Linux Netfilter / IP Tables Devel
[Prev Page][Next Page]
- Re: [PATCH 2/2 libnftnl v2] tunnel: add support to geneve options, (continued)
- [net-next PATCH] selftests: netfilter: Fix skip of wildcard interface test,
Phil Sutter
- [PATCH ulogd2 v2 0/4] Add support for logging ARP packets,
Jeremy Sowden
- [PATCH v2 1/1] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid,
Lance Yang
- [PATCH] ipset: Modify pernet_operations check,
Mike Pagano
- [PATCH net-next,v2 00/26] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 02/26] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds, Pablo Neira Ayuso
- [PATCH net-next 01/26] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation, Pablo Neira Ayuso
- [PATCH net-next 03/26] selftests: netfilter: nft_fib.sh: add 'type' mode tests, Pablo Neira Ayuso
- [PATCH net-next 04/26] selftests: netfilter: move fib vrf test to nft_fib.sh, Pablo Neira Ayuso
- [PATCH net-next 05/26] netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy, Pablo Neira Ayuso
- [PATCH net-next 07/26] selftests: netfilter: nft_fib.sh: add type and oif tests with and without VRFs, Pablo Neira Ayuso
- [PATCH net-next 06/26] netfilter: nf_tables: nft_fib: consistent l3mdev handling, Pablo Neira Ayuso
- [PATCH net-next 09/26] netfilter: nf_dup{4, 6}: Move duplication check to task_struct, Pablo Neira Ayuso
- [PATCH net-next 08/26] netfilter: nft_tunnel: fix geneve_opt dump, Pablo Neira Ayuso
- [PATCH net-next 10/26] netfilter: nft_inner: Use nested-BH locking for nft_pcpu_tun_ctx, Pablo Neira Ayuso
- [PATCH net-next 12/26] netfilter: conntrack: make nf_conntrack_id callable without a module dependency, Pablo Neira Ayuso
- [PATCH net-next 11/26] netfilter: nf_dup_netdev: Move the recursion counter struct netdev_xmit, Pablo Neira Ayuso
- [PATCH net-next 13/26] netfilter: nf_tables: add packets conntrack state to debug trace info, Pablo Neira Ayuso
- [PATCH net-next 14/26] netfilter: nf_tables: Introduce functions freeing nft_hook objects, Pablo Neira Ayuso
- [PATCH net-next 16/26] netfilter: nf_tables: Introduce nft_register_flowtable_ops(), Pablo Neira Ayuso
- [PATCH net-next 15/26] netfilter: nf_tables: Introduce nft_hook_find_ops{,_rcu}(), Pablo Neira Ayuso
- [PATCH net-next 17/26] netfilter: nf_tables: Pass nf_hook_ops to nft_unregister_flowtable_hook(), Pablo Neira Ayuso
- [PATCH net-next 18/26] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook, Pablo Neira Ayuso
- [PATCH net-next 20/26] netfilter: nf_tables: Respect NETDEV_REGISTER events, Pablo Neira Ayuso
- [PATCH net-next 19/26] netfilter: nf_tables: Prepare for handling NETDEV_REGISTER events, Pablo Neira Ayuso
- [PATCH net-next 21/26] netfilter: nf_tables: Wrap netdev notifiers, Pablo Neira Ayuso
- [PATCH net-next 23/26] netfilter: nf_tables: Sort labels in nft_netdev_hook_alloc(), Pablo Neira Ayuso
- [PATCH net-next 24/26] netfilter: nf_tables: Support wildcard netdev hook specs, Pablo Neira Ayuso
- [PATCH net-next 22/26] netfilter: nf_tables: Handle NETDEV_CHANGENAME events, Pablo Neira Ayuso
- [PATCH net-next 26/26] selftests: netfilter: Torture nftables netdev hooks, Pablo Neira Ayuso
- [PATCH net-next 25/26] netfilter: nf_tables: Add notifications for hook changes, Pablo Neira Ayuso
- [PATCH nf-next 0/3] netfilter: nf_set_pipapo_avx2: fix initial map fill,
Florian Westphal
- [PATCH v2] selftests: net: fix spelling and grammar mistakes,
Praveen Balakrishnan
