summaryrefslogtreecommitdiffstats
path: root/net/netfilter
Commit message (Expand)AuthorAgeFilesLines
* netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal2016-07-101-0/+74
* netfilter: x_tables: do compat validation via translate_tableFlorian Westphal2016-07-101-0/+8
* netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal2016-07-101-3/+2
* netfilter: x_tables: don't reject valid target size on some architecturesFlorian Westphal2016-07-101-2/+2
* netfilter: x_tables: validate all offsets and sizes in a ruleFlorian Westphal2016-07-101-5/+76
* netfilter: x_tables: check for bogus target offsetFlorian Westphal2016-07-101-2/+15
* netfilter: x_tables: check standard target size tooFlorian Westphal2016-07-101-0/+15
* netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal2016-07-101-0/+22
* netfilter: x_tables: assert minimum target sizeFlorian Westphal2016-07-101-0/+3
* netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal2016-07-101-0/+34
* ipvs: drop first packet to redirect conntrackJulian Anastasov2016-07-101-9/+28
* ipvs: correct initial offset of Call-ID header search in SIP persistence engineMarco Angaroni2016-07-101-1/+1
* nf_conntrack: avoid kernel pointer value leak in slab nameLinus Torvalds2016-05-171-1/+3
* ipvs: call skb_sender_cpu_clearJulian Anastasov2015-10-221-0/+6
* ipvs: fix crash with sync protocol v0 and FTPJulian Anastasov2015-10-221-1/+1
* ipvs: skb_orphan in case of forwardingAlex Gartrell2015-10-221-0/+27
* ipvs: fix crash if scheduler is changedJulian Anastasov2015-10-223-37/+69
* ipvs: do not use random local source address for tunnelsJulian Anastasov2015-10-221-1/+0
* netfilter: nf_log: don't zap all loggers on unregisterFlorian Westphal2015-10-221-2/+6
* netfilter: nft_compat: skip family comparison in case of NFPROTO_UNSPECPablo Neira Ayuso2015-10-221-6/+18
* netfilter: nf_log: wait for rcu grace after logger unregistrationPablo Neira Ayuso2015-10-221-0/+1
* netfilter: nftables: Do not run chains in the wrong network namespaceEric W. Biederman2015-10-221-1/+6
* netfilter: nf_qeueue: Drop queue entries on nf_unregister_hookEric W. Biederman2015-10-224-1/+42
* netfilter: ctnetlink: put back references to master ct and expect objectsPablo Neira Ayuso2015-10-221-5/+0
* netfilter: nf_conntrack: Support expectations in different zonesJoe Stringer2015-10-221-1/+2
* netfilter: nfnetlink: work around wrong endianess in res_id fieldPablo Neira Ayuso2015-10-221-1/+7
* netfilter: nfnetlink_{log,queue}: Register pernet in first placeFrancesco Ruggeri2015-05-202-18/+19
* netfilter: nf_tables: fix bogus warning in nft_data_uninit()Mirek Kratochvil2015-05-151-2/+2
* conntrack: RFC5961 challenge ACK confuse conntrack LAST-ACK transitionJesper Dangaard Brouer2015-05-151-3/+32
* netfilter: avoid build error if TPROXY/SOCKET=y && NF_DEFRAG_IPV6=mFlorian Westphal2015-05-151-0/+2
* ipvs: fix memory leak in ip_vs_ctl.cTommi Rantala2015-05-081-0/+3
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nfDavid S. Miller2015-04-271-2/+1
|\
| * netfilter: nf_tables: fix wrong length for jump/goto verdictsFlorian Westphal2015-04-241-2/+1
* | netfilter; Add some missing default cases to switch statements in nft_reject.David S. Miller2015-04-272-0/+4
|/
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2015-04-1423-497/+591
|\
| * netfilter: nf_tables: get rid of the expression example codePablo Neira Ayuso2015-04-131-94/+0
| * netfilter: nft_dynset: dynamic stateful expression instantiationPatrick McHardy2015-04-131-4/+50
| * netfilter: nf_tables: add flag to indicate set contains expressionsPatrick McHardy2015-04-132-2/+9
| * netfilter: nf_tables: mark stateful expressionsPatrick McHardy2015-04-132-0/+2
| * netfilter: nf_tables: prepare for expressions associated to set elementsPatrick McHardy2015-04-131-0/+9
| * netfilter: nf_tables: add helper functions for expression handlingPatrick McHardy2015-04-131-5/+51
| * netfilter: nf_tables: variable sized set element keys / dataPatrick McHardy2015-04-133-18/+16
| * netfilter: nf_tables: support variable sized data in nft_data_init()Patrick McHardy2015-04-134-16/+28
| * netfilter: nf_tables: switch registers to 32 bit addressingPatrick McHardy2015-04-1311-34/+70
| * netfilter: nf_tables: add register parsing/dumping helpersPatrick McHardy2015-04-1313-52/+64
| * netfilter: nf_tables: convert sets to u32 data pointersPatrick McHardy2015-04-132-8/+6
| * netfilter: nf_tables: kill nft_data_cmp()Patrick McHardy2015-04-133-8/+7
| * netfilter: nf_tables: convert expressions to u32 register pointersPatrick McHardy2015-04-137-65/+61
| * netfilter: nf_tables: use struct nft_verdict within struct nft_dataPatrick McHardy2015-04-131-17/+21
| * netfilter: nf_tables: get rid of NFT_REG_VERDICT usagePatrick McHardy2015-04-1319-86/+89