netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 00/84] netfilter: netfilter update for 2.6.35
@ 2010-05-10 20:17 kaber
  2010-05-10 20:17 ` [PATCH 01/84] netfilter: include/linux/netfilter/nf_conntrack_tuple_common.h: Checkpatch cleanup kaber
                   ` (84 more replies)
  0 siblings, 85 replies; 89+ messages in thread
From: kaber @ 2010-05-10 20:17 UTC (permalink / raw)
  To: davem; +Cc: netfilter-devel, netdev

Hi Dave,

appologies for not sending this earlier in smaller batches, as mentioned
earlier I ran into some problems with git. Following is a first netfilter
update for 2.6.35, containing:

- various smaller cleanups, optimizations, Kconfig updates etc.

- merging of the xt_MARK module with xt_mark and xt_CONNMARK with xt_connmark
  to decrease overhead when using modular kernels, saving 14k on 32 bit,
  from Jan

- scheduling of the NOTRACK module for removal, obsoleted by the CT module

- removal of the compat /proc directory of xt_recent

- addition of an entry reaper to the recent module, from Tim Gardner

- support for changing UID/GID of the recent /proc files, from Jan

- use of NFPROTO values in NF_HOOK calls in IPv4/IPv6/bridging/DECnet, from Jan

- a change to the xtables ->checkentry() function signature to support
  returning errno codes, from Jan

- removal of old revisions of the hashlimit, multiport and string matches,
  from Jan

- ctnetlink message size computation fixes with conntrack accounting,
  from Jiri Pirko

- hashlimit match RCU conversion, from Eric

- userspace queuing checksum fixes, from Herbert

- fixes for netfilter RCU warnings, from myself

- fixes for the LED target to avoid invalid errors when replacing the
  ruleset

- fixes for iproute compilation breakage due to XT_ALIGN cleanups, from
  Alexey Dobriyan

- bridge netfilter cleanups, simplification and comment updates from Bart

- bridge netfilter MAC header fixes when using DNAT

- bridge netfilter refragmentation fixes for PPPoe, from Bart

- a change to the IPv6 POST_ROUTING invocation to make it receive
  unfragmented packets like IPv4, from Jan

- a fix for the IPv6 xfrm lookup in ip6_route_me_harder, from Ulrich Weber

- more appropriate default log level (KERNL_NOTICE instead of KERN_EMERG) for
  the IPv4 and IPv6 LOG targets, from myself

- addition of the TEE target, which can be used to clone packets and send
  them to other hosts, f.i. IDS or logging hosts, from Jan

- a patch to make iptables and ip6tables reentrant by moving the jump stack
  to a seperately allocated area. This will allow to get rid of the per
  CPU ruleset duplication in the future. From Jan.

The patches won't apply cleanly because of some conflicts resolved during
merges, please pull from:

git://git.kernel.org/pub/scm/linux/kernel/git/kaber/nf-next-2.6.git master

Thanks!


^ permalink raw reply	[flat|nested] 89+ messages in thread

end of thread, other threads:[~2010-05-11 11:42 UTC | newest]

