From: Pablo Neira Ayuso <pablo@netfilter.org>
To: netfilter-devel@vger.kernel.org
Cc: davem@davemloft.net, netdev@vger.kernel.org, kuba@kernel.org
Subject: [PATCH net-next 0/5] Netfilter updates for net-next
Date: Mon, 1 Nov 2021 09:39:35 +0100 [thread overview]
Message-ID: <20211101083940.51007-1-pablo@netfilter.org> (raw)
Hi,
The following patchset contains Netfilter updates for net-next:
1) Use array_size() in ebtables, from Gustavo A. R. Silva.
2) Attach IPS_ASSURED to internal UDP stream state, reported by
Maciej Zenczykowski.
3) Add NFT_META_IFTYPE to match on the interface type either
from ingress or egress.
4) Generalize pktinfo->tprot_set to flags field.
5) Allow to match on inner headers / payload data.
Please, pull these changes from:
git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-next.git
Thanks.
----------------------------------------------------------------
The following changes since commit ab98bbee072c7c30c391ae742b209efebb468273:
Merge branch 'ax88796c-spi-ethernet-adapter' (2021-10-21 16:28:44 -0700)
are available in the Git repository at:
git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-next.git HEAD
for you to fetch changes up to c46b38dc8743535e686b911d253a844f0bd50ead:
netfilter: nft_payload: support for inner header matching / mangling (2021-11-01 09:31:03 +0100)
----------------------------------------------------------------
Gustavo A. R. Silva (1):
netfilter: ebtables: use array_size() helper in copy_{from,to}_user()
Pablo Neira Ayuso (4):
netfilter: conntrack: set on IPS_ASSURED if flows enters internal stream state
netfilter: nft_meta: add NFT_META_IFTYPE
netfilter: nf_tables: convert pktinfo->tprot_set to flags field
netfilter: nft_payload: support for inner header matching / mangling
include/net/netfilter/nf_tables.h | 10 ++++--
include/net/netfilter/nf_tables_ipv4.h | 7 ++--
include/net/netfilter/nf_tables_ipv6.h | 6 ++--
include/uapi/linux/netfilter/nf_tables.h | 6 +++-
net/bridge/netfilter/ebtables.c | 7 ++--
net/netfilter/nf_conntrack_proto_udp.c | 7 ++--
net/netfilter/nf_tables_core.c | 2 +-
net/netfilter/nf_tables_trace.c | 4 +--
net/netfilter/nft_meta.c | 8 +++--
net/netfilter/nft_payload.c | 60 +++++++++++++++++++++++++++++---
10 files changed, 94 insertions(+), 23 deletions(-)
next reply other threads:[~2021-11-01 8:39 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-11-01 8:39 Pablo Neira Ayuso [this message]
2021-11-01 8:39 ` [PATCH net-next 1/5] netfilter: ebtables: use array_size() helper in copy_{from,to}_user() Pablo Neira Ayuso
2021-11-01 13:10 ` patchwork-bot+netdevbpf
2021-11-01 8:39 ` [PATCH net-next 2/5] netfilter: conntrack: set on IPS_ASSURED if flows enters internal stream state Pablo Neira Ayuso
2021-11-01 8:39 ` [PATCH net-next 3/5] netfilter: nft_meta: add NFT_META_IFTYPE Pablo Neira Ayuso
2021-11-01 8:39 ` [PATCH net-next 4/5] netfilter: nf_tables: convert pktinfo->tprot_set to flags field Pablo Neira Ayuso
2021-11-01 8:39 ` [PATCH net-next 5/5] netfilter: nft_payload: support for inner header matching / mangling Pablo Neira Ayuso
-- strict thread matches above, loose matches on Subject: below --
2023-03-22 21:07 [PATCH net-next 0/5] netfilter updates for net-next Florian Westphal
2023-07-27 13:35 Florian Westphal
2023-08-08 12:41 Florian Westphal
2025-09-11 14:38 [PATCH net-next 0/5] netfilter: " Florian Westphal
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20211101083940.51007-1-pablo@netfilter.org \
--to=pablo@netfilter.org \
--cc=davem@davemloft.net \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).