* [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core
@ 2026-05-26 21:58 Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 1/5 nf-next v4] netfilter: synproxy: drop packets if timestamp adjustment fails Fernando Fernandez Mancera
` (5 more replies)
0 siblings, 6 replies; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-26 21:58 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil, Fernando Fernandez Mancera
This series fixes several long standing issues during synproxy timestamp
adjustment and concurrent hook registration. From ignored error handling
to unaligned memory access. Most of this are not issues impacting real
setups as they would have been reported before.
FWIW; I am sending these fixes as separated patches because they are
addressing independent issues.
Fernando Fernandez Mancera (5):
netfilter: synproxy: drop packets if timestamp adjustment fails
netfilter: synproxy: adjust duplicate timestamp options
netfilter: synproxy: fix unaligned memory access in timestamp
adjustment
netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
netfilter: synproxy: add mutex to guard hook reference counting
net/netfilter/nf_conntrack_seqadj.c | 2 +
net/netfilter/nf_synproxy_core.c | 64 ++++++++++++++++++-----------
2 files changed, 41 insertions(+), 25 deletions(-)
--
2.53.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* [PATCH 1/5 nf-next v4] netfilter: synproxy: drop packets if timestamp adjustment fails
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
@ 2026-05-26 21:58 ` Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 2/5 nf-next v4] netfilter: synproxy: adjust duplicate timestamp options Fernando Fernandez Mancera
` (4 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-26 21:58 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil, Fernando Fernandez Mancera
If a packet was malformed or if skb_ensure_writable() failed, the
synproxy_tstamp_adjust() function returned 0 indicating an error but it
was ignored on the callers.
Make the function return a boolean instead to clarify the result and
drop the packet if synproxy_tstamp_adjust() failed due to ENOMEM from
skb_ensure_writable(). In addition, if there are malformed options, skip
the tstamp update but do not drop the packet as that should be done by
the policy directly.
Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
net/netfilter/nf_synproxy_core.c | 22 +++++++++++++---------
1 file changed, 13 insertions(+), 9 deletions(-)
diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index 57f57e2fc80a..e523b64bf839 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -182,7 +182,7 @@ synproxy_check_timestamp_cookie(struct synproxy_options *opts)
opts->options |= opts->tsecr & (1 << 5) ? NF_SYNPROXY_OPT_ECN : 0;
}
-static unsigned int
+static bool
synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
struct tcphdr *th, struct nf_conn *ct,
enum ip_conntrack_info ctinfo,
@@ -192,20 +192,20 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
__be32 *ptr, old;
if (synproxy->tsoff == 0)
- return 1;
+ return true;
optoff = protoff + sizeof(struct tcphdr);
optend = protoff + th->doff * 4;
if (skb_ensure_writable(skb, optend))
- return 0;
+ return false;
while (optoff < optend) {
unsigned char *op = skb->data + optoff;
switch (op[0]) {
case TCPOPT_EOL:
- return 1;
+ return true;
case TCPOPT_NOP:
optoff++;
continue;
@@ -213,7 +213,7 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
if (optoff + 1 == optend ||
optoff + op[1] > optend ||
op[1] < 2)
- return 0;
+ return true;
if (op[0] == TCPOPT_TIMESTAMP &&
op[1] == TCPOLEN_TIMESTAMP) {
if (CTINFO2DIR(ctinfo) == IP_CT_DIR_REPLY) {
@@ -229,12 +229,12 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
}
inet_proto_csum_replace4(&th->check, skb,
old, *ptr, false);
- return 1;
+ return true;
}
optoff += op[1];
}
}
- return 1;
+ return true;
}
#ifdef CONFIG_PROC_FS
@@ -745,7 +745,9 @@ ipv4_synproxy_hook(void *priv, struct sk_buff *skb,
break;
}
- synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy);
+ if (!synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy))
+ return NF_DROP_REASON(skb, SKB_DROP_REASON_NETFILTER_DROP, ENOMEM);
+
return NF_ACCEPT;
}
EXPORT_SYMBOL_GPL(ipv4_synproxy_hook);
@@ -1168,7 +1170,9 @@ ipv6_synproxy_hook(void *priv, struct sk_buff *skb,
break;
}
- synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy);
+ if (!synproxy_tstamp_adjust(skb, thoff, th, ct, ctinfo, synproxy))
+ return NF_DROP_REASON(skb, SKB_DROP_REASON_NETFILTER_DROP, ENOMEM);
+
return NF_ACCEPT;
}
EXPORT_SYMBOL_GPL(ipv6_synproxy_hook);
--
2.53.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH 2/5 nf-next v4] netfilter: synproxy: adjust duplicate timestamp options
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 1/5 nf-next v4] netfilter: synproxy: drop packets if timestamp adjustment fails Fernando Fernandez Mancera
@ 2026-05-26 21:58 ` Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 3/5 nf-next v4] netfilter: synproxy: fix unaligned memory access in timestamp adjustment Fernando Fernandez Mancera
` (3 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-26 21:58 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil, Fernando Fernandez Mancera
RFC 9293 does not mention anything about duplicated options and each
networking stack handles it in their own way. Currently, Linux kernel is
processing options sequentially and in case of duplicated timestamp
options, the value from the latest one overrides the others.