- [PATCH net-next 00/26] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH net-next 03/26] selftests: netfilter: nft_fib.sh: add 'type' mode tests, Pablo Neira Ayuso
- [PATCH net-next 01/26] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation, Pablo Neira Ayuso
- [PATCH net-next 02/26] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds, Pablo Neira Ayuso
- [PATCH net-next 04/26] selftests: netfilter: move fib vrf test to nft_fib.sh, Pablo Neira Ayuso
- [PATCH net-next 07/26] selftests: netfilter: nft_fib.sh: add type and oif tests with and without VRFs, Pablo Neira Ayuso
- [PATCH net-next 05/26] netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy, Pablo Neira Ayuso
- [PATCH net-next 08/26] netfilter: nft_tunnel: fix geneve_opt dump, Pablo Neira Ayuso
- [PATCH net-next 12/26] netfilter: conntrack: make nf_conntrack_id callable without a module dependency, Pablo Neira Ayuso
- [PATCH net-next 11/26] netfilter: nf_dup_netdev: Move the recursion counter struct netdev_xmit, Pablo Neira Ayuso
- [PATCH net-next 06/26] netfilter: nf_tables: nft_fib: consistent l3mdev handling, Pablo Neira Ayuso
- [PATCH net-next 09/26] netfilter: nf_dup{4, 6}: Move duplication check to task_struct, Pablo Neira Ayuso
- [PATCH net-next 10/26] netfilter: nft_inner: Use nested-BH locking for nft_pcpu_tun_ctx, Pablo Neira Ayuso
- [PATCH net-next 16/26] netfilter: nf_tables: Introduce nft_register_flowtable_ops(), Pablo Neira Ayuso
- [PATCH net-next 19/26] netfilter: nf_tables: Prepare for handling NETDEV_REGISTER events, Pablo Neira Ayuso
- [PATCH net-next 15/26] netfilter: nf_tables: Introduce nft_hook_find_ops{,_rcu}(), Pablo Neira Ayuso
- [PATCH net-next 13/26] netfilter: nf_tables: add packets conntrack state to debug trace info, Pablo Neira Ayuso
- [PATCH net-next 14/26] netfilter: nf_tables: Introduce functions freeing nft_hook objects, Pablo Neira Ayuso
- [PATCH net-next 17/26] netfilter: nf_tables: Pass nf_hook_ops to nft_unregister_flowtable_hook(), Pablo Neira Ayuso
- [PATCH net-next 18/26] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook, Pablo Neira Ayuso
- [PATCH net-next 25/26] netfilter: nf_tables: Add notifications for hook changes, Pablo Neira Ayuso
- [PATCH net-next 24/26] netfilter: nf_tables: Support wildcard netdev hook specs, Pablo Neira Ayuso
- [PATCH net-next 20/26] netfilter: nf_tables: Respect NETDEV_REGISTER events, Pablo Neira Ayuso
- [PATCH net-next 21/26] netfilter: nf_tables: Wrap netdev notifiers, Pablo Neira Ayuso
- [PATCH net-next 22/26] netfilter: nf_tables: Handle NETDEV_CHANGENAME events, Pablo Neira Ayuso
- [PATCH net-next 23/26] netfilter: nf_tables: Sort labels in nft_netdev_hook_alloc(), Pablo Neira Ayuso
- [PATCH net-next 26/26] selftests: netfilter: Torture nftables netdev hooks, Pablo Neira Ayuso
- [PATCH nf-next,v2] netfilter: conntrack: remove DCCP protocol support,
Pablo Neira Ayuso
- [PATCH libnftnl v2] trace: add support for TRACE_CT information,
Florian Westphal
- [PATCH nf-next v2 0/2] netfilter: nf_tables: include conntrack state in trace messages,
Florian Westphal
- nft_queues.sh failures,
Paolo Abeni
- [PATCH nf-next] netfilter: conntrack: remove DCCP protocol support, Pablo Neira Ayuso
- [nf-next PATCH v7 00/13] Dynamic hook interface binding part 2,
Phil Sutter
- [nf-next PATCH v7 03/13] netfilter: nf_tables: Introduce nft_register_flowtable_ops(), Phil Sutter
- [nf-next PATCH v7 02/13] netfilter: nf_tables: Introduce nft_hook_find_ops{,_rcu}(), Phil Sutter
- [nf-next PATCH v7 13/13] selftests: netfilter: Torture nftables netdev hooks, Phil Sutter
- [nf-next PATCH v7 11/13] netfilter: nf_tables: Support wildcard netdev hook specs, Phil Sutter
- [nf-next PATCH v7 01/13] netfilter: nf_tables: Introduce functions freeing nft_hook objects, Phil Sutter
- [nf-next PATCH v7 08/13] netfilter: nf_tables: Wrap netdev notifiers, Phil Sutter
- [nf-next PATCH v7 10/13] netfilter: nf_tables: Sort labels in nft_netdev_hook_alloc(), Phil Sutter
- [nf-next PATCH v7 06/13] netfilter: nf_tables: Prepare for handling NETDEV_REGISTER events, Phil Sutter
- [nf-next PATCH v7 07/13] netfilter: nf_tables: Respect NETDEV_REGISTER events, Phil Sutter
- [nf-next PATCH v7 05/13] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook, Phil Sutter
- [nf-next PATCH v7 12/13] netfilter: nf_tables: Add notifications for hook changes, Phil Sutter
- [nf-next PATCH v7 04/13] netfilter: nf_tables: Pass nf_hook_ops to nft_unregister_flowtable_hook(), Phil Sutter
- [nf-next PATCH v7 09/13] netfilter: nf_tables: Handle NETDEV_CHANGENAME events, Phil Sutter
- [nft PATCH 0/4] Continue upon netlink deserialization failures,
Phil Sutter
- Re: [PATCH] netfilter: nf_conntrack: table full detailed log, Pablo Neira Ayuso
- [PATCH nf] netfilter: nft_tunnel: fix geneve_opt dump, Fernando Fernandez Mancera
- [PATCH nf-next v2 0/5] netfilter: resolve fib+vrf issues,
Florian Westphal
- [PATCH 6.1 88/97] netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx, Greg Kroah-Hartman
- [PATCH 6.1 89/97] netfilter: nf_tables: wait for rcu grace period on net_device removal, Greg Kroah-Hartman
- [PATCH 6.1 90/97] netfilter: nf_tables: do not defer rule destruction via call_rcu, Greg Kroah-Hartman
- [PATCH 5.15 58/59] netfilter: nf_tables: do not defer rule destruction via call_rcu, Greg Kroah-Hartman
- [PATCH 5.15 56/59] netfilter: nf_tables: pass nft_chain to destroy function, not nft_ctx, Greg Kroah-Hartman
- [PATCH 5.15 57/59] netfilter: nf_tables: wait for rcu grace period on net_device removal, Greg Kroah-Hartman
- [PATCH nf-next,v2 1/4] netfilter: nf_tables: add infrastructure for chain validation on updates,
Pablo Neira Ayuso
- [PATCH nf-next,v2 1/2] netfilter: nf_tables: honor EINTR in ruleset validation from commit/abort path,
Pablo Neira Ayuso
- [PATCH v5 1/2] netfilter: nf_tables: Implement jump limit for nft_table_validate,
Shaun Brady
- [PATCH nft] tests: shell: check if kernel supports for cgroupsv2 matching, Pablo Neira Ayuso
- [PATCH -stable,5.10 0/3] Netfilter fixes for -stable,
Pablo Neira Ayuso
- [PATCH nft] tests: shell: skip egress in netdev chain release path test, Pablo Neira Ayuso
- [PATCH -stable,5.15 0/3] Netfilter fixes for -stable,
Pablo Neira Ayuso
- [PATCH -stable,6.1 0/3] Netfilter fixes for -stable,
Pablo Neira Ayuso
- [ANNOUNCE] ipset 7.24 released, Jozsef Kadlecsik
- [nft PATCH 0/2] Sanitize two error conditions in netlink code,
Phil Sutter
- [PATCH nf-next] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds,
Florian Westphal
- [PATCH v4] netfilter: nf_tables: Implement jump limit for nft_table_validate,
Shaun Brady
- [PATCH nf-next 0/5] netfilter: resolve fib+vrf issues,
Florian Westphal
- [PATCH nf-next,v1 0/6] revisiting nf_tables ruleset validation,
Pablo Neira Ayuso
- [PATCH nf-next,v1 3/6] netfilter: nf_tables: add infrastructure for chain validation on updates, Pablo Neira Ayuso
- [PATCH nf-next,v1 4/6] netfilter: nf_tables: add new binding infrastructure, Pablo Neira Ayuso
- [PATCH nf-next,v1 1/6] netfilter: nf_tables: honor EINTR in ruleset validation from commit/abort path, Pablo Neira Ayuso
- [PATCH nf-next,v1 2/6] netfilter: nf_tables: honor validation state in preparation phase, Pablo Neira Ayuso
- [PATCH nf-next,v1 5/6] netfilter: nf_tables: use new binding infrastructure, Pablo Neira Ayuso
- [PATCH nf-next,v1 6/6] netfilter: nf_tables: add support for validating incremental ruleset updates, Pablo Neira Ayuso
- Re: [PATCH nf-next,v1 0/6] revisiting nf_tables ruleset validation, Florian Westphal
- Packets sent to local interface seemingly not accepted by nfq_set_verdict despite ACCEPT call., G.W. Haywood
- Recommendations for choice of compiler; does it matter?, Sunny73Cr
- libmnl name definition,
Sunny73Cr
- [RESEND PATCH 1/1] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid,
Lance Yang
- [PATCH 1/1] netfilter: load nf_log_syslog on enabling nf_conntrack_log_invalid, Lance Yang
- Looking for TODO,
Shaun Brady
- [nft RFC] table: Embed creating nft version into userdata, Phil Sutter
- [PATCH v3] netfilter: nf_tables: Implement jump limit for nft_table_validate,
Shaun Brady
- [PATCH nf-next v1 0/3] netfilter: Cover more per-CPU storage with local nested BH locking.,
Sebastian Andrzej Siewior
- Fix resource leak in iptables/xtables-restore.c,
周恺航
- [PATCH 5.10.y] netfilter: nf_tables: fix memleak in map from abort path, jianqi.ren.cn
- [PATCH 5.15.y] netfilter: nf_tables: fix memleak in map from abort path, jianqi.ren.cn
- [PATCH 6.1.y] netfilter: nf_tables: fix memleak in map from abort path,
jianqi.ren.cn
- [nft PATCH] tests: shell: Include kernel taint value in warning,
Phil Sutter
- [PATCH nft] src: add conntrack information to trace monitor mode,
Florian Westphal
- [PATCH libnftnl] trace: add support for TRACE_CT information, Florian Westphal
- [PATCH nf-next 0/2] netfilter: nf_tables: include conntrack state in trace messages,
Florian Westphal
- [PATCH nft] src: netlink: fix crash when ops doesn't support udata,
Florian Westphal
- [nft PATCH] tests/shell: Skip netdev_chain_dev_addremove on tainted kernels,
Phil Sutter
- [PATCHv2 net-next 0/6] selftests: net: configure rp_filter in setup_ns,
Hangbin Liu
- [nft PATCH] parser_json: Introduce parse_flags_array(),
Phil Sutter
- [PATCH 0/1] ipset patch to fix region locking,
Jozsef Kadlecsik
- [PATCH net-next 0/6] selftests: net: configure rp_filter in setup_ns,
Hangbin Liu
- [PATCH net-next] selftests: netfilter: fix conntrack stress test failures on debug kernels,
Florian Westphal
- [PATCH nf-next] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation,
Florian Westphal
- nftables netlink cache initialization failure with dnsmasq,
Monib
- [PATCH v2] netfilter: nf_tables: Implement jump limit for nft_table_validate,
Shaun Brady
- [PATCH AUTOSEL 5.10 033/114] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH AUTOSEL 5.15 048/153] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH AUTOSEL 6.1 067/212] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH AUTOSEL 6.6 084/294] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH AUTOSEL 5.4 25/79] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH AUTOSEL 6.12 135/486] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH AUTOSEL 6.14 169/642] netfilter: conntrack: Bound nf_conntrack sysctl writes, Sasha Levin
- [PATCH nf] ipvs: fix uninit-value for saddr in do_output_route4,
Julian Anastasov
- [syzbot] [lvs?] KMSAN: uninit-value in do_output_route4,
syzbot
- [PATCH net-next v3 08/18] netfilter: nf_dup_netdev: Move the recursion counter struct netdev_xmit, Sebastian Andrzej Siewior
- [PATCH net-next v3 07/18] netfilter: nft_inner: Use nested-BH locking for nft_pcpu_tun_ctx, Sebastian Andrzej Siewior
- Privatkredit, theodoseraymond5
- [PATCH v1] nf_conntrack: sysctl: expose gc worker scan interval via sysctl,
avimalin
- [PATCH net-next 0/6,v3] Netfilter updates for net-next,
Pablo Neira Ayuso
- Re: [PATCH V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl,
Pablo Neira Ayuso
- [PATCH] net:ipv4: Use shift left 2 to calculate the length of the IPv4 header., Chaohai Chen
- [PATCH iptables] extensions: libebt_redirect: prevent translation,
Miao Wang via B4 Relay
- Fail to clone iptables,ipset,nftables,
Sunny73Cr
- [PATCH net-next,v2 0/7] Netfilter updates for net-next,
Pablo Neira Ayuso
- [PATCH nf-next] tools: selftests: prepare for non-default IP_TABLES_LEGACY,
Florian Westphal
- [PATCH 5.10/5.15/6.1] netfilter: ipt_CLUSTERIP: change mutex location, Evgeny Pimenov
- [PATCH nf-next] netfilter: nf_tables: fix debug splat when dumping pipapo avx2 set,
Florian Westphal
- [iptables PATCH] xshared: Accept an option if any given command allows it,
Phil Sutter
- [PATCH nf-next] selftests: netfilter: nft_fib.sh: check lo packets bypass fib lookup,
Florian Westphal
- Bug: iptables -L and -Z at the same time now refuses other options, Adam Nielsen
- [PATCH v2 nf-next] netfilter: nf_conntrack: speed up reads from nf_conntrack proc file, Florian Westphal
- [ANNOUNCE] nftables 1.1.3 release,
Pablo Neira Ayuso
- [no subject], Unknown
- [PATCH] netfilter: nf_tables: Implement jump limit for nft_table_validate,
Shaun Brady
- [PATCH nf-next] netfilter: use `NFPROTO_*` constants in "nf-logger-" module aliasses,
Jeremy Sowden
- [PATCH ulogd2 0/6] Add support for logging ARP packets,
Jeremy Sowden
- [PATCH ulogd2 3/6] IP2HBIN, IP2STR: correct typo's, Jeremy Sowden
- [PATCH ulogd2 2/6] db, IP2BIN: correct `format_ipv6()` output buffer sizes, Jeremy Sowden
- [PATCH ulogd2 1/6] IP2STR: correct address buffer size, Jeremy Sowden
- [PATCH ulogd2 4/6] IP2BIN, IP2HBIN, IP2STR: refactor `interp` call-backs, Jeremy Sowden
- [PATCH ulogd2 6/6] Add support for logging ARP packets, Jeremy Sowden
- [PATCH ulogd2 5/6] Use `NFPROTO_*` constants for protocol families, Jeremy Sowden
- [PATCH nft] evalute: make vlan pcp updates work,
Florian Westphal
- [PATCH nft] netlink: bogus concatenated set ranges with netlink message overrun, Pablo Neira Ayuso
- [PATCH nf-next v2] netfilter: nft_quota: match correctly when the quota just depleted,
Zhongqiu Duan
- [PATCH nf-next] selftests: netfilter: add conntrack stress test,
Florian Westphal
- [nftables PATCH v3] tools: add a systemd unit for static rulesets,
Jan Engelhardt
- [PATCH nft] Revert "intervals: do not merge intervals with different timeout",
Pablo Neira Ayuso
- [syzbot] Monthly netfilter report (Apr 2025), syzbot
- [PATCH] tests: shell: Update packetpath/flowtables,
Yi Chen
- [PATCH 1/2 libnftnl] src: use uint64_t for flags fields,
Fernando Fernandez Mancera
- [nf-next PATCH v6 00/12] Dynamic hook interface binding part 2,
Phil Sutter
- [nf-next PATCH v6 01/12] netfilter: nf_tables: Introduce functions freeing nft_hook objects, Phil Sutter
- [nf-next PATCH v6 09/12] netfilter: nf_tables: Handle NETDEV_CHANGENAME events, Phil Sutter
- [nf-next PATCH v6 03/12] netfilter: nf_tables: Introduce nft_register_flowtable_ops(), Phil Sutter
- [nf-next PATCH v6 11/12] netfilter: nf_tables: Add notications for hook changes, Phil Sutter
- [nf-next PATCH v6 02/12] netfilter: nf_tables: Introduce nft_hook_find_ops{,_rcu}(), Phil Sutter
- [nf-next PATCH v6 10/12] netfilter: nf_tables: Support wildcard netdev hook specs, Phil Sutter
- [nf-next PATCH v6 07/12] netfilter: nf_tables: Respect NETDEV_REGISTER events, Phil Sutter
- [nf-next PATCH v6 05/12] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook, Phil Sutter
- [nf-next PATCH v6 08/12] netfilter: nf_tables: Wrap netdev notifiers, Phil Sutter
- [nf-next PATCH v6 04/12] netfilter: nf_tables: Pass nf_hook_ops to nft_unregister_flowtable_hook(), Phil Sutter
- [nf-next PATCH v6 06/12] netfilter: nf_tables: Prepare for handling NETDEV_REGISTER events, Phil Sutter
- [nf-next PATCH v6 12/12] selftests: netfilter: Torture nftables netdev hooks, Phil Sutter
- Re: [nf-next PATCH v6 00/12] Dynamic hook interface binding part 2, Phil Sutter
- Re: [nf-next PATCH v6 00/12] Dynamic hook interface binding part 2, Pablo Neira Ayuso
- [PATCH nf] netfilter: conntrack: fix erronous removal of offload bit, Florian Westphal
- [ANNOUNCE] nftables 1.1.2 release,
Pablo Neira Ayuso
- [ANNOUNCE] libnftnl 1.2.9 release, Pablo Neira Ayuso
- [PATCH net-next v2 08/18] netfilter: nf_dup_netdev: Move the recursion counter struct netdev_xmit, Sebastian Andrzej Siewior
- [PATCH net-next v2 07/18] netfilter: nft_inner: Use nested-BH locking for nft_pcpu_tun_ctx, Sebastian Andrzej Siewior
- [PATCH libnftnl] tunnel: add missing inner nested netlink attribute for vxlan options, Fernando Fernandez Mancera
- [PATCH v2 4/5] ipvs: ip_vs_conn_expire_now: Rename del_timer in comment, WangYuli
- Re: [PATCH V5] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl,
Jakub Kicinski
- Re: SYNPROXY affecting initial BBR throughput,
Florian Westphal
- [PATCH nft] parser_bison: add selector_expr rule to restrict typeof_expr, Pablo Neira Ayuso
- [no subject], Unknown
- [PATCH nf-next,v2 1/2] netfilter: nft_set_pipapo: prevent overflow in lookup table allocation,
Pablo Neira Ayuso
- [PATCH nf-next] netfilter: nft_set_pipapo: prevent overflow in allocations, Pablo Neira Ayuso
- [PATCH] net: Move specific fragmented packet to slow_path instead of dropping it,
Huajian Yang
- [PATCH nf] netfilter: nft_quota: make nft_overquota() really over the quota,
Zhongqiu Duan
- [PATCH nft] optimize: invalidate merge in case of duplicated key in set/map, Pablo Neira Ayuso
- [PATCH] net: Expand headroom to send fragmented packets in bridge fragment forward,
Huajian Yang
- Re: [PATCH V3] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl,
Florian Westphal
[no subject], Unknown
[RFC bpf-next 00/13] bpf: Introduce modular verifier,
Daniel Xu
[PATCH v2 nf-next 0/3] flow offload teardown when layer 2 roaming,
Eric Woudstra
[PATCH v11 nf-next 0/6] netfilter: Add bridge-fastpath,
Eric Woudstra
[PATCH v11 nf-next 0/3] netfilter: fastpath fixes,
Eric Woudstra
[PATCH v11 nf-next 0/2] conntrack: bridge: add double vlan, pppoe and pppoe-in-q,
Eric Woudstra
[PATCH v11 nf-next 0/2] Add nf_flow_encap_push() for xmit direct,
Eric Woudstra
[RFC PATCH v1 nf-next] selftests: netfilter: Add bridge_fastpath.sh, Eric Woudstra
[PATCH v2 nftables 0/4] src: print count variable in normal set listings,
Florian Westphal
[PATCH v2 libnftnl] set: dump set backend name (hash, rbtree...) and elem count, if available, Florian Westphal
[PATCH v2 nf-next] netfilter: nf_tables: export set count and backend name to userspace,
Florian Westphal
