summaryrefslogtreecommitdiffstats
path: root/net/netfilter
Commit message (Expand)AuthorAgeFilesLines
* Revert "netfilter: conntrack: fix race in __nf_conntrack_confirm against get_...Pablo Neira2014-11-251-8/+6
* netfilter: nfnetlink: fix insufficient validation in nfnetlink_bindPablo Neira Ayuso2014-11-171-1/+11
* netfilter: conntrack: fix race in __nf_conntrack_confirm against get_next_corpsebill bonaparte2014-11-141-6/+8
* netfilter: nf_tables: restore synchronous object release from commit/abortPablo Neira Ayuso2014-11-121-16/+8
* netfilter: nft_compat: use the match->table to validate dependenciesPablo Neira Ayuso2014-11-121-2/+2
* netfilter: nft_compat: relax chain type validationPablo Neira Ayuso2014-11-121-30/+2
* netfilter: nft_compat: use current net namespacePablo Neira Ayuso2014-11-121-2/+2
* ipvs: Keep skb->sk when allocating headroom on tunnel xmitCalvin Owens2014-11-121-0/+2
* netfilter: ipset: small potential read beyond the end of bufferDan Carpenter2014-11-111-0/+6
* ipvs: Avoid null-pointer deref in debug codeAlex Gartrell2014-10-281-2/+2
* netfilter: nft_compat: fix wrong target lookup in nft_target_select_ops()Arturo Borrero2014-10-271-1/+1
* netfilter: nf_log: release skbuff on nlmsg put failureHoucheng Lin2014-10-241-9/+8
* netfilter: nfnetlink_log: fix maximum packet length logged to userspaceFlorian Westphal2014-10-241-3/+5
* netfilter: nf_log: account for size of NLMSG_DONE attributeFlorian Westphal2014-10-241-3/+3
* netfilter: nf_tables: check for NULL in nf_tables_newchain pcpu stats allocationSabrina Dubroca2014-10-221-2/+2
* netfilter: ipset: off by one in ip_set_nfnl_get_byindex()Dan Carpenter2014-10-221-1/+1
* netfilter: nf_conntrack: allow server to become a client in TW handlingMarcelo Leitner2014-10-221-2/+2
* net: make skb_gso_segment error handling more robustFlorian Westphal2014-10-201-1/+1
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nfDavid S. Miller2014-10-204-41/+150
|\
| * netfilter: nft_nat: dump attributes if they are setPablo Neira Ayuso2014-10-181-9/+11
| * netfilter: nft_nat: NFTA_NAT_REG_ADDR_MAX depends on NFTA_NAT_REG_ADDR_MINPablo Neira Ayuso2014-10-181-22/+28
| * netfilter: nft_nat: insufficient attribute validationPablo Neira Ayuso2014-10-181-1/+3
| * netfilter: nft_compat: validate chain type in match/targetPablo Neira Ayuso2014-10-181-9/+66
| * netfilter: nft_compat: fix hook validation for non-base chainsPablo Neira Ayuso2014-10-141-0/+4
| * netfilter: nf_tables: restrict nat/masq expressions to nat chain typePablo Neira Ayuso2014-10-133-0/+38
* | netfilter: replace strnicmp with strncasecmpRasmus Villemoes2014-10-145-18/+18
|/
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2014-10-101-6/+4
|\
| * netfilter: fix wrong arithmetics regarding NFT_REJECT_ICMPX_MAXPablo Neira Ayuso2014-10-071-6/+4
* | Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net-nextLinus Torvalds2014-10-0871-738/+2003
|\ \ | |/
| * Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2014-10-0510-120/+161
| |\
| | * netfilter: explicit module dependency between br_netfilter and physdevPablo Neira Ayuso2014-10-021-0/+3
| | * netfilter: nft_compat: remove incomplete 32/64 bits arch compat codePablo Neira Ayuso2014-10-021-101/+15
| | * netfilter: nf_tables: wait for call_rcu completion on module removalPablo Neira Ayuso2014-10-021-0/+1
| | * netfilter: use IS_ENABLED(CONFIG_BRIDGE_NETFILTER)Pablo Neira Ayuso2014-10-025-15/+15
| | * netfilter: nft_reject: introduce icmp code abstraction for inet and bridgePablo Neira Ayuso2014-10-022-4/+127
| * | Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/netDavid S. Miller2014-10-024-8/+71
| |\ \ | | |/ | |/|
| * | net: sched: make bstats per cpu and estimator RCU safeJohn Fastabend2014-09-301-1/+1
| * | netfilter: conntrack: disable generic tracking for known protocolsFlorian Westphal2014-09-291-1/+25
| * | netfilter: nf_tables: store and dump set policyArturo Borrero2014-09-291-0/+6
| * | net/netfilter/x_tables.c: use __seq_open_private()Rob Jones2014-09-261-26/+4
| * | netfilter: nf_tables: export rule-set generation IDPablo Neira Ayuso2014-09-191-26/+114
| * | netfilter: nfnetlink: use original skbuff when committing/abortingPablo Neira Ayuso2014-09-191-3/+3
| * | Merge branch 'ipvs-next'Pablo Neira Ayuso2014-09-1821-222/+529
| |\ \
| | * | ipvs: Allow heterogeneous pools now that we support themAlex Gartrell2014-09-181-4/+20
| | * | ipvs: use the new dest addr family fieldJulian Anastasov2014-09-184-16/+43
| | * | ipvs: use correct address family in scheduler logsJulian Anastasov2014-09-189-12/+15
| | * | ipvs: address family of LBLCR entry depends on svc familyJulian Anastasov2014-09-161-6/+6
| | * | ipvs: address family of LBLC entry depends on svc familyJulian Anastasov2014-09-161-6/+6
| | * | ipvs: support ipv4 in ipv6 and ipv6 in ipv4 tunnel forwardingAlex Gartrell2014-09-162-43/+117
| | * | ipvs: Add generic ensure_mtu_is_adequate to handle mixed poolsAlex Gartrell2014-09-161-26/+51
OpenPOWER on IntegriCloud