As SYNPROXY is modifying only the first timestamp option found, a packet
can reach the backend server and it might parse the wrong timestamp
value. Let's just continue parsing the following options and in case a
duplicated timestamp is found, adjust it too.
Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
net/netfilter/nf_synproxy_core.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index e523b64bf839..6bd63f5ab75d 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -229,7 +229,6 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
}
inet_proto_csum_replace4(&th->check, skb,
old, *ptr, false);
- return true;
}
optoff += op[1];
}
--
2.53.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH 3/5 nf-next v4] netfilter: synproxy: fix unaligned memory access in timestamp adjustment
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 1/5 nf-next v4] netfilter: synproxy: drop packets if timestamp adjustment fails Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 2/5 nf-next v4] netfilter: synproxy: adjust duplicate timestamp options Fernando Fernandez Mancera
@ 2026-05-26 21:58 ` Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 4/5 nf-next v4] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock Fernando Fernandez Mancera
` (2 subsequent siblings)
5 siblings, 0 replies; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-26 21:58 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil, Fernando Fernandez Mancera
Use get_unaligned_be32() and put_unaligned_be32() to safely read and
write the timestamp fields. This prevents performance degradation due to
unaligned memory access or even a crash on strict alignment
architectures.
This follows the implementation of timestamp parsing in the networking
stack at tcp_parse_options() and synproxy_parse_options().
Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
net/netfilter/nf_synproxy_core.c | 19 +++++++++----------
1 file changed, 9 insertions(+), 10 deletions(-)
diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index 6bd63f5ab75d..5413133a42fa 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -189,7 +189,7 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
const struct nf_conn_synproxy *synproxy)
{
unsigned int optoff, optend;
- __be32 *ptr, old;
+ u32 new, old;
if (synproxy->tsoff == 0)
return true;
@@ -217,18 +217,17 @@ synproxy_tstamp_adjust(struct sk_buff *skb, unsigned int protoff,
if (op[0] == TCPOPT_TIMESTAMP &&
op[1] == TCPOLEN_TIMESTAMP) {
if (CTINFO2DIR(ctinfo) == IP_CT_DIR_REPLY) {
- ptr = (__be32 *)&op[2];
- old = *ptr;
- *ptr = htonl(ntohl(*ptr) -
- synproxy->tsoff);
+ old = get_unaligned_be32(&op[2]);
+ new = old - synproxy->tsoff;
+ put_unaligned_be32(new, &op[2]);
} else {
- ptr = (__be32 *)&op[6];
- old = *ptr;
- *ptr = htonl(ntohl(*ptr) +
- synproxy->tsoff);
+ old = get_unaligned_be32(&op[6]);
+ new = old + synproxy->tsoff;
+ put_unaligned_be32(new, &op[6]);
}
inet_proto_csum_replace4(&th->check, skb,
- old, *ptr, false);
+ cpu_to_be32(old),
+ cpu_to_be32(new), false);
}
optoff += op[1];
}
--
2.53.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH 4/5 nf-next v4] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
` (2 preceding siblings ...)
2026-05-26 21:58 ` [PATCH 3/5 nf-next v4] netfilter: synproxy: fix unaligned memory access in timestamp adjustment Fernando Fernandez Mancera
@ 2026-05-26 21:58 ` Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 5/5 nf-next v4] netfilter: synproxy: add mutex to guard hook reference counting Fernando Fernandez Mancera
2026-05-27 14:10 ` [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
5 siblings, 0 replies; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-26 21:58 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil, Fernando Fernandez Mancera
nf_ct_seqadj_init() is called without holding the ct lock. This can race
with nf_ct_seq_adjust() when a connection is in CLOSE state due to an
RST or connection reopening. In addition for SYN_RECV state, concurrent
processing of packets can trigger nf_ct_seq_adjust() too. These
situations create a read/write data race.
As synproxy is the only user of nf_ct_seqadj_init() at the moment, fix
this by holding ct->lock inside nf_ct_seqadj_init() until all is done.
