summaryrefslogtreecommitdiffstats
path: root/net/ipv6/netfilter
Commit message (Expand)AuthorAgeFilesLines
* Revert "net: fix percpu memory leaks"Jesper Dangaard Brouer2017-09-201-9/+3
* netfilter: use fwmark_reflect in nf_send_resetPau Espin Pedrol2017-08-111-0/+3
* ipv6: orphan skbs in reassembly unitEric Dumazet2017-03-221-0/+1
* netfilter: ipv6: nf_defrag: drop mangled skb on ream errorFlorian Westphal2016-11-292-3/+3
* netfilter: Update nf_send_reset6 to consider L3 domainDavid Ahern2016-11-241-0/+1
* netfilter: nft_dup: do not use sreg_dev if the user doesn't specify itLiping Zhang2016-10-311-2/+4
* Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/davem/...Pablo Neira Ayuso2016-09-252-3/+8
|\
| * Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller2016-09-231-3/+7
| |\
| | * netfilter: nft_chain_route: re-route before skb is queued to userspaceLiping Zhang2016-09-061-3/+7
| * | Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller2016-09-121-0/+1
| |\|
| | * netfilter: nft_reject: restrict to INPUT/FORWARD/OUTPUTLiping Zhang2016-08-251-0/+1
* | | netfilter: nf_log: get rid of XT_LOG_* macrosLiping Zhang2016-09-251-7/+7
* | | netfilter: nft_log: complete NFTA_LOG_FLAGS attr supportLiping Zhang2016-09-252-3/+3
* | | netfilter: Remove explicit rcu_read_lock in nf_hook_slowAaron Conole2016-09-242-2/+2
* | | netfilter: Add the missed return value check of nft_register_chain_typeGao Feng2016-09-121-1/+4
* | | netfilter: nf_tables: don't drop IPv6 packets that cannot parse transportPablo Neira Ayuso2016-09-122-6/+2
|/ /
* / netfilter: log: Check param to avoid overflow in nf_log_setGao Feng2016-08-301-2/+1
|/
* netfilter: x_tables: speed up jump target validationFlorian Westphal2016-07-181-21/+24
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2016-07-062-12/+8
|\
| * netfilter: Convert FWINV<[foo]> macros and uses to NF_INVFJoe Perches2016-07-031-8/+8
| * netfilter: x_tables: simplify ip{6}table_mangle_hook()Pablo Neira Ayuso2016-07-011-4/+0
* | Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nfDavid S. Miller2016-06-011-0/+1
|\ \ | |/ |/|
| * netfilter: nf_dup_ipv6: set again FLOWI_FLAG_KNOWN_NH at flowi6_flagsPaolo Abeni2016-05-301-0/+1
* | netfilter: x_tables: get rid of old and inconsistent debuggingPablo Neira Ayuso2016-05-051-188/+41
* | netfilter: fix IS_ERR_VALUE usagePablo Neira Ayuso2016-04-291-2/+4
* | netfilter: ip6t_SYNPROXY: unnecessary to check whether ip6_route_output retur...Liping Zhang2016-04-251-1/+1
* | netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal2016-04-141-44/+5
* | netfilter: x_tables: remove obsolete checkFlorian Westphal2016-04-141-7/+0
* | netfilter: x_tables: remove obsolete overflow check for compat case tooFlorian Westphal2016-04-141-2/+0
* | netfilter: x_tables: do compat validation via translate_tableFlorian Westphal2016-04-141-125/+23
* | netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal2016-04-141-18/+9
* | netfilter: ip6_tables: simplify translate_compat_table argsFlorian Westphal2016-04-141-35/+24
* | netfilter: x_tables: check for bogus target offsetFlorian Westphal2016-04-141-2/+3
* | netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal2016-04-141-1/+2
* | netfilter: x_tables: kill check_entry helperFlorian Westphal2016-04-141-12/+8
* | netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal2016-04-141-11/+1
* | netfilter: x_tables: validate targets of jumpsFlorian Westphal2016-04-141-0/+16
* | netfilter: x_tables: don't move to non-existent next ruleFlorian Westphal2016-04-141-0/+4
* | Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2016-04-122-27/+31
|\ \ | |/ |/|
| * netfilter: ipv6: unnecessary to check whether ip6_route_output() returns NULLHaishuang Yan2016-04-071-1/+1
| * netfilter: ip6t_SYNPROXY: remove magic number for hop_limitLiping Zhang2016-03-291-26/+30
* | netfilter: x_tables: enforce nul-terminated table name from getsockopt GET_EN...Pablo Neira Ayuso2016-03-281-0/+2
* | netfilter: x_tables: fix unconditional helperFlorian Westphal2016-03-281-12/+11
* | netfilter: x_tables: make sure e->next_offset covers remaining blob sizeFlorian Westphal2016-03-281-2/+4
* | netfilter: x_tables: validate e->target_offset earlyFlorian Westphal2016-03-281-9/+8
|/
* netfilter: Allow calling into nat helper without skb_dst.Jarno Rajahalme2016-03-141-22/+8
* netfilter: nft_masq: support port rangePablo Neira Ayuso2016-03-021-1/+6
* netfilter: xtables: don't hook tables by defaultFlorian Westphal2016-03-026-85/+137
* netfilter: xtables: prepare for on-demand hook registerFlorian Westphal2016-03-026-30/+37
* netfilter: conntrack: resched in nf_ct_iterate_cleanupFlorian Westphal2016-02-011-3/+71