Linux TCP/IP Netfilter Devel
[Prev Page][Next Page]
- Re: [PATCH] net/netfilter/ipvs: Fix data-race in ip_vs_add_service / ip_vs_out_hook
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net/netfilter/ipvs: Fix data-race in ip_vs_add_service / ip_vs_out_hook
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [ANNOUNCE] nftables 1.0.6.1 (stable) release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] trace: Fix for memleak in trace_alloc_list() error path
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] net/netfilter/ipvs: Fix data-race in ip_vs_add_service / ip_vs_out_hook
- From: Zhang Tengfei <zhtfdev@xxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft 12/12] src: replace compound_expr_alloc() by type safe function
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next 0/2] netfilter: nft_set_pipapo: speed up insertions
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 2/6] setftests: net: netfilter: fix spelling mistakes in output
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nft_set_pipapo_avx2: split lookup function in two parts
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH] netfilter: ebtables: Use vmalloc_array() to improve code
- From: Qianfeng Rong <rongqianfeng@xxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nft-testing v3 0/2] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: nftables 1.0.6.y stable branch updates (strike 2)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [conntrack-tools PATCH] nfct: helper: Extend error message for EEXIST
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v2 0/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next 2/2] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nft] src: ensure chain policy evaluation when specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 3/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- [PATCH nft-testing v3 2/2] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [nft PATCH 00/14] json: Do not reduce single-item arrays on output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next 2/2] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next v2 4/7] net: Switch to skb_dstref_steal/skb_dstref_restore for ip_route_input callers
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next v2 1/7] net: Add skb_dstref_steal and skb_dstref_restore
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH nft-testing v3 1/2] netfilter: nft_set_pipapo*: Move FPU handling to pipapo_get_avx2()
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- [PATCH net-next v2 7/7] net: Add skb_dst_check_unset
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- Re: modprobe returns 0 upon -EEXIST from insmod
- From: Phil Sutter <phil@xxxxxx>
- [nf-next v2] netfilter: ctnetlink: remove refcounting in dying list dumping
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next v2 2/7] xfrm: Switch to skb_dstref_steal to clear dst_entry
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH nf-next v6 2/2] selftests: netfilter: nft_flowtable.sh: Add IPIP flowtable selftest
- From: Lorenzo Bianconi <lorenzo@xxxxxxxxxx>
- [PATCH net-next v2 5/7] staging: octeon: Convert to skb_dst_drop
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- Re: modprobe returns 0 upon -EEXIST from insmod
- From: Christophe Leroy <christophe.leroy@xxxxxxxxxx>
- Re: [PATCH nft 1/2] evaluate: check XOR RHS operand is a constant value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v6 0/2] Add IPIP flowtable SW acceleratio
- From: Lorenzo Bianconi <lorenzo@xxxxxxxxxx>
- [PATCH nf-next v2 2/3] netfilter: nft_set_pipapo_avx2: Drop the comment regarding protection
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [nft PATCH 00/14] json: Do not reduce single-item arrays on output
- From: Phil Sutter <phil@xxxxxx>
- [nf PATCH] netfilter: conntrack: helper: Replace -EEXIST by -EBUSY
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 00/12] replace compound_expr_*() by type safe function
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft 01/12] segtree: incorrect type when aggregating concatenated set ranges
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next 0/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- [PATCH nf-next v6 1/2] net: netfilter: Add IPIP flowtable SW acceleration
- From: Lorenzo Bianconi <lorenzo@xxxxxxxxxx>
- [PATCH nf-next v2 1/3] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- [PATCH nft,v2] src: ensure chain policy evaluation when specified
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/6] setftests: net: netfilter: fix spelling mistakes in output
- From: Soham Metha <sohammetha01@xxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nft_set_pipapo_avx2: split lookup function in two parts
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- [PATCH nf-next 1/2] netfilter: nft_set_pipapo_avx2: split lookup function in two parts
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next v2 6/7] chtls: Convert to skb_dst_reset
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next v2 3/7] netfilter: Switch to skb_dstref_steal to clear dst_entry
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: ctnetlink: remove refcounting in dying list dumping
- From: kernel test robot <lkp@xxxxxxxxx>
- [PATCH net-next v2 0/7] net: Convert to skb_dstref_steal and skb_dstref_restore
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 3/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [nft PATCH 00/14] json: Do not reduce single-item arrays on output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 0/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- [PATCH net-next v2] netfilter: nft_payload: Use csum_replace4() instead of opencoding
- From: Christophe Leroy <christophe.leroy@xxxxxxxxxx>
- Re: [PATCH nft 1/2] evaluate: check XOR RHS operand is a constant value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next 1/2] netfilter: nft_set_pipapo_avx2: split lookup function in two parts
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] fib: restore JSON output for relational expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net-next 1/6] netfilter: ctnetlink: remove refcounting in dying list dumping
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [nft PATCH 00/14] json: Do not reduce single-item arrays on output
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Qingjie Xing <xqjcool@xxxxxxxxx>
- Re: [PATCH net] netfilter: br_netfilter: reread nf_conn from skb after confirm()
- From: Wang Liang <wangliang74@xxxxxxxxxx>
- Re: [PATCH 1/7 nft v2] src: add tunnel template support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 libnftnl v3] tunnel: rework options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net v2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: Wang Liang <wangliang74@xxxxxxxxxx>
- Re: [PATCH nft] src: fix memory leak in anon chain error handling
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft-testing v3 1/2] netfilter: nft_set_pipapo*: Move FPU handling to pipapo_get_avx2()
- From: Florian Westphal <fw@xxxxxxxxx>
- [syzbot ci] Re: net: Convert to skb_dstref_steal and skb_dstref_restore
- From: syzbot ci <syzbot+ci77a5caa9fce14315@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH 1/7 nft v2] src: add tunnel template support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Qingjie Xing <xqjcool@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next 0/2] netfilter: nf_tables: make set flush more resistant to memory pressure
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next 0/2] netfilter: nf_tables: make set flush more resistant to memory pressure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/7 nft v2] src: add tunnel template support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Qingjie Xing <xqjcool@xxxxxxxxx>
- Re: [PATCH net-next v2 0/7] net: Convert to skb_dstref_steal and skb_dstref_restore
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [PATCH net] netfilter: br_netfilter: reread nf_conn from skb after confirm()
- From: Wang Liang <wangliang74@xxxxxxxxxx>
- Re: [PATCH net v2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next v2 1/2] netfilter: nf_tables: allow iter callbacks to sleep
- From: Florian Westphal <fw@xxxxxxxxx>
- [syzbot] Monthly netfilter report (Aug 2025)
- From: syzbot <syzbot+list9abda43ae935f9073c3e@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [syzbot ci] Re: net: Convert to skb_dstref_steal and skb_dstref_restore
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- [PATCH nf-next v2 2/2] netfilter: nf_tables: all transaction allocations can now sleep
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [syzbot ci] Re: net: Convert to skb_dstref_steal and skb_dstref_restore
- From: Aleksandr Nogikh <nogikh@xxxxxxxxxx>
- [PATCH nf-next v2 0/2] netfilter: nf_tables: avoid atomic allocations for set flush
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: br_netfilter: reread nf_conn from skb after confirm()
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] tests: shell: cover sets as set elems evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 2/2] tests: shell: coverage for simple verdict map merger
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] mnl: silence compiler warning
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nftables PATCH v3] tools: add a systemd unit for static rulesets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] mnl: silence compiler warning
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 3/6] netfilter: nft_set_pipapo_avx2: split lookup function in two parts
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 4/6] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 6/6] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 1/6] netfilter: ctnetlink: remove refcounting in dying list dumping
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 0/6] netfilter: updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 2/6] netfilter: nft_set_pipapo_avx2: Drop the comment regarding protection
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 4/6] netfilter: nft_set_pipapo: use avx2 algorithm for insertions too
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [syzbot ci] Re: net: Convert to skb_dstref_steal and skb_dstref_restore
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Qingjie Xing <xqjcool@xxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net] netfilter: br_netfilter: reread nf_conn from skb after confirm()
- From: Wang Liang <wangliang74@xxxxxxxxxx>
- Re: [PATCH net-next 5/6] netfilter: nft_set_pipapo: Store real pointer, adjust later.
