summaryrefslogtreecommitdiff
path: root/include/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2025-02-01netfilter: nft_dynset: honor stateful expressions in set definitionPablo Neira Ayuso1-0/+2
2025-01-09netfilter: nft_set_hash: unaligned atomic read on struct nft_set_extPablo Neira Ayuso1-2/+5
2024-10-17netfilter: nft_set_pipapo: walk over current view on netlink dumpPablo Neira Ayuso1-0/+13
2024-08-19netfilter: nf_tables: allow clone callbacks to sleepPablo Neira Ayuso1-2/+2
2024-08-19netfilter: nf_tables: use timestamp to check for set element timeoutPablo Neira Ayuso1-2/+19
2024-07-05netfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registersPablo Neira Ayuso1-0/+5
2024-06-16netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEVPablo Neira Ayuso1-0/+2
2024-02-23netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()Dan Carpenter1-2/+2
2023-11-28netfilter: nf_tables: fix table flag updatesPablo Neira Ayuso1-6/+0
2023-11-28netfilter: nftables: update table flags from the commit phasePablo Neira Ayuso1-3/+6
2023-11-20netfilter: nft_redir: use `struct nf_nat_range2` throughout and deduplicate e...Jeremy Sowden1-2/+1
2023-10-10netfilter: nf_tables: fix kdoc warnings after gc reworkFlorian Westphal1-0/+1
2023-10-10netfilter: nf_tables: add and use nft_thoff helperFlorian Westphal1-0/+5
2023-10-10netfilter: nf_tables: add and use nft_sk helperFlorian Westphal1-0/+5
2023-10-10netfilter: use actual socket sk for REJECT actionJan Engelhardt2-5/+4
2023-10-10netfilter: nf_tables: fix memleak when more than 255 elements expiredFlorian Westphal1-1/+1
2023-10-10netfilter: nf_tables: defer gc run if previous batch is still pendingFlorian Westphal1-0/+5
2023-10-10netfilter: nf_tables: remove busy mark and gc batch APIPablo Neira Ayuso1-94/+3
2023-10-10netfilter: nf_tables: GC transaction API to avoid race with control planePablo Neira Ayuso1-1/+60
2023-10-10netfilter: nf_tables: integrate pipapo into commit protocolPablo Neira Ayuso1-1/+3
2023-08-16netfilter: nf_tables: report use refcount overflowPablo Neira Ayuso1-4/+27
2023-07-27netfilter: nf_tables: drop map element references from preparation phasePablo Neira Ayuso1-1/+4
2023-07-27netfilter: nf_tables: reject unbound anonymous set before commit phasePablo Neira Ayuso1-0/+3
2023-07-27netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chainPablo Neira Ayuso1-0/+2
2023-07-27netfilter: nf_tables: fix chain binding transaction logicPablo Neira Ayuso1-1/+20
2023-07-27netfilter: nf_tables: use net_generic infra for transaction dataFlorian Westphal1-0/+10
2023-06-28netfilter: nftables: statify nft_parse_register()Pablo Neira Ayuso1-1/+0
2023-05-17netfilter: nf_tables: deactivate anonymous set from preparation phasePablo Neira Ayuso1-0/+1
2023-03-17netfilter: tproxy: fix deadlock due to missing BH disableFlorian Westphal1-0/+7
2022-08-31netfilter: nf_tables: disallow jump to implicit chain from set elementPablo Neira Ayuso1-0/+5
2022-08-31netfilter: nf_tables: upfront validation of data via nft_data_init()Pablo Neira Ayuso1-2/+2
2022-08-31netfilter: nft_cmp: optimize comparison for 16-bytesPablo Neira Ayuso1-0/+9
2022-06-29netfilter: nftables: add nft_parse_register_store() and use itPablo Neira Ayuso4-9/+9
2022-06-29netfilter: nftables: add nft_parse_register_load() and use itPablo Neira Ayuso3-5/+5
2022-06-14netfilter: nf_tables: bail out early if hardware offload is not supportedPablo Neira Ayuso1-1/+1
2022-06-14netfilter: nf_tables: delete flowtable hooks via transaction listPablo Neira Ayuso1-1/+0
2022-06-06netfilter: conntrack: re-fetch conntrack after insertionFlorian Westphal1-1/+6
2022-03-08netfilter: nf_queue: fix possible use-after-freeFlorian Westphal1-1/+1
2022-03-02netfilter: nf_tables_offload: incorrect flow offload action array sizePablo Neira Ayuso2-3/+1
2021-12-14netfilter: conntrack: annotate data-races around ct->timeoutEric Dumazet1-3/+3
2021-06-03netfilter: flowtable: Remove redundant hw refresh bitRoi Dayan1-1/+0
2021-05-14netfilter: nftables_offload: VLAN id needs host byteorder in flow dissectorPablo Neira Ayuso1-1/+10
2021-05-14netfilter: nft_payload: fix C-VLAN offload supportPablo Neira Ayuso1-0/+1
2021-03-30netfilter: nftables: allow to update flowtable flagsPablo Neira Ayuso1-0/+3
2020-12-08netfilter: nft_dynset: fix timeouts later than 23 daysPablo Neira Ayuso1-0/+4
2020-11-27netfilter: nftables_offload: build mask based from the matching bytesPablo Neira Ayuso1-0/+3
2020-11-27netfilter: nftables_offload: set address type in control dissectorPablo Neira Ayuso1-0/+4
2020-10-20netfilter: nftables_offload: KASAN slab-out-of-bounds Read in nft_flow_rule_c...Saeed Mirzamohammadi1-0/+6
2020-10-15Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski1-0/+1
2020-10-14netfilter: restore NF_INET_NUMHOOKSPablo Neira Ayuso1-1/+3