Patches

Show patches with: Submitter = Pablo Neira       |    Archived = No   
« 1 2 3 425 26 »
Patch A/R/T S/W/F Date Submitter Delegate State
[4/4] netfilter: ctnetlink: fix incorrect nf_ct_put during hash resize - - - 0 0 0 2017-05-29 Pablo Neira davem Accepted
[3/4] netfilter: nat: use atomic bit op to clear the _SRC_NAT_DONE_BIT - - - 0 0 0 2017-05-29 Pablo Neira davem Accepted
[2/4] netfilter: nft_set_rbtree: handle element re-addition after deletion - - 1 0 0 0 2017-05-29 Pablo Neira davem Accepted
[1/4] netfilter: conntrack: fix false CRC32c mismatch using paged skb - - - 0 0 0 2017-05-29 Pablo Neira davem Accepted
[0/4] Netfilter fixes for net - - - 0 0 0 2017-05-29 Pablo Neira davem Accepted
[12/12] netfilter: xtables: fix build failure from COMPAT_XT_ALIGN outside CONFIG_COMPAT - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[11/12] ebtables: arpreply: Add the standard target sanity check - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[10/12] netfilter: nf_tables: revisit chain/object refcounting from elements - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[09/12] netfilter: nf_tables: missing sanitization in data from userspace - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[08/12] netfilter: nf_tables: can't assume lock is acquired when dumping set elems - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[07/12] netfilter: synproxy: fix conntrackd interaction - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[06/12] netfilter: xtables: zero padding in data_to_user - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[05/12] netfilter: nfnl_cthelper: reject del request if helper obj is in use - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[04/12] netfilter: introduce nf_conntrack_helper_put helper function - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[03/12] netfilter: don't setup nat info for confirmed ct 1 - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[02/12] netfilter: ctnetlink: Make some parameters integer to avoid enum mismatch - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[01/12] ipvs: SNAT packet replies only for NATed connections - - 1 0 0 0 2017-05-19 Pablo Neira davem Accepted
[00/12] Netfilter/IPVS fixes for net - - - 0 0 0 2017-05-19 Pablo Neira davem Accepted
[16/16] netfilter: nf_tables: check if same extensions are set when adding elements - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[15/16] netfilter: update MAINTAINERS file 1 - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[14/16] netfilter: x_tables: unlock on error in xt_find_table_lock() 1 - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[13/16] ipvs: explicitly forbid ipv6 service/dest creation if ipv6 mod is disabled 1 - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[12/16] netfilter: Wrong icmp6 checksum for ICMPV6_TIME_EXCEED in reverse SNATv6 path - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[11/16] netfilter: nft_dynset: continue to next expr if _OP_ADD succeeded - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[10/16] bridge: ebtables: fix reception of frames DNAT-ed to bridge device/port - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[09/16] netfilter: xt_socket: Fix broken IPv6 handling 1 - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[08/16] netfilter: ctnetlink: acquire ct->lock before operating nf_ct_seqadj - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[07/16] netfilter: ctnetlink: make it safer when updating ct->status - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[06/16] netfilter: ctnetlink: fix deadlock due to acquire _expect_lock twice - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[05/16] netfilter: ctnetlink: drop the incorrect cthelper module request - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[04/16] netfilter: nft_set_bitmap: free dummy elements when destroy the set - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[03/16] netfilter: nf_ct_helper: permit cthelpers with different names via nfnetlink - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[02/16] openvswitch: Delete conntrack entry clashing with an expectation. 1 - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[01/16] netfilter: xt_CT: fix refcnt leak on error path - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[00/16] Netfilter/IPVS/OVS fixes for net - - - 0 0 0 2017-05-03 Pablo Neira davem Accepted
[53/53] netfilter: nf_ct_ext: invoke destroy even when ext is not attached - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[52/53] netfilter: snmp: avoid stack size warning - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[51/53] netfilter: nf_queue: only call synchronize_net twice if nf_queue is active - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[50/53] netfilter: nf_log: don't call synchronize_rcu in nf_log_unset - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[49/53] netfilter: batch synchronize_net calls during hook unregister - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[48/53] ipvs: change comparison on sync_refresh_period - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[47/53] ipvs: remove unused function ip_vs_set_state_timeout - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[46/53] netfilter: don't attach a nat extension by default - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[45/53] netfilter: pptp: attach nat extension when needed - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[44/53] netfilter: masquerade: attach nat extension if not present - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[43/53] netfilter: conntrack: handle initial extension alloc via krealloc - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[42/53] netfilter: conntrack: mark extension structs as const - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[41/53] netfilter: conntrack: remove prealloc support - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[40/53] netfilter: SYNPROXY: Return NF_STOLEN instead of NF_DROP during handshaking - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[39/53] ebtables: remove nf_hook_register usage - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[38/53] netfilter: decnet: only register hooks in init namespace - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[37/53] ipvs: convert to use pernet nf_hook api - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[36/53] netfilter: synproxy: only register hooks when needed - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[35/53] netfilter: tcp: Use TCP_MAX_WSCALE instead of literal 14 - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[34/53] netfilter: ipvs: fix incorrect conflict resolution - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[33/53] nefilter: eache: reduce struct size from 32 to 24 byte - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[32/53] netfilter: allow early drop of assured conntracks 1 - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[31/53] netfilter: conntrack: use u8 for extension sizes again - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[30/53] netfilter: remove last traces of variable-sized extensions - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[29/53] netfilter: helpers: remove data_len usage for inkernel helpers - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[28/53] netfilter: nfnetlink_cthelper: reject too large userspace allocation requests - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[27/53] netfilter: helper: add build-time asserts for helper data size - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[26/53] netfilter: conntrack: move helper struct to nf_conntrack_helper.h - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[25/53] netfilter: nft_ct: allow to set ctnetlink event types of a connection - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[24/53] netfilter: remove nf_ct_is_untracked - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[23/53] netfilter: kill the fake untracked conntrack objects - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[22/53] netfilter: ecache: Refine the nf_ct_deliver_cached_events - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[21/53] netfilter: nf_nat: Fix return NF_DROP in nfnetlink_parse_nat_setup - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[20/53] ipset: remove unused function __ip_set_get_netlink 1 - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[19/53] netfilter: nf_conntrack: remove double assignment - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[18/53] netfilter: nf_tables: remove double return statement - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[17/53] netfilter: nat: remove rcu_read_lock in __nf_nat_decode_session. - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[16/53] netfilter: udplite: Remove duplicated udplite4/6 declaration - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[15/53] netfilter: ip6_tables: Remove unneccessary comments - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[14/53] netfilter: Remove exceptional & on function name - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[13/53] net: netfilter: Use list_{next/prev}_entry instead of list_entry - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[12/53] netfilter: Use seq_puts()/seq_putc() where possible 1 - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[11/53] netfilter: Remove unnecessary cast on void pointer - 1 - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[10/53] netfilter: Add nfnl_msg_type() helper function - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[09/53] netfilter: ctnetlink: Expectations must have a conntrack helper area - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[08/53] netfilter: nat: avoid use of nf_conn_nat extension - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[07/53] netfilter: nat: nf_nat_mangle_{udp,tcp}_packet returns boolean - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[06/53] netfilter: nf_ct_expect: Add nf_ct_remove_expect() - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[05/53] netfilter: expect: Make sure the max_expected limit is effective - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[04/53] netfilter: nf_tables: add nft_is_base_chain() helper - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[03/53] ipvs: remove unused variable - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[02/53] netfilter: ipvs: Replace kzalloc with kcalloc. - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[01/53] netfilter: ipvs: don't check for presence of nat extension - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[00/53] Netfilter/IPVS updates for net-next - - - 0 0 0 2017-05-01 Pablo Neira davem Accepted
[9/9] netfilter: ipt_CLUSTERIP: Fix wrong conntrack netns refcnt usage - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[8/9] netfilter: nft_hash: do not dump the auto generated seed - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[7/9] netfilter: nf_ct_expect: use proper RCU list traversal/update APIs - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[6/9] netfilter: ctnetlink: skip dumping expect when nfct_help(ct) is NULL - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[5/9] netfilter: make it safer during the inet6_dev->addr_list traversal - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[4/9] netfilter: ctnetlink: make it safer when checking the ct helper name - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[3/9] netfilter: helper: Add the rcu lock when call __nf_conntrack_helper_find - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[2/9] netfilter: ctnetlink: using bit to represent the ct event - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[1/9] netfilter: xt_TCPMSS: add more sanity tests on tcph->doff - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[0/9] Netfilter fixes for net - - - 0 0 0 2017-04-14 Pablo Neira davem Accepted
[Outreachy,kernel,v3] net: netfilter: Add nfnl_msg_type() helper function - - - 0 0 0 2017-04-06 Pablo Neira davem Awaiting Upstream
« 1 2 3 425 26 »