Re: [PATCH nf-next 1/7] netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello:

This series was applied to netdev/net-next.git (main)
by Pablo Neira Ayuso <pablo@xxxxxxxxxxxxx>:

On Tue,  6 May 2025 01:41:45 +0200 you wrote:
> From: Huajian Yang <huajianyang@xxxxxxxxxxxx>
> 
> The config NF_CONNTRACK_BRIDGE will change the bridge forwarding for
> fragmented packets.
> 
> The original bridge does not know that it is a fragmented packet and
> forwards it directly, after NF_CONNTRACK_BRIDGE is enabled, function
> nf_br_ip_fragment and br_ip6_fragment will check the headroom.
> 
> [...]

Here is the summary with links:
  - [nf-next,1/7] netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it
    https://git.kernel.org/netdev/net-next/c/aa04c6f45b92
  - [nf-next,2/7] selftests: netfilter: add conntrack stress test
    https://git.kernel.org/netdev/net-next/c/d33f889fd80c
  - [nf-next,3/7] netfilter: nft_quota: match correctly when the quota just depleted
    https://git.kernel.org/netdev/net-next/c/bfe7cfb65c75
  - [nf-next,4/7] netfilter: nf_conntrack: speed up reads from nf_conntrack proc file
    https://git.kernel.org/netdev/net-next/c/5e4d107abd79
  - [nf-next,5/7] netfilter: nft_set_pipapo: prevent overflow in lookup table allocation
    https://git.kernel.org/netdev/net-next/c/4c5c6aa9967d
  - [nf-next,6/7] netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX
    https://git.kernel.org/netdev/net-next/c/b85e3367a571
  - [nf-next,7/7] selftests: netfilter: nft_fib.sh: check lo packets bypass fib lookup
    https://git.kernel.org/netdev/net-next/c/fc91d5e6d948

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html






[Index of Archives]     [Netfitler Users]     [Berkeley Packet Filter]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux