aboutsummaryrefslogtreecommitdiff
path: root/net/netfilter/nf_tables_api.c
AgeCommit message (Expand)AuthorFilesLines
2024-01-24netfilter: nf_tables: reject QUEUE/DROP verdict parametersGravatar Florian Westphal 1-10/+6
2024-01-24netfilter: nf_tables: restrict anonymous set and map names to 16 bytesGravatar Florian Westphal 1-0/+4
2024-01-17netfilter: nf_tables: reject NFT_SET_CONCAT with not field length descriptionGravatar Pablo Neira Ayuso 1-1/+5
2024-01-17netfilter: nf_tables: skip dead set elements in netlink dumpGravatar Pablo Neira Ayuso 1-1/+1
2024-01-17netfilter: nf_tables: do not allow mismatch field size and set key lengthGravatar Pablo Neira Ayuso 1-1/+5
2024-01-17netfilter: nf_tables: check if catch-all set element is active in next genera...Gravatar Pablo Neira Ayuso 1-1/+1
2024-01-17netfilter: nf_tables: bail out if stateful expression provides no .cloneGravatar Pablo Neira Ayuso 1-8/+7
2024-01-17netfilter: nf_tables: validate .maxattr at expression registrationGravatar Pablo Neira Ayuso 1-0/+3
2024-01-17netfilter: nf_tables: reject invalid set policyGravatar Pablo Neira Ayuso 1-1/+9
2024-01-04Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netGravatar Jakub Kicinski 1-1/+1
2023-12-22netfilter: nf_tables: validate chain type update if availableGravatar Pablo Neira Ayuso 1-1/+10
2023-12-22netfilter: nf_tables: mark newset as dead on transaction abortGravatar Florian Westphal 1-0/+1
2023-12-22netfilter: nf_tables: Add locking for NFT_MSG_GETSETELEM_RESET requestsGravatar Phil Sutter 1-17/+81
2023-12-22netfilter: nf_tables: Introduce nft_set_dump_ctx_init()Gravatar Phil Sutter 1-16/+33
2023-12-22netfilter: nf_tables: Pass const set to nft_get_set_elemGravatar Phil Sutter 1-3/+3
2023-12-20netfilter: nf_tables: skip set commit for deleted/destroyed setsGravatar Pablo Neira Ayuso 1-1/+1
2023-12-06netfilter: nf_tables: validate family when identifying table via handleGravatar Pablo Neira Ayuso 1-2/+3
2023-11-14netfilter: nf_tables: split async and sync catchall in two functionsGravatar Pablo Neira Ayuso 1-25/+30
2023-11-14netfilter: nf_tables: bogus ENOENT when destroying element which does not existGravatar Pablo Neira Ayuso 1-2/+3
2023-11-08netfilter: nf_tables: remove catchall element in GC sync pathGravatar Pablo Neira Ayuso 1-5/+17
2023-11-08netfilter: add missing module descriptionsGravatar Florian Westphal 1-0/+1
2023-10-24netfilter: nf_tables: Carry reset boolean in nft_set_dump_ctxGravatar Phil Sutter 1-10/+8
2023-10-24netfilter: nf_tables: set->ops->insert returns opaque set element in case of ...Gravatar Pablo Neira Ayuso 1-7/+10
2023-10-24netfilter: nf_tables: shrink memory consumption of set elementsGravatar Pablo Neira Ayuso 1-91/+75
2023-10-24netfilter: nf_tables: expose opaque set element as struct nft_elem_privGravatar Pablo Neira Ayuso 1-12/+15
2023-10-24netfilter: nf_tables: set backend .flush always succeedsGravatar Pablo Neira Ayuso 1-8/+1
2023-10-24netfilter: nf_tables: Carry reset boolean in nft_obj_dump_ctxGravatar Phil Sutter 1-6/+6
2023-10-24netfilter: nf_tables: nft_obj_filter fits into cb->ctxGravatar Phil Sutter 1-11/+5
2023-10-24netfilter: nf_tables: Carry s_idx in nft_obj_dump_ctxGravatar Phil Sutter 1-4/+5
2023-10-24netfilter: nf_tables: A better name for nft_obj_filterGravatar Phil Sutter 1-16/+16
2023-10-24netfilter: nf_tables: Unconditionally allocate nft_obj_filterGravatar Phil Sutter 1-21/+15
2023-10-24netfilter: nf_tables: Drop pointless memset in nf_tables_dump_objGravatar Phil Sutter 1-3/+0
2023-10-24netfilter: nf_tables: Add locking for NFT_MSG_GETRULE_RESET requestsGravatar Phil Sutter 1-13/+64
2023-10-24netfilter: nf_tables: Introduce nf_tables_getrule_single()Gravatar Phil Sutter 1-31/+43
2023-10-24netfilter: nf_tables: Open-code audit log call in nf_tables_getrule()Gravatar Phil Sutter 1-4/+15
2023-10-19Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netGravatar Jakub Kicinski 1-36/+34
2023-10-18netfilter: nf_tables: revert do not remove elements if set backend implements...Gravatar Pablo Neira Ayuso 1-4/+1
2023-10-18netfilter: nf_tables: audit log object reset once per tableGravatar Phil Sutter 1-22/+28
2023-10-12nf_tables: fix NULL pointer dereference in nft_expr_inner_parse()Gravatar Xingyuan Mo 1-1/+1
2023-10-12netfilter: nf_tables: do not refresh timeout when resetting elementGravatar Pablo Neira Ayuso 1-13/+5
2023-10-12netfilter: nf_tables: do not remove elements if set backend implements .abortGravatar Pablo Neira Ayuso 1-1/+4
2023-10-10netfilter: nf_tables: Don't allocate nft_rule_dump_ctxGravatar Phil Sutter 1-13/+6
2023-10-10netfilter: nf_tables: Carry s_idx in nft_rule_dump_ctxGravatar Phil Sutter 1-4/+4
2023-10-10netfilter: nf_tables: Carry reset flag in nft_rule_dump_ctxGravatar Phil Sutter 1-10/+9
2023-10-10netfilter: nf_tables: Drop pointless memset when dumping rulesGravatar Phil Sutter 1-4/+0
2023-10-10netfilter: nf_tables: Always allocate nft_rule_dump_ctxGravatar Phil Sutter 1-27/+21
2023-10-05Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netGravatar Jakub Kicinski 1-16/+28
2023-10-04netfilter: nf_tables: Deduplicate nft_register_obj audit logsGravatar Phil Sutter 1-16/+28
2023-09-28netfilter: nf_tables: Utilize NLA_POLICY_NESTED_ARRAYGravatar Phil Sutter 1-9/+9
2023-09-28netfilter: nf_tables: missing extended netlink error in lookup functionsGravatar Pablo Neira Ayuso 1-6/+19