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: conntrack: drop expectations before freeing templates
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net] netfilter: br_netfilter: reread nf_conn from skb after confirm()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net v2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net v2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 1/2 libnftnl v4] tunnel: rework options
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 1/7 nft v3] src: add tunnel template support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [syzbot] [netfilter?] WARNING in nf_reject_fill_skb_dst
- From: syzbot <syzbot+b17c05ecb64771a892d1@xxxxxxxxxxxxxxxxxxxxxxxxx>
- [PATCH 6/7 nft v3] tunnel: add tunnel object and statement json support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 3/7 nft v3] src: add tunnel statement and expression support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH nft,v2 02/11] src: replace compound_expr_add() by type safe set_expr_add()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [iptables PATCH] extensions: man: Add a note about route_localnet sysctl
- From: Łukasz Stelmach <l.stelmach@xxxxxxxxxxx>
- [PATCH] doc: Add a note about route_localnet sysctl
- From: Łukasz Stelmach <l.stelmach@xxxxxxxxxxx>
- [PATCH 7/7 nft v3] tests: add tunnel shell and python tests
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH nft,v2 03/11] src: replace compound_expr_add() by type safe concat_expr_add()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 2/2 libnftnl v4] tunnel: add support to geneve options
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 5/7 nft v3] tunnel: add geneve support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 2/7 nft v3] tunnel: add erspan support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH nft,v2 04/11] src: replace compound_expr_add() by type safe list_expr_add()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 11/11] src: replace compound_expr_alloc() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 08/11] expression: replace compound_expr_remove() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 01/11] src: add expr_type_catchall() helper and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/2] tests: shell: combine flowtable devices with variable expression
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH 4/7 nft v3] tunnel: add vxlan support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH nft,v2 06/11] expression: replace compound_expr_clone() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 09/11] expression: replace compound_expr_destroy() by type safe funtion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 10/11] expression: replace compound_expr_print() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 05/11] segtree: rename set_compound_expr_add() to set_expr_add_splice()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/2] evaluate: simplify set to list normalisation for device expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 00/11] replace compound_expr_*() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2 07/11] expression: remove compound_expr_add()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] doc: Add a note about route_localnet sysctl
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [iptables PATCH] extensions: man: Add a note about route_localnet sysctl
- From: Florian Westphal <fw@xxxxxxxxx>
- [ipset] Can't resolve domain names containing an hyphen "-"
- From: Pierre Mazière <star+netfilterdevelml@xxxxxxxxxxxxx>
- Re: [ipset] Can't resolve domain names containing an hyphen "-"
- From: Jan Engelhardt <ej@xxxxxxx>
- Re: [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [nft PATCH] tests: monitor: Fix for flag arrays in JSON output
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] tests: monitor: Fix for flag arrays in JSON output
- From: Phil Sutter <phil@xxxxxx>
- Re: repeated 'add chain'/'delete chain' 5x and ...