Fixes: 48b1de4c110a ("netfilter: add SYNPROXY core/target")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
net/netfilter/nf_conntrack_seqadj.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/netfilter/nf_conntrack_seqadj.c b/net/netfilter/nf_conntrack_seqadj.c
index 7ab2b25b57bc..b7e99f34dfce 100644
--- a/net/netfilter/nf_conntrack_seqadj.c
+++ b/net/netfilter/nf_conntrack_seqadj.c
@@ -17,12 +17,14 @@ int nf_ct_seqadj_init(struct nf_conn *ct, enum ip_conntrack_info ctinfo,
if (off == 0)
return 0;
+ spin_lock_bh(&ct->lock);
set_bit(IPS_SEQ_ADJUST_BIT, &ct->status);
seqadj = nfct_seqadj(ct);
this_way = &seqadj->seq[dir];
this_way->offset_before = off;
this_way->offset_after = off;
+ spin_unlock_bh(&ct->lock);
return 0;
}
EXPORT_SYMBOL_GPL(nf_ct_seqadj_init);
--
2.53.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* [PATCH 5/5 nf-next v4] netfilter: synproxy: add mutex to guard hook reference counting
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
` (3 preceding siblings ...)
2026-05-26 21:58 ` [PATCH 4/5 nf-next v4] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock Fernando Fernandez Mancera
@ 2026-05-26 21:58 ` Fernando Fernandez Mancera
2026-05-27 14:10 ` [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
5 siblings, 0 replies; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-26 21:58 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil, Fernando Fernandez Mancera
As the synproxy infrastructure register netfilter hooks on-demand when a
user adds the first iptables target or nftables expression, if done
concurrently they can race each other.
Introduce a mutex to serialize the refcount control blocks access from
both frontends. While a per namespace mutex might be more efficient, it
is not needed for target/expression like SYNPROXY.
Fixes: ad49d86e07a4 ("netfilter: nf_tables: Add synproxy support")
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
net/netfilter/nf_synproxy_core.c | 24 ++++++++++++++++++------
1 file changed, 18 insertions(+), 6 deletions(-)
diff --git a/net/netfilter/nf_synproxy_core.c b/net/netfilter/nf_synproxy_core.c
index 5413133a42fa..47fe218a112f 100644
--- a/net/netfilter/nf_synproxy_core.c
+++ b/net/netfilter/nf_synproxy_core.c
@@ -22,6 +22,8 @@
#include <net/netfilter/nf_conntrack_zones.h>
#include <net/netfilter/nf_synproxy.h>
+static DEFINE_MUTEX(synproxy_mutex);
+
unsigned int synproxy_net_id;
EXPORT_SYMBOL_GPL(synproxy_net_id);
@@ -767,26 +769,31 @@ static const struct nf_hook_ops ipv4_synproxy_ops[] = {
int nf_synproxy_ipv4_init(struct synproxy_net *snet, struct net *net)
{
- int err;
+ int err = 0;
+ mutex_lock(&synproxy_mutex);
if (snet->hook_ref4 == 0) {
err = nf_register_net_hooks(net, ipv4_synproxy_ops,
ARRAY_SIZE(ipv4_synproxy_ops));
if (err)
- return err;
+ goto out;
}
snet->hook_ref4++;
- return 0;
+out:
+ mutex_unlock(&synproxy_mutex);
+ return err;
}
EXPORT_SYMBOL_GPL(nf_synproxy_ipv4_init);
void nf_synproxy_ipv4_fini(struct synproxy_net *snet, struct net *net)
{
+ mutex_lock(&synproxy_mutex);
snet->hook_ref4--;
if (snet->hook_ref4 == 0)
nf_unregister_net_hooks(net, ipv4_synproxy_ops,
ARRAY_SIZE(ipv4_synproxy_ops));
+ mutex_unlock(&synproxy_mutex);
}
EXPORT_SYMBOL_GPL(nf_synproxy_ipv4_fini);
@@ -1193,27 +1200,32 @@ static const struct nf_hook_ops ipv6_synproxy_ops[] = {
int
nf_synproxy_ipv6_init(struct synproxy_net *snet, struct net *net)
{
- int err;
+ int err = 0;
+ mutex_lock(&synproxy_mutex);
if (snet->hook_ref6 == 0) {
err = nf_register_net_hooks(net, ipv6_synproxy_ops,
ARRAY_SIZE(ipv6_synproxy_ops));
if (err)
- return err;
+ goto out;
}
snet->hook_ref6++;
- return 0;
+out:
+ mutex_unlock(&synproxy_mutex);
+ return err;
}
EXPORT_SYMBOL_GPL(nf_synproxy_ipv6_init);
void
nf_synproxy_ipv6_fini(struct synproxy_net *snet, struct net *net)
{
+ mutex_lock(&synproxy_mutex);
snet->hook_ref6--;
if (snet->hook_ref6 == 0)
nf_unregister_net_hooks(net, ipv6_synproxy_ops,
ARRAY_SIZE(ipv6_synproxy_ops));
+ mutex_unlock(&synproxy_mutex);
}
EXPORT_SYMBOL_GPL(nf_synproxy_ipv6_fini);
#endif /* CONFIG_IPV6 */
--
2.53.0
^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
` (4 preceding siblings ...)
