| [GIT,PULL,nf] IPVS fix for v3.10 |
2013-06-19 |
Simon Horman |
|
New |
| [nf] ipvs: SCTP ports should be writable in ICMP packets |
2013-06-19 |
Simon Horman |
|
New |
| [libnftables] test: add testbench for XML |
2013-06-18 |
Arturo Borrero |
|
Under Review |
| [2/2] conntrack: snprintf: add connlabel format specifier |
2013-06-18 |
Florian Westphal |
|
Under Review |
| [lnfct-ct,1/2] conntrack: snprintf: add labels in hex representation by default |
2013-06-18 |
Florian Westphal |
|
Under Review |
| netfilter: prevent harmless integer overflow |
2013-06-18 |
Dan Carpenter |
|
Under Review |
| [v2,5/5] iptables (userspace): add set match "inner" flag support |
2013-06-16 |
Mr Dash Four |
kadlec |
Under Review |
| [v2,4/5] iptables: add set match "inner" flag support |
2013-06-16 |
Mr Dash Four |
kadlec |
Under Review |
| [v2,3/5] ipset: add set match "inner" flag support |
2013-06-16 |
Mr Dash Four |
kadlec |
Under Review |
| [v2,2/5] ipset: add "inner" flag implementation |
2013-06-16 |
Mr Dash Four |
kadlec |
Under Review |
| [v2,1/5] iptables: bugfix: prevent wrong syntax being accepted by the set match |
2013-06-16 |
Mr Dash Four |
kadlec |
Under Review |
| [RFC,-next] netfilter: nfqueue: add ability to dump list of supported attributes |
2013-06-04 |
Florian Westphal |
pablo |
Under Review |
| [nf-next] netfilter: xt_socket: add XT_SOCKET_NOWILDCARD flag |
2013-06-03 |
Eric Dumazet |
pablo |
Under Review |
| [libnftables,2/2] Add code for testing the new functions for exporting rules to JSON Format |
2013-06-13 |
Alvaro Neira |
pablo |
Under Review |
| [libnftables,1/2] Add function for exporting rule to JSON format |
2013-06-13 |
Alvaro Neira |
pablo |
Under Review |
| [next] netfilter: conntrack: avoid large timeout for mid-stream pickup |
2013-06-13 |
Florian Westphal |
pablo |
Under Review |
| [nf-next] netfilter: ct: check return code from nla_parse_tested |
2013-06-12 |
Daniel Borkmann |
pablo |
Under Review |
| [-next] Revert "netfilter: tproxy: do not assign timewait sockets to skb->sk" |
2013-05-29 |
Florian Westphal |
pablo |
Under Review |
| [libnftables,7/7] chain: handle attribute is relevant if only there is no name to use |
2013-05-14 |
Tomasz Bursztyka |
pablo |
Under Review |
| [libnftables,6/7] expr: add support for expr list and capability to add it into a rule |
2013-05-14 |
Tomasz Bursztyka |
pablo |
Under Review |
| [nf-next] netfilter: conntrack: remove the central spinlock |
2013-05-09 |
Eric Dumazet |
pablo |
Under Review |
| netfilter: nf_queue: add NFQA_SKB_CSUM_NOTVERIFIED info flag |
2013-05-26 |
Florian Westphal |
pablo |
Under Review |
| [1/3] netfilter: ctnetlink: attach expectations to unconfirmed conntracks |
2013-05-23 |
Pablo Neira |
pablo |
Under Review |
| net: ICMPv6 packets transmitted on wrong interface if nfmark is mangled |
2012-12-03 |
Dries De Winter |
|
Under Review |
| netfilter: xt_osf: fix inversion |
2013-03-24 |
Pablo Neira |
|
Under Review |
| [5/5] libxtables: constify xtables_option_[mt]fcall argument |
2013-03-05 |
Jan Engelhardt |
|
Under Review |
| [4/5] build: do not dereference symlinks on installation |
2013-03-05 |
Jan Engelhardt |
|
Under Review |
| [3/5] iptables: fall back to using save function when print is not defined |
2013-03-05 |
Jan Engelhardt |
|
Under Review |
| [2/5] extensions: eui64: set userspacesize=0 |
2013-03-05 |
Jan Engelhardt |
|
Under Review |
| [1/5] libxtables: centralize checking for a .save function |
2013-03-05 |
Jan Engelhardt |
|
Under Review |
| [2/2] netfilter: nf_tables: don't skip inactive rules and dump generation mask |
2013-02-28 |
Pablo Neira |
|