Thread overview: 89+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-05-10 20:17 [PATCH 00/84] netfilter: netfilter update for 2.6.35 kaber
2010-05-10 20:17 ` [PATCH 01/84] netfilter: include/linux/netfilter/nf_conntrack_tuple_common.h: Checkpatch cleanup kaber
2010-05-10 20:17 ` [PATCH 02/84] netfilter: ebt_ip6: Use ipv6_masked_addr_cmp() kaber
2010-05-10 20:17 ` [PATCH 03/84] netfilter: remove stale declaration for ip6_masked_addrcmp() kaber
2010-05-10 20:17 ` [PATCH 04/84] netfilter: net/netfilter/ipvs/ip_vs_ftp.c: Remove use of NIPQUAD kaber
2010-05-10 20:17 ` [PATCH 05/84] netfilter: xt_CT: par->family is an nfproto kaber
2010-05-10 20:17 ` [PATCH 06/84] netfilter: xt_NFQUEUE: consolidate v4/v6 targets into one kaber
2010-05-10 20:17 ` [PATCH 07/84] netfilter: xtables: add comment markers to Xtables Kconfig kaber
2010-05-10 20:17 ` [PATCH 08/84] netfilter: xtables: merge xt_MARK into xt_mark kaber
2010-05-10 20:17 ` [PATCH 09/84] netfilter: xtables: merge xt_CONNMARK into xt_connmark kaber
2010-05-10 20:17 ` [PATCH 10/84] netfilter: xtables: schedule xt_NOTRACK for removal kaber
2010-05-10 20:17 ` [PATCH 11/84] netfilter: update my email address kaber
2010-05-10 20:17 ` [PATCH 12/84] netfilter: ebt_ip6: add principal maintainer in a MODULE_AUTHOR tag kaber
2010-05-10 20:17 ` [PATCH 13/84] netfilter: xt_recent: update description kaber
2010-05-10 20:17 ` [PATCH 14/84] netfilter: xt_recent: remove old proc directory kaber
2010-05-10 20:17 ` [PATCH 15/84] netfilter: xt_recent: add an entry reaper kaber
2010-05-10 20:17 ` [PATCH 16/84] netfilter: xt_recent: check for unsupported user space flags kaber
2010-05-10 20:17 ` [PATCH 17/84] netfilter: remove unused headers in net/netfilter/nfnetlink.c kaber
2010-05-10 20:17 ` [PATCH 18/84] netfilter: xtables: do without explicit XT_ALIGN kaber
2010-05-10 20:17 ` [PATCH 19/84] netfilter: xtables: clean up xt_mac match routine kaber
2010-05-10 20:17 ` [PATCH 20/84] netfilter: xtables: limit xt_mac to ethernet devices kaber
2010-05-10 20:17 ` [PATCH 21/84] netfilter: xtables: resort osf kconfig text kaber
2010-05-10 20:17 ` [PATCH 22/84] netfilter: xtables: make use of caller family rather than match family kaber
2010-05-10 20:17 ` [PATCH 23/84] netfilter: update documentation fields of x_tables.h kaber
2010-05-10 20:17 ` [PATCH 24/84] netfilter: xtables: remove almost-unused xt_match_param.data member kaber
2010-05-10 20:17 ` [PATCH 25/84] netfilter: xtables: reduce holes in struct xt_target kaber
2010-05-10 20:17 ` [PATCH 26/84] netfilter: xtables: do not print any messages on ENOMEM kaber
2010-05-10 20:17 ` [PATCH 27/84] netfilter: xtables: replace custom duprintf with pr_debug kaber
2010-05-10 20:17 ` [PATCH 28/84] netfilter: xt extensions: use pr_<level> kaber
2010-05-10 20:18 ` [PATCH 29/84] netfilter: remove unused headers in net/ipv6/netfilter/ip6t_LOG.c kaber
2010-05-10 20:18 ` [PATCH 30/84] netfilter: remove unused headers in net/ipv4/netfilter/nf_nat_h323.c kaber
2010-05-10 20:18 ` [PATCH 31/84] netfilter: xtables: make use of caller family rather than target family kaber
2010-05-10 20:18 ` [PATCH 32/84] netfilter: xt extensions: use pr_<level> (2) kaber
2010-05-10 20:18 ` [PATCH 33/84] netfilter: xtables: make use of xt_request_find_target kaber
2010-05-10 20:18 ` [PATCH 34/84] netfilter: xtables: consolidate code into xt_request_find_match kaber
2010-05-10 20:18 ` [PATCH 35/84] netfilter: xt_recent: allow changing ip_list_[ug]id at runtime kaber
2010-05-10 20:18 ` [PATCH 36/84] netfilter: bridge: use NFPROTO values for NF_HOOK invocation kaber
2010-05-10 20:18 ` [PATCH 37/84] netfilter: ipv4: " kaber
2010-05-10 20:18 ` [PATCH 38/84] netfilter: ipv6: " kaber
2010-05-10 20:18 ` [PATCH 39/84] netfilter: decnet: " kaber
2010-05-10 20:18 ` [PATCH 40/84] netfilter: ipvs: " kaber
2010-05-11  3:07   ` Simon Horman
2010-05-10 20:18 ` [PATCH 41/84] netfilter: xtables: untangle spaghetti if clauses in checkentry kaber
2010-05-10 20:18 ` [PATCH 42/84] netfilter: xtables: change xt_match.checkentry return type kaber
2010-05-10 20:18 ` [PATCH 43/84] netfilter: xtables: change xt_target.checkentry " kaber