2026-05-26 21:58 ` [PATCH 5/5 nf-next v4] netfilter: synproxy: add mutex to guard hook reference counting Fernando Fernandez Mancera
@ 2026-05-27 14:10 ` Fernando Fernandez Mancera
2026-05-27 22:24 ` Pablo Neira Ayuso
5 siblings, 1 reply; 8+ messages in thread
From: Fernando Fernandez Mancera @ 2026-05-27 14:10 UTC (permalink / raw)
To: netfilter-devel; +Cc: coreteam, pablo, fw, phil
On 5/26/26 11:58 PM, Fernando Fernandez Mancera wrote:
> This series fixes several long standing issues during synproxy timestamp
> adjustment and concurrent hook registration. From ignored error handling
> to unaligned memory access. Most of this are not issues impacting real
> setups as they would have been reported before.
>
> FWIW; I am sending these fixes as separated patches because they are
> addressing independent issues.
>
> Fernando Fernandez Mancera (5):
> netfilter: synproxy: drop packets if timestamp adjustment fails
> netfilter: synproxy: adjust duplicate timestamp options
> netfilter: synproxy: fix unaligned memory access in timestamp
> adjustment
> netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
Sashiko pointed out another issue around nf_ct_seqadj_init() not related
to these patches. Could we get this merged (if it looks good) and the
move forward with a follow-up? I am afraid of pilling up a series that
it is too big.
Any thoughts?
P.S: I am owning the follow-up I just want to reduce the complexity of
getting everything merged together.
> netfilter: synproxy: add mutex to guard hook reference counting
>
> net/netfilter/nf_conntrack_seqadj.c | 2 +
> net/netfilter/nf_synproxy_core.c | 64 ++++++++++++++++++-----------
> 2 files changed, 41 insertions(+), 25 deletions(-)
>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core
2026-05-27 14:10 ` [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
@ 2026-05-27 22:24 ` Pablo Neira Ayuso
0 siblings, 0 replies; 8+ messages in thread
From: Pablo Neira Ayuso @ 2026-05-27 22:24 UTC (permalink / raw)
To: Fernando Fernandez Mancera; +Cc: netfilter-devel, coreteam, fw, phil
On Wed, May 27, 2026 at 04:10:36PM +0200, Fernando Fernandez Mancera wrote:
> On 5/26/26 11:58 PM, Fernando Fernandez Mancera wrote:
> > This series fixes several long standing issues during synproxy timestamp
> > adjustment and concurrent hook registration. From ignored error handling
> > to unaligned memory access. Most of this are not issues impacting real
> > setups as they would have been reported before.
> >
> > FWIW; I am sending these fixes as separated patches because they are
> > addressing independent issues.
> >
> > Fernando Fernandez Mancera (5):
> > netfilter: synproxy: drop packets if timestamp adjustment fails
> > netfilter: synproxy: adjust duplicate timestamp options
> > netfilter: synproxy: fix unaligned memory access in timestamp
> > adjustment
> > netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock
>
> Sashiko pointed out another issue around nf_ct_seqadj_init() not related to
> these patches. Could we get this merged (if it looks good) and the move
> forward with a follow-up? I am afraid of pilling up a series that it is too
> big.
>
> Any thoughts?
>
> P.S: I am owning the follow-up I just want to reduce the complexity of
> getting everything merged together.
Follow up should be fine, thanks Fernando.
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-05-27 22:24 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-05-26 21:58 [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 1/5 nf-next v4] netfilter: synproxy: drop packets if timestamp adjustment fails Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 2/5 nf-next v4] netfilter: synproxy: adjust duplicate timestamp options Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 3/5 nf-next v4] netfilter: synproxy: fix unaligned memory access in timestamp adjustment Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 4/5 nf-next v4] netfilter: synproxy: protect nf_ct_seqadj_init() with conntrack lock Fernando Fernandez Mancera
2026-05-26 21:58 ` [PATCH 5/5 nf-next v4] netfilter: synproxy: add mutex to guard hook reference counting Fernando Fernandez Mancera
2026-05-27 14:10 ` [PATCH 0/5 nf-next v4] netfilter: synproxy: misc fixes about synproxy core Fernando Fernandez Mancera
2026-05-27 22:24 ` Pablo Neira Ayuso
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox