summaryrefslogtreecommitdiff
path: root/net/netfilter/xt_socket.c
AgeCommit message (Expand)AuthorFilesLines
2022-02-13netfilter: xt_socket: missing ifdef CONFIG_IP6_NF_IPTABLES dependencyPablo Neira Ayuso1-0/+2
2022-02-09netfilter: xt_socket: fix a typo in socket_mt_destroy()Eric Dumazet1-1/+1
2021-04-26netfilter: disable defrag once its no longer neededFlorian Westphal1-0/+14
2019-06-19treewide: Replace GPLv2 boilerplate/reference with SPDX - rule 500Thomas Gleixner1-5/+1
2018-09-28netfilter: xt_socket: check sk before checking for netns.Flavio Leitner1-2/+2
2018-06-28netfilter: check if the socket netns is correct.Flavio Leitner1-0/+8
2018-06-03netfilter: Decrease code duplication regarding transparent socket optionMáté Eckl1-2/+2
2018-02-14netfilter: x_tables: use pr ratelimiting in all remaining spotsFlorian Westphal1-4/+6
2017-09-26netfilter: xt_socket: Restore mark from full sockets onlySubash Abhinov Kasiviswanathan1-2/+2
2017-04-24netfilter: xt_socket: Fix broken IPv6 handlingPeter Tirsek1-1/+1
2016-12-06netfilter: defrag: only register defrag functionality if neededFlorian Westphal1-5/+28
2016-11-03netfilter: x_tables: move hook state into xt_action_param structurePablo Neira Ayuso1-2/+2
2016-11-01netfilter: move socket lookup infrastructure to nf_socket_ipv{4,6}.cPablo Neira Ayuso1-295/+10
2016-04-04tcp/dccp: do not touch listener sk_refcnt under synfloodEric Dumazet1-3/+3
2016-02-11inet: refactor inet[6]_lookup functions to take skbCraig Gallek1-7/+21
2015-09-18netfilter: x_tables: Use par->net instead of computing from the passed net de...Eric W. Biederman1-6/+8
2015-06-18netfilter: xt_socket: add XT_SOCKET_RESTORESKMARK flagHarout Hedeshian1-6/+53
2015-04-08netfilter: x_tables: don't extract flow keys on early demuxed sks in socket m...Daniel Borkmann1-45/+50
2015-03-17netfilter: xt_socket: prepare for TCP_NEW_SYN_RECV supportEric Dumazet1-12/+22
2015-02-16netfilter: xt_socket: fix a stack corruption bugEric Dumazet1-9/+12
2013-10-17netfilter: xt_socket: use sock_gen_put()Eric Dumazet1-11/+2
2013-10-09ipv6: make lookups simpler and fasterEric Dumazet1-1/+1
2013-08-20Merge branch 'master' of git://git.kernel.org/pub/scm/linux/kernel/git/pablo/...David S. Miller1-5/+61
2013-07-31netfilter: tproxy: remove nf_tproxy_core.hFlorian Westphal1-5/+61
2013-07-15netfilter: xt_socket: fix broken v0 supportEric Dumazet1-3/+7
2013-06-20netfilter: xt_socket: add XT_SOCKET_NOWILDCARD flagEric Dumazet1-8/+62
2013-05-23netfilter: xt_socket: use IP early demuxEric Dumazet1-10/+16
2012-09-03netfilter: xt_socket: fix compilation warnings with gcc 4.7Pablo Neira Ayuso1-6/+6
2012-05-09netfilter: ip6_tables: add flags parameter to ipv6_find_hdr()Hans Schillstrom1-2/+2
2011-12-16net:netfilter: use IS_ENABLEDIgor Maravić1-2/+2
2011-12-03ipv6: Add fragment reporting to ipv6_skip_exthdr().Jesse Gross1-1/+3
2011-06-06netfilter: add more values to enum ip_conntrack_infoEric Dumazet1-2/+2
2011-02-17netfilter: tproxy: do not assign timewait sockets to skb->skFlorian Westphal1-2/+11
2010-10-28netfilter: xt_socket: Make tproto signed in socket_mt6_v1().David S. Miller1-4/+3
2010-10-25netfilter: fix module dependency issues with IPv6 defragmentation, ip6tables ...KOVACS Krisztian1-4/+8
2010-10-21tproxy: added IPv6 support to the socket matchBalazs Scheidler1-11/+154
2010-10-21tproxy: kick out TIME_WAIT sockets in case a new connection comes in with the...Balazs Scheidler1-1/+1
2010-06-08netfilter: nf_conntrack: IPS_UNTRACKED bitEric Dumazet1-1/+1
2010-05-11netfilter: xtables: deconstify struct xt_action_param for matchesJan Engelhardt1-3/+3
2010-05-11netfilter: xtables: substitute temporary defines by final nameJan Engelhardt1-3/+3
2010-03-25netfilter: xt extensions: use pr_<level> (2)Jan Engelhardt1-3/+2
2009-10-29netfilter: xt_socket: make module available for INPUT chainJan Engelhardt1-2/+4
2009-10-18inet: rename some inet_sock fieldsEric Dumazet1-1/+1
2009-06-09netfilter: xt_socket: added new revision of the 'socket' match supporting flagsLaszlo Attila Toth1-11/+52
2008-12-07tproxy: fixe a possible read from an invalid location in the socket matchBalazs Scheidler1-1/+1
2008-10-08netfilter: xtables: move extension arguments into compound structure (1/6)Jan Engelhardt1-9/+2
2008-10-08netfilter: iptables socket matchKOVACS Krisztian1-0/+192