Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [PATCH nft v3 2/6] tests/shell: check and generate JSON dump files, (continued)
- [PATCH nft,v2] src: expand create commands, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: split async and sync catchall in two functions, Pablo Neira Ayuso
- [PATCH 0/1] ipset patch to fix race condition between swap/destroy and add/del/test, v3,
Jozsef Kadlecsik
- [PATCH nf] netfilter: nf_tables: bogus ENOENT when destroying element which does not exist, Pablo Neira Ayuso
- [PATCH nft] src: expand create commands, Pablo Neira Ayuso
- [PATCH nft,v2 01/11] tests: shell: skip pipapo tests if kernel lacks support,
Pablo Neira Ayuso
- [PATCH nft,v2 06/11] tests: shell: skip multidevice chain tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft,v2 03/11] tests: shell: skip stateful expression in sets tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft,v2 02/11] tests: shell: skip prerouting reject tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft,v2 04/11] tests: shell: skip NAT netmap tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft,v2 05/11] tests: shell: skip comment tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft,v2 07/11] tests: shell: skip if kernel does not support bitshift, Pablo Neira Ayuso
- [PATCH nft,v2 10/11] tests: shell: split single element in anonymous set, Pablo Neira Ayuso
- [PATCH nft,v2 08/11] tests: shell: split set NAT interval test, Pablo Neira Ayuso
- [PATCH nft,v2 09/11] tests: shell: split map test, Pablo Neira Ayuso
- [PATCH nft,v2 11/11] tests: shell: split merge nat optimization in two tests, Pablo Neira Ayuso
- ebtables documentation updates,
Jan Engelhardt
- iptables manpage updates,
Jan Engelhardt
- libnfnetlink dependency elimination,
Duncan Roe
- [PATCH libnetfilter_queue] utils: Add example of setting socket buffer size,
Duncan Roe
- [PATCH nft 1/3] parser: don't mark "string" as const,
Thomas Haller
- [PATCH nft 00/12] update tests/shell for 5.4 kernels,
Pablo Neira Ayuso
- [PATCH nft 02/12] tests: shell: skip pipapo tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft 03/12] tests: shell: skip prerouting reject tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft 01/12] tests: shell: export DIFF to use it from feature scripts, Pablo Neira Ayuso
- [PATCH nft 06/12] tests: shell: skip comment tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft 08/12] tests: shell: skip if kernel does not support bitshift, Pablo Neira Ayuso
- [PATCH nft 04/12] tests: shell: skip stateful expression in sets tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft 12/12] tests: shell: split merge nat optimization in two tests, Pablo Neira Ayuso
- [PATCH nft 05/12] tests: shell: skip NAT netmap tests if kernel lacks support, Pablo Neira Ayuso
- [PATCH nft 09/12] tests: shell: split set NAT interval test, Pablo Neira Ayuso
- [PATCH nft 10/12] tests: shell: split map test, Pablo Neira Ayuso
- [PATCH nft 11/12] tests: shell: split single element in anonymous set, Pablo Neira Ayuso
- [PATCH nft 07/12] tests: shell: skip multidevice chain tests if kernel lacks support, Pablo Neira Ayuso
- Re: [PATCH nft 00/12] update tests/shell for 5.4 kernels, Florian Westphal
- [nf-next PATCH v4 0/3] Add locking for NFT_MSG_GETSETELEM_RESET,
Phil Sutter
- [PATCH nft 1/2] utils: add memory_allocation_check() helper,
Thomas Haller
- [PATCH nft] netlink: fix buffer size for user data in netlink_delinearize_chain(),
Thomas Haller
- [PATCH nf] netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses, Florian Westphal
- [iptables PATCH 1/3] arptables: Fix formatting of numeric --h-type output,
Phil Sutter
- [iptables PATCH] ebtables: Fix corner-case noflush restore bug,
Phil Sutter
- [PATCH v2 iptables 0/4] xtables-nft: add arptranslate support,
Florian Westphal
- [PATCH nf] ipvs: add missing module descriptions,
Florian Westphal
- [PATCH nft,v2 1/2] evaluate: reset statement length context only for set mappings,
Pablo Neira Ayuso
- [PATCH nf,v4] netfilter: nf_tables: remove catchall element in GC sync path, Pablo Neira Ayuso
- [PATCH nf,v3] netfilter: nf_tables: remove catchall element in GC sync path,
Pablo Neira Ayuso
- [PATCH nf,v2] netfilter: nf_tables: remove catchall element in GC sync path, Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: remove catchall element in GC sync path, Pablo Neira Ayuso
- [PATCH nft] evaluate: place byteorder conversion before rshift in payload expressions, Pablo Neira Ayuso
- [PATCH net v2] netfilter: xt_recent: fix (increase) ipv6 literal buffer length,
Maciej Żenczykowski
- [PATCH nft] evaluate: reset statement length context only for set mappings, Pablo Neira Ayuso
- [PATCH nft v2 0/5] add infrastructure for unit tests,
Thomas Haller
- [PATCH libmnl v2] nlmsg: fix false positives when validating buffer sizes,
Jeremy Sowden
- [PATCH net] net: xt_recent: fix (increase) ipv6 literal buffer length,
Maciej Żenczykowski
- [PATCH nf] netfilter: add missing module descriptions, Florian Westphal
- [PATCH 0/1] ipset patch to fix race condition between swap/destroy and add/del/test, v2,
Jozsef Kadlecsik
- [PATCH] netfilter: nat: add MODULE_DESCRIPTION,
Randy Dunlap
- [PATCH nft v2 0/6] add and check dump files for JSON in tests/shell,
Thomas Haller
- Re: [PATCH nft v2 0/6] add and check dump files for JSON in tests/shell, Pablo Neira Ayuso
[PATCH nft v3 0/2] drop warning messages from stmt_print_json()/expr_print_json(),
Thomas Haller
[PATCH nft 0/6] add infrastructure for unit tests,
Thomas Haller
- [PATCH nft 4/6] build: add check for consistency of source tree, Thomas Haller
- [PATCH nft 1/6] gitignore: ignore build artifacts from top level file, Thomas Haller
- [PATCH nft 5/6] build: cleanup if blocks for conditional compilation, Thomas Haller
- [PATCH nft 2/6] build: add basic "check-{local,more,all}" and "build-all" make targets, Thomas Haller
- [PATCH nft 3/6] build: add `make check-tests-build` to add build test, Thomas Haller
- [PATCH nft 6/6] tests/unit: add unit tests for libnftables, Thomas Haller
- Re: [PATCH nft 0/6] add infrastructure for unit tests, Pablo Neira Ayuso
- Re: [PATCH nft 0/6] add infrastructure for unit tests, Florian Westphal
Re: net/netfilter/nft_set_rbtree.c:636:33: warning: variable 'nft_net' set but not used, Pablo Neira Ayuso
[PATCH iptables 0/4] add arptables-translate,
Florian Westphal
[PATCH net] netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval(),
Dan Carpenter
[nft PATCH v2] tests: shell: Fix sets/reset_command_0 for current kernels,
Phil Sutter
[nft PATCH] tests: shell: Fix sets/reset_command_0 for current kernels,
Phil Sutter
[nf-next PATCH v3] netfilter: nf_tables: Add locking for NFT_MSG_GETSETELEM_RESET requests,
Phil Sutter
[nft PATCH] tproxy: Drop artificial port printing restriction,
Phil Sutter
[PATCH nft] tests: meta: test hour decoding wrap,
Florian Westphal
[PATCH nft] meta: fix hour decoding when timezone offset is negative, Florian Westphal
