index
:
kernel/linux.git
linux-2.6.11.y
linux-2.6.12.y
linux-2.6.13.y
linux-2.6.14.y
linux-2.6.15.y
linux-2.6.16.y
linux-2.6.17.y
linux-2.6.18.y
linux-2.6.19.y
linux-2.6.20.y
linux-2.6.21.y
linux-2.6.22.y
linux-2.6.23.y
linux-2.6.24.y
linux-2.6.25.y
linux-2.6.26.y
linux-2.6.27.y
linux-2.6.28.y
linux-2.6.29.y
linux-2.6.30.y
linux-2.6.31.y
linux-2.6.32.y
linux-2.6.33.y
linux-2.6.34.y
linux-2.6.35.y
linux-2.6.36.y
linux-2.6.37.y
linux-2.6.38.y
linux-2.6.39.y
linux-3.0.y
linux-3.1.y
linux-3.10.y
linux-3.11.y
linux-3.12.y
linux-3.13.y
linux-3.14.y
linux-3.15.y
linux-3.16.y
linux-3.17.y
linux-3.18.y
linux-3.19.y
linux-3.2.y
linux-3.3.y
linux-3.4.y
linux-3.5.y
linux-3.6.y
linux-3.7.y
linux-3.8.y
linux-3.9.y
linux-4.0.y
linux-4.1.y
linux-4.10.y
linux-4.11.y
linux-4.12.y
linux-4.13.y
linux-4.14.y
linux-4.15.y
linux-4.16.y
linux-4.17.y
linux-4.18.y
linux-4.19.y
linux-4.2.y
linux-4.20.y
linux-4.3.y
linux-4.4.y
linux-4.5.y
linux-4.6.y
linux-4.7.y
linux-4.8.y
linux-4.9.y
linux-5.0.y
linux-5.1.y
linux-5.10.y
linux-5.11.y
linux-5.12.y
linux-5.13.y
linux-5.14.y
linux-5.15.y
linux-5.16.y
linux-5.17.y
linux-5.18.y
linux-5.19.y
linux-5.2.y
linux-5.3.y
linux-5.4.y
linux-5.5.y
linux-5.6.y
linux-5.7.y
linux-5.8.y
linux-5.9.y
linux-6.0.y
linux-6.1.y
linux-6.10.y
linux-6.2.y
linux-6.3.y
linux-6.4.y
linux-6.5.y
linux-6.6.y
linux-6.7.y
linux-6.8.y
linux-6.9.y
linux-rockchip-6.1.y
linux-rockchip-6.5.y
linux-rolling-lts
linux-rolling-stable
master
Linux kernel stable tree (mirror)
Andrey V.Kosteltsev
summary
refs
log
tree
commit
diff
log msg
author
committer
range
path:
root
/
net
/
netfilter
Age
Commit message (
Expand
)
Author
Files
Lines
2024-03-01
netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new
Xin Long
1
-1
/
+1
2024-02-23
netfilter: ipset: Missing gc cancellations fixed
Jozsef Kadlecsik
2
-2
/
+4
2024-02-23
netfilter: ipset: fix performance regression in swap operation
Jozsef Kadlecsik
4
-18
/
+61
2024-02-23
work around gcc bugs with 'asm goto' with outputs
Linus Torvalds
1
-1
/
+1
2024-02-16
netfilter: nft_set_rbtree: skip end interval element from gc
Pablo Neira Ayuso
1
-3
/
+3
2024-02-16
netfilter: nft_set_pipapo: remove scratch_aligned pointer
Florian Westphal
3
-39
/
+10
2024-02-16
netfilter: nft_set_pipapo: add helper to release pcpu scratch area
Florian Westphal
1
-5
/
+23
2024-02-16
netfilter: nft_set_pipapo: store index in scratch maps
Florian Westphal
3
-26
/
+44
2024-02-16
netfilter: nft_ct: reject direction for ct id
Pablo Neira Ayuso
1
-0
/
+3
2024-02-16
netfilter: nft_compat: restrict match/target protocol to u16
Pablo Neira Ayuso
1
-1
/
+7
2024-02-16
netfilter: nft_compat: reject unused compat flag
Pablo Neira Ayuso
1
-1
/
+2
2024-02-16
netfilter: nft_compat: narrow down revision to unsigned 8-bits
Pablo Neira Ayuso
1
-3
/
+3
2024-02-05
netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations
Pablo Neira Ayuso
1
-0
/
+24
2024-02-05
netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger
Pablo Neira Ayuso
1
-3
/
+4
2024-02-05
netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV
Pablo Neira Ayuso
2
-5
/
+10
2024-02-05
netfilter: conntrack: correct window scaling with retransmitted SYN
Ryan Schaefer
1
-4
/
+6
2024-02-01
netfilter: nf_tables: reject QUEUE/DROP verdict parameters
Florian Westphal
1
-10
/
+6
2024-02-01
netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain
Pablo Neira Ayuso
1
-2
/
+9
2024-02-01
netfilter: nf_tables: validate NFPROTO_* family
Pablo Neira Ayuso
8
-2
/
+47
2024-02-01
netfilter: nf_tables: restrict anonymous set and map names to 16 bytes
Florian Westphal
1
-0
/
+4
2024-02-01
netfilter: nft_limit: reject configurations that cause integer overflow
Florian Westphal
1
-7
/
+16
2024-01-26
ipvs: avoid stat macros calls from preemptible context
Fedor Pchelkin
1
-2
/
+2
2024-01-26
netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description
Pablo Neira Ayuso
1
-1
/
+5
2024-01-26
netfilter: nf_tables: skip dead set elements in netlink dump
Pablo Neira Ayuso
1
-1
/
+1
2024-01-26
netfilter: nf_tables: do not allow mismatch field size and set key length
Pablo Neira Ayuso
1
-1
/
+5
2024-01-26
netfilter: propagate net to nf_bridge_get_physindev
Pavel Tikhomirov
4
-12
/
+13
2024-01-26
netfilter: nf_queue: remove excess nf_bridge variable
Pavel Tikhomirov
1
-3
/
+1
2024-01-26
netfilter: nfnetlink_log: use proper helper for fetching physinif
Pavel Tikhomirov
1
-4
/
+4
2024-01-26
netfilter: nft_limit: do not ignore unsupported flags
Pablo Neira Ayuso
1
-7
/
+12
2024-01-26
netfilter: nf_tables: reject invalid set policy
Pablo Neira Ayuso
1
-1
/
+9
2024-01-26
netfilter: nf_tables: check if catch-all set element is active in next genera...
Pablo Neira Ayuso
1
-1
/
+1
2024-01-26
netfilter: nf_tables: validate chain type update if available
Pablo Neira Ayuso
1
-1
/
+10
2024-01-26
netfilter: nf_tables: mark newset as dead on transaction abort
Florian Westphal
1
-0
/
+1
2024-01-10
netfilter: nft_immediate: drop chain reference counter on error
Pablo Neira Ayuso
1
-1
/
+1
2024-01-10
netfilter: nf_nat: fix action not being set for all ct states
Brad Cowie
1
-1
/
+2
2024-01-10
netfilter: nf_tables: set transport offset from mac header for netdev/egress
Pablo Neira Ayuso
1
-1
/
+1
2024-01-05
netfilter: nf_tables: skip set commit for deleted/destroyed sets
Pablo Neira Ayuso
1
-1
/
+1
2023-12-13
netfilter: nft_set_pipapo: skip inactive elements during set walk
Florian Westphal
1
-0
/
+3
2023-12-13
netfilter: xt_owner: Fix for unsafe access of sk->sk_socket
Phil Sutter
1
-4
/
+12
2023-12-13
netfilter: nf_tables: validate family when identifying table via handle
Pablo Neira Ayuso
1
-2
/
+3
2023-12-13
netfilter: nf_tables: bail out on mismatching dynset and set expressions
Pablo Neira Ayuso
1
-4
/
+9
2023-12-13
netfilter: nf_tables: fix 'exist' matching on bigendian arches
Florian Westphal
2
-4
/
+8
2023-12-13
netfilter: bpf: fix bad registration on nf_defrag
D. Wythe
1
-5
/
+5
2023-12-13
netfilter: ipset: fix race condition between swap/destroy and kernel side add...
Jozsef Kadlecsik
1
-7
/
+7
2023-11-28
netfilter: nf_tables: split async and sync catchall in two functions
Pablo Neira Ayuso
1
-29
/
+32
2023-11-28
netfilter: nf_tables: remove catchall element in GC sync path
Pablo Neira Ayuso
1
-5
/
+21
2023-11-28
netfilter: nf_tables: bogus ENOENT when destroying element which does not exist
Pablo Neira Ayuso
1
-2
/
+3
2023-11-28
netfilter: nf_tables: fix pointer math issue in nft_byteorder_eval()
Dan Carpenter
2
-3
/
+4
2023-11-20
netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses
Florian Westphal
1
-1
/
+26
2023-11-20
netfilter: xt_recent: fix (increase) ipv6 literal buffer length
Maciej Żenczykowski
1
-1
/
+1
[next]