Under Review |
| [1/2] netfilter: nf_tables: rework atomic transaction updates |
2013-03-28 |
Pablo Neira |
|
Under Review |
| [2/2] netfilter: nf_tables: set NLM_F_DUMP_INTR if dump is invalid |
2013-03-28 |
Pablo Neira |
|
Under Review |
| [10/13] iptables: implement --line-numbers for iptables -S |
2012-12-25 |
Jan Engelhardt |
|
Under Review |
| [08/17] iptables-restore: kill unused -b option |
2012-09-30 |
Jan Engelhardt |
|
Under Review |
| [06/17] iptables: fix order of internal commands list |
2012-09-30 |
Jan Engelhardt |
|
Under Review |
| netfilter: remove pointless conditional before kfree_skb() |
2012-08-28 |
Wei Yongjun |
|
Under Review |
| death_by_event() does not check IPS_DYING_BIT - race condition against ctnetlink_del_conntrack |
2012-08-28 |
Pablo Neira |
|
Under Review |
| IPv6 fragment packet handling |
2012-06-28 |
Kristof Provost |
|
Under Review |
| [libnftables,4/5] expr: xml: don't print target&match info |
2013-06-03 |
Arturo Borrero |
|
Accepted |
| [libnftables,2/2] examples: unset chain & rule handle |
2013-06-05 |
Arturo Borrero |
|
Accepted |
| [libnftables,3/3] rule: xml: delete trailing space |
2013-06-15 |
Arturo Borrero |
pablo |
Accepted |
| [libnftables,1/3] nat: xml: fix xml_snprintf buffer offset |
2013-06-15 |
Arturo Borrero |
pablo |
Accepted |
| [v3] iptables-nftables: function nft_chain_zero_counters added. |
2013-06-17 |
Giuseppe Longo |
|
Accepted |
| [3/3] netfilter: xt_TCPMSS: Fix missing fragmentation handling |
2013-06-17 |
Pablo Neira |
|
Accepted |
| [2/3] netfilter: xt_TCPMSS: Fix IPv6 default MSS too |
2013-06-17 |
Pablo Neira |
|
Accepted |
| [1/3] netfilter: xt_TCPOPTSTRIP: don't use tcp_hdr() |
2013-06-17 |
Pablo Neira |
|
Accepted |
| [0/3] netfilter fixes for net |
2013-06-17 |
Pablo Neira |
|
Accepted |
| [libnftables,2/3] nat: xml: fix non-mandatory element |
2013-06-15 |
Arturo Borrero |
pablo |
Accepted |
| [libnftables] expr: bitwise: xml_parse: fix casting |
2013-06-15 |
Arturo Borrero |
pablo |
Accepted |
| netfilter: xt_TCPOPTSTRIP: don't use tcp_hdr() |
2013-06-11 |
Pablo Neira |
|
Accepted |
| netfilter: xt_TCPMSS: Add IPv6 default MSS |
2013-06-10 |
Phil Oester |
|
Accepted |
| netfilter: xt_TCPMSS: Add safe fragmentation handling |
2013-06-10 |
Phil Oester |
|
Accepted |
| [nftables,2/2] counter: fix restoration |
2013-06-08 |
Eric Leblond |
|
Accepted |
| [nftables,1/2] rule: display hook info |
2013-06-08 |
Eric Leblond |
|
Accepted |
| iptables: Fix connlabel.conf install location |
2013-06-10 |
Phil Oester |
|
Accepted |
| [libnftables,5/5] examples: get XML ruleset |
2013-06-03 |
Arturo Borrero |
pablo |
Accepted |
| [libnftables,3/5] src: xml: set errno to EINVAL when invalid parsing |
2013-06-03 |
Arturo Borrero |
pablo |
Accepted |
| [libnftables,1/5] data_reg: xml: fix bytes movements |
2013-06-03 |
Arturo Borrero |
pablo |
Accepted |
| [Ulogd] pgsql: add var to specify arbitrary conn params |
2013-05-28 |
Eric Leblond |
regit |
Accepted |
| [v4] xtables: Add locking to prevent concurrent instances |
2013-05-31 |
Phil Oester |
pablo |
Accepted |
| [5/5] ipvs: info leak in __ip_vs_get_dest_entries() |
2013-06-10 |
Pablo Neira |
|
Accepted |
| [4/5] netfilter: nfnetlink_queue: fix missing HW protocol |
2013-06-10 |
Pablo Neira |
|
Accepted |
| [3/5] netfilter: xt_TCPMSS: Fix violation of RFC879 in absence of MSS option |
2013-06-10 |
Pablo Neira |
|
Accepted |
| [2/5] netfilter: nfnetlink_cttimeout: fix incomplete dumping of objects |
2013-06-10 |
Pablo Neira |
|
Accepted |
| [1/5] netfilter: nfnetlink_acct: fix incomplete dumping of objects |
2013-06-10 |
Pablo Neira |
|
Accepted |
