summaryrefslogtreecommitdiffstats
path: root/net/ipv4/netfilter
Commit message (Expand)AuthorAgeFilesLines
* netfilter: don't track fragmented packetsFlorian Westphal2017-12-162-5/+4
* netfilter: invoke synchronize_rcu after set the _hook_ to NULLLiping Zhang2017-10-081-0/+1
* netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal2016-06-242-86/+10
* netfilter: x_tables: do compat validation via translate_tableFlorian Westphal2016-06-242-217/+52
* netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal2016-06-242-29/+14
* netfilter: ip_tables: simplify translate_compat_table argsFlorian Westphal2016-06-241-35/+24
* netfilter: arp_tables: simplify translate_compat_table argsFlorian Westphal2016-06-241-46/+36
* netfilter: x_tables: check for bogus target offsetFlorian Westphal2016-06-242-4/+6
* netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal2016-06-242-2/+4
* netfilter: x_tables: kill check_entry helperFlorian Westphal2016-06-242-23/+16
* netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal2016-06-242-21/+2
* netfilter: x_tables: validate targets of jumpsFlorian Westphal2016-06-242-0/+32
* netfilter: x_tables: don't move to non-existent next ruleFlorian Westphal2016-06-242-3/+9
* netfilter: x_tables: fix unconditional helperFlorian Westphal2016-06-242-21/+20
* netfilter: x_tables: make sure e->next_offset covers remaining blob sizeFlorian Westphal2016-06-242-4/+8
* netfilter: x_tables: validate e->target_offset earlyFlorian Westphal2016-06-242-18/+16
* ipv4: Don't do expensive useless work during inetdev destroy.David S. Miller2016-04-201-2/+10
* inet: frag: Always orphan skbs inside ip_defrag()Joe Stringer2016-03-031-2/+0
* netfilter: nf_dup: add missing dependencies with NF_CONNTRACKPablo Neira Ayuso2015-12-101-0/+1
* netfilter: Fix removal of GRE expectation entries created by PPTPAnthony Lineham2015-11-091-1/+1
* ipv4: use sk_fullsock() in ipv4_conntrack_defrag()Eric Dumazet2015-11-051-3/+2
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller2015-10-242-3/+2
|\
| * netfilter: ipt_rpfilter: remove the nh_scope test in rpfilter_lookup_reverselucien2015-10-121-3/+1
| * netfilter: fix Kconfig dependencies for nf_dup_ipv{4,6}Pablo Neira Ayuso2015-10-011-0/+1
* | Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/davem/...Pablo Neira Ayuso2015-10-174-6/+7
|\ \
| * | ipv4: Pass struct net into ip_defrag and ip_check_defragEric W. Biederman2015-10-121-3/+4
| * | ipv4, ipv6: Pass net into ip_local_out and ip6_local_outEric W. Biederman2015-10-083-3/+3
| * | ipv4: Merge ip_local_out and ip_local_out_skEric W. Biederman2015-10-083-3/+3
* | | netfilter: ipv4: whitespace around operatorsIan Morris2015-10-163-6/+6
* | | netfilter: ipv4: code indentationIan Morris2015-10-163-5/+5
* | | netfilter: ipv4: function definition layoutIan Morris2015-10-162-6/+6
* | | netfilter: ipv4: ternary operator layoutIan Morris2015-10-162-5/+5
* | | netfilter: ipv4: label placementIan Morris2015-10-162-2/+2
* | | netfilter: remove hook owner refcountingFlorian Westphal2015-10-164-14/+0
|/ /
* | ipv4: Pass struct net into ip_route_me_harderEric W. Biederman2015-09-295-5/+7
* | netfilter: ipt_SYNPROXY: Pass snet into synproxy_send_tcpEric W. Biederman2015-09-291-7/+9
* | ipv4: Push struct net down into nf_send_resetEric W. Biederman2015-09-293-3/+3
* | netfilter: Pass net into nf_xfrm_me_harderEric W. Biederman2015-09-181-2/+2
* | netfilter: Pass priv instead of nf_hook_ops to netfilter hooksEric W. Biederman2015-09-1815-51/+51
* | netfilter: nf_conntrack: Add a struct net parameter to l4_pkt_to_tupleEric W. Biederman2015-09-181-2/+2
* | netfilter: Pass net to nf_dup_ipv4 and nf_dup_ipv6Eric W. Biederman2015-09-182-20/+5
* | netfilter: x_tables: Use par->net instead of computing from the passed net de...Eric W. Biederman2015-09-182-4/+3
* | netfilter: x_tables: Pass struct net in xt_action_paramEric W. Biederman2015-09-182-0/+2
* | netfilter: nf_tables: kill nft_pktinfo.opsEric W. Biederman2015-09-188-10/+9
* | inet netfilter: Prefer state->hook to ops->hooknumEric W. Biederman2015-09-183-10/+10
* | inet netfilter: Remove hook from ip6t_do_table, arp_do_table, ipt_do_tableEric W. Biederman2015-09-188-22/+15
* | netfilter: Use nf_hook_state.netEric W. Biederman2015-09-1710-30/+19
|/
* netfilter: nf_dup{4, 6}: fix build error when nf_conntrack disabledDaniel Borkmann2015-09-021-0/+1
* Revert "netfilter: xtables: compute exact size needed for jumpstack"Florian Westphal2015-08-282-30/+17
* netfilter: nf_dup: fix sparse warningsPablo Neira Ayuso2015-08-211-1/+1