2010-05-10 20:18 ` [PATCH 44/84] netfilter: xtables: change matches to return error code kaber
2010-05-10 20:18 ` [PATCH 45/84] netfilter: xtables: change targets " kaber
2010-05-10 20:18 ` [PATCH 46/84] netfilter: xtables: slightly better error reporting kaber
2010-05-10 20:18 ` [PATCH 47/84] netfilter: xtables: shorten up return clause kaber
2010-05-10 20:18 ` [PATCH 48/84] netfilter: xtables: remove xt_hashlimit revision 0 kaber
2010-05-10 20:18 ` [PATCH 49/84] netfilter: xtables: remove xt_multiport " kaber
2010-05-10 20:18 ` [PATCH 50/84] netfilter: xtables: remove xt_string " kaber
2010-05-10 20:18 ` [PATCH 51/84] netfilter: xtables: merge registration structure to NFPROTO_UNSPEC kaber
2010-05-10 20:18 ` [PATCH 52/84] netfilter: ctnetlink: compute message size properly kaber
2010-05-10 20:18 ` [PATCH 53/84] netfilter: CLUSTERIP: clusterip_seq_stop() fix kaber
2010-05-10 20:18 ` [PATCH 54/84] netfilter: xt_hashlimit: RCU conversion kaber
2010-05-10 20:18 ` [PATCH 55/84] IPVS: fix potential stack overflow with overly long protocol names kaber
2010-05-10 20:18 ` [PATCH 56/84] netfilter: only do skb_checksum_help on CHECKSUM_PARTIAL in ip_queue kaber
2010-05-10 20:18 ` [PATCH 57/84] netfilter: only do skb_checksum_help on CHECKSUM_PARTIAL in ip6_queue kaber
2010-05-10 20:18 ` [PATCH 58/84] netfilter: only do skb_checksum_help on CHECKSUM_PARTIAL in nfnetlink_queue kaber
2010-05-10 20:18 ` [PATCH 59/84] netfilter: remove invalid rcu_dereference() calls kaber
2010-05-10 20:18 ` [PATCH 60/84] netfilter: xt_LED: add refcounts to LED target kaber
2010-05-10 20:18 ` [PATCH 61/84] netfilter: xtables: make XT_ALIGN() usable in exported headers by exporting __ALIGN_KERNEL() kaber
2010-05-10 20:18 ` [PATCH 62/84] netfilter: fix some coding styles and remove moduleparam.h kaber
2010-05-10 20:18 ` [PATCH 63/84] netfilter: bridge-netfilter: cleanup br_netfilter.c kaber
2010-05-10 20:18 ` [PATCH 64/84] netfilter: bridge-netfilter: update a comment in br_forward.c about ip_fragment() kaber
2010-05-10 20:18 ` [PATCH 65/84] Restore __ALIGN_MASK() kaber
2010-05-10 20:18 ` [PATCH 66/84] netfilter: ipv6: move POSTROUTING invocation before fragmentation kaber
2010-05-10 20:18 ` [PATCH 67/84] netfilter: ipv6: add IPSKB_REROUTED exclusion to NF_HOOK/POSTROUTING invocation kaber
2010-05-10 20:18 ` [PATCH 68/84] netfilter: bridge-netfilter: simplify IP DNAT kaber
2010-05-10 20:18 ` [PATCH 69/84] netfilter: bridge-netfilter: Fix MAC header handling with " kaber
2010-05-10 20:18 ` [PATCH 70/84] netfilter: ipv6: move xfrm_lookup at end of ip6_route_me_harder kaber
2010-05-10 20:18 ` [PATCH 71/84] netfilter: ipt_LOG/ip6t_LOG: use more appropriate log level as default kaber
2010-05-10 20:18 ` [PATCH 72/84] netfilter: xtables: inclusion of xt_TEE kaber
2010-05-10 20:52   ` Eric Dumazet
2010-05-11 11:42     ` Patrick McHardy
2010-05-10 20:18 ` [PATCH 73/84] netfilter: xtables: make ip_tables reentrant kaber
2010-05-10 20:18 ` [PATCH 74/84] netfilter: xt_TEE: have cloned packet travel through Xtables too kaber
2010-05-10 20:18 ` [PATCH 75/84] netfilter: xtables: remove old comments about reentrancy kaber
2010-05-10 20:18 ` [PATCH 76/84] netfilter: xt_TEE: resolve oif using netdevice notifiers kaber
2010-05-10 20:18 ` [PATCH 77/84] netfilter: bridge-netfilter: fix refragmenting IP traffic encapsulated in PPPoE traffic kaber
2010-05-10 20:18 ` [PATCH 78/84] netfilter: x_tables: move sleeping allocation outside BH-disabled region kaber
2010-05-10 20:18 ` [PATCH 79/84] netfilter: ip_tables: convert pr_devel() to pr_debug() kaber
2010-05-10 20:18 ` [PATCH 80/84] netfilter: nf_conntrack: extend with extra stat counter kaber
2010-05-10 20:18 ` [PATCH 81/84] netfilter: x_tables: rectify XT_FUNCTION_MAXNAMELEN usage kaber
2010-05-10 20:18 ` [PATCH 82/84] netfilter: nf_ct_h323: switch "incomplete TPKT" message to pr_debug() kaber
2010-05-10 20:18 ` [PATCH 83/84] netfilter: nf_conntrack_proto: fix warning with CONFIG_PROVE_RCU kaber
2010-05-10 20:18 ` [PATCH 84/84] netfilter: use rcu_dereference_protected() kaber
2010-05-11  6:14 ` [PATCH 00/84] netfilter: netfilter update for 2.6.35 David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).