summaryrefslogtreecommitdiffstats
path: root/net/ipv4/netfilter
Commit message (Expand)AuthorAgeFilesLines
* netfilter: on sockopt() acquire sock lock only in the required scopePaolo Abeni2018-02-251-1/+5
* netfilter: ipt_CLUSTERIP: fix out-of-bounds accesses in clusterip_tg_check()Dmitry Vyukov2018-02-251-3/+13
* netfilter: nf_nat_snmp: Fix panic when snmp_trap_helper fails to registerGao Feng2017-12-251-18/+1
* netfilter: invoke synchronize_rcu after set the _hook_ to NULLLiping Zhang2017-10-081-0/+1
* netfilter: Fix switch statement warnings with recent gcc.David Miller2017-02-081-0/+2
* netfilter: x_tables: speed up jump target validationFlorian Westphal2016-08-032-44/+49
* netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal2016-07-122-86/+10
* netfilter: x_tables: do compat validation via translate_tableFlorian Westphal2016-07-122-210/+50
* netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal2016-07-122-29/+14
* netfilter: ip_tables: simplify translate_compat_table argsFlorian Westphal2016-07-121-36/+25
* netfilter: arp_tables: simplify translate_compat_table argsFlorian Westphal2016-07-121-46/+36
* netfilter: x_tables: check for bogus target offsetFlorian Westphal2016-07-122-4/+6
* netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal2016-07-122-2/+4
* netfilter: x_tables: kill check_entry helperFlorian Westphal2016-07-122-23/+16
* netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal2016-07-122-21/+2
* netfilter: x_tables: validate targets of jumpsFlorian Westphal2016-07-122-0/+32
* netfilter: x_tables: don't move to non-existent next ruleFlorian Westphal2016-07-122-3/+9
* netfilter: x_tables: fix unconditional helperFlorian Westphal2016-07-122-21/+20
* netfilter: x_tables: make sure e->next_offset covers remaining blob sizeFlorian Westphal2016-07-122-4/+8
* netfilter: x_tables: validate e->target_offset earlyFlorian Westphal2016-07-122-18/+16
* ipv4: Don't do expensive useless work during inetdev destroy.David S. Miller2016-07-121-2/+10
* netfilter: nft_masq: fix uninitialized range in nft_masq_{ipv4, ipv6}_evalDaniel Borkmann2014-11-101-0/+1
* netfilter: nf_reject_ipv4: split nf_send_reset() in smaller functionsPablo Neira Ayuso2014-10-311-26/+62
* netfilter: nf_tables: restrict nat/masq expressions to nat chain typePablo Neira Ayuso2014-10-131-0/+1
* netfilter: missing module license in the nf_reject_ipvX modulesPablo Neira Ayuso2014-10-111-0/+3
* netfilter: nft_masq: register/unregister notifiers on module init/exitArturo Borrero2014-10-031-23/+11
* netfilter: use IS_ENABLED(CONFIG_BRIDGE_NETFILTER)Pablo Neira Ayuso2014-10-022-2/+2
* netfilter: move nf_send_resetX() code to nf_reject_ipvX modulesPablo Neira Ayuso2014-10-023-0/+136
* netfilter: nft_reject: introduce icmp code abstraction for inet and bridgePablo Neira Ayuso2014-10-021-1/+0
* netfilter: masquerading needs to be independent of x_tables in KconfigPablo Neira Ayuso2014-09-121-12/+15
* netfilter: NFT_CHAIN_NAT_IPV* is independent of NFT_NATPablo Neira Ayuso2014-09-121-10/+9
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2014-09-108-418/+536
|\
| * netfilter: nf_tables: add new nft_masq expressionArturo Borrero2014-09-093-0/+96
| * netfilter: nf_nat: generalize IPv4 masquerading support for nf_tablesArturo Borrero2014-09-094-99/+170
| * netfilter: nft_chain_nat_ipv4: use generic IPv4 NAT code from corePablo Neira Ayuso2014-09-021-120/+37
| * netfilter: nat: move specific NAT IPv4 to corePablo Neira Ayuso2014-09-022-199/+233
* | Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller2014-09-072-48/+56
|\ \
| * | netfilter: move NAT Kconfig switches out of the iptables scopePablo Neira Ayuso2014-08-182-48/+56
| |/
* / net: use reciprocal_scale() helperDaniel Borkmann2014-08-231-1/+1
|/
* netfilter: kill remnants of ulog targetsPaul Bolle2014-07-251-1/+0
* netfilter: nf_conntrack: remove exceptional & on function nameHimangi Saraogi2014-07-251-1/+1
* netfilter: use IS_ENABLED() macroDuan Jiong2014-06-306-10/+14
* netfilter: fix several Kconfig problems in NF_LOG_*Pablo Neira Ayuso2014-06-281-10/+10
* netfilter: add generic ARP packet loggerPablo Neira Ayuso2014-06-273-0/+155
* netfilter: log: nf_log_packet() as real unified interfacePablo Neira Ayuso2014-06-271-7/+7
* netfilter: log: split family specific code to nf_log_{ip,ip6,common}.c filesPablo Neira Ayuso2014-06-273-0/+393
* netfilter: kill ulog targetsPablo Neira Ayuso2014-06-252-517/+0
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2014-05-302-20/+6
|\
| * netfilter: add helper for adding nat extensionFlorian Westphal2014-04-292-20/+6
* | net: rename local_df to ignore_dfWANG Cong2014-05-121-1/+1