aboutsummaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2022-07-26netfilter: nft_queue: only allow supported familes and hooksGravatar Florian Westphal 1-0/+27
2022-07-26netfilter: nf_tables: add rescheduling points during loop detection walksGravatar Florian Westphal 1-0/+6
2022-07-26netfilter: nf_queue: do not allow packet truncation below transport header of...Gravatar Florian Westphal 1-1/+6
2022-07-15ip: Fix data-races around sysctl_ip_default_ttl.Gravatar Kuniyuki Iwashima 1-1/+1
2022-07-09netfilter: nf_tables: replace BUG_ON by element length checkGravatar Pablo Neira Ayuso 1-21/+51
2022-07-09netfilter: nf_log: incorrect offset to network headerGravatar Pablo Neira Ayuso 1-4/+4
2022-07-07netfilter: conntrack: fix crash due to confirmed bit load reorderingGravatar Florian Westphal 3-0/+26
2022-07-02netfilter: nft_set_pipapo: release elements in clone from abort pathGravatar Pablo Neira Ayuso 1-15/+33
2022-07-02netfilter: nf_tables: stricter validation of element dataGravatar Pablo Neira Ayuso 1-1/+8
2022-06-27netfilter: nf_tables: avoid skb access on nf_stolenGravatar Florian Westphal 2-23/+45
2022-06-27netfilter: nft_dynset: restore set element counter when failing to updateGravatar Pablo Neira Ayuso 1-0/+2
2022-06-21netfilter: nf_dup_netdev: add and use recursion counterGravatar Florian Westphal 1-4/+15
2022-06-21netfilter: nf_dup_netdev: do not push mac header a second timeGravatar Florian Westphal 1-4/+10
2022-06-17netfilter: cttimeout: fix slab-out-of-bounds read typo in cttimeout_net_exitGravatar Florian Westphal 1-1/+1
2022-06-08netfilter: use get_random_u32 instead of prandomGravatar Florian Westphal 2-20/+5
2022-06-06netfilter: nf_tables: bail out early if hardware offload is not supportedGravatar Pablo Neira Ayuso 2-2/+23
2022-06-06netfilter: nf_tables: memleak flow rule from commit pathGravatar Pablo Neira Ayuso 1-0/+6
2022-06-06netfilter: nf_tables: release new hooks on unsupported flowtable flagsGravatar Pablo Neira Ayuso 1-4/+8
2022-06-02netfilter: nf_tables: always initialize flowtable hook list in transactionGravatar Pablo Neira Ayuso 1-0/+1
2022-06-02netfilter: nf_tables: delete flowtable hooks via transaction listGravatar Pablo Neira Ayuso 1-25/+6
2022-06-01netfilter: nf_tables: use kfree_rcu(ptr, rcu) to release hooks in clean_net pathGravatar Pablo Neira Ayuso 1-1/+1
2022-06-01netfilter: nat: really support inet nat without l3 addressGravatar Florian Westphal 1-1/+2
2022-05-31netfilter: flowtable: fix nft_flow_route source address for nat caseGravatar wenxu 1-2/+2
2022-05-31netfilter: flowtable: fix missing FLOWI_FLAG_ANYSRC flagGravatar wenxu 1-0/+2
2022-05-31netfilter: nf_tables: double hook unregistration in netns pathGravatar Pablo Neira Ayuso 1-13/+41
2022-05-31netfilter: nf_tables: hold mutex on netns pre_exit pathGravatar Pablo Neira Ayuso 1-0/+4
2022-05-31netfilter: nf_tables: sanitize nft_set_desc_concat_parse()Gravatar Pablo Neira Ayuso 1-4/+13
2022-05-27netfilter: nf_tables: set element extended ACK reporting supportGravatar Pablo Neira Ayuso 1-3/+9
2022-05-27netfilter: cttimeout: fix slab-out-of-bounds read in cttimeout_net_exitGravatar Florian Westphal 1-2/+3
2022-05-27netfilter: nfnetlink: fix warn in nfnetlink_unbindGravatar Florian Westphal 1-19/+5
2022-05-26netfilter: nft_limit: Clone packet limits' cost valueGravatar Phil Sutter 1-0/+2
2022-05-26netfilter: nf_tables: disallow non-stateful expression in sets earlierGravatar Pablo Neira Ayuso 1-9/+10
2022-05-19Merge git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-nextGravatar Jakub Kicinski 3-48/+17
2022-05-19Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netGravatar Jakub Kicinski 4-70/+48
2022-05-18netfilter: nf_tables: disable expression reduction infraGravatar Pablo Neira Ayuso 1-10/+1
2022-05-18netfilter: flowtable: move dst_check to packet pathGravatar Ritaro Takenaka 2-22/+20
2022-05-18netfilter: flowtable: fix TCP flow teardownGravatar Pablo Neira Ayuso 2-27/+9
2022-05-18netfilter: ctnetlink: fix up for "netfilter: conntrack: remove unconfirmed list"Gravatar Stephen Rothwell 1-0/+2
2022-05-16netfilter: conntrack: remove pr_debug callsites from tcp trackerGravatar Florian Westphal 1-48/+4
2022-05-16netfilter: nf_conncount: reduce unnecessary GCGravatar William Tu 1-0/+11
2022-05-16netfilter: nft_flow_offload: fix offload with pppoe + vlanGravatar Felix Fietkau 1-1/+2
2022-05-16netfilter: nft_flow_offload: skip dst neigh lookup for ppp devicesGravatar Felix Fietkau 1-9/+13
2022-05-16netfilter: flowtable: fix excessive hw offload attempts after failureGravatar Felix Fietkau 1-1/+3
2022-05-16Merge git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-nextGravatar David S. Miller 12-300/+411
2022-05-13netfilter: flowtable: nft_flow_route use more data for reverse routeGravatar Sven Auhagen 1-0/+8
2022-05-13netfilter: conntrack: add nf_conntrack_events autodetect modeGravatar Florian Westphal 3-8/+24
2022-05-13netfilter: conntrack: un-inline nf_ct_ecache_ext_addGravatar Florian Westphal 2-3/+33
2022-05-13netfilter: nfnetlink: allow to detect if ctnetlink listeners existGravatar Florian Westphal 1-3/+37
2022-05-13netfilter: conntrack: add nf_ct_iter_data object for nf_ct_iterate_cleanup*()Gravatar Pablo Neira Ayuso 5-41/+47
2022-05-13netfilter: conntrack: avoid unconditional local_bh_disableGravatar Florian Westphal 1-5/+2