summaryrefslogtreecommitdiffstats
path: root/net/netfilter (follow)
Commit message (Expand)AuthorAgeFilesLines
* netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to yGeert Uytterhoeven2022-08-171-1/+0
* netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specifiedPablo Neira Ayuso2022-08-151-0/+5
* netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVA...Pablo Neira Ayuso2022-08-151-0/+3
* netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flagsPablo Neira Ayuso2022-08-151-0/+24
* netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flagPablo Neira Ayuso2022-08-121-4/+9
* netfilter: nf_tables: really skip inactive sets when allocating namePablo Neira Ayuso2022-08-111-1/+1
* netfilter: nfnetlink: re-enable conntrack expectation eventsFlorian Westphal2022-08-111-12/+71
* netfilter: nf_tables: fix scheduling-while-atomic splatFlorian Westphal2022-08-111-4/+0
* netfilter: nf_ct_irc: cap packet search space to 4kFlorian Westphal2022-08-111-3/+9
* netfilter: nf_ct_ftp: prefer skb_linearizeFlorian Westphal2022-08-111-18/+6
* netfilter: nf_ct_h323: cap packet size at 64kFlorian Westphal2022-08-111-1/+9
* netfilter: nf_ct_sane: remove pseudo skb linearizationFlorian Westphal2022-08-111-38/+30
* netfilter: nf_tables: possible module reference underflow in error pathPablo Neira Ayuso2022-08-101-1/+1
* netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERV...Pablo Neira Ayuso2022-08-101-0/+1
* netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id a...Pablo Neira Ayuso2022-08-101-7/+13
* netfilter: nf_tables: fix null deref due to zeroed list headFlorian Westphal2022-08-091-0/+1
* netfilter: nf_tables: disallow jump to implicit chain from set elementPablo Neira Ayuso2022-08-091-0/+4
* netfilter: nf_tables: upfront validation of data via nft_data_init()Pablo Neira Ayuso2022-08-095-113/+124
* netfilter: nf_tables: do not allow RULE_ID to refer to another chainThadeu Lima de Souza Cascardo2022-08-091-2/+5
* netfilter: nf_tables: do not allow CHAIN_ID to refer to another tableThadeu Lima de Souza Cascardo2022-08-091-2/+4
* netfilter: nf_tables: do not allow SET_ID to refer to another tableThadeu Lima de Souza Cascardo2022-08-091-1/+3
* netfilter: nf_tables: validate variable length element extensionPablo Neira Ayuso2022-08-092-16/+70
* netfilter: flowtable: fix incorrect Kconfig dependenciesPablo Neira Ayuso2022-08-061-2/+1
* netfilter: nf_tables: fix crash when nf_trace is enabledFlorian Westphal2022-08-061-11/+10
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski2022-07-293-1/+39
|\
| * netfilter: nft_queue: only allow supported familes and hooksFlorian Westphal2022-07-261-0/+27
| * netfilter: nf_tables: add rescheduling points during loop detection walksFlorian Westphal2022-07-261-0/+6
| * netfilter: nf_queue: do not allow packet truncation below transport header of...Florian Westphal2022-07-261-1/+6
* | Merge https://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-nextJakub Kicinski2022-07-233-139/+342
|\ \
| * | net: netfilter: Add kfuncs to set and change CT statusLorenzo Bianconi2022-07-223-37/+74
| * | net: netfilter: Add kfuncs to set and change CT timeoutKumar Kartikeya Dwivedi2022-07-223-11/+58
| * | net: netfilter: Add kfuncs to allocate and insert CTLorenzo Bianconi2022-07-222-27/+189
| * | net: netfilter: Deduplicate code in bpf_{xdp,skb}_ct_lookupKumar Kartikeya Dwivedi2022-07-221-34/+18
| * | bpf: Switch to new kfunc flags infrastructureKumar Kartikeya Dwivedi2022-07-221-38/+11
* | | Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski2022-07-211-1/+1
|\ \ \ | | |/ | |/|
| * | ip: Fix data-races around sysctl_ip_default_ttl.Kuniyuki Iwashima2022-07-151-1/+1
* | | Merge git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-nextJakub Kicinski2022-07-2131-260/+385
|\ \ \ | |/ / |/| |
| * | netfilter: xt_TPROXY: remove pr_debug invocationsJustin Stitt2022-07-211-23/+2
| * | netfilter: flowtable: prefer refcount_incFlorian Westphal2022-07-211-8/+3
| * | netfilter: ipvs: Use the bitmap API to allocate bitmapsChristophe JAILLET2022-07-211-3/+2
| * | netfilter: nf_tables: move nft_cmp_fast_mask to where its usedFlorian Westphal2022-07-111-0/+12
| * | netfilter: nf_tables: use correct integer typesFlorian Westphal2022-07-114-11/+12
| * | netfilter: nf_tables: add and use BE register load-store helpersFlorian Westphal2022-07-111-3/+3
| * | netfilter: nf_tables: use the correct get/put helpersFlorian Westphal2022-07-114-10/+11
| * | netfilter: x_tables: use correct integer typesFlorian Westphal2022-07-113-9/+9
| * | netfilter: nfnetlink: add missing __be16 castFlorian Westphal2022-07-111-1/+1
| * | netfilter: nft_set_bitmap: Fix spelling mistakeZhang Jiaming2022-07-111-2/+2
| * | netfilter: h323: merge nat hook pointers into oneFlorian Westphal2022-07-111-161/+99
| * | netfilter: nf_conntrack: use rcu accessors where neededFlorian Westphal2022-07-117-16/+57
| * | netfilter: nf_conntrack: add missing __rcu annotationsFlorian Westphal2022-07-113-3/+3