Ayuso
- [PATCH 1/9] netfilter: nft_reject: introduce icmp code abstraction for inet and bridge, Pablo Neira Ayuso
- [PATCH 4/9] netfilter: nf_tables: wait for call_rcu completion on module removal, Pablo Neira Ayuso
- [PATCH 3/9] netfilter: use IS_ENABLED(CONFIG_BRIDGE_NETFILTER), Pablo Neira Ayuso
- [PATCH 2/9] netfilter: move nf_send_resetX() code to nf_reject_ipvX modules, Pablo Neira Ayuso
- [PATCH 8/9] ipvs: Clean up comment style in ip_vs.h, Pablo Neira Ayuso
- [PATCH 9/9] netfilter: nft_masq: register/unregister notifiers on module init/exit, Pablo Neira Ayuso
- [PATCH 7/9] netfilter: explicit module dependency between br_netfilter and physdev, Pablo Neira Ayuso
- [PATCH 6/9] netfilter: nf_tables: allow to filter from prerouting and postrouting, Pablo Neira Ayuso
- [PATCH 5/9] netfilter: nft_compat: remove incomplete 32/64 bits arch compat code, Pablo Neira Ayuso
- Re: [PATCH 0/9] Netfilter/IPVS updates for net-next, David Miller
How to generate statistics for a TCP flow using netfilter conntrack?, Phuong Cao
[nft PATCH 1/2] src: add nat persistent and random options,
Arturo Borrero Gonzalez
[nf-next PATCH] netfilter: nft_masq: fix register/unregister notifier on module _init and _exit,
Arturo Borrero Gonzalez
[PATCH v2] netfilter: explicit module dependency between br_netfilter and physdev,
Pablo Neira Ayuso
Migrating an established TCP connection to a different port, Anuradha Ratnaweera
[libnftnl PATCH 1/3] expr: masq: optional printing of flags attr in snprintf_default,
Arturo Borrero Gonzalez
[PATCH 1/4] netfilter: use IS_ENABLED(CONFIG_BRIDGE_NETFILTER),
Pablo Neira Ayuso
[PATCH] netfilter: explicit module dependency between br_netfilter and physdev,
Pablo Neira Ayuso
[nft PATCH] build: allow disabling libreadline-support,
Steven Barth
[PATCH 1/3] xtables: bootstrap xtables-eb for nftables,
Giuseppe Longo
merge of iptables-tests to master, Pablo Neira Ayuso
[PATCH iptables-compat] iptables-compat: get rid of error reporting via perror, Pablo Neira Ayuso
[PATCH iptables-compat 1/2] iptables-compat: nft: use nft_batch_begin and nft_batch_end from libnftnl,
Pablo Neira Ayuso
[PATCH nft] mnl: use nft_batch_begin and nft_batch_end from libnftnl, Pablo Neira Ayuso
[nft PATCH 1/4 v3] payload: generate dependency in the appropriate byteorder,
Alvaro Neira Ayuso
[PATCH iptables-compat] iptables-compat: fix address prefix, Pablo Neira Ayuso
[PATCH] netfilter: fix nf_conn_nat->masq_index visibility,
Arnd Bergmann
[PATCH lnfct] qa: build unshared nfct environment,
Ken-ichirou MATSUZAWA
[PATCH net-next] netfilter: bridge: build br_nf_core only if required,
Pablo Neira Ayuso
[PATCH] ipvs: Clean up comment style in ip_vs.h,
Simon Horman
[PATCH 0/7] seq_printf cleanups,
Joe Perches
[libnftnl PATCH] examples: nft-table-add: fix wrong buffer pointer,
Arturo Borrero Gonzalez
[PATCH 00/34] pull request: netfilter/ipvs updates for net-next,
Pablo Neira Ayuso
- [PATCH 03/34] netfilter: NFT_CHAIN_NAT_IPV* is independent of NFT_NAT, Pablo Neira Ayuso
- [PATCH 11/34] netfilter: ipset: send nonzero skbinfo extensions only, Pablo Neira Ayuso
- [PATCH 10/34] netfilter: ipset: Add skbinfo extension support to SET target., Pablo Neira Ayuso
- [PATCH 13/34] ipvs: Add simple weighted failover scheduler, Pablo Neira Ayuso
- [PATCH 12/34] netfilter: ipset: hash:mac type added to ipset, Pablo Neira Ayuso
- [PATCH 19/34] ipvs: Pull out crosses_local_route_boundary logic, Pablo Neira Ayuso
- [PATCH 15/34] ipvs: Supply destination addr family to ip_vs_{lookup_dest,find_dest}, Pablo Neira Ayuso
- [PATCH 22/34] ipvs: support ipv4 in ipv6 and ipv6 in ipv4 tunnel forwarding, Pablo Neira Ayuso
- [PATCH 24/34] ipvs: address family of LBLCR entry depends on svc family, Pablo Neira Ayuso
- [PATCH 27/34] ipvs: Allow heterogeneous pools now that we support them, Pablo Neira Ayuso
