summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
2025-09-19netfilter: nft_set_pipapo: fix null deref for empty setFlorian Westphal1-3/+2
2025-09-19netfilter: nf_tables: restart set lookup on base_seq changeFlorian Westphal2-2/+32
2025-09-19netfilter: nf_tables: make nft_set_do_lookup available unconditionallyFlorian Westphal1-5/+12
2025-09-19netfilter: nf_tables: place base_seq in struct netFlorian Westphal1-32/+33
2025-09-19netfilter: nf_tables: Reintroduce shortened deletion notificationsPhil Sutter1-17/+50
2025-09-19netfilter: nft_set_rbtree: continue traversal if element is inactiveFlorian Westphal1-3/+3
2025-09-19netfilter: nft_set_pipapo: don't check genbit from packetpath lookupsFlorian Westphal2-5/+19
2025-09-19netfilter: nft_set_pipapo: don't return bogus extension pointerFlorian Westphal1-6/+6
2025-09-19netfilter: nft_set_pipapo: merge pipapo_get/lookupFlorian Westphal1-130/+58
2025-09-19netfilter: nft_set: remove one argument from lookup and update functionsFlorian Westphal8-91/+95
2025-09-19netfilter: nft_set_pipapo: remove unused argumentsFlorian Westphal1-9/+5
2025-09-19netfilter: nft_set_bitmap: fix lockdep splat due to missing annotationFlorian Westphal1-1/+2
2025-09-09netfilter: nf_tables: Introduce NFTA_DEVICE_PREFIXPhil Sutter1-11/+31
2025-09-09netfilter: conntrack: helper: Replace -EEXIST by -EBUSYPhil Sutter1-2/+2
2025-08-20netfilter: nft_set_pipapo: prefer kvmalloc for scratch mapsFlorian Westphal1-5/+4
2025-08-20netfilter: nf_tables: reject duplicate device on updatesPablo Neira Ayuso1-0/+30
2025-08-20ipvs: Fix estimator kthreads preferred affinityFrederic Weisbecker1-1/+2
2025-08-20netfilter: ctnetlink: remove refcounting in expectation dumpersFlorian Westphal1-24/+17
2025-08-20netfilter: ctnetlink: fix refcount leak on table dumpFlorian Westphal1-11/+13
2025-08-15bpf: Check netfilter ctx accesses are alignedPaul Chaignon1-0/+3
2025-08-15netfilter: xt_nfacct: don't assume acct name is null-terminatedFlorian Westphal1-2/+2
2025-08-15bpf: Disable migration in nf_hook_run_bpf().Kuniyuki Iwashima1-1/+1
2025-08-15netfilter: nf_tables: adjust lockdep assertions handlingFedor Pchelkin1-2/+2
2025-08-15netfilter: nf_tables: Drop dead code from fill_*_info routinesPhil Sutter1-25/+0
2025-07-17netfilter: nf_conntrack: fix crash due to removal of uninitialised entryFlorian Westphal1-6/+20
2025-07-14Revert "netfilter: nf_tables: Add notifications for hook changes"Phil Sutter3-62/+0
2025-07-14netfilter: nf_tables: hide clash bit from userspaceFlorian Westphal1-0/+3
2025-06-08treewide, timers: Rename from_timer() to timer_container_of()Ingo Molnar10-11/+15
2025-06-05netfilter: nf_nat: also check reverse tuple to obtain clashing entryFlorian Westphal1-3/+9
2025-06-05netfilter: nf_set_pipapo_avx2: fix initial map fillFlorian Westphal1-1/+20
2025-05-26Merge tag 'nf-next-25-05-23' of git://git.kernel.org/pub/scm/linux/kernel/git...Paolo Abeni13-153/+514
2025-05-23netfilter: nf_tables: Add notifications for hook changesPhil Sutter3-0/+62
2025-05-23netfilter: nf_tables: Support wildcard netdev hook specsPhil Sutter2-16/+15
2025-05-23netfilter: nf_tables: Sort labels in nft_netdev_hook_alloc()Phil Sutter1-9/+7
2025-05-23netfilter: nf_tables: Handle NETDEV_CHANGENAME eventsPhil Sutter2-18/+48
2025-05-23netfilter: nf_tables: Wrap netdev notifiersPhil Sutter2-26/+46
2025-05-23netfilter: nf_tables: Respect NETDEV_REGISTER eventsPhil Sutter2-9/+60
2025-05-23netfilter: nf_tables: Prepare for handling NETDEV_REGISTER eventsPhil Sutter2-14/+24
2025-05-23netfilter: nf_tables: Have a list of nf_hook_ops in nft_hookPhil Sutter3-62/+133
2025-05-23netfilter: nf_tables: Pass nf_hook_ops to nft_unregister_flowtable_hook()Phil Sutter1-11/+9
2025-05-23netfilter: nf_tables: Introduce nft_register_flowtable_ops()Phil Sutter1-11/+21
2025-05-23netfilter: nf_tables: Introduce nft_hook_find_ops{,_rcu}()Phil Sutter4-5/+26
2025-05-23netfilter: nf_tables: Introduce functions freeing nft_hook objectsPhil Sutter1-14/+24
2025-05-23netfilter: nf_tables: add packets conntrack state to debug trace infoFlorian Westphal1-1/+53
2025-05-23netfilter: conntrack: make nf_conntrack_id callable without a module dependencyFlorian Westphal1-0/+6
2025-05-23netfilter: nf_dup_netdev: Move the recursion counter struct netdev_xmitSebastian Andrzej Siewior1-4/+18
2025-05-23netfilter: nft_inner: Use nested-BH locking for nft_pcpu_tun_ctxSebastian Andrzej Siewior1-3/+15
2025-05-23netfilter: nf_dup{4, 6}: Move duplication check to task_structSebastian Andrzej Siewior1-3/+0
2025-05-23netfilter: nft_tunnel: fix geneve_opt dumpFernando Fernandez Mancera1-4/+4
2025-05-22netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only...Florian Westphal2-3/+3