summaryrefslogtreecommitdiffstats
path: root/net/ipv4/netfilter
Commit message (Expand)AuthorAgeFilesLines
...
* | | netfilter: Add the missed return value check of nft_register_chain_typeGao Feng2016-09-122-2/+8
* | | netfilter: nf_tables: ensure proper initialization of nft_pktinfo fieldsPablo Neira Ayuso2016-09-121-1/+1
* | | netfilter: gre: Use consistent GRE and PTTP header structure instead of the o...Gao Feng2016-09-071-6/+7
* | | netfilter: gre: Use consistent GRE_* macros instead of ones defined by netfil...Gao Feng2016-09-071-2/+2
|/ /
* | netfilter: log: Check param to avoid overflow in nf_log_setGao Feng2016-08-302-4/+2
* | netfilter: log_arp: Use ARPHRD_ETHER instead of literal '1'Gao Feng2016-08-301-1/+1
* | netfilter: remove ip_conntrack* sysctl compat codePablo Neira Ayuso2016-08-135-615/+1
* | netfilter: use_nf_conn_expires helper in more placesFlorian Westphal2016-08-121-2/+1
* | netfilter: nf_dup4: remove redundant checksum recalculationLiping Zhang2016-08-121-6/+4
|/
* netfilter: x_tables: speed up jump target validationFlorian Westphal2016-07-182-43/+49
* netfilter: conntrack: fix race between nf_conntrack proc read and hash resizeLiping Zhang2016-07-111-4/+10
* netfilter: Convert FWINV<[foo]> macros and uses to NF_INVFJoe Perches2016-07-032-32/+29
* netfilter: x_tables: simplify ip{6}table_mangle_hook()Pablo Neira Ayuso2016-07-011-4/+0
* netfilter: nf_reject_ipv4: don't send tcp RST if the packet is non-TCPLiping Zhang2016-06-241-0/+3
* netfilter: conntrack: use a single expectation table for all namespacesFlorian Westphal2016-05-061-4/+2
* netfilter: conntrack: check netns when walking expect hashFlorian Westphal2016-05-061-0/+3
* netfilter: x_tables: get rid of old and inconsistent debuggingPablo Neira Ayuso2016-05-052-385/+76
* netfilter: conntrack: use a single hashtable for all namespacesFlorian Westphal2016-05-052-7/+5
* netfilter: conntrack: check netns when comparing conntrack objectsFlorian Westphal2016-05-051-2/+6
* netfilter: conntrack: small refactoring of conntrack seq_printfFlorian Westphal2016-05-051-5/+19
* netfilter: fix IS_ERR_VALUE usagePablo Neira Ayuso2016-04-292-4/+8
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2016-04-242-455/+175
|\
| * netfilter: x_tables: introduce and use xt_copy_counters_from_userFlorian Westphal2016-04-142-86/+10
| * netfilter: x_tables: remove obsolete checkFlorian Westphal2016-04-142-15/+0
| * netfilter: x_tables: remove obsolete overflow check for compat case tooFlorian Westphal2016-04-142-4/+0
| * netfilter: x_tables: do compat validation via translate_tableFlorian Westphal2016-04-142-217/+52
| * netfilter: x_tables: xt_compat_match_from_user doesn't need a retvalFlorian Westphal2016-04-142-29/+14
| * netfilter: arp_tables: simplify translate_compat_table argsFlorian Westphal2016-04-141-46/+36
| * netfilter: ip_tables: simplify translate_compat_table argsFlorian Westphal2016-04-141-35/+24
| * netfilter: x_tables: check for bogus target offsetFlorian Westphal2016-04-142-4/+6
| * netfilter: x_tables: add compat version of xt_check_entry_offsetsFlorian Westphal2016-04-142-2/+4
| * netfilter: x_tables: kill check_entry helperFlorian Westphal2016-04-142-23/+16
| * netfilter: x_tables: add and use xt_check_entry_offsetsFlorian Westphal2016-04-142-21/+2
| * netfilter: x_tables: validate targets of jumpsFlorian Westphal2016-04-142-0/+32
| * netfilter: x_tables: don't move to non-existent next ruleFlorian Westphal2016-04-142-3/+9
* | netfilter: arp_tables: register table in initnsFlorian Westphal2016-04-071-0/+6
|/
* netfilter: ipv4: fix NULL dereferenceLiping Zhang2016-03-281-26/+28
* netfilter: x_tables: enforce nul-terminated table name from getsockopt GET_EN...Pablo Neira Ayuso2016-03-282-0/+4
* netfilter: x_tables: fix unconditional helperFlorian Westphal2016-03-282-21/+20
* netfilter: x_tables: make sure e->next_offset covers remaining blob sizeFlorian Westphal2016-03-282-4/+8
* netfilter: x_tables: validate e->target_offset earlyFlorian Westphal2016-03-282-18/+16
* Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-nextDavid S. Miller2016-03-141-22/+8
|\
| * netfilter: Allow calling into nat helper without skb_dst.Jarno Rajahalme2016-03-141-22/+8
* | ipv4: Don't do expensive useless work during inetdev destroy.David S. Miller2016-03-131-2/+10
|/
* netfilter: nft_masq: support port rangePablo Neira Ayuso2016-03-021-1/+6
* netfilter: xtables: don't hook tables by defaultFlorian Westphal2016-03-028-96/+180
* netfilter: xtables: prepare for on-demand hook registerFlorian Westphal2016-03-028-46/+55
* netfilter: nf_defrag_ipv4: Drop redundant ip_send_check()Joe Stringer2016-03-021-3/+1
* ipv4: Namespaceify ip_default_ttl sysctl knobNikolay Borisov2016-02-161-1/+2
* inet: frag: Always orphan skbs inside ip_defrag()Joe Stringer2016-01-281-2/+0