Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- [nft PATCH] tests: shell: Fix sets/reset_command_0 for current kernels,
Phil Sutter
- [nf-next PATCH v3] netfilter: nf_tables: Add locking for NFT_MSG_GETSETELEM_RESET requests,
Phil Sutter
- [nft PATCH] tproxy: Drop artificial port printing restriction,
Phil Sutter
- [PATCH nft] tests: meta: test hour decoding wrap,
Florian Westphal
- [PATCH nft] meta: fix hour decoding when timezone offset is negative, Florian Westphal
- [GIT PULL] Landlock updates for v6.7,
Mickaël Salaün
- [PATCH nft 1/2] json: implement json() hook for "symbol_expr_ops"/"variabl_expr_ops",
Thomas Haller
- [PATCH nft 1/1] tests/shell: fix mount command in "test-wrapper.sh",
Thomas Haller
- [PATCH] netfilter: bridge: initialize err to 0,
xiaolinkui
- [PATCH net-next] netfilter: nf_tables: Remove unused variable nft_net,
Yang Li
- [PATCH nft 0/7] add and check dump files for JSON in tests/shell,
Thomas Haller
- [PATCH AUTOSEL 4.19 05/12] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- [PATCH AUTOSEL 5.15 17/28] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- [PATCH AUTOSEL 5.4 06/13] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- [PATCH AUTOSEL 5.10 07/16] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- [PATCH AUTOSEL 4.14 05/11] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- [PATCH AUTOSEL 6.1 35/39] netfilter: nf_tables: audit log object reset once per table, Sasha Levin
- [PATCH AUTOSEL 6.1 18/39] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- [PATCH AUTOSEL 6.5 47/52] netfilter: nf_tables: audit log object reset once per table, Sasha Levin
- [PATCH AUTOSEL 6.5 24/52] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
- Re: [RFC Draft PATCHv2 net-next] Doc: update bridge doc,
Florian Westphal
- [PATCH net-next 0/4] net: fill in 18 MODULE_DESCRIPTION()s, Jakub Kicinski
- [PATCH 01/10] man: display number ranges with an en dash,
Jan Engelhardt
- [PATCH v14 00/12] Network support for Landlock,
Konstantin Meskhidze
- [PATCH v14 01/12] landlock: Make ruleset's access masks more generic, Konstantin Meskhidze
- [PATCH v14 02/12] landlock: Allow FS topology changes for domains without such rule type, Konstantin Meskhidze
- [PATCH v14 03/12] landlock: Refactor landlock_find_rule/insert_rule, Konstantin Meskhidze
- [PATCH v14 04/12] landlock: Refactor merge/inherit_ruleset functions, Konstantin Meskhidze
- [PATCH v14 05/12] landlock: Move and rename layer helpers, Konstantin Meskhidze
- [PATCH v14 06/12] landlock: Refactor layer helpers, Konstantin Meskhidze
- [PATCH v14 07/12] landlock: Refactor landlock_add_rule() syscall, Konstantin Meskhidze
- [PATCH v14 08/12] landlock: Add network rules and TCP hooks support, Konstantin Meskhidze
- [PATCH v14 09/12] selftests/landlock: Share enforce_ruleset(), Konstantin Meskhidze
- [PATCH v14 11/12] samples/landlock: Support TCP restrictions, Konstantin Meskhidze
- [PATCH v14 10/12] selftests/landlock: Add network tests, Konstantin Meskhidze
- [PATCH v14 12/12] landlock: Document network support, Konstantin Meskhidze
- Re: [PATCH v14 00/12] Network support for Landlock, Mickaël Salaün
- [PATCH] selftests/landlock: Add tests for FS topology changes with network rules, Mickaël Salaün
- [nf-next PATCH v3 0/3] Add locking for NFT_MSG_GETOBJ_RESET requests,
Phil Sutter
- [PATCH nft] evaluate: reject set in concatenation, Pablo Neira Ayuso
- [PATCH nf] sched: act_ct: additional checks for outdated flows,
Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_flow_table: GC pushes back packets to classic path,
Pablo Neira Ayuso
- [PATCH net] netfilter: flowtable: additional checks for outdated flows,
Vlad Buslov
- [PATCH 1/6] man: encode minushyphen the way groff/man requires it,
Jan Engelhardt
- [nf-next PATCH] netfilter: nf_tables: Carry reset boolean in nft_set_dump_ctx, Phil Sutter
- [iptables PATCH 0/2] Fix up string match man page,
Phil Sutter
- [PATCH nft] check-tree.sh: check and flag /bin/sh usage,
Florian Westphal
- [PATCH nft v2 0/4] [RESENT] remove xfree() and add free_const()+nft_gmp_free(),
Thomas Haller
- Fwd: Guidance on deterministic NAT (CGNAT), Clint Todish
- [PATCH nf-next 0/5] nf_tables set updates,
Pablo Neira Ayuso
- [PATCH libnetfilter_queue 0/1] libnfnetlink dependency elimination,
Duncan Roe
- [PATCH nft 1/3] tests/shell: add "bogons/nft-f/zero_length_devicename2_assert",
Thomas Haller
- [PATCH nft 1/2] tests/shell: inline input data in "single_anon_set" test,
Thomas Haller
- [PATCH nft 1/1] tests/shell: test for maximum length of "comment" in "comments_objects_0", Thomas Haller
- [PATCH nft] tests/shell: add missing "elem_opts_compat_0.nodump" file,
Thomas Haller
- [PATCH netfilter] Fix hw flow offload from nftables,
Donald Hunter
- Re: KASAN: vmalloc-out-of-bounds in ipt_do_table,
Pablo Neira Ayuso
- [PATCH libnetfilter_queue] include: all: remove trailing spaces, Duncan Roe
- Netfilter queue is unable to mangle fragmented UDP6: bug?,
Duncan Roe
- [PATCH libnetfilter_queue v2 0/1] New example program nfq6,
Duncan Roe
- [PATCH] treewide: Add SPDX identifier to IETF ASN.1 modules,
Lukas Wunner
- [nf-next PATCH 0/6] Refactor nft_obj_filter into nft_obj_dump_ctx,
Phil Sutter
- [PATCH nf-next] netfilter: conntrack: switch connlabels to atomic_t,
Florian Westphal
- [PATCH nf-next] br_netfilter: use single forward hook for ip and arp,
Florian Westphal
- [PATCH RFC] netfilter: nf_tables: add flowtable map for xdp offload,
Florian Westphal
- [PATCH 0/1] ipset patch to fix race condition between swap/destroy and add/del/test,
Jozsef Kadlecsik
- [PATCH v5 05/12] x86/bugs: Rename RETPOLINE to MITIGATION_RETPOLINE, Breno Leitao
- [nft PATCH v2] parser_bison: Fix for broken compatibility with older dumps,
Phil Sutter
- [nft PATCH] parser_bison: Fix for broken compatibility with older dumps, Phil Sutter
- [PATCH nf-next,RFC 0/8] nf_tables set updates,
Pablo Neira Ayuso
- [PATCH nf-next,RFC 1/8] netfilter: nft_set_pipapo: no need to call pipapo_deactivate() from flush, Pablo Neira Ayuso
- [PATCH nf-next,RFC 2/8] netfilter: nf_tables: set backend .flush always succeeds, Pablo Neira Ayuso
- [PATCH nf-next,RFC 7/8] netfilter: nf_tables: add timeout extension to elements to prepare for updates, Pablo Neira Ayuso
- [PATCH nf-next,RFC 6/8] netfilter: nf_tables: use timestamp to check for set element timeout, Pablo Neira Ayuso
- [PATCH nf-next,RFC 5/8] netfilter: nf_tables: set->ops->insert returns opaque set element in case of EEXIST, Pablo Neira Ayuso
- [PATCH nf-next,RFC 8/8] netfilter: nf_tables: set element timeout update support, Pablo Neira Ayuso
- [PATCH nf-next,RFC 3/8] netfilter: nf_tables: expose opaque set element as struct nft_elem_priv, Pablo Neira Ayuso
- [PATCH nf-next,RFC 4/8] netfilter: nf_tables: shrink memory consumption of set elements, Pablo Neira Ayuso
- [nf-next PATCH v4 0/3] Introduce locking for rule reset requests,
Phil Sutter
- [PATCH nft v2 0/7] no recursive make,
Thomas Haller
- [ANNOUNCE] nftables 1.0.9 release, Pablo Neira Ayuso
- [nf-next PATCH v3 0/3] Introduce locking for rule reset requests,
Phil Sutter
- [PATCH nf-next,RFC 2/2] netfilter: nf_tables: set element timeout update support, Pablo Neira Ayuso
- [PATCH nf-next,RFC 1/2] netfilter: nf_tables: add timeout extension to elements to prepare for updates, Pablo Neira Ayuso
- [PATCH net 0/4] netfilter: updates for net,
Florian Westphal
- [PATCH nf] Revert "netfilter: nf_tables: do not remove elements if set backend implements .abort", Pablo Neira Ayuso
- Re: [nftables/nft] nft equivalent of "ipset test",
imnozi
- [PATCH nft 1/1] tests/shell: add NFT_TEST_FAIL_ON_SKIP_EXCEPT for allow-list of skipped tests (XFAIL),
Thomas Haller
- [syzbot] [netfilter?] WARNING in __nf_unregister_net_hook (6), syzbot
- [PATCH nft] evaluate: validate maximum log statement prefix length, Pablo Neira Ayuso
- [PATCH] netfilter: ipset: fix race condition in ipset swap, destroy and test/add/del,
xiaolinkui
- [PATCH nf] netfilter: nft_set_rbtree: .deactivate fails if element has expired, Pablo Neira Ayuso
- [net-next PATCH v2] net: skb_find_text: Ignore patterns extending past 'to',
Phil Sutter
- [PATCH nft v2 0/3] add "eval-exit-code" and skip tests based on kernel version,
Thomas Haller
- 0x17: Schedule is now up, Jamal Hadi Salim
- [PATCH 1/2] netfilter: ipset: rename ref_netlink to ref_swapping,
xiaolinkui
- [PATCH nft 1/2] tests/shell: use bash instead of /bin/sh for tests,
Thomas Haller
- [PATCH nft 1/3] tests/shell: skip "table_onoff" test if kernel patch is missing,
Thomas Haller
- [PATCH libnetfilter_queue 0/1] New example program nfq6,
Duncan Roe
- [PATCH v13 00/12] Network support for Landlock,
Konstantin Meskhidze
- [PATCH v13 01/12] landlock: Make ruleset's access masks more generic, Konstantin Meskhidze
- [PATCH v13 03/12] landlock: Refactor landlock_find_rule/insert_rule, Konstantin Meskhidze
- [PATCH v13 02/12] landlock: Allow FS topology changes for domains without such rule type, Konstantin Meskhidze
- [PATCH v13 04/12] landlock: Refactor merge/inherit_ruleset functions, Konstantin Meskhidze
- [PATCH v13 05/12] landlock: Move and rename layer helpers, Konstantin Meskhidze
- [PATCH v13 06/12] landlock: Refactor layer helpers, Konstantin Meskhidze
- [PATCH v13 09/12] selftests/landlock: Share enforce_ruleset(), Konstantin Meskhidze
- [PATCH v13 08/12] landlock: Add network rules and TCP hooks support, Konstantin Meskhidze
- [PATCH v13 07/12] landlock: Refactor landlock_add_rule() syscall, Konstantin Meskhidze
- [PATCH v13 11/12] samples/landlock: Add network demo, Konstantin Meskhidze
- [PATCH v13 10/12] selftests/landlock: Add 7 new test variants dedicated to network, Konstantin Meskhidze
- [PATCH v13 12/12] landlock: Document Landlock's network support, Konstantin Meskhidze
- [nf PATCH] selftests: netfilter: Run nft_audit.sh in its own netns, Phil Sutter
- [net-next PATCH] net: skb_find_text: Ignore patterns extending past 'to',
Phil Sutter
- [PATCH nf-next,RFC] netfilter: nf_tables: shrink memory consumption of set elements,
Pablo Neira Ayuso
- [PATCH nf-next 0/3] netfilter: nf_tables: remove rbtree async garbage collection,
Florian Westphal
- [PATCH nft] evaluate: suggest != in negation error message,
Florian Westphal
- [PATCH conntrack,v6] conntrack: ct label update requires proper ruleset, Pablo Neira Ayuso
- [PATCH conntrack,v4] conntrack: label update requires a previous label in place, Pablo Neira Ayuso
- [iptables PATCH] extensions: string: Clarify description of --to,
Phil Sutter
- [iptables PATCH] libiptc: Fix for another segfault due to chain index NULL pointer,
Phil Sutter
- [nf PATCH v2] netfilter: nf_tables: audit log object reset once per table, Phil Sutter
- [PATCH conntrack,v3] conntrack: label update requires a previous label in place, Pablo Neira Ayuso
- [PATCH conntrack] conntrack: label update requires a previous label in place,
Pablo Neira Ayuso
- [PATCH nf-next 0/6] netfilter: more accurate drop statistics,
Florian Westphal
- [PATCH nft,v2] doc: remove references to timeout in reset command,
Pablo Neira Ayuso
- [PATCH net-next 0/8] netfilter updates for next,
Florian Westphal
- [PATCH nft] doc: remove references to timeout in reset command,
Pablo Neira Ayuso
- [ANNOUNCE] iptables 1.8.10 release, Phil Sutter
- [RFC] nftables 1.0.6 -stable backports,
Pablo Neira Ayuso
- [PATCH nf 1/2] nf_tables: fix NULL pointer dereference in nft_inner_init(),
Xingyuan Mo
- [PATCH nf] netfilter: nft_payload: fix wrong mac header matching, Florian Westphal
- [PATCH libnetfilter_queue] src: Fix IPv6 Fragment Header processing,
Duncan Roe
- iptales-restore cmd crash, wenli xie
- [PATCH] netfilter: remove inaccurate code comments from struct nft_table,
George Guo
- [nft PATCH 1/3] tests/shell: mount all of "/var/run" in "test-wrapper.sh",
Thomas Haller
- [PATCH nf-next] netfilter: conntrack: prefer tcp_error_log to pr_debug, Florian Westphal
- [PATCH nf-next] netfilter: conntrack: simplify nf_conntrack_alter_reply, Florian Westphal
- [PATCH] netfilter: ipset: wait for xt_recseq on all cpus,
xiaolinkui
- [PATCH nf] netfilter: nf_tables: work around newrule after chain binding, Florian Westphal
- [PATCH nf] netfilter: nfnetlink_log: silence bogus compiler warning, Florian Westphal
- [PATCH net 0/6] netfilter patches for net,
Florian Westphal
- [PATCH nf] netfilter: nf_tables: do not remove elements if set backend implements .abort, Pablo Neira Ayuso
- [PATCH] netfilter: nf_tables: Annotate struct nft_pipapo_match with __counted_by,
Kees Cook
- [PATCHv2 nf 0/2] netfilter: handle the sctp collision properly and add selftest,
Xin Long
- [PATCH nf,v2] netfilter: nf_tables: do not refresh timeout when resetting element, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: do not refresh timeout when resetting element,
Pablo Neira Ayuso
- [PATCH nf] netfilter: handle the connecting collision properly in nf_conntrack_proto_sctp,
Xin Long
- [nf-next PATCH 0/5] nf_tables: nft_rule_dump_ctx fits into netlink_callback,
Phil Sutter
- [nft PATCH] tests: shell: sets/reset_command_0: Fix drop_seconds(),
Phil Sutter
- [PATCH nf 1/2] netfilter: nft_set_rbtree: move sync GC from insert path to set->ops->commit,
Pablo Neira Ayuso
- [ANNOUNCE] conntrack-tools 1.4.8 release, Pablo Neira Ayuso
- [PATCH nft] rule: never merge across non-expr statements, Florian Westphal
- [PATCH libnetfilter_conntrack] src: reverse calloc() invocation, Pablo Neira Ayuso
- [PATCH nft] tests: shell: add vlan match test case, Florian Westphal
- [PATCH nf] netfilter: nft_payload: rebuild vlan header on h_proto access,
Florian Westphal
- [PATCH libnetfilter_queue v3] make the HTML main page available as `man 7 libnetfilter_queue`, Duncan Roe
- [nf PATCH v2 0/8] Introduce locking for reset requests,
Phil Sutter
- [nft PATCH] tests: shell: Fix for failing nft-f/sample-ruleset, Phil Sutter
- [PATCH nf] netfilter: nf_tables: nft_set_rbtree: fix spurious insertion failure,
Florian Westphal
- [PATCH nft 0/5] more various cleanups related to struct datatype,
Thomas Haller
- [PATCH nft 1/1] include: include <string.h> in <nft.h>,
Thomas Haller
- [PATCH v3 0/2] Prevent potential write out of bounds,
joao
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]