Re: [PATCH V2] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl,
Florian Westphal
[PATCH v2 nf-next] docs: tproxy: fix formatting for nft code block,
Chen Linxuan
[PATCH v3 nf 0/3] nft_set_pipapo: fix incorrect avx2 match of 5th field octet,
Florian Westphal
Re: [PATCH] docs: tproxy: fix formatting for nft code block,
Simon Horman
Re: [PATCH] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl,
Florian Westphal
[PATCH v4] netfilter: Exclude LEGACY TABLES on PREEMPT_RT.,
Sebastian Andrzej Siewior
[PATCH 1/1] netfilter: Exclude LEGACY TABLES on PREEMPT_RT., Pablo Neira Ayuso
[PATCH v2 nf 0/3] nft_set_pipapo: fix incorrect avx2 match of 5th field octet,
Florian Westphal
[PATCH nf-next] netfilter: Remove redundant NFCT_ALIGN call,
Xuanqiang Luo
[PATCH nf 0/3] nft_set_pipapo: fix incorrect avx2 match of 5th field octet,
Florian Westphal
[PATCH nft] evaluate: bail out early if referenced set is invalid, Florian Westphal
[PATCH net v1] netfilter: nft_tunnel: fix geneve_opt type confusion addition, Lin Ma
[PATCH nft] evaluate: bail out if ct saddr/daddr dependency cannot be inserted,
Florian Westphal
[PATCH net] netfilter: nft_tunnel: fix geneve_opt type confusion addition,
Lin Ma
[PATCH nft 1/2] evaluate: rename recursion counter to recursion.binop,
Florian Westphal
[PATCH nf,v2] netfilter: nf_tables: don't unregister hook when table is dormant, Pablo Neira Ayuso
[PATCH libnetfilter_queue] src: doc: Fix spelling and function name (x2), Duncan Roe
[PATCH nft] parser_json: only allow concatenations with 2 or more expressions,
Florian Westphal
[PATCH nft] optimize: expand expression list when merging into concatenation, Pablo Neira Ayuso
[PATCH nft] cache: prevent possible crash rule filter is NULL, Pablo Neira Ayuso
[PATCH nft 1/2] parser_json: allow statement stateful statement only in set elements,
Pablo Neira Ayuso
[PATCH nft] cache: don't crash when filter is NULL,
Florian Westphal
[PATCH nf] netfilter: nft_set_hash: GC reaps elements with conncount for dynamic sets only, Pablo Neira Ayuso
[PATCH nf] netfilter: nf_tables: don't unregister hook when table is dormant,
Florian Westphal
[PATCH v3 0/3] netfilter: Make xt_cgroup independent from net_cls,
Michal Koutný
[PATCH nft] expression: incorrect assert() list_expr_to_binop, Pablo Neira Ayuso
[PATCH nft,v2] parser_json: reject empty jump/goto chain, Pablo Neira Ayuso
[syzbot] [netfilter?] WARNING in __nf_unregister_net_hook (8), syzbot
[PATCH nft] parser_json: reject empty jump/goto chain, Pablo Neira Ayuso
[PATCH nft] expression: initialize list of expression to silence gcc compile warning, Pablo Neira Ayuso
[PATCH nft 1/2] evaluate: compact STMT_F_STATEFUL checks,
Florian Westphal
[PATCH nft 1/2] evaluate: reject: remove unused expr function argument,
Florian Westphal
[PATCH ulogd2 1/2] ulog: remove input plugin,
Corubba Smith
[iptables PATCH] extensions: icmp: Support info-request/-reply type names,
Phil Sutter
[PATCH nft] json: fix error protagation when parsing binop lhs/rhs,
Florian Westphal
[nft PATCH] tests: shell: Fix owner/0002-persist on aarch64,
Phil Sutter
[nft PATCH] tests: shell: Add socat availability feature test,
Phil Sutter
[PATCH nft v2] json: don't BUG when asked to list synproxies,
Florian Westphal
[PATCH nft] expression: don't try to import empty string,
Florian Westphal
[PATCH ulogd2,v3 1/4] ulogd: add linux namespace helper,
Corubba Smith
[Index of Archives]
[LARTC]
[Berkeley Packet Filter]
[Bugtraq]
[Yosemite Discussion]