Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [syzbot] [netfilter?] WARNING in nft_socket_init (2), (continued)
- [nf-next RFC] netfilter: nf_tables: Introduce NFTA_DEVICE_WILDCARD,
Phil Sutter
- [PATCH nft] src: fix memory leak in anon chain error handling,
Florian Westphal
- [PATCH net v2] selftests: netfilter: ipvs.sh: Explicity disable rp_filter on interface tunl0,
Yi Chen
- [PATCH] selftests: netfilter: ipvs.sh: Explicity disable rp_filter on interface tunl0,
Yi Chen
- [nf PATCH] selftests: netfilter: Ignore tainted kernels in interface stress test, Phil Sutter
- [PATCH nft] parser_bison: fix memory leak when parsing flowtable hook declaration,
Florian Westphal
- Subject: [nftables] Bug: dup rule fails to modify MAC address on netdev/ingress hook,
zs@xxxxxxxx
- Re: [PATCH V2] netfilter: nf_conntrack: table full detailed log,
Pablo Neira Ayuso
- [PATCH v2 bpf] bpf: Disable migration in nf_hook_run_bpf().,
Kuniyuki Iwashima
- [ipset PATCH] tests: Fix for standalone calls to setlist_resize.sh, Phil Sutter
- [iptables PATCH 1/2] Revert "libxtables: Promote xtopt_esize_by_type() as xtopt_psize getter",
Phil Sutter
- [PATCH v2 net] selftests: netfilter: tone-down conntrack clash test,
Florian Westphal
- [PATCH nf-next v5 0/2] Add IPIP flowtable SW acceleratio,
Lorenzo Bianconi
- [PATCH nft] parser_json: fix assert due to empty interface name,
Florian Westphal
- [PATCH nft] parser_json: reject non-concat expression,
Florian Westphal
- [PATCH nft] evaluate: maps: check element data mapping matches set data definition,
Florian Westphal
- [syzbot] Monthly netfilter report (Jul 2025), syzbot
- [PATCH bpf-next] netfilter: bpf: Disable migrate before bpf_prog run,
Tao Chen
- [iptables PATCH] libxtables: Promote xtopt_esize_by_type() as xtopt_psize getter,
Phil Sutter
- [PATCH nf-next v4 0/2] Add IPIP flowtable SW acceleratio,
Lorenzo Bianconi
- [syzbot] [netfilter?] KASAN: slab-out-of-bounds Read in nfacct_mt_checkentry,
syzbot
- [PATCH v1 bpf] bpf: Disable migration in nf_hook_run_bpf().,
Kuniyuki Iwashima
- [syzbot] [netfilter?] [sctp?] BUG: assuming non migratable context at ./include/linux/filter.h:LINE, syzbot
- [PATCH net,v2 0/7] Netfilter fixes for net,
Pablo Neira Ayuso
- [PATCH iptables v2] extensions: libebt_redirect: prevent translation,
Miao Wang via B4 Relay
- [nft PATCH v4 0/3] Support wildcard netdev hooks,
Phil Sutter
- [PATCH v2 nf] netfilter: nf_conntrack: fix crash due to removal of uninitialised entry, Florian Westphal
- __nf_ct_delete_from_lists crash, with bisected guilty commit found,
Razvan Cojocaru
- [libnftnl PATCH] utils: Add helpers for interface name wildcards,
Phil Sutter
- [nft PATCH v3 0/4] Support wildcard netdev hooks,
Phil Sutter
- [libnftnl PATCH v3] utils: Add helpers for interface name wildcards,
Phil Sutter
- [nft PATCH v2 0/3] Support wildcard netdev hooks,
Phil Sutter
- [libnftnl PATCH v2] utils: Add helpers for interface name wildcards,
Phil Sutter
- [PATCH] tests: shell: add type route chain test case,
Yi Chen
- [PATCH nft] json: BASECHAIN flag no longer implies presence of priority expression, Florian Westphal
- Who's focused on dynamic 'nft' autocomplete?, S Egbert
- [no subject], Unknown
- Feedback on variable sized set elements,
Shaun Brady
- [nf PATCH] Revert "netfilter: nf_tables: Add notifications for hook changes",
Phil Sutter
- add_cmd non-terminal symbol in Bison parser needs to go on a diet, S Egbert
- [PATCH bpf-next v4 0/7] Move attach_type into bpf_link,
Tao Chen
- Netfilter updates for net-next (v2),
Pablo Neira Ayuso
- [PATCH nft] doc: expand on gc-interval, size and a few other set/map keywords,
Florian Westphal
- [PATCH conntrack-tools] Typo in contrackd-conf manpage,
Xavier Claude
- [PATCH nf-next v2 0/5] netfilter: nft_set updates,
Florian Westphal
- [PATCH bpf-next v3 0/7] Add attach_type in bpf_link,
Tao Chen
- [PATCH nft 0/4] detach concat, list and set expression layouts,
Pablo Neira Ayuso
- [PATCH nft] rule: print chain and flowtable devices in quotes,
Pablo Neira Ayuso
- [PATCH v14 nf-next 0/3] conntrack: bridge: add double vlan, pppoe and pppoe-in-q,
Eric Woudstra
- [nft PATCH] mnl: Support NFNL_HOOK_TYPE_NFT_FLOWTABLE,
Phil Sutter
- [nf-next PATCH 1/2] netfilter: nfnetlink: New NFNLA_HOOK_INFO_DESC helper,
Phil Sutter
- [PATCH bpf-next v2 0/7] Add attach_type in bpf_link,
Tao Chen
- [PATCH nft v3] src: add conntrack information to trace monitor mode,
Florian Westphal
- [PATCH nf] netfilter: nf_tables: hide clash bit from userspace,
Florian Westphal
- [PATCH bpf-next 0/6] Move attach_type into bpf_link,
Tao Chen
- [PATCH net] netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto(),
Eric Dumazet
- [syzbot] [netfilter?] KMSAN: uninit-value in nf_flow_offload_inet_hook (2), syzbot
- [PATCH nft 0/2] src: add conntrack information to trace monitor mode,
Florian Westphal
- [PATCH v13 nf-next 0/3] conntrack: bridge: add double vlan, pppoe and pppoe-in-q,
Eric Woudstra
- [nf-next 0/2] netfilter: nf_tables: make set flush more resistant to memory pressure,
Florian Westphal
- [PATCH nft 0/3] make the mss and wscale fields optional for synproxy object,
Zhongqiu Duan
- [PATCH RESEND] ipvs: ip_vs_conn_expire_now: Rename del_timer in comment,
WangYuli
- [PATCH nft v2] tests: py: re-enables nft-test.py to load the local nftables.py, Zhongqiu Duan
- [PATCH nf-next v3 0/2] Add IPIP flowtable SW acceleratio,
Lorenzo Bianconi
- [PATCH nft] tests: py: correct the py utils path in the source tree,
Zhongqiu Duan
- [PATCH nft] tests: shell: use the given NFT instead of the one in the search path,
Zhongqiu Duan
- [no subject], Unknown
- [nf-next RFC] netfilter: nf_tables: Feature ifname-based hook registration,
Phil Sutter
- [iptables PATCH] extensions: sctp: Translate bare '-m sctp' match,
Phil Sutter
- [PATCH nf-next 0/3] netfilter: nft_set_pipapo: Use nested-BH locking for nft_pipapo_scratch,
Sebastian Andrzej Siewior
- [PATCH nf-next 0/5] netfilter: nft_set updates,
Florian Westphal
- [PATCH nf] selftests: netfilter: nft_concat_range.sh: send packets to empty set, Florian Westphal
- [PATCH v5 0/3] netfilter: Exclude LEGACY TABLES on PREEMPT_RT.,
Sebastian Andrzej Siewior
- [PATCH nft] doc: Clarify cgroup meta variable, Michal Koutný
- More json files pushed to nftables.git, Florian Westphal
- [PATCH net-next] netfilter: conntrack: Remove unused net in nf_conntrack_double_lock(),
Yue Haibing
- [PATCH nf 0/4] netfilter: conntrack: fix obscure confirmed race,
Florian Westphal
- [PATCH net-next v2 0/2] Add IPIP flowtable SW acceleratio,
Lorenzo Bianconi
- [PATCH nft] src: provide elem_stmt structure to shrink compact counters,
Pablo Neira Ayuso
- [PATCH nft] evaluate: check element key vs. set definition, Florian Westphal
- [PATCH nft] evaluate: prevent merge of sets with incompatible keys,
Florian Westphal
- [nft PATCH] tests: shell: Fix ifname_based_hooks feature check,
Phil Sutter
- Cannot allocate memory delete table inet filter,
Sven Auhagen
- [no subject], Unknown
- [PATCH nft] json: reject too long interface names,
Florian Westphal
- [PATCH nft] evaluate: avoid double-free on error handling of bogus objref maps,
Florian Westphal
- [PATCH nft] evaluate: make sure chain jump name comes with a null byte,
Florian Westphal
- [PATCH nft,v2 1/2] fib: allow to check if route exists in maps,
Pablo Neira Ayuso
- [PATCH nft 0/2] fib expression fixes,
Pablo Neira Ayuso
- [PATCH nf] netfilter: nf_tables: adjust lockdep assertions handling,
Fedor Pchelkin
- [PATCH net-next] netfilter: nf_tables: Remove unused nft_reduce_is_readonly(),
Yue Haibing
- [PATCH net-next] netfilter: x_tables: Remove unused functions xt_{in|out}name(), Yue Haibing
- [PATCH nft v2] evaluate: check that set type is identical before merging,
Florian Westphal
- [PATCH nft] evaluate: refuse to merge set and map,
Florian Westphal
- [PATCH net-next] net: netfilter: Add IPIP flowtable SW acceleration,
Lorenzo Bianconi
- [PATCH conntrack-tools v3 0/2] conntrack: introduce --labelmap option to specify connlabel.conf path,
Christoph Heiss
- [PATCH v2 1/4] test: shell: Don't use system nft binary,
Yi Chen
- When routed to VRF, NF _output_ hook is run unexpectedly,
Eugene Crosser
- [PATCH] netfilter: ipset: fix typo in hash size macro,
RubenKelevra
- [syzbot] Monthly netfilter report (Jun 2025), syzbot
- [PATCH conntrack-tools v2 0/2] conntrack: introduce --labelmap option to specify connlabel.conf path,
Christoph Heiss
- [PATCH] tests: shell: Add a test case to verify the limit statement.,
Yi Chen
[PATCH] tests: shell: Verify limit statement with new test case., Yi Chen
[PATCH v2] tests: shell: Verify limit statement with new test case., Yi Chen
[PATCH v3 nf-next 0/3] flow offload teardown when layer 2 roaming,
Eric Woudstra
[RFC PATCH v2 nf-next] selftests: netfilter: Add bridge_fastpath.sh,
Eric Woudstra
[PATCH v12 nf-next 0/2] conntrack: bridge: add double vlan, pppoe and pppoe-in-q,
Eric Woudstra
[PATCH nft 0/3] memory reduction in concatenation and maps,
Pablo Neira Ayuso
[PATCH v2 1/1] asn: fix missing quiet checks in xt_asn_build,
Philip Prindeville
[PATCH nft 0/5] assorted updates and fixes,
Pablo Neira Ayuso
[PATCH nft] evalute: don't BUG on unexpected base datatype,
Florian Westphal
[nf-next PATCH v2 0/2] netfilter: nf_tables: Fix for extra data in delete notifications,
Phil Sutter
[PATCH conntrack-tools] conntrack: introduce --labelmap option to specify connlabel.conf path,
Christoph Heiss
[nft PATCH] netlink: Avoid crash upon missing NFTNL_OBJ_CT_TIMEOUT_ARRAY attribute,
Phil Sutter
[nf-next PATCH v2] netfilter: nf_tables: Fix for extra data in delete notifications,
Phil Sutter
[PATCH v2 nft] src: move BASECHAIN flag toggle to netlink linearize code for device update, Florian Westphal
[nf-next PATCH] netfilter: nf_tables: Fix for extra data in delete notifications, Phil Sutter
[nf-next PATCH 0/3] netfilter: nf_tables: Report found devices when creating a netdev hook,
Phil Sutter
[nft PATCH 0/7] Misc fixes,
Phil Sutter
[PATCH nft] src: use constant range expression for interval+concatenation sets, Pablo Neira Ayuso
[syzbot] [netfilter?] WARNING: refcount bug in nf_nat_masq_schedule, syzbot
[PATCH libnftnl,v2,WIP] tunnel: rework options, Pablo Neira Ayuso
[PATCH libnftnl] tunnel: rework options, Pablo Neira Ayuso
Status of native NAT64/NAT46 in Netfilter?,
Klaus Frank
[PATCH nft v2 1/2] evaluate: rename recursion counter to recursion.binop,
Florian Westphal
[PATCH nft] evaluate: fix crash when set name is null,
Florian Westphal
[nft] mnl: catch bogus expressions before crashing,
Florian Westphal
[PATCH nft] src: move BASECHAIN flag toggle to netlink linearize code for device update,
Florian Westphal
[PATCH] tests: shell: Add a test case for FTP helper combined with NAT.,
Yi Chen
[PATCH -stable,5.4 0/1] Netfilter fix for -stable,
Pablo Neira Ayuso
[ANNOUNCE] knft testing/fuzzer utility for nftables, Pablo Neira Ayuso
[nft PATCH] doc: Basic documentation of anonymous chains,
Phil Sutter
Document anonymous chain creation,
Folsk Pratima
[Bug] kernel panic: Hard LOCKUP at 'net/netfilter/nf_conntrack_core.c' in Linux kernel v6.12, Luka
[PATCH AUTOSEL 6.12 54/93] netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX, Sasha Levin
[PATCH AUTOSEL 6.14 063/108] netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX, Sasha Levin
[PATCH AUTOSEL 6.15 071/118] netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX, Sasha Levin
[PATCH 5.10 113/270] netfilter: nf_tables: wait for rcu grace period on net_device removal, Greg Kroah-Hartman
[PATCH 5.10 114/270] netfilter: nf_tables: do not defer rule destruction via call_rcu,
Greg Kroah-Hartman
[PATCH 5.4 186/204] netfilter: nf_tables: wait for rcu grace period on net_device removal, Greg Kroah-Hartman
[PATCH 5.4 187/204] netfilter: nf_tables: do not defer rule destruction via call_rcu, Greg Kroah-Hartman
[PATCH 5.4 185/204] netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx, Greg Kroah-Hartman
[PATCH 5.10 112/270] netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx, Greg Kroah-Hartman
[PATCH 5.10] netfilter: nft_socket: fix sk refcount leaks,
Denis Arefev
[PATCH nft] json: prevent null deref if chain->policy is not set,
Florian Westphal
[PATCH nft] json: work around fuzzer-induced assert crashes,
Florian Westphal
[PATCH nft] tests: py: fix json single-flag output for fib & synproxy,
Florian Westphal
[PATCH nf 1/2] netfilter: nf_nat: also check reverse tuple to obtain clashing entry,
Florian Westphal
[PATCH xtables-addons v2 0/3] Some fixes for v6.15,
Jeremy Sowden
[PATCH xtables-addons 0/3] Some fixes for v6.15,
Jeremy Sowden
[PATCH nft] tests: shell: check for features not available in 5.4, Pablo Neira Ayuso
[PATCH -stable,5.4 0/3] Netfilter fixes for -stable,
Pablo Neira Ayuso
[bug report, linux 6.15-rc4] A large number of connections in the SYN_SENT state caused the nf_conntrack table to be full.,
ying chen
[BUG REPORT] netfilter: DNS/SNAT Issue in Kubernetes Environment,
Yafang Shao
[PATCH] f, Elie Khalil
[PATCH 0/7 nft] Add nftables tunnel expr, stmt and object support,
Fernando Fernandez Mancera
[PATCH 1/2 libnftnl v2] src: use uint64_t for flags fields,
Fernando Fernandez Mancera
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]