| [0/5] netfilter fixes for 3.10-rc5 |
2013-06-10 |
Pablo Neira |
|
Accepted |
| ipvs: info leak in __ip_vs_get_dest_entries() |
2013-06-03 |
Dan Carpenter |
|
Accepted |
| [v2] nft: fix leak of iterators |
2013-06-08 |
Giuseppe Longo |
|
Accepted |
| [nftables,5/5] cli: reset terminal when CTRL+d is pressed |
2013-06-02 |
Eric Leblond |
|
Accepted |
| [nftables,4/5] cli: add quit command |
2013-06-02 |
Eric Leblond |
|
Accepted |
| [nftables,3/5] rule: list elements in set in any case |
2013-06-02 |
Eric Leblond |
|
Accepted |
| [nftables,1/5] doc: fix inversion of operator and object. |
2013-06-02 |
Eric Leblond |
|
Accepted |
| netfilter: nfnetlink_queue: fix missing HW protocol |
2013-06-07 |
Pablo Neira |
|
Accepted |
| datatype: concat expression only releases dynamically allocated datatype |
2013-06-06 |
Pablo Neira |
|
Accepted |
| [libnftables] data_reg: xml: delete unreachable code in _veredict_xml_parse() |
2013-06-08 |
Arturo Borrero |
|
Accepted |
| fix leak of iter in nft_rule_list |
2013-06-08 |
Giuseppe Longo |
|
Accepted |
| [libnftables,2/2] Implementation for to test the function for exporting chains to JSON format |
2013-06-08 |
Alvaro Neira |
|
Accepted |
| [libnftables,1/2] Add function for exporting chain to JSON Format |
2013-06-08 |
Alvaro Neira |
|
Accepted |
| [1/2] conntrack: nfct_cmp: also compare labels |
2013-06-05 |
Florian Westphal |
|
Accepted |
| [2/2] qa: nfct_cmp: verify individual attr comparision |
2013-06-05 |
Florian Westphal |
|
Accepted |
| [libnftables,v3] src: add _unset functions |
2013-06-07 |
Arturo Borrero |
|
Accepted |
| [libnftables,2/2] Add implementation for to proof the JSON export function |
2013-06-07 |
Alvaro Neira |
|
Accepted |
| [libnftables,1/2] Add functions for exporting tables to JSON format |
2013-06-07 |
Alvaro Neira |
|
Accepted |
| [libnftables,v3] src: xml: add versioning |
2013-06-03 |
Arturo Borrero |
|
Accepted |
| [09/12] netfilter: nfnetlink_queue: avoid peer_portid test |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [12/12] netfilter: nfnetlink_queue: only add CAP_LEN attr when needed |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [11/12] netfilter: nfnetlink_queue: cleanup copy_range usage |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [10/12] netfilter: Implement RFC 1123 for FTP conntrack |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [08/12] ipvs: change type of netns_ipvs->sysctl_sync_qlen_max |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [07/12] ipvs: use cond_resched_rcu() helper when walking connections |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [06/12] sched: add cond_resched_rcu() helper |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [05/12] netfilter: {ipt,ebt}_ULOG: rise warning on deprecation |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [04/12] netfilter: don't panic on error while walking through the init path |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [03/12] bridge: netfilter: using strlcpy() instead of strncpy() |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [02/12] netfilter: xt_socket: use IP early demux |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [01/12] netfilter: xt_CT: optimize XT_CT_NOTRACK |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [00/12] Netfilter/IPVS updates for net-next |
2013-06-05 |
Pablo Neira |
|
Accepted |
| [2/3] conntrack, expect: fix _cmp api with STRICT checking |
2013-06-01 |
Florian Westphal |
pablo |
Accepted |
| [lnf-conntrack,1/3] qa: add api test for nfct_cmp and nfct_exp functions |
2013-06-01 |
Florian Westphal |
pablo |
Accepted |