Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- [PATCH nf-next 2/3] netfilter: nf_tables: add enum nft_flowtable_flags to uapi
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: conntrack: export nf_ct_acct_update()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 1/3] netfilter: flowtable: Use rw sem as flow block lock
- From: Paul Blakey <paulb@xxxxxxxxxxxx>
- [PATCH net-next 3/3] net/mlx5: CT: Use rhashtable's ct entries instead of a seperate list
- From: Paul Blakey <paulb@xxxxxxxxxxxx>
- [PATCH net-next 2/3] netfilter: flowtable: Use work entry per offload command
- From: Paul Blakey <paulb@xxxxxxxxxxxx>
- [PATCH net-next 0/3] netfilter: flowtable: Support offload of tuples in parallel
- From: Paul Blakey <paulb@xxxxxxxxxxxx>
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/2] netfilter: nft_fwd_netdev: validate family and chain type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf 2/2] netfilter: nft_fwd_netdev: allow to redirect to ifb via ingress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH net-next v2] netfilter: Fix incorrect tc_setup_type type for flowtable offload
- Re: [PATCH net-next] flow_offload: add TC_SETP_FT type in flow_indr_block_call
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH v3 nf] selftests: netfilter: add nfqueue test case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] selftests: netfilter: add nfqueue test case
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf] selftests: netfilter: add nfqueue test case
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] selftests: netfilter: add nfqueue test case
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: general protection fault in nf_flow_table_offload_setup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: general protection fault in nf_flow_table_offload_setup
- From: syzbot <syzbot+e93c1d9ae19a0236289c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_ip_add
- From: syzbot <syzbot+f3e96783d74ee8ea9aa3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nf v2 4/4] nft_set_rbtree: Detect partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf v2 3/4] nft_set_rbtree: Introduce and use nft_rbtree_interval_start()
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf v2 2/4] nft_set_pipapo: Separate partial and complete overlap cases on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf v2 1/4] nf_tables: Allow set back-ends to report partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf v2 0/4] nftables: Consistently report partial and entire set overlaps
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH NOMERGE iptables 2/2] man: xt_set: Describe --update-counters-first flag
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH NOMERGE iptables 1/2] man: xt_set: Reflect current behaviour of counter update and match flags
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH NOMERGE iptables 0/2] man: xt_set: Describe existing behaviour and new counters update flag
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 3/3] net/sched: act_ct: add nf_conn_acct for SW act_ct flowtable offload
- [PATCH nf-next 0/3] netfilter: nf_flow_table_offload: add nf_conn_acct for flowtable offload
- [PATCH nf-next 1/3] netfilter: nf_flow_table: add nf_conn_acct for SW flowtable offload
- [PATCH nf-next 2/3] netfilter: nf_flow_table: add nf_conn_acct for HW flowtable offload
- Re: [PATCH 0/4] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH 1/4] netfilter: flowtable: reload ip{v6}h in nf_flow_nat_ip{v6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] netfilter: flowtable: populate addr_type mask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/4] netfilter: flowtable: Fix flushing of offloaded flows on free
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/4] netfilter: flowtable: reload ip{v6}h in nf_flow_tuple_ip{v6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/4] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2] netfilter: nf_flow_table_offload: set hw_stats_type of flow_action_entry to FLOW_ACTION_HW_STATS_ANY
- Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] tests: py: update nat expressions payload to include proto flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 2/2] expr: nat: snprint flags in hexadecimal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 1/2] expr: masq: revisit _snprintf()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter:nf_flow_table: add HW stats type support in flowtable
- Re: INFO: task hung in htable_put
- From: syzbot <syzbot+84936245a918e2cddb32@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH] iptables: open eBPF programs in read only mode
- From: Maciej Żenczykowski <zenczykowski@xxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_flow_table: populate addr_type mask
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nf_flow_table_offload: fix potential NULL pointer dereference for dst_cache in handling lwtstate
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 2/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_tuple_ip{v6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 1/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_nat_ip{v6}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: flowtable: Fix flushing of offloaded flows on free
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH net-next 6/6] netfilter: nf_flow_table: hardware offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nf_flow_table: populate addr_type mask
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH net-next 6/6] netfilter: nf_flow_table: hardware offload support
- From: Paul Blakey <paulb@xxxxxxxxxxxx>
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Eric Dumazet <eric.dumazet@xxxxxxxxx>
- Re: [PATCH net-next 6/6] netfilter: nf_flow_table: hardware offload support
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH 19/29] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 19/29] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Linus Walleij <linus.walleij@xxxxxxxxxx>
- Re: [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: flowtable: Fix flushing of offloaded flows on free
- From: Paul Blakey <paulb@xxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
- From: Сергей Маринкевич <s@xxxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
- From: Сергей Маринкевич <s@xxxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_flow_table_offload: fix potential NULL pointer dereference for dst_cache in handling lwtstate
- Re: Bug URGENT Report with new kernel 5.5.10-5.6-rc6
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH AUTOSEL 5.4 20/73] netfilter: cthelper: add missing attribute validation for cthelper
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 21/73] netfilter: nft_payload: add missing attribute validation for payload csum flags
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 26/73] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 27/73] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 31/73] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 16/37] netfilter: nft_payload: add missing attribute validation for payload csum flags
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 15/37] netfilter: cthelper: add missing attribute validation for cthelper
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.19 17/37] netfilter: nft_tunnel: add missing attribute validation for tunnels
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.14 13/28] netfilter: cthelper: add missing attribute validation for cthelper
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH AUTOSEL 4.14 14/28] netfilter: nft_payload: add missing attribute validation for payload csum flags
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 4.9 08/15] netfilter: cthelper: add missing attribute validation for cthelper
- From: Sasha Levin <sashal@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- [PATCH AUTOSEL 4.4 06/12] netfilter: cthelper: add missing attribute validation for cthelper
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 22/73] netfilter: nft_tunnel: add missing attribute validation for tunnels
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nft] evaluate: add range specified flag setting (missing NF_NAT_RANGE_PROTO_SPECIFIED)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: add nft_set_elem_expr_destroy() and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH v2] ipvs: optimize tunnel dumps for icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- Re: compilation of netfilter missing libnftnl functions - undefined reference - (RASPBERRY pi 3B)
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: nf_flow_table_offload: fix kernel NULL pointer dereference in nf_flow_table_indr_block_cb
- Re: [bug report] netfilter: nf_tables: add elements with stateful expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [bug report] netfilter: nf_tables: add elements with stateful expressions
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [PATCH net-next] flow_offload: add TC_SETP_FT type in flow_indr_block_call
- Re: [PATCH 00/29] Netfilter updates for net-next
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH 00/29] Netfilter updates for net-next
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- [PATCH 01/29] netfilter: flowtable: Use nf_flow_offload_tuple for stats as well
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 05/29] netfilter: nf_tables: make all set structs const
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/29] netfilter: cleanup unused macro
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/29] netfilter: bitwise: use more descriptive variable-names.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/29] netfilter: nft_set_pipapo: make the symbol 'nft_pipapo_get' static
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 14/29] netfilter: flowtable: add tunnel encap/decap action offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/29] netfilter: xt_IDLETIMER: clean up some indenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/29] netfilter: flowtable: add nf_flow_table_block_offload_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 13/29] netfilter: flowtable: add tunnel match offload support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 21/29] netfilter: nf_tables: add nft_set_elem_expr_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/29] netfilter: Replace zero-length array with flexible-array member
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 12/29] netfilter: flowtable: add indr block setup support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 22/29] netfilter: nf_tables: statify nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 20/29] nft_set_pipapo: Prepare for single ranged field usage
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 17/29] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 23/29] netfilter: nf_tables: add elements with stateful expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 25/29] netfilter: nft_lookup: update element stateful expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 24/29] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 16/29] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 26/29] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 27/29] netfilter: Rename ingress hook include file
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 28/29] netfilter: Generalize ingress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 19/29] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 29/29] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 18/29] nft_set_pipapo: Prepare for vectorised implementation: helpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 15/29] nft_set_pipapo: Generalise group size for buckets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/29] netfilter: nf_tables: make sets built-in
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/29] netfilter: xtables: Add snapshot of hardidletimer target
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/29] netfilter: nft_tunnel: add support for geneve opts
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/29] Netfilter updates for net-next
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/3] Netfilter egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nf_tables: fix double-free on set expression from the error path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH ghak25 v3 3/3] audit: add subj creds to NETFILTER_CFG record to cover async unregister
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak25 v3 2/3] netfilter: add audit table unregister actions
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak25 v3 1/3] audit: tidy and extend netfilter_cfg x_tables and ebtables logging
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH ghak25 v3 0/3] Address NETFILTER_CFG issues
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH nft] src: support for counter in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] set: support for NFTNL_SET_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: nf_tables: allow to specify stateful expression in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: nf_tables: pass context to nft_set_destroy()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: nf_tables: move nft_expr_clone() to nf_tables_api.c
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/3] support for stateful expressions in set definition
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2 2/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_tuple_ip{v6}
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH v2 1/2] netfilter: nf_flow_table: reload ip{v6}h in nf_flow_nat_ip{v6}
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_gc
- From: syzbot <syzbot+c1a1fb435465986efe35@xxxxxxxxxxxxxxxxxxxxxxxxx>
- compilation of netfilter missing libnftnl functions - undefined reference - (RASPBERRY pi 3B)
- From: "MELCHOR PENA, Bernardo Santiago" <B.S.Melchor-Pena@xxxxxxxx>
- [PATCH] netfilter: nft_masq: add range specified flag setting
- From: Sergey Marinkevich <s@xxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_ip_ext_cleanup
- From: syzbot <syzbot+6491ea8f6dddbf04930e@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_ext_cleanup
- From: syzbot <syzbot+c400f7b04cadb5df6ea7@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 2/5] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/1] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/4] netfilter: nf_flow_table: reload iph in nf_flow_tuple_ip
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 3/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_tuple_ipv6
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 2/4] netfilter: nf_flow_table: reload iph in nf_flow_nat_ip
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/4] netfilter: nf_flow_table: reload ipv6h in nf_flow_nat_ipv6
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/6] nft_set_pipapo: Performance improvements: Season 1
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: cache: Fix iptables-save segfault under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] ipvs: optimize tunnel dumps for icmp errors
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] ipvs: optimize tunnel dumps for icmp errors
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH] ipvs: optimize tunnel dumps for icmp errors
- From: Julian Anastasov <ja@xxxxxx>
- [PATCH] ipvs: optimize tunnel dumps for icmp errors
- From: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_port_ext_cleanup
- From: syzbot <syzbot+7b6206fb525c1f5ec3f8@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: BUG: corrupted list in __nf_tables_abort
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_port_destroy
- From: syzbot <syzbot+b96275fd6ad891076ced@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: BUG: corrupted list in __nf_tables_abort
- From: syzbot <syzbot+437bf61d165c87bd40fb@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: slab-out-of-bounds Read in bitmap_ipmac_destroy
- From: syzbot <syzbot+a85062dec5d65617cc1c@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [iptables PATCH] nft: cache: Fix iptables-save segfault under stress
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH] nft: cache: Fix for unused variable warnings
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Steve Grubb <sgrubb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Paul Moore <paul@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: WARNING in geneve_exit_batch_net (2)
- From: Dmitry Vyukov <dvyukov@xxxxxxxxxx>
- linux-next: manual merge of the netfilter-next tree with the net-next tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: WARNING in geneve_exit_batch_net (2)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/3 V2] inet: Use fallthrough;
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 2/3 V2] inet: Use fallthrough;
- From: Joe Perches <joe@xxxxxxxxxxx>
- Re: [PATCH 2/3] net: [IPv4/IPv6]: Use fallthrough;
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH ghak90 V8 16/16] audit: add capcontid to set contid outside init_user_ns
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 13/16] audit: track container nesting
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak90 V8 07/16] audit: add contid support for signalling the audit daemon
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH 2/3] net: [IPv4/IPv6]: Use fallthrough;
- From: Joe Perches <joe@xxxxxxxxxxx>
- [PATCH 0/3] treewide: Convert unscriptable /* fallthrough */ comments to fallthrough;
- From: Joe Perches <joe@xxxxxxxxxxx>
- rebasing nf-next...
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: WARNING in geneve_exit_batch_net (2)
- From: syzbot <syzbot+68a8ed58e3d17c700de5@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 1/1] netfilter: conntrack: re-visit sysctls in unprivileged namespaces
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nft 2/2] src: support for restoring element counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] netlink: remove unused parameter from netlink_gen_stmt_stateful()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH 5/5] netfilter: nft_lookup: update element stateful expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/5] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/5] netfilter: nf_tables: add elements with stateful expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/5] netfilter: nf_tables: add nft_set_elem_expr_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/5] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/5 nf-next,v2] enhance stateful expression support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] set_elem: missing set and build for NFTNL_SET_ELEM_EXPR
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 4/4] netfilter: nft_lookup: update element stateful expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 3/4] netfilter: nf_tables: add nft_set_elem_update_expr() helper function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/4] netfilter: nf_tables: add elements with stateful expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/4] netfilter: nf_tables: remove EXPORT_SYMBOL_GPL for nft_expr_init()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 0/4] enhance stateful expression support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: Support netdev egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 2/3] netfilter: Generalize ingress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 3/3] netfilter: Introduce egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 1/3] netfilter: Rename ingress hook include file
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH nf-next 0/3] Netfilter egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- [PATCH 4/8] netfilter: Add missing annotation for ctnetlink_parse_nat_setup()
- From: Jules Irenge <jbi.octave@xxxxxxxxx>
- [PATCH 5/8] netfilter: conntrack: Add missing annotations for nf_conntrack_all_lock() and nf_conntrack_all_unlock()
- From: Jules Irenge <jbi.octave@xxxxxxxxx>
- Re: [nft PATCH] tests/py: Move tcpopt.t to any/ directory
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] tests/py: Move tcpopt.t to any/ directory
- From: Phil Sutter <phil@xxxxxx>
- Re: Restoring rulesets containing dynamic sets with counters
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- Re: Restoring rulesets containing dynamic sets with counters
- From: Frank Myhr <fmyhr@xxxxxxxxxxx>
- Re: [PATCH nft 0/4] Help and getopt improvements
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: Restoring rulesets containing dynamic sets with counters
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 1/2] parser_json: Support ranges in concat expressions
- From: Eric Garver <eric@xxxxxxxxxxx>
- Re: [PATCH nf-next V2] netfilter: ctnetlink: add kernel side filtering for dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] parser_bison: fix rshift statement expression.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] parser_bison: fix rshift statement expression.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf-next V2] netfilter: ctnetlink: add kernel side filtering for dump
- From: Florent Fourcot <florent.fourcot@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: shift_stmt_expr grammar question
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- shift_stmt_expr grammar question
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next v2 5/6] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 6/6] nft_set_pipapo: Prepare for single ranged field usage
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 4/6] nft_set_pipapo: Prepare for vectorised implementation: helpers
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 3/6] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 2/6] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 1/6] nft_set_pipapo: Generalise group size for buckets
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next v2 0/6] nft_set_pipapo: Performance improvements: Season 1
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [nft PATCH v2 2/2] tests/py: Add tests involving concatenated ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH 00/11] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [nft PATCH v2 1/2] parser_json: Support ranges in concat expressions
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 2/2] tests/py: Add tests involving concatenated ranges
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] tests/py: Fix JSON output for changed timezone
- From: Phil Sutter <phil@xxxxxx>
- [PATCH 05/11] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 01/11] netfilter: nf_conntrack: ct_cpu_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 06/11] netfilter: cthelper: add missing attribute validation for cthelper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 04/11] netfilter: x_tables: xt_mttg_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 07/11] netfilter: nft_payload: add missing attribute validation for payload csum flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 09/11] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 08/11] netfilter: nft_tunnel: add missing attribute validation for tunnels
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 11/11] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 10/11] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 03/11] netfilter: xt_recent: recent_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 02/11] netfilter: synproxy: synproxy_cpu_seq_next should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 00/11] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: missing module ownership in chain type definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: missing module ownership in chain type definitions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_chain_nat: inet family is missing module ownership
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] parser_json: Support ranges in concat expressions
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] parser_json: Support ranges in concat expressions
- From: Eric Garver <eric@xxxxxxxxxxx>
- [nft PATCH] parser_json: Support ranges in concat expressions
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nft] tests: Introduce test for insertion of overlapping and non-overlapping ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 4/4] nft_set_rbtree: Detect partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 3/4] nft_set_rbtree: Introduce and use nft_rbtree_interval_start()
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 2/4] nft_set_pipapo: Separate partial and complete overlap cases on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 1/4] nf_tables: Allow set back-ends to report partial overlaps on insertion
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 0/4] nftables: Consistently report partial and entire set overlaps
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 24/58] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.4 25/58] netfilter: ipset: Fix forceadd evaluation path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 29/67] netfilter: ipset: Fix forceadd evaluation path
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH AUTOSEL 5.5 28/67] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Sasha Levin <sashal@xxxxxxxxxx>
- [PATCH nft 4/4] main: use one data-structure to initialize getopt_long(3) arguments and help.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 1/4] main: include '-d' in help.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 0/4] Help and getopt improvements
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 2/4] main: include '--reversedns' in help.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 3/4] main: interpolate default include path into help format-string.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] main: add more information to `nft -V`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: fix infinite loop when expr is not available
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: wenxu <wenxu@xxxxxxxxx>
- Re: [PATCH nf-next,RFC 0/5] Netfilter egress hook
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH v2] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next,RFC 0/5] Netfilter egress hook
- From: Lukas Wunner <lukas@xxxxxxxxx>
- Re: [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] main: add more information to `nft -V`.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] connlabel: Allow numeric labels even if connlabel.conf exists
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH netfilter 0/3] netfilter: add missing attribute validation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 0/4] netfilter: seq_file .next functions should increase position index
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] main: add more information to `nft -V`.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: dump NFTA_CHAIN_FLAGS attribute
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: support for offload chain flags
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- From: wenxu <wenxu@xxxxxxxxx>
- [PATCH libnftnl] chain: add NFTNL_CHAIN_FLAGS
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft v3 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 11/18] evaluate: don't clobber binop bitmask lengths.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 17/18] tests: shell: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 12/18] netlink_delinearize: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 16/18] tests: shell: remove stray debug flag.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 15/18] netlink_delinearize: add postprocessing for payload binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 09/18] src: support (de)linearization of bitwise op's with variable right operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 04/18] evaluate: convert the byte-order of payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 08/18] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 07/18] src: fix leaks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 03/18] evaluate: don't evaluate payloads twice.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 06/18] netlink_delinearize: set shift RHS byte-order.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 02/18] evaluate: simplify calculation of payload size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 01/18] evaluate: add separate variables for lshift and xor binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v3 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nft v2 11/18] netlink_linearize: round binop bitmask length up.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: + seq_read-info-message-about-buggy-next-functions.patch added to -mm tree
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH netfilter 1/3] netfilter: add missing attribute validation for cthelper
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH netfilter 3/3] netfilter: nf_tables: add missing attribute validation for tunnels
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH netfilter 2/3] netfilter: add missing attribute validation for payload csum flags
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH netfilter 0/3] netfilter: add missing attribute validation
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [iptables PATCH 4/4] nft: cache: Review flush_cache()
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Phil Sutter <phil@xxxxxx>
- linux-next: manual merge of the netfilter-next tree with Linus' tree
- From: Stephen Rothwell <sfr@xxxxxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nft v2 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 12/18] netlink_delinearize: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 17/18] tests: shell: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 16/18] tests: shell: remove stray debug flag.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 11/18] netlink_linearize: round binop bitmask length up.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 15/18] netlink_delinearize: add postprocessing for payload binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 04/18] evaluate: convert the byte-order of payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 09/18] src: support (de)linearization of bitwise op's with variable right operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 07/18] src: fix leaks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 08/18] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 06/18] netlink_delinearize: set shift RHS byte-order.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 03/18] evaluate: don't evaluate payloads twice.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 01/18] evaluate: add separate variables for lshift and xor binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft v2 02/18] evaluate: simplify calculation of payload size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: free flowtable hooks on hook register error
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 4/4] nft: cache: Review flush_cache()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- memory leak in nf_tables_parse_netdev_hooks (2)
- From: syzbot <syzbot+a2ff6fa45162a5ed4dd3@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [iptables PATCH 4/4] nft: cache: Review flush_cache()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/4] nft: cache: Fix nft_release_cache() under stress
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/4] nft: cache: Make nft_rebuild_cache() respect fake cache
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 3/4] nft: cache: Simplify chain list allocation
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 0/4] Fix for iptables-nft-restore under pressure
- From: Phil Sutter <phil@xxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Edward Cree <ecree@xxxxxxxxxxxxxx>
- Re: [PATCH nft 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH libnftnl 0/3] bitwise: support for passing mask and xor via registers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][next] netfilter: Replace zero-length array with flexible-array member
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- Re: [PATCH] netfilter: ipt_CLUSTERIP: Pass lockdep expression to RCU lists
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: clean up some indenting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] netfilter: bitwise: support variable RHS operands
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][next] netfilter: Replace zero-length array with flexible-array member
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- general protection fault in gc_worker
- From: syzbot <syzbot+2a2fe383b2ce0e44b6ea@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Jiri Pirko <jiri@xxxxxxxxxxx>
- Re: [PATCH net] netlink: Use netlink header as base to calculate bad attribute offset
- From: David Miller <davem@xxxxxxxxxxxxx>
- 0x14: COVID-19 update, postponement of Netdev conf 0x14
- From: Jamal Hadi Salim <jhs@xxxxxxxxxxxx>
- Re: [patch net-next v2 01/12] flow_offload: Introduce offload of HW stats type
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 16/18] tests: shell: remove stray debug flag.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 12/18] netlink_delinearize: fix typo.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 15/18] netlink_delinearize: add postprocessing for payload binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 10/18] evaluate: allow boolean binop expressions with variable righthand arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 14/18] netlink_delinearize: add support for processing variable payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 13/18] netlink_delinearize: refactor stmt_payload_binop_postprocess.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 17/18] tests: shell: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 18/18] tests: py: add variable binop RHS tests.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 11/18] netlink_linearize: round binop bitmask length up.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 04/18] evaluate: convert the byte-order of payload statement arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 06/18] netlink_delinearize: set shift RHS byte-order.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 05/18] evaluate: no need to swap byte-order for values of fewer than 16 bits.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 03/18] evaluate: don't evaluate payloads twice.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 02/18] evaluate: simplify calculation of payload size.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 01/18] evaluate: add separate variables for lshift and xor binops.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 09/18] src: support (de)linearization of bitwise op's with variable right operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 00/18] Support for boolean binops with variable RHS operands.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 07/18] src: fix leaks.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 08/18] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: Ipv6 address in concatenation
- From: Phil Sutter <phil@xxxxxx>
- Ipv6 address in concatenation
- From: "Serguei Bezverkhi (sbezverk)" <sbezverk@xxxxxxxxx>
- Re: [PATCH 0/6] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- [PATCH 3/6] selftests: nft_concat_range: Move option for 'list ruleset' before command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/6] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/6] nft_set_pipapo: Actually fetch key data in nft_pipapo_remove()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/6] selftests: nft_concat_range: Add test for reported add/flush/add issue
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/6] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] netfilter: ipset: Fix forceadd evaluation path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/6] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netlink: Use netlink header as base to calculate bad attribute offset
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 0/2] ipset patches for nf
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 1/2] expressions: concat: add typeof support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] tests: update nat_addr_port with typeof+concat maps
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] expressions: concat: add typeof support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Null Pointer Dereference in nf_nat
- From: Alex Buie <alex.buie@xxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf] selftests: nft_concat_range: Move option for 'list ruleset' before command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH v2 4/4] xt_mttg_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 3/4] recent_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 2/4] synproxy_cpu_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 1/4] ct_cpu_seq_next should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH v2 0/4] netfilter: seq_file .next functions should increase position index
- From: Vasily Averin <vvs@xxxxxxxxxxxxx>
- [PATCH] netfilter: clean up some indenting
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- Re: [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: ensure rcu_read_lock() in ipv4_find_option()
- From: Matteo Croce <mcroce@xxxxxxxxxx>
- Re: [PATCH nft 0/6] allow s/dnat to map to both addr and port
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft 0/6] allow s/dnat to map to both addr and port
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/6 nft,v2] tests: shell: adjust tests to new nat concatenation syntax
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/6 nft,v2] src: nat concatenation support with anonymous maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] ipset: Update byte and packet counters regardless of whether they match
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nft 6/6] tests: nat: add and use maps with both address and service
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl 3/3] bitwise: add support for passing mask and xor via registers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 1/3] tests: bitwise: fix error message.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 2/3] include: update nf_tables.h.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH libnftnl 0/3] bitwise: support for passing mask and xor via registers
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nft 7/6] src: nat concatenation support with anonymous maps
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: bitwise: use more descriptive variable-names.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: bitwise: add support for passing mask and xor values in registers.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: bitwise: support variable RHS operands
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue v3] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v5 4/4] netfilter: flowtable: add tunnel encap/decap action offload support
- [PATCH nf-next v5 2/4] netfilter: flowtable: add indr block setup support
- [PATCH nf-next v5 3/4] netfilter: flowtable: add tunnel match offload support
- [PATCH nf-next v5 1/4] netfilter: flowtable: add nf_flow_table_block_offload_init()
- [PATCH nf-next v5 0/4] netfilter: flowtable: add indr-block offload
- [PATCH libnetfilter_queue v3] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH libnetfilter_queue v2] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH nft 6/6] tests: nat: add and use maps with both address and service
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 5/6] src: allow nat maps containing both ip(6) address and port
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 4/6] evaluate: add two new helpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 3/6] netlink: handle concatenations on set elements mappings
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/6] evaluate: process concat expressions when used as mapped-to expr
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/6] tests: add initial nat map test
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 0/6] allow s/dnat to map to both addr and port
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnetfilter_queue] src: add nfq_get_skbinfo()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH libnetfilter_queue] build: doc: "make" builds & installs a full set of man pages
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue 1/1] src: move static nfq_hdr_put from examples/nf-queue.c into the library since everyone is going to want it.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 5/5] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] evaluate: don't eval unary arguments.
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- Re: [iptables PATCH 1/3] xtables: Align effect of -4/-6 options with legacy
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] ulogd: printpkt: always print IPv6 protocol
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH][nf-next] netfilter: cleanup unused macro
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 0/2] netfilter: nf_tables: make sets built-in
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCHv2 nf-next] netfilter: nft_tunnel: add support for geneve opts
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] [nf-next,v4] netfilter: xtables: Add snapshot of hardidletimer target
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: flowtable: Use nf_flow_offload_tuple for stats as well
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 5/5] nft_set_pipapo: Introduce AVX2-based lookup implementation
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 3/5] nft_set_pipapo: Prepare for vectorised implementation: alignment
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 4/5] nft_set_pipapo: Prepare for vectorised implementation: helpers
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 2/5] nft_set_pipapo: Add support for 8-bit lookup groups and dynamic switch
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 0/5] nft_set_pipapo: Performance improvements: Season 1
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 1/5] nft_set_pipapo: Generalise group size for buckets
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH 2/2] netfilter: Pass lockdep expression to instance_lookup traversal
- From: Amol Grover <frextrite@xxxxxxxxx>
- [PATCH 1/2] netfilter: Pass lockdep expression to __instance_lookup traversal
- From: Amol Grover <frextrite@xxxxxxxxx>
- [PATCH nft] expression: use common code for expr_ops/expr_ops_by_type
- From: Florian Westphal <fw@xxxxxxxxx>
- [ANNOUNCE] ipset 7.6 released
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- KMSAN: uninit-value in nf_flow_table_offload_setup
- From: syzbot <syzbot+8fbe17d9bdd5c8815211@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH 1/2] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 2/2] netfilter: ipset: Fix forceadd evaluation path
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 0/2] ipset patches for nf
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [iptables PATCH] iptables-test.py: Fix --host mode
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [nft PATCH 3/4] segtree: Fix for potential NULL-pointer deref in ei_insert()
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Phil Sutter <phil@xxxxxx>
- Re: KASAN: slab-out-of-bounds Write in bitmap_ip_del
- From: syzbot <syzbot+24d0577de55b8b8f6975@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/2] parser_json: fix parsing prefix inside concat
- From: Eric Garver <eric@xxxxxxxxxxx>
- [iptables PATCH 3/3] xtables: Review nft_init()
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 1/3] xtables: Align effect of -4/-6 options with legacy
- From: Phil Sutter <phil@xxxxxx>
- [iptables PATCH 2/3] xtables: Drop -4 and -6 support from xtables-{save,restore}
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] ulogd: printpkt: always print IPv6 protocol
- From: Andreas Jaggi <andreas.jaggi@xxxxxxxxxxxx>
- [PATCH nf] selftests: nft_concat_range: Move option for 'list ruleset' before command
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 2/2] selftests: nft_concat_range: Add test for reported add/flush/add issue
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 1/2] nft_set_pipapo: Actually fetch key data in nft_pipapo_remove()
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf 0/2] nft_set_pipapo: Fix crash due to dangling entries in mapping table
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Duncan Roe <duncan_roe@xxxxxxxxxxxxxxx>
- [PATCH 2/2] tests: shell: json parsing prefix inside concat
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH 1/2] parser_json: fix parsing prefix inside concat
- From: Eric Garver <eric@xxxxxxxxxxx>
- [PATCH][next] netfilter: Replace zero-length array with flexible-array member
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- Re: [PATCH nf-next v4 0/9] nftables: Set implementation for arbitrary concatenation of ranges
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH nf-next v4 0/9] nftables: Set implementation for arbitrary concatenation of ranges
- From: Phil Sutter <phil@xxxxxx>
- [PATCH][nf-next] netfilter: cleanup unused macro
- From: Li RongQing <lirongqing@xxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- [PATCH nft 2/2,v2] mnl: do not use expr->identifier to fetch device name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] mnl: do not use expr->identifier to fetch device name
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] parser_bison: memleak in device parser
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnetfilter_queue v2] src: Add faster alternatives to pktb_alloc()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft v5] tests: Introduce test for set with concatenated ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ipmac_ext_cleanup
- From: syzbot <syzbot+33fc3ad6fa11675e1a7e@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH nft 3/3] src: improve error reporting when remove rules
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/3] src: improve error reporting when setting policy on non-base chain
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/3] mnl: extended error support for create command
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [libnftnl PATCH] src: Fix for reading garbage in nftnl_chain getters
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] netfilter: ipt_CLUSTERIP: Pass lockdep expression to RCU lists
- From: Amol Grover <frextrite@xxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ip_ext_cleanup
- From: syzbot <syzbot+b554d01b6c7870b17da2@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ip_destroy
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: KASAN: use-after-free Read in bitmap_ip_destroy
- From: syzbot <syzbot+8b5f151de2f35100bbc5@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 0/9] Netfilter fixes for net
- From: David Miller <davem@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH ghak25 v2 4/9] audit: record nfcfg params
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- Re: [PATCH ghak25 v2 7/9] netfilter: ebtables audit table registration
- From: Richard Guy Briggs <rgb@xxxxxxxxxx>
- [PATCH 2/9] netfilter: xt_hashlimit: limit the max size of hashtable
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/9] netfilter: conntrack: remove two args from resolve_clash
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 3/9] netfilter: flowtable: skip offload setup if disabled
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 5/9] netfilter: conntrack: place confirm-bit setting in a helper
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 8/9] netfilter: nft_set_pipapo: Fix mapping table example in comments
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 7/9] netfilter: conntrack: allow insertion of clashing entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 9/9] netfilter: nft_set_pipapo: Don't abuse unlikely() in pipapo_refill()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 6/9] netfilter: conntrack: split resolve_clash function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/9] netfilter: xt_hashlimit: reduce hashlimit_mutex scope for htable_put()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 0/9] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Cong Wang <xiyou.wangcong@xxxxxxxxx>
- Re: [Patch nf] netfilter: xt_hashlimit: unregister proc file before releasing mutex
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 0/2] Two non-functional fixes for nft_set_pipapo
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH libnftnl] src: add nftnl_*_{get,set}_array()
- From: Phil Sutter <phil@xxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] ebtables: among: Support mixed MAC and MAC/IP entries
- From: Phil Sutter <phil@xxxxxx>
- Re: [iptables PATCH] ebtables: among: Support mixed MAC and MAC/IP entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] src: Fix nftnl_assert() on data_len
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH libnftnl] src: add nftnl_*_{get,set}_array()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [iptables PATCH] nft: Drop pointless assignment
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] src: combine extended netlink error reporting with mispelling support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 1/1] netfilter: ipset: Fix "INFO: rcu detected stall in hash_xxx" reports
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- [PATCH 0/1] ipset patch for nf
- From: Jozsef Kadlecsik <kadlec@xxxxxxxxxxxxx>
- Re: Strange nf_conntrack_tcp_timeout_established behavior
- From: FUSTE Emmanuel <emmanuel.fuste@xxxxxxxxxxxxxxx>
- [PATCH nf-next v2 2/2] netfilter: nf_tables: make all set structs const
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 1/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 0/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] src: initial extended netlink error reporting
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH][next] netfilter: ebtables: Replace zero-length array with flexible-array member
- From: "Gustavo A. R. Silva" <gustavo@xxxxxxxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: conntrack: allow insertion of clashing entries
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/4] netfilter: conntrack: allow insertion of clashing entries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Strange nf_conntrack_tcp_timeout_established behavior
- From: FUSTE Emmanuel <emmanuel.fuste@xxxxxxxxxxxxxxx>
- Re: Proposing to add a structure to UserData
- From: Phil Sutter <phil@xxxxxx>
- Re: Proposing to add a structure to UserData
- From: sbezverk <sbezverk@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nf_tables: make all set structs const
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nf_tables: make all set structs const
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: Proposing to add a structure to UserData
- From: Florian Westphal <fw@xxxxxxxxx>
- [iptables PATCH] nft: Drop pointless assignment
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next 2/2] netfilter: nf_tables: make all set structs const
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: nf_tables: make sets built-in
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: WARNING in nf_tables_table_destroy
- From: Florian Westphal <fw@xxxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]