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH xtables] man: iptables-restore.8: document flush behaviour for user-defined chains
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH xtables] man: iptables-restore.8: document flush behaviour for user-defined chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] icmp: fix icmp_ndo_send address translation for reply direction
- From: Fabian Bläse <fabian@xxxxxxxxx>
- [PATCH] icmp: fix icmp_ndo_send address translation for reply direction
- From: Fabian Bläse <fabian@xxxxxxxxx>
- Re: [PATCH] net/netfilter/ipvs: Fix data-race in ip_vs_add_service / ip_vs_out_hook
- From: Julian Anastasov <ja@xxxxxx>
- [nft PATCH] Makefile: Fix for 'make distcheck'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] Makefile: Fix for 'make distcheck'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] Makefile: Fix for 'make distcheck'
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v3] icmp: fix icmp_ndo_send address translation for reply direction
- From: Fabian Bläse <fabian@xxxxxxxxx>
- Re: nftables monitor json mode is broken
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables monitor json mode is broken
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] net/netfilter/ipvs: Fix data-race in ip_vs_add_service / ip_vs_out_hook
- From: Julian Anastasov <ja@xxxxxx>
- Re: [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] icmp: fix icmp_ndo_send address translation for reply direction
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [conntrack-tools PATCH] nfct: helper: Extend error message for EEXIST
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Phil Sutter <phil@xxxxxx>
- Re: [libnftnl PATCH] udata: Introduce NFTNL_UDATA_TABLE_NFT{VER,BLD}
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net v2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] libnftables: continue on ENOBUFS errors when processing batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v2] mnl: continue on ENOBUFS errors when processing batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft,v3] mnl: continue on ENOBUFS errors when processing batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] icmp: fix icmp_ndo_send address translation for reply direction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] icmp: fix icmp_ndo_send address translation for reply direction
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH] nfct: helper: Extend error message for EEXIST
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH] nfct: helper: Extend error message for EEXIST
- From: Phil Sutter <phil@xxxxxx>
- Re: nftables monitor json mode is broken
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] icmp: fix icmp_ndo_send address translation for reply direction
- From: Florian Westphal <fw@xxxxxxxxx>
- [conntrack-tools PATCH v2] nfct: helper: Extend error message for EBUSY
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next] netfilter: nft_payload: extend offset to 65535 bytes
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_payload: extend offset to 65535 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next] netfilter: nft_payload: extend offset to 65535 bytes
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_payload: extend offset to 65535 bytes
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3] icmp: fix icmp_ndo_send address translation for reply direction
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v3] icmp: fix icmp_ndo_send address translation for reply direction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft,v4] mnl: continue on ENOBUFS errors when processing batch
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net] ipvs: Fix estimator kthreads preferred affinity
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [nft PATCH] Makefile: Fix for 'make distcheck'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v2 1/2] netfilter: nf_tables: allow iter callbacks to sleep
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v2 1/2] netfilter: nf_tables: allow iter callbacks to sleep
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] build: make `make distcheck` succeed in the face of absolute paths
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] trace: Fix for memleak in trace_alloc_list() error path
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net 2/2] netfilter: conntrack: helper: Replace -EEXIST by -EBUSY
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH] build: make `make distcheck` succeed in the face of absolute paths
- From: Jan Engelhardt <jengelh@xxxxxxx>
- [PATCH net 0/2] netfilter updates for net
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next v2] netfilter: nft_payload: Use csum_replace4() instead of opencoding
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [nft PATCH] Makefile: Fix for 'make distcheck'
- From: Jan Engelhardt <ej@xxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft] build: disable --with-unitdir by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] build: make `make distcheck` succeed in the face of absolute paths
- From: Phil Sutter <phil@xxxxxx>
- [no subject]
- From: Zhang Tengfei <zhtfdev@xxxxxxxxx>
- Re: [PATCH nft] build: disable --with-unitdir by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net] netfilter: nft_flowtable.sh: re-run with random mtu sizes
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] icmp: fix icmp_ndo_send address translation for reply direction
- From: Fabian Bläse <fabian@xxxxxxxxx>
- [PATCH nf] selftests: netfilter: fix udpclash tool hang
- From: Florian Westphal <fw@xxxxxxxxx>
- nftables monitor json mode is broken
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] icmp: fix icmp_ndo_send address translation for reply direction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nft_set_pipapo: remove redundant test for avx feature bit
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next v2 1/2] netfilter: nf_tables: allow iter callbacks to sleep
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nftables monitor json mode is broken
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: nftables monitor json mode is broken
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] build: disable --with-unitdir by default
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nft] build: disable --with-unitdir by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Nikolaos Gkarlis <nickgarlis@xxxxxxxxx>
- [ANNOUNCE] nftables 1.1.5 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re:
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_set_pipapo: remove redundant test for avx feature bit
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: nftables monitor json mode is broken
- From: Phil Sutter <phil@xxxxxx>
- Re: nftables monitor json mode is broken
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v2] net/netfilter/ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enable
- From: Zhang Tengfei <zhtfdev@xxxxxxxxx>
- [PATCH] netfilter: ipset: Remove unused htable_bits in macro ahash_region
- From: Zhen Ni <zhen.ni@xxxxxxxxxxxx>
- Re: [PATCH nft 1/2] evaluate: simplify set to list normalisation for device expressions
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [conntrack-tools PATCH] nfct: helper: Extend error message for EEXIST
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft,v2 00/11] replace compound_expr_*() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/7 nft v3] src: add tunnel template support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH 1/2 libnftnl v4] tunnel: rework options
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] build: make `make distcheck` succeed in the face of absolute paths
- From: Jan Engelhardt <ej@xxxxxxx>
- Re: [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: xt_hashlimit: fix inconsistent return type in hashlimit_mt_*
- From: Miaoqian Lin <linmq006@xxxxxxxxx>
- Re: [PATCH v2] net/netfilter/ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enable
- From: Zhang Tengfei <zhtfdev@xxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl PATCH] udata: Introduce NFTNL_UDATA_TABLE_NFT{VER,BLD}
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH] netfilter: xt_hashlimit: fix inconsistent return type in hashlimit_mt_*
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: ipset: Remove unused htable_bits in macro ahash_region
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 4/5] monitor: Inform JSON printer when reporting an object delete event
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 5/5] tests: monitor: Extend testcases a bit
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 3/5] mnl: Allow for updating devices on existing inet ingress hook chains
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/5] Fixes (and fallout) from running tests/monitor in JSON mode
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/5] monitor: Quote device names in chain declarations, too
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/5] tools: gitignore nftables.service file
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: xt_hashlimit: fix inconsistent return type in hashlimit_mt_*
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_reject_ipv4: remove unneeded exports
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf-next] netfilter: nf_reject: don't reply to icmp error messages
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] build: disable --with-unitdir by default
- From: Jeremy Sowden <jeremy@xxxxxxxxxx>
- [nft PATCH v2 1/7] tests: Prepare exit codes for automake
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 7/7] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 2/7] tests: monitor: Support running all tests in one go
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 0/7] Run all test suites via 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 3/7] tests: py: Set default options based on RUN_FULL_TESTSUITE
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 5/7] tests: shell: Skip packetpath/nat_ftp in fake root env
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 4/7] tests: json_echo: Skip if run as non-root
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v2 6/7] tests: build: Do not assume caller's CWD
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] net/netfilter/ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enable
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Nick Garlis <nickgarlis@xxxxxxxxx>
- Re: [PATCH net 1/2] netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net] netfilter: nft_flowtable.sh: re-run with random mtu sizes
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net] netfilter: nft_flowtable.sh: re-run with random mtu sizes
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [REGRESSION] v6.16 system hangs (bisected to nf_conntrack fix)
- From: Dan Moulding <dan@xxxxxxxx>
- Re: [PATCH v14 nf-next 3/3] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v14 nf-next 3/3] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
- From: Eric Woudstra <ericwouds@xxxxxxxxx>
- Re: [PATCH v3 nf-next 0/3] flow offload teardown when layer 2 roaming
- From: Eric Woudstra <ericwouds@xxxxxxxxx>
- [PATCH nft] gitignore: ignore "tools/nftables.service"
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH v2 net-next 4/7] netfilter: nf_tables: all transaction allocations can now sleep
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] gitignore: ignore "tools/nftables.service"
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH net-next 5/8] netfilter: nf_tables: Introduce NFTA_DEVICE_PREFIX
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [nft PATCH 0/5] Fixes (and fallout) from running tests/monitor in JSON mode
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH nft] gitignore: ignore "tools/nftables.service"
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v3 nf-next 0/3] flow offload teardown when layer 2 roaming
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH libnftnl] expr: meta: introduce ibrhwdr meta expression
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH net-next 0/8] netfilter: updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft] gitignore: ignore "tools/nftables.service"
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 3/7] netfilter: nf_tables: allow iter callbacks to sleep
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 6/7] netfilter: nf_reject: remove unneeded exports
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 7/7] netfilter: nft_payload: extend offset to 65535 bytes
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 0/7] netfilter: updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 1/7] netfilter: ebtables: Use vmalloc_array() to improve code
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 5/7] netfilter: nft_set_pipapo: remove redundant test for avx feature bit
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net-next 2/7] netfilter: nft_payload: Use csum_replace4() instead of opencoding
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [nft PATCH v2 7/7] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 2/7] tests: monitor: Support running all tests in one go
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 3/7] tests: py: Set default options based on RUN_FULL_TESTSUITE
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Fernando Fernandez Mancera <ffmancera@xxxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH nf-next] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 2/2] netfilter: nf_tables: Introduce NFTA_DEVICE_PREFIX
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 1/2] selftests: netfilter: fix udpclash tool hang
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 0/2] netfilter: updates for net
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Nikolaos Gkarlis <nickgarlis@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Nick Garlis <nickgarlis@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH v2 3/7] tests: py: Set default options based on RUN_FULL_TESTSUITE
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2 7/7] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2 7/7] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 7/7] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v2 2/7] tests: monitor: Support running all tests in one go
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: Nikolaos Gkarlis <nickgarlis@xxxxxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH v3 nf-next] ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enable
- From: Julian Anastasov <ja@xxxxxx>
- [nft PATCH v3 05/11] tests: monitor: Excercise all syntaxes and variants by default
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 07/11] tests: Prepare exit codes for automake
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 06/11] tests: py: Enable JSON and JSON schema by default
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 03/11] tests: monitor: Test JSON echo mode as well
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 00/11] Run all test suites via 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 04/11] tests: monitor: Extend debug output a bit
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 02/11] tests: monitor: Fix regex collecting expected echo output
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 09/11] tests: shell: Skip packetpath/nat_ftp in fake root env
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 08/11] tests: json_echo: Skip if run as non-root
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 10/11] tests: build: Do not assume caller's CWD
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 01/11] tests: monitor: Label diffs to help users
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2] netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: kernel test robot <lkp@xxxxxxxxx>
- [syzbot ci] Re: netfilter: nft_ct: reject ambiguous conntrack expressions in inet tables
- From: syzbot ci <syzbot+ci86bf0c7d9e28d066@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net 1/2] selftests: netfilter: fix udpclash tool hang
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH v2 net-next 1/7] netfilter: ebtables: Use vmalloc_array() to improve code
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 1/2] selftests: netfilter: fix udpclash tool hang
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 1/2] selftests: netfilter: fix udpclash tool hang
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net 2/2] netfilter: nf_tables: Introduce NFTA_DEVICE_PREFIX
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net 1/2] selftests: netfilter: fix udpclash tool hang
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH v2 net 0/2] netfilter: updates for net
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH v5 2/3] parser_bison: Accept ASTERISK_STRING in flowtable_expr_member
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v5 1/3] mnl: Support simple wildcards in netdev hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH v4 1/8] tests: monitor: Excercise all syntaxes and variants by default
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH v4 8/8] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 3/8] tests: Prepare exit codes for automake
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 2/8] tests: py: Enable JSON and JSON schema by default
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 0/8] Run all test suites via 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v4 2/8] tests: py: Enable JSON and JSON schema by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v3 06/11] tests: py: Enable JSON and JSON schema by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v3 00/11] Run all test suites via 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 7/8] tests: build: Avoid a recursive 'make check' run
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 5/8] tests: shell: Skip packetpath/nat_ftp in fake root env
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 4/8] tests: json_echo: Skip if run as non-root
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v4 6/8] tests: build: Do not assume caller's CWD
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2 net 1/2] selftests: netfilter: fix udpclash tool hang
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v4 2/8] tests: py: Enable JSON and JSON schema by default
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v4 2/8] tests: py: Enable JSON and JSON schema by default
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v4 2/8] tests: py: Enable JSON and JSON schema by default
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v5 2/3] parser_bison: Accept ASTERISK_STRING in flowtable_expr_member
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v5 1/3] mnl: Support simple wildcards in netdev hooks
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v5 1/3] mnl: Support simple wildcards in netdev hooks
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 1/7] src: normalize set element with EXPR_MAPPING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 7/7] src: move flags from EXPR_SET_ELEM to key
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 3/7] src: assert on EXPR_SET only contains EXPR_SET_ELEM in the expressions list
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 5/7] evaluate: clean up expr_evaluate_set()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 4/7] evaluate: simplify sets as set elems evaluation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 6/7] segtree: rename set_elem_add() to set_elem_expr_add()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 0/7] prepare for EXPR_SET_ELEM removal
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 2/7] src: allocate EXPR_SET_ELEM for EXPR_SET in embedded set declaration in sets
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf-next v6 0/2] Add IPIP flowtable SW acceleratio
- From: Lorenzo Bianconi <lorenzo@xxxxxxxxxx>
- Re: [PATCH v14 nf-next 3/3] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
- From: Eric Woudstra <ericwouds@xxxxxxxxx>
- Re: [PATCH v14 nf-next 1/3] netfilter: utils: nf_checksum(_partial) correct data!=networkheader
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v14 nf-next 2/3] netfilter: bridge: Add conntrack double vlan and pppoe
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v14 nf-next 3/3] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nft 1/7] src: normalize set element with EXPR_MAPPING
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH 1/1] IPVS: Fix use-after-free issue in ip_vs_unbind_app()
- From: Slavin Liu <slavin452@xxxxxxxxx>
- Re: [PATCH nft 1/7] src: normalize set element with EXPR_MAPPING
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 3/5] mnl: Allow for updating devices on existing inet ingress hook chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 4/5] monitor: Inform JSON printer when reporting an object delete event
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 5/5] tests: monitor: Extend testcases a bit
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 3/5] mnl: Allow for updating devices on existing inet ingress hook chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH] netfilter: Set expressions out of range in nft_add_set_elem()
- From: Chen Yufeng <chenyufeng@xxxxxxxxx>
- Re: [PATCH] netfilter: Set expressions out of range in nft_add_set_elem()
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: Set expressions out of range in nft_add_set_elem()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nf-next 3/3] netfilter: nf_flow_table_ip: don't follow fastpath when marked teardown
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v3 nf-next 2/3] netfilter: nf_flow_table_core: teardown direct xmit when destination changed
- From: Florian Westphal <fw@xxxxxxxxx>
- [nft PATCH] Makefile: Fix for 'make CFLAGS=...'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH 3/5] mnl: Allow for updating devices on existing inet ingress hook chains
- From: Phil Sutter <phil@xxxxxx>
- [syzbot] [bridge?] [netfilter?] WARNING in br_nf_local_in
- From: syzbot <syzbot+aa8e2b2bfec0dd8e7e81@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [nft PATCH 3/5] mnl: Allow for updating devices on existing inet ingress hook chains
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v14 nf-next 2/3] netfilter: bridge: Add conntrack double vlan and pppoe
- From: Eric Woudstra <ericwouds@xxxxxxxxx>
- Re: [PATCH v14 nf-next 3/3] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
- From: Eric Woudstra <ericwouds@xxxxxxxxx>
- Re: [nft PATCH] Makefile: Fix for 'make CFLAGS=...'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] Makefile: Fix for 'make CFLAGS=...'