[GIT PULL] Landlock updates for v6.7,
Mickaël Salaün
[PATCH nft 1/2] json: implement json() hook for "symbol_expr_ops"/"variabl_expr_ops",
Thomas Haller
[PATCH nft 1/1] tests/shell: fix mount command in "test-wrapper.sh",
Thomas Haller
[PATCH] netfilter: bridge: initialize err to 0,
xiaolinkui
[PATCH net-next] netfilter: nf_tables: Remove unused variable nft_net,
Yang Li
[PATCH nft 0/7] add and check dump files for JSON in tests/shell,
Thomas Haller
[PATCH AUTOSEL 4.19 05/12] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
[PATCH AUTOSEL 5.15 17/28] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
[PATCH AUTOSEL 5.4 06/13] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
[PATCH AUTOSEL 5.10 07/16] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
[PATCH AUTOSEL 4.14 05/11] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
[PATCH AUTOSEL 6.1 35/39] netfilter: nf_tables: audit log object reset once per table, Sasha Levin
[PATCH AUTOSEL 6.1 18/39] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
[PATCH AUTOSEL 6.5 47/52] netfilter: nf_tables: audit log object reset once per table, Sasha Levin
[PATCH AUTOSEL 6.5 24/52] netfilter: nfnetlink_log: silence bogus compiler warning, Sasha Levin
Re: [RFC Draft PATCHv2 net-next] Doc: update bridge doc,
Florian Westphal
[PATCH net-next 0/4] net: fill in 18 MODULE_DESCRIPTION()s, Jakub Kicinski
[PATCH 01/10] man: display number ranges with an en dash,
Jan Engelhardt
[PATCH v14 00/12] Network support for Landlock,
Konstantin Meskhidze
- [PATCH v14 01/12] landlock: Make ruleset's access masks more generic, Konstantin Meskhidze
- [PATCH v14 02/12] landlock: Allow FS topology changes for domains without such rule type, Konstantin Meskhidze
- [PATCH v14 03/12] landlock: Refactor landlock_find_rule/insert_rule, Konstantin Meskhidze
- [PATCH v14 04/12] landlock: Refactor merge/inherit_ruleset functions, Konstantin Meskhidze
- [PATCH v14 05/12] landlock: Move and rename layer helpers, Konstantin Meskhidze
- [PATCH v14 06/12] landlock: Refactor layer helpers, Konstantin Meskhidze
- [PATCH v14 07/12] landlock: Refactor landlock_add_rule() syscall, Konstantin Meskhidze
- [PATCH v14 08/12] landlock: Add network rules and TCP hooks support, Konstantin Meskhidze
- [PATCH v14 09/12] selftests/landlock: Share enforce_ruleset(), Konstantin Meskhidze
- [PATCH v14 11/12] samples/landlock: Support TCP restrictions, Konstantin Meskhidze
- [PATCH v14 10/12] selftests/landlock: Add network tests, Konstantin Meskhidze
- [PATCH v14 12/12] landlock: Document network support, Konstantin Meskhidze
- Re: [PATCH v14 00/12] Network support for Landlock, Mickaël Salaün
- [PATCH] selftests/landlock: Add tests for FS topology changes with network rules, Mickaël Salaün
[nf-next PATCH v3 0/3] Add locking for NFT_MSG_GETOBJ_RESET requests,
Phil Sutter
[PATCH nft] evaluate: reject set in concatenation, Pablo Neira Ayuso
[PATCH nf] sched: act_ct: additional checks for outdated flows,
Pablo Neira Ayuso
[PATCH nf] netfilter: nf_flow_table: GC pushes back packets to classic path,
Pablo Neira Ayuso
[PATCH net] netfilter: flowtable: additional checks for outdated flows,
Vlad Buslov
[PATCH 1/6] man: encode minushyphen the way groff/man requires it,
Jan Engelhardt
[nf-next PATCH] netfilter: nf_tables: Carry reset boolean in nft_set_dump_ctx, Phil Sutter
[iptables PATCH 0/2] Fix up string match man page,
Phil Sutter
[PATCH nft] check-tree.sh: check and flag /bin/sh usage,