- [PATCH 30/34] net/netfilter/x_tables.c: use __seq_open_private(), Pablo Neira Ayuso
- [PATCH 34/34] netfilter: conntrack: disable generic tracking for known protocols, Pablo Neira Ayuso
- [PATCH 29/34] netfilter: nf_tables: export rule-set generation ID, Pablo Neira Ayuso
- [PATCH 31/34] netfilter: bridge: nf_bridge_copy_header as static inline in header, Pablo Neira Ayuso
- [PATCH 32/34] netfilter: bridge: move br_netfilter out of the core, Pablo Neira Ayuso
- [PATCH 21/34] ipvs: Add generic ensure_mtu_is_adequate to handle mixed pools, Pablo Neira Ayuso
- [PATCH 33/34] netfilter: nf_tables: store and dump set policy, Pablo Neira Ayuso
- [PATCH 28/34] netfilter: nfnetlink: use original skbuff when committing/aborting, Pablo Neira Ayuso
- [PATCH 23/34] ipvs: address family of LBLC entry depends on svc family, Pablo Neira Ayuso
- [PATCH 26/34] ipvs: use the new dest addr family field, Pablo Neira Ayuso
- [PATCH 20/34] ipvs: Pull out update_pmtu code, Pablo Neira Ayuso
- [PATCH 25/34] ipvs: use correct address family in scheduler logs, Pablo Neira Ayuso
- [PATCH 14/34] ipvs: Add destination address family to netlink interface, Pablo Neira Ayuso
- [PATCH 18/34] ipvs: prevent mixing heterogeneous pools and synchronization, Pablo Neira Ayuso
- [PATCH 17/34] ipvs: Supply destination address family to ip_vs_conn_new, Pablo Neira Ayuso
- [PATCH 16/34] ipvs: Pass destination address family to ip_vs_trash_get_dest, Pablo Neira Ayuso
- [PATCH 08/34] netfilter: ipset: Add skbinfo extension kernel support for the hash set types., Pablo Neira Ayuso
- [PATCH 07/34] netfilter: ipset: Add skbinfo extension kernel support for the bitmap set types., Pablo Neira Ayuso
- [PATCH 04/34] netfilter: masquerading needs to be independent of x_tables in Kconfig, Pablo Neira Ayuso
- [PATCH 09/34] netfilter: ipset: Add skbinfo extension kernel support for the list set type., Pablo Neira Ayuso
- [PATCH 05/34] netfilter: ipset: Fix static checker warning in ip_set_core.c, Pablo Neira Ayuso
- [PATCH 06/34] netfilter: ipset: Add skbinfo extension kernel support in the ipset core., Pablo Neira Ayuso
- [PATCH 01/34] netfilter: fix compilation of masquerading without IP_NF_TARGET_MASQUERADE, Pablo Neira Ayuso
- [PATCH 02/34] netfilter: nf_tables: add NFTA_MASQ_UNSPEC to nft_masq_attributes, Pablo Neira Ayuso
- Re: [PATCH 00/34] pull request: netfilter/ipvs updates for net-next, David Miller
[PATCH] netfilter: bridge: unshare bridge info before change it,
Gao feng
[libnftnl PATCH 1/2] examples: nft-set-json-add: generalize parsing format support,
Arturo Borrero Gonzalez
Re: [libnftnl PATCH 1/2] examples: nft-set-json-add: generalize parsing format support, Pablo Neira Ayuso
[nft] using `nft -i' as user shell,
Arturo Borrero Gonzalez
Re: mmotm 2014-09-25-16-28 uploaded (nf_nat_masquerade_ipv4.c),
Randy Dunlap
[nft PATCH 1/4 v2] payload: generate dependency in the appropriate byteorder,
Alvaro Neira Ayuso
[nft PATCH 3/3 v3] src: add list ruleset command,
Arturo Borrero Gonzalez
[PATCH 1/2 nf-next] netfilter: nft_reject: introduce icmp code abstraction for inet and bridge,
Pablo Neira Ayuso
[PATCH 0/6 -stable] netfilter/ipvs patches,
Pablo Neira Ayuso
[PATCH nf v2] netfilter: conntrack: disable generic tracking for known protocols,
Florian Westphal
[PATCH nf] netfilter: conntrack: disable generic protocol tracking,
Florian Westphal
[conntrack-tools PATCH] man: fix hyphen used as minus sign,
Arturo Borrero Gonzalez
[PATCH] Allow to compile for < 3.17 kernel version,
Vadim Kochan
[PATCH 0/3]: parser cleanups,
Patrick McHardy
[nft PATCH 1/3] rule: rename do_command_list_cleanup() to table_cleanup(),
Arturo Borrero Gonzalez
[nft PATCH 1/2] rule: factorize chain and table listing code,
Arturo Borrero Gonzalez
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]