- From: Phil Sutter <phil@xxxxxx>
- Re: [syzbot] [bridge?] [netfilter?] WARNING in br_nf_local_in
- From: Ido Schimmel <idosch@xxxxxxxxxx>
- [PATCH net 4/7] netfilter: nf_tables: place base_seq in struct net
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 0/7] netfilter: updates for net
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 2/7] netfilter: nft_set_pipapo: don't check genbit from packetpath lookups
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 6/7] netfilter: nf_tables: restart set lookup on base_seq change
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 3/7] netfilter: nft_set_rbtree: continue traversal if element is inactive
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 5/7] netfilter: nf_tables: make nft_set_do_lookup available unconditionally
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 1/7] netfilter: nft_set_bitmap: fix lockdep splat due to missing annotation
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 7/7] MAINTAINERS: add Phil as netfilter reviewer
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/7] netfilter: nft_set_bitmap: fix lockdep splat due to missing annotation
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH net 0/7] netfilter: updates for net: manual merge
- From: Matthieu Baerts <matttbe@xxxxxxxxxx>
- Re: [nft PATCH] fib: Fix for existence check on Big Endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf-next v2 defer] netfilter: nft_byteorder: remove multi-register support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf 0/5] netfilter: nf_tables: fix false negative lookups with ongoing transaction
- From: Gabriel Goller <g.goller@xxxxxxxxxxx>
- Re: [nft PATCH] fib: Fix for existence check on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf 0/5] netfilter: nf_tables: fix false negative lookups with ongoing transaction
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH 4/5] monitor: Inform JSON printer when reporting an object delete event
- From: Phil Sutter <phil@xxxxxx>
- Re: [syzbot] [bridge?] [netfilter?] WARNING in br_nf_local_in
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_set_bitmap: fix lockdep splat due to missing annotation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v14 nf-next 3/3] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH 1/1] IPVS: Fix use-after-free issue in ip_vs_unbind_app()
- From: Julian Anastasov <ja@xxxxxx>
- Re: [conntrack-tools PATCH v2] nfct: helper: Extend error message for EBUSY
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH nf-next v6 1/2] net: netfilter: Add IPIP flowtable SW acceleration
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH v2] ipvs: Check ipvs->enable before unregistration in __ip_vs_ftp_exit()
- From: Slavin Liu <slavin452@xxxxxxxxx>
- Re: [nft PATCH] fib: Fix for existence check on Big Endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH] fib: Fix for existence check on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] fib: Fix for existence check on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- [PATCH nf 4/5] netfilter: nf_tables: make nft_set_do_lookup available unconditionally
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/5] netfilter: nft_set_rbtree: continue traversal if element is inactive
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/5] netfilter: nf_tables: fix false negative lookups with ongoing transaction
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 3/5] netfilter: nf_tables: place base_seq in struct net
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 1/5] netfilter: nft_set_pipapo: don't check genbit from packetpath lookups
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 5/5] netfilter: nf_tables: restart set lookup on base_seq change
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v2] ipvs: Check ipvs->enable before unregistration in __ip_vs_ftp_exit()
- From: Julian Anastasov <ja@xxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next 4/5] ipvs: Use READ_ONCE/WRITE_ONCE for ipvs->enable
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC PATCH v3] ipvs: Defer ip_vs_ftp unregister during netns cleanup
- From: Slavin Liu <slavin452@xxxxxxxxx>
- [PATCH net-next 5/5] netfilter: nf_reject: don't reply to icmp error messages
- From: Florian Westphal <fw@xxxxxxxxx>
- [libnftnl RFC] data_reg: Improve data reg value printing
- From: Phil Sutter <phil@xxxxxx>
- [PATCH net-next 3/5] netfilter: nft_meta_bridge: introduce NFT_META_BRI_IIFHWADDR support
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] fib: Fix for existence check on Big Endian
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 2/5] netfilter: ipset: Remove unused htable_bits in macro ahash_region
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 0/5] netfilter: updates for net-next
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next 1/5] selftest:net: fixed spelling mistakes
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [libnftnl RFC] data_reg: Improve data reg value printing
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH v3 11/11] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [libnftnl RFC] data_reg: Improve data reg value printing
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v4 0/8] Run all test suites via 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH 0/5] Fixes (and fallout) from running tests/monitor in JSON mode
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] fib: Fix for existence check on Big Endian
- From: Phil Sutter <phil@xxxxxx>
- [PATCH v4] ipvs: Defer ip_vs_ftp unregister during netns cleanup
- From: Slavin Liu <slavin452@xxxxxxxxx>
- [PATCH RFC nf-next 1/2] netfilter: nft_set_pipapo_avx2: fix skip of expired entries
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH RFC nf-next 2/2] selftests: netfilter: nft_concat_range.sh: add check for double-create bug
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next RFC] netfilter: flowtable: add CT metadata action for nft flowtables
- From: Elad Yifee <eladwf@xxxxxxxxx>
- Re: [PATCH RFC nf-next 1/2] netfilter: nft_set_pipapo_avx2: fix skip of expired entries
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH RFC nf-next 2/2] selftests: netfilter: nft_concat_range.sh: add check for double-create bug
- From: Stefano Brivio <sbrivio@xxxxxxxxxx>
- Re: [PATCH net-next 1/5] selftest:net: fixed spelling mistakes
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH v4] ipvs: Defer ip_vs_ftp unregister during netns cleanup
- From: Julian Anastasov <ja@xxxxxx>
- Re: [PATCH RFC nf-next 1/2] netfilter: nft_set_pipapo_avx2: fix skip of expired entries
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next RFC] netfilter: flowtable: add CT metadata action for nft flowtables
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH v4] ipvs: Defer ip_vs_ftp unregister during netns cleanup
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next RFC] netfilter: flowtable: add CT metadata action for nft flowtables
- From: Elad Yifee <eladwf@xxxxxxxxx>
- [PATCH nf-next] netfilter: ctnetlink: remove refcounting in dying list dumping
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nf_reject: don't leak dst refcount for loopback packets
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 1/7] net: Add skb_dst_reset and skb_dst_restore
- From: Stanislav Fomichev <stfomichev@xxxxxxxxx>
- Re: netfilter: br_netfilter:NS packet was incorrectly matched by the nftables rule
- From: Florian Westphal <fw@xxxxxxxxx>
- netfilter: br_netfilter:NS packet was incorrectly matched by the nftables rule
- From: gaoxingwang <gaoxingwang1@xxxxxxxxxx>
- [PATCH 3/7 nft v2] src: add tunnel statement and expression support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 2/7 nft v2] tunnel: add erspan support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 1/7 nft v2] src: add tunnel template support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 1/2 libnftnl v3] tunnel: rework options
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 7/7 nft v2] tests: add tunnel shell and python tests
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 6/7 nft v2] tunnel: add tunnel object and statement json support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 5/7 nft v2] tunnel: add geneve support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 4/7 nft v2] tunnel: add vxlan support
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- [PATCH 2/2 libnftnl v3] tunnel: add support to geneve options
- From: Fernando Fernandez Mancera <fmancera@xxxxxxx>
- Re: [PATCH net-next] netfilter: nft_payload: Use csum_replace4() instead of opencoding
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [PATCH net-next 1/7] net: Add skb_dst_reset and skb_dst_restore
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net-next 1/7] net: Add skb_dst_reset and skb_dst_restore
- From: Jakub Kicinski <kuba@xxxxxxxxxx>
- Re: [PATCH net 1/3] netfilter: nft_set_pipapo: fix null deref for empty set
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- [nft PATCH] table: Embed creating nft version into userdata
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 08/14] tests: py: Drop duplicate test from inet/vxlan.t
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 03/14] tests: py: Drop stale payload from any/rawpayload.t.payload
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 14/14] json: Do not reduce single-item arrays on output
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 07/14] tests: py: Drop stale entry from inet/tcp.t.json
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 01/14] tests: py: Drop duplicate test in any/meta.t
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 06/14] tests: py: Drop duplicate test from inet/gretap.t
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 12/14] tests: py: Drop stale entry from ip/snat.t.payload
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 11/14] tests: py: Drop stale entries from ip6/{ct,meta}.t.json
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 04/14] tests: py: Drop duplicate test from inet/geneve.t
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 00/14] json: Do not reduce single-item arrays on output
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 02/14] tests: py: Drop stale entries since redundant test case removal
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH] udata: Introduce NFTNL_UDATA_TABLE_NFT{VER,BLD}
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 10/14] tests: py: Drop stale entry from ip/snat.t.json
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 13/14] tests: py: Fix tests added for 'icmpv6 taddr' support
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 09/14] tests: py: Drop redundant payloads for ip/ip.t
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 05/14] tests: py: Drop duplicate test from inet/gre.t
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] src: netlink: netlink_delinearize_table() may return NULL
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next 5/7] staging: octeon: Convert to skb_dst_drop
- From: Greg KH <gregkh@xxxxxxxxxxxxxxxxxxx>
- [PATCH nft 12/12] src: replace compound_expr_alloc() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 11/12] expression: replace compound_expr_print() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 10/12] expression: replace compound_expr_destroy() by type safe funtion
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 09/12] expression: replace compound_expr_remove() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 03/12] src: replace compound_expr_add() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 01/12] segtree: incorrect type when aggregating concatenated set ranges
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 00/12] replace compound_expr_*() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 07/12] expression: replace compound_expr_clone() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 08/12] expression: remove compound_expr_add()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 05/12] src: replace compound_expr_add() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 06/12] segtree: rename set_compound_expr_add() to set_expr_add_splice()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 04/12] src: replace compound_expr_add() by type safe function
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nft 02/12] src: add expr_type_catchall() helper and use it
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: reject duplicate device on updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/3] netfilter: nf_tables: reject duplicate device on updates
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 1/3] netfilter: nft_set_pipapo: fix null deref for empty set
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 2/3] ipvs: Fix estimator kthreads preferred affinity
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net 0/3] Netfilter fixes for net
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [syzbot ci] Re: net: Convert to skb_dst_reset and skb_dst_restore
- From: Florian Westphal <fw@xxxxxxxxx>
- [syzbot ci] Re: net: Convert to skb_dst_reset and skb_dst_restore
- From: syzbot ci <syzbot+ci1b726090b21fedf1@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH net-next 3/7] netfilter: Switch to skb_dst_reset to clear dst_entry
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nf_tables: reject duplicate device on updates
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nft_flowtable.sh selftest failures
- From: Eric Biggers <ebiggers@xxxxxxxxxx>
- [PATCH nf] netfilter: nf_tables: reject duplicate device on updates
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net-next 7/7] net: Add skb_dst_check_unset
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 4/7] net: Switch to skb_dst_reset/skb_dst_restore for ip_route_input callers
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 5/7] staging: octeon: Convert to skb_dst_drop
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 6/7] chtls: Convert to skb_dst_reset
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 3/7] netfilter: Switch to skb_dst_reset to clear dst_entry
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 2/7] xfrm: Switch to skb_dst_reset to clear dst_entry
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 1/7] net: Add skb_dst_reset and skb_dst_restore
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- [PATCH net-next 0/7] net: Convert to skb_dst_reset and skb_dst_restore
- From: Stanislav Fomichev <sdf@xxxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Phil Sutter <phil@xxxxxx>
- Re: nft_flowtable.sh selftest failures
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH net-next] netfilter: nft_payload: Use csum_replace4() instead of opencoding
- From: Christophe Leroy <christophe.leroy@xxxxxxxxxx>
- Re: nft_flowtable.sh selftest failures
- From: Matthieu Baerts <matttbe@xxxxxxxxxx>
- Re: nft_flowtable.sh selftest failures
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: nft_flowtable.sh selftest failures
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- nft_flowtable.sh selftest failures
- From: Paolo Abeni <pabeni@xxxxxxxxxx>
- Re: [nft PATCH] table: Embed creating nft version into userdata
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nft] tests: py: revert dccp python tests
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH nf] netfilter: nft_set_pipapo: fix null deref for empty set
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft] tests: py: revert dccp python tests
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net 1/7] MAINTAINERS: resurrect my netfilter maintainer entry
- From: Antonio Ojea <antonio.ojea.garcia@xxxxxxxxx>
- Re: [PATCH net 1/7] MAINTAINERS: resurrect my netfilter maintainer entry
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: linux-next: Tree for Jul 29 (net/ipv4/netfilter/arp_tables.o)
- From: Sebastian Andrzej Siewior <bigeasy@xxxxxxxxxxxxx>
- [nft PATCH] table: Embed creating nft version into userdata
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] src: netlink: netlink_delinearize_table() may return NULL
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net 1/7] MAINTAINERS: resurrect my netfilter maintainer entry
- From: Simon Horman <horms@xxxxxxxxxx>
- Re: [nf-next RFC] netfilter: nf_tables: Introduce NFTA_DEVICE_WILDCARD
- From: Phil Sutter <phil@xxxxxx>
- [nf-next PATCH] netfilter: nf_tables: Introduce NFTA_DEVICE_PREFIX
- From: Phil Sutter <phil@xxxxxx>
- Re: [RFC nf-next] netfilter: nf_tables: remove element flush allocation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH v2 net] ipvs: Fix estimator kthreads preferred affinity
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next RFC] netfilter: nf_tables: Introduce NFTA_DEVICE_WILDCARD
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [RFC nf-next] netfilter: nf_tables: remove element flush allocation
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH net-next 06/19] netfilter: Exclude LEGACY TABLES on PREEMPT_RT.