Florian Westphal
[PATCH nft v2 0/4] [RESENT] remove xfree() and add free_const()+nft_gmp_free(),
Thomas Haller
Fwd: Guidance on deterministic NAT (CGNAT), Clint Todish
[PATCH nf-next 0/5] nf_tables set updates,
Pablo Neira Ayuso
[PATCH libnetfilter_queue 0/1] libnfnetlink dependency elimination,
Duncan Roe
[PATCH nft 1/3] tests/shell: add "bogons/nft-f/zero_length_devicename2_assert",
Thomas Haller
[PATCH nft 1/2] tests/shell: inline input data in "single_anon_set" test,
Thomas Haller
[PATCH nft 1/1] tests/shell: test for maximum length of "comment" in "comments_objects_0", Thomas Haller
[PATCH nft] tests/shell: add missing "elem_opts_compat_0.nodump" file,
Thomas Haller
[PATCH netfilter] Fix hw flow offload from nftables,
Donald Hunter
Re: KASAN: vmalloc-out-of-bounds in ipt_do_table,
Pablo Neira Ayuso
[PATCH libnetfilter_queue] include: all: remove trailing spaces, Duncan Roe
Netfilter queue is unable to mangle fragmented UDP6: bug?,
Duncan Roe
[PATCH libnetfilter_queue v2 0/1] New example program nfq6,
Duncan Roe
[PATCH] treewide: Add SPDX identifier to IETF ASN.1 modules,
Lukas Wunner
[nf-next PATCH 0/6] Refactor nft_obj_filter into nft_obj_dump_ctx,
Phil Sutter
[PATCH nf-next] netfilter: conntrack: switch connlabels to atomic_t,
Florian Westphal
[PATCH nf-next] br_netfilter: use single forward hook for ip and arp,
Florian Westphal
[PATCH RFC] netfilter: nf_tables: add flowtable map for xdp offload,
Florian Westphal
[PATCH 0/1] ipset patch to fix race condition between swap/destroy and add/del/test,
Jozsef Kadlecsik
[PATCH v5 05/12] x86/bugs: Rename RETPOLINE to MITIGATION_RETPOLINE, Breno Leitao
[nft PATCH v2] parser_bison: Fix for broken compatibility with older dumps,
Phil Sutter
[nft PATCH] parser_bison: Fix for broken compatibility with older dumps, Phil Sutter
[PATCH nf-next,RFC 0/8] nf_tables set updates,
Pablo Neira Ayuso
- [PATCH nf-next,RFC 1/8] netfilter: nft_set_pipapo: no need to call pipapo_deactivate() from flush, Pablo Neira Ayuso
- [PATCH nf-next,RFC 2/8] netfilter: nf_tables: set backend .flush always succeeds, Pablo Neira Ayuso
- [PATCH nf-next,RFC 7/8] netfilter: nf_tables: add timeout extension to elements to prepare for updates, Pablo Neira Ayuso
- [PATCH nf-next,RFC 6/8] netfilter: nf_tables: use timestamp to check for set element timeout, Pablo Neira Ayuso
- [PATCH nf-next,RFC 5/8] netfilter: nf_tables: set->ops->insert returns opaque set element in case of EEXIST, Pablo Neira Ayuso
- [PATCH nf-next,RFC 8/8] netfilter: nf_tables: set element timeout update support, Pablo Neira Ayuso
- [PATCH nf-next,RFC 3/8] netfilter: nf_tables: expose opaque set element as struct nft_elem_priv, Pablo Neira Ayuso
- [PATCH nf-next,RFC 4/8] netfilter: nf_tables: shrink memory consumption of set elements, Pablo Neira Ayuso
[nf-next PATCH v4 0/3] Introduce locking for rule reset requests,
Phil Sutter
[PATCH nft v2 0/7] no recursive make,
Thomas Haller
[ANNOUNCE] nftables 1.0.9 release, Pablo Neira Ayuso
[nf-next PATCH v3 0/3] Introduce locking for rule reset requests,
Phil Sutter
[PATCH nf-next,RFC 2/2] netfilter: nf_tables: set element timeout update support, Pablo Neira Ayuso
[PATCH nf-next,RFC 1/2] netfilter: nf_tables: add timeout extension to elements to prepare for updates, Pablo Neira Ayuso
[PATCH net 0/4] netfilter: updates for net,
Florian Westphal
[PATCH nf] Revert "netfilter: nf_tables: do not remove elements if set backend implements .abort", Pablo Neira Ayuso
Re: [nftables/nft] nft equivalent of "ipset test",
imnozi
[PATCH nft 1/1] tests/shell: add NFT_TEST_FAIL_ON_SKIP_EXCEPT for allow-list of skipped tests (XFAIL),
Thomas Haller
[syzbot] [netfilter?] WARNING in __nf_unregister_net_hook (6), syzbot
[PATCH nft] evaluate: validate maximum log statement prefix length, Pablo Neira Ayuso
[PATCH] netfilter: ipset: fix race condition in ipset swap, destroy and test/add/del,
xiaolinkui
[PATCH nf] netfilter: nft_set_rbtree: .deactivate fails if element has expired, Pablo Neira Ayuso
[net-next PATCH v2] net: skb_find_text: Ignore patterns extending past 'to',
Phil Sutter
[PATCH nft v2 0/3] add "eval-exit-code" and skip tests based on kernel version,
Thomas Haller
0x17: Schedule is now up, Jamal Hadi Salim
[PATCH 1/2] netfilter: ipset: rename ref_netlink to ref_swapping,
xiaolinkui
[PATCH nft 1/2] tests/shell: use bash instead of /bin/sh for tests,
Thomas Haller
[PATCH nft 1/3] tests/shell: skip "table_onoff" test if kernel patch is missing,
Thomas Haller
[PATCH libnetfilter_queue 0/1] New example program nfq6,
Duncan Roe
[PATCH v13 00/12] Network support for Landlock,
Konstantin Meskhidze
- [PATCH v13 01/12] landlock: Make ruleset's access masks more generic, Konstantin Meskhidze
- [PATCH v13 03/12] landlock: Refactor landlock_find_rule/insert_rule, Konstantin Meskhidze
- [PATCH v13 02/12] landlock: Allow FS topology changes for domains without such rule type, Konstantin Meskhidze
- [PATCH v13 04/12] landlock: Refactor merge/inherit_ruleset functions, Konstantin Meskhidze
- [PATCH v13 05/12] landlock: Move and rename layer helpers, Konstantin Meskhidze
- [PATCH v13 06/12] landlock: Refactor layer helpers, Konstantin Meskhidze
- [PATCH v13 09/12] selftests/landlock: Share enforce_ruleset(), Konstantin Meskhidze
- [PATCH v13 08/12] landlock: Add network rules and TCP hooks support, Konstantin Meskhidze
- [PATCH v13 07/12] landlock: Refactor landlock_add_rule() syscall, Konstantin Meskhidze
- [PATCH v13 11/12] samples/landlock: Add network demo, Konstantin Meskhidze
- [PATCH v13 10/12] selftests/landlock: Add 7 new test variants dedicated to network, Konstantin Meskhidze
- [PATCH v13 12/12] landlock: Document Landlock's network support, Konstantin Meskhidze
[nf PATCH] selftests: netfilter: Run nft_audit.sh in its own netns, Phil Sutter
[net-next PATCH] net: skb_find_text: Ignore patterns extending past 'to',
Phil Sutter
[PATCH nf-next,RFC] netfilter: nf_tables: shrink memory consumption of set elements,
Pablo Neira Ayuso
[PATCH nf-next 0/3] netfilter: nf_tables: remove rbtree async garbage collection,
Florian Westphal
[PATCH nft] evaluate: suggest != in negation error message,
Florian Westphal
[PATCH conntrack,v6] conntrack: ct label update requires proper ruleset, Pablo Neira Ayuso
[PATCH conntrack,v4] conntrack: label update requires a previous label in place, Pablo Neira Ayuso
[iptables PATCH] extensions: string: Clarify description of --to,
Phil Sutter
[iptables PATCH] libiptc: Fix for another segfault due to chain index NULL pointer,
Phil Sutter
[nf PATCH v2] netfilter: nf_tables: audit log object reset once per table, Phil Sutter
[PATCH conntrack,v3] conntrack: label update requires a previous label in place, Pablo Neira Ayuso
[PATCH conntrack] conntrack: label update requires a previous label in place,
Pablo Neira Ayuso
[PATCH nf-next 0/6] netfilter: more accurate drop statistics,
Florian Westphal
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]