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH net 1/7] MAINTAINERS: resurrect my netfilter maintainer entry
- From: Eric Dumazet <edumazet@xxxxxxxxxx>
- [PATCH net 7/7] netfilter: nft_socket: remove WARN_ON_ONCE with huge level value
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 6/7] netfilter: conntrack: clean up returns in nf_conntrack_log_invalid_sysctl()
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 5/7] netfilter: nft_set_pipapo: don't return bogus extension pointer
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 4/7] netfilter: ctnetlink: remove refcounting in expectation dumpers
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 3/7] netfilter: ctnetlink: fix refcount leak on table dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 2/7] netfilter: add back NETFILTER_XTABLES dependencies
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 1/7] MAINTAINERS: resurrect my netfilter maintainer entry
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [PATCH net 0/7] Netfilter fixes for net
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: ctnetlink: fix refcount leak on table dump
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_socket: remove WARN_ON_ONCE with giant cgroup tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH nf 1/2] netfilter: ctnetlink: fix refcount leak on table dump
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH] tests: shell: Fix packetpath/rate_limit for old socat
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH] tests: shell: Fix packetpath/rate_limit for old socat
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH nf] netfilter: nft_socket: remove WARN_ON_ONCE with giant cgroup tree
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf] netfilter: nft_socket: remove WARN_ON_ONCE with giant cgroup tree
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [netfilter-nf:main 37/38] ERROR: modpost: __ex_table+0x2280 references non-executable section '.data..Lubsan_type5'
- From: kernel test robot <lkp@xxxxxxxxx>
- [netfilter-nf:main 21/38] ERROR: modpost: __ex_table+0x15a8 references non-executable section '.bss.dfs_dir_mtd'
- From: kernel test robot <lkp@xxxxxxxxx>
- Re: [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] libnftnl 1.3.0 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] nftables 1.1.4 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [ANNOUNCE] nftables 1.1.4 release
- From: Jan Engelhardt <ej@xxxxxxx>
- Re: [ANNOUNCE] libnftnl 1.3.0 release
- From: Jan Engelhardt <ej@xxxxxxx>
- [nft PATCH] tests: shell: Fix packetpath/rate_limit for old socat
- From: Phil Sutter <phil@xxxxxx>
- [ANNOUNCE] nftables 1.1.4 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [ANNOUNCE] libnftnl 1.3.0 release
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: When routed to VRF, NF _output_ hook is run unexpectedly
- From: Nicolas Dichtel <nicolas.dichtel@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/4] selftests/bpf: add icmp_send_unreach kfunc tests
- From: Jordan Rife <jordan@xxxxxxxx>
- [PATCH nft 2/2] tests: shell: add parser and packetpath test
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nft 1/2] evaluate: check XOR RHS operand is a constant value
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH net-next 06/19] netfilter: Exclude LEGACY TABLES on PREEMPT_RT.
- From: Ryan Roberts <ryan.roberts@xxxxxxx>
- Re: [PATCH net-next] netfilter: clean up returns in nf_conntrack_log_invalid_sysctl()
- From: Lance Yang <lance.yang@xxxxxxxxx>
- [PATCH net-next] netfilter: clean up returns in nf_conntrack_log_invalid_sysctl()
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Lance Yang <lance.yang@xxxxxxxxx>
- [PATCH nf] netfilter: nft_set_pipapo: don't return bogus extension pointer
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Lance Yang <lance.yang@xxxxxxxxx>
- Re: [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Lance Yang <lance.yang@xxxxxxxxx>
- Re: [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Lance Yang <lance.yang@xxxxxxxxx>
- [bug report] netfilter: nft_set: remove one argument from lookup and update functions
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- [bug report] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid
- From: Dan Carpenter <dan.carpenter@xxxxxxxxxx>
- Re: [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Yonghong Song <yonghong.song@xxxxxxxxx>
- Re: [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Alexei Starovoitov <alexei.starovoitov@xxxxxxxxx>
- Re: [PATCH bpf-next v3 0/4] bpf: add icmp_send_unreach kfunc
- From: Mahe Tardy <mahe.tardy@xxxxxxxxx>
- Re: [PATCH bpf 4/4] selftests/bpf: Test for unaligned flow_dissector ctx access
- From: Yonghong Song <yonghong.song@xxxxxxxxx>
- Re: [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Yonghong Song <yonghong.song@xxxxxxxxx>
- Re: [PATCH bpf 1/4] bpf: Check flow_dissector ctx accesses are aligned
- From: patchwork-bot+netdevbpf@xxxxxxxxxx
- Re: [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Eduard Zingerman <eddyz87@xxxxxxxxx>
- Re: [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Paul Chaignon <paul.chaignon@xxxxxxxxx>
- Re: [PATCH bpf 4/4] selftests/bpf: Test for unaligned flow_dissector ctx access
- From: Eduard Zingerman <eddyz87@xxxxxxxxx>
- [nft PATCH 4/6] tests: json_echo: Skip if run as non-root
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 1/6] tests: Prepare exit codes for automake
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 3/6] tests: py: Set default options based on RUN_FULL_TESTSUITE
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 6/6] Makefile: Enable support for 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 2/6] tests: monitor: Support running all tests in one go
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 0/6] Run all test suites via 'make check'
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH 5/6] tests: shell: Skip packetpath/nat_ftp in fake root env
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Eduard Zingerman <eddyz87@xxxxxxxxx>
- Re: [PATCH bpf 2/4] bpf: Check netfilter ctx accesses are aligned
- From: Eduard Zingerman <eddyz87@xxxxxxxxx>
- Re: [PATCH bpf 1/4] bpf: Check flow_dissector ctx accesses are aligned
- From: Eduard Zingerman <eddyz87@xxxxxxxxx>
- Re: [PATCH bpf 2/4] bpf: Check netfilter ctx accesses are aligned
- From: Yonghong Song <yonghong.song@xxxxxxxxx>
- Re: [PATCH bpf 1/4] bpf: Check flow_dissector ctx accesses are aligned
- From: Yonghong Song <yonghong.song@xxxxxxxxx>
- [PATCH nf 1/2] netfilter: ctnetlink: fix refcount leak on table dump
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 2/2] netfilter: ctnetlink: remove refcounting in expectation dumpers
- From: Florian Westphal <fw@xxxxxxxxx>
- [PATCH nf 0/2] netfilter: ctnetlink: fix memory leak in ctnetlink dump
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH] doc: nft.8: Minor NAT STATEMENTS section review
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH] doc: nft.8: Minor NAT STATEMENTS section review
- From: Phil Sutter <phil@xxxxxx>
- [PATCH bpf 4/4] selftests/bpf: Test for unaligned flow_dissector ctx access
- From: Paul Chaignon <paul.chaignon@xxxxxxxxx>
- [PATCH bpf 3/4] bpf: Improve ctx access verifier error message
- From: Paul Chaignon <paul.chaignon@xxxxxxxxx>
- [PATCH bpf 2/4] bpf: Check netfilter ctx accesses are aligned
- From: Paul Chaignon <paul.chaignon@xxxxxxxxx>
- [PATCH bpf 1/4] bpf: Check flow_dissector ctx accesses are aligned
- From: Paul Chaignon <paul.chaignon@xxxxxxxxx>
- nftables 1.0.6.y stable branch updates (strike 2)
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next RFC] netfilter: nf_tables: Introduce NFTA_DEVICE_WILDCARD
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v5 3/3] tests: shell: Test ifname-based hooks
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v5 2/3] parser_bison: Accept ASTERISK_STRING in flowtable_expr_member
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v5 1/3] mnl: Support simple wildcards in netdev hooks
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v5 0/3] Support wildcard netdev hooks
- From: Phil Sutter <phil@xxxxxx>
- [libnftnl PATCH v4] utils: Add helpers for interface name wildcards
- From: Phil Sutter <phil@xxxxxx>
- Re: [PATCH] netfilter: add back NETFILTER_XTABLES dependencies
- From: Breno Leitao <leitao@xxxxxxxxxx>
- Re: [REGRESSION] v6.16 system hangs (bisected to nf_conntrack fix)
- From: Dan Moulding <dan@xxxxxxxx>
- Re: [REGRESSION] v6.16 system hangs (bisected to nf_conntrack fix)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [PATCH] netfilter: add back NETFILTER_XTABLES dependencies
- From: Florian Westphal <fw@xxxxxxxxx>
- [RFC nf-next] netfilter: nf_tables: remove element flush allocation
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nft PATCH v3 0/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Phil Sutter <phil@xxxxxx>
- Re: [nft PATCH v3 0/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- [nft PATCH v3 1/3] expression: Introduce is_symbol_value_expr() macro
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 2/3] parser_json: Parse into symbol range expression if possible
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 0/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Phil Sutter <phil@xxxxxx>
- [nft PATCH v3 3/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Phil Sutter <phil@xxxxxx>
- [PATCH] netfilter: add back NETFILTER_XTABLES dependencies
- From: Arnd Bergmann <arnd@xxxxxxxxxx>
- Re: [nft PATCH v2 0/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 3/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nft PATCH v2 0/3] evaluate: Fix for 'meta hour' ranges spanning date boundaries
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [nf-next 0/2] netfilter: nf_tables: make set flush more resistant to memory pressure
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [nf-next 0/2] netfilter: nf_tables: make set flush more resistant to memory pressure
- From: Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>
- Re: [PATCH v2 net] ipvs: Fix estimator kthreads preferred affinity
- From: Julian Anastasov <ja@xxxxxx>
- [syzbot] [netfilter?] WARNING in __nf_unregister_net_hook (9)
- From: syzbot <syzbot+78ac1e46d2966eb70fda@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Re: [PATCH bpf-next v3 0/4] bpf: add icmp_send_unreach kfunc
- From: Martin KaFai Lau <martin.lau@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/4] selftests/bpf: add icmp_send_unreach kfunc tests
- From: Martin KaFai Lau <martin.lau@xxxxxxxxx>
- Re: linux-next: Tree for Jul 29 (net/ipv4/netfilter/arp_tables.o)
- From: Randy Dunlap <rdunlap@xxxxxxxxxxxxx>
- Re: [PATCH bpf-next v3 4/4] selftests/bpf: add icmp_send_unreach kfunc tests
- From: Martin KaFai Lau <martin.lau@xxxxxxxxx>
- Re: [PATCH bpf-next v3 4/4] selftests/bpf: add icmp_send_unreach kfunc tests
- From: Martin KaFai Lau <martin.lau@xxxxxxxxx>
- Re: [PATCH bpf-next v3 3/4] bpf: add bpf_icmp_send_unreach cgroup_skb kfunc
- From: Martin KaFai Lau <martin.lau@xxxxxxxxx>
- Re: [REGRESSION] v6.16 system hangs (bisected to nf_conntrack fix)
- From: Florian Westphal <fw@xxxxxxxxx>
- Re: [REGRESSION] v6.16 system hangs (bisected to nf_conntrack fix)
- From: Dan Moulding <dan@xxxxxxxx>
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite News]
[Samba]