At 2017-05-16 17:43:24, "Pablo Neira Ayuso" <pa...@netfilter.org> wrote:
>On Tue, May 16, 2017 at 10:24:00AM +0200, Pablo Neira Ayuso wrote:
>> On Tue, May 16, 2017 at 09:30:18AM +0800, gfree.w...@vip.163.com wrote:
>> > From: Gao Feng <gfree.w...@vip.163.com
At 2017-05-16 00:56:59, "Pablo Neira Ayuso" <pa...@netfilter.org> wrote:
>On Mon, May 15, 2017 at 06:56:02PM +0200, Pablo Neira Ayuso wrote:
>> On Fri, May 12, 2017 at 05:44:10PM +0800, gfree.w...@vip.163.com wrote:
>> > From: Gao Feng <gfree.w...@vip.163.com
Hi Liping,
At 2017-05-05 09:59:06, "Liping Zhang" wrote:
>Hi Feng,
>
>2017-05-05 8:55 GMT+08:00 :
>[...]
>> +static void
>> +nf_ct_flush_expect(const struct module *me)
>> +{
>> + struct nf_conntrack_expect *exp;
>> + const struct
> From: Eric Dumazet [mailto:eric.duma...@gmail.com]
> On Thu, 2017-04-20 at 08:44 +0800, Gao Feng wrote:
> > > On Wed, Apr 19, 2017 at 09:57:55PM +0200, Pablo Neira Ayuso wrote:
> > > > On Wed, Apr 19, 2017 at 09:22:08AM -0700, Eric Dumazet wrote:
> > > &
il.com
> wrote:
> > > > > From: Gao Feng <f...@ikuai8.com>
> > > > >
> > > > > The window scale may be enlarged from 14 to 15 according to the
> > > > > itef draft
https://tools.ietf.org/html/draft-nishida-tcpm-maxwin-03.
> >
Hi Pablo,
> From: netfilter-devel-ow...@vger.kernel.org
> [mailto:netfilter-devel-ow...@vger.kernel.org] On Behalf Of Pablo Neira
> Ayuso
> On Fri, Apr 14, 2017 at 08:46:44AM +0800, Gao Feng wrote:
> > > -Original Message-
> > > From: Pablo Neira Ayuso [mail
> -Original Message-
> From: netfilter-devel-ow...@vger.kernel.org
> On Fri, Apr 14, 2017 at 07:04:44AM +0800, Gao Feng wrote:
> > > -Original Message-
> > > From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> > >
> > > On W
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> On Fri, Apr 14, 2017 at 09:13:40AM +0800, gfree.w...@foxmail.com wrote:
> > From: Gao Feng <f...@ikuai8.com>
> >
> > The function ctnl_untimeout is used to untimeout every conntrack which
> > is using the
> -Original Message-
> From: Liping Zhang [mailto:zlpnob...@gmail.com]
> Hi Pablo,
>
> 2017-04-14 6:30 GMT+08:00 Pablo Neira Ayuso :
> >> We should call module_put when the time policy is not found.
> >> Otherwise, the related cthelper module cannot be removed
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> On Fri, Mar 31, 2017 at 06:38:20PM +0800, gfree.w...@foxmail.com wrote:
> > +static struct nf_ct_nat_helper pptp_nat = {
> > + .name = "pptp_nat",
>
> Why all these with "xyz_nat" names?
I
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
>
> On Wed, Apr 12, 2017 at 10:14:50AM +0800, gfree.w...@foxmail.com wrote:
> >
> > Current SYNPROXY codes return NF_DROP during normal TCP handshaking,
> > it is not friendly to caller. Because the nf_hook_slow
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> On Thu, Apr 06, 2017 at 07:09:09PM +0800, gfree.w...@foxmail.com wrote:
> >
> > The function ctnl_untimeout is used to untimeout every conntrack which
> > is using the timeout. But it is necessary to add one
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Friday, April 14, 2017 5:45 AM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf 1/1] netfilter: seqadj: Fix
Hi Liping,
> -Original Message-
> From: Liping Zhang [mailto:zlpnob...@gmail.com]
> Sent: Thursday, April 13, 2017 11:15 AM
> To: Gao Feng <gfree.w...@foxmail.com>
> Cc: Liping Zhang <zlpnob...@163.com>; Pablo Neira Ayuso
> <pa...@netfilter.org&g
> -Original Message-
> From: Gao Feng [mailto:gfree.w...@foxmail.com]
> Sent: Thursday, April 13, 2017 10:42 AM
> To: 'Liping Zhang' <zlpnob...@163.com>; 'pa...@netfilter.org'
> <pa...@netfilter.org>
> Cc: 'netfilter-devel@vger.kernel.org' <netfilter
Hi Liping,
> -Original Message-
> From: netfilter-devel-ow...@vger.kernel.org
> [mailto:netfilter-devel-ow...@vger.kernel.org] On Behalf Of Liping Zhang
> Sent: Wednesday, April 12, 2017 11:57 PM
> To: pa...@netfilter.org
> Cc: netfilter-devel@vger.kernel.org; cerne...@chromium.org;
Hi Pablo,
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Monday, April 10, 2017 8:07 PM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf 1/1] netfilter:
> -Original Message-
> From: Gao Feng [mailto:gfree.w...@foxmail.com]
> Sent: Friday, April 7, 2017 6:16 AM
> To: 'Pablo Neira Ayuso' <pa...@netfilter.org>
> Cc: 'netfilter-devel@vger.kernel.org' <netfilter-devel@vger.kernel.org>;
'Gao
> Feng' <f...@iku
Hi Pablo,
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Friday, April 7, 2017 3:55 AM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf-next 1/1] netfilt
Hi Palbo,
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Friday, April 7, 2017 3:25 AM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf-next v2 1/1]
> -Original Message-
> From: kbuild test robot [mailto:l...@intel.com]
> Sent: Thursday, April 6, 2017 4:01 AM
> To: gfree.w...@foxmail.com
> Cc: kbuild-...@01.org; pa...@netfilter.org;
netfilter-devel@vger.kernel.org;
> Gao Feng <f...@ikuai8.com>
> Subj
Hi Florian,
> -Original Message-
> From: Florian Westphal [mailto:f...@strlen.de]
> Sent: Wednesday, April 5, 2017 9:17 PM
> To: gfree.w...@foxmail.com
> Cc: pa...@netfilter.org; netfilter-devel@vger.kernel.org; Gao Feng
> <f...@ikuai8.com>
> Subject: Re: [P
Hi,
> -Original Message-
> From: gfree.w...@foxmail.com [mailto:gfree.w...@foxmail.com]
> Sent: Wednesday, April 5, 2017 9:23 AM
> To: pa...@netfilter.org; netfilter-devel@vger.kernel.org
> Cc: Gao Feng <f...@ikuai8.com>
> Subject: [PATCH nf-next 1/1] net
Hi Pablo,
> -Original Message-
> From: netfilter-devel-ow...@vger.kernel.org
> [mailto:netfilter-devel-ow...@vger.kernel.org] On Behalf Of Pablo Neira
Ayuso
> Sent: Wednesday, March 29, 2017 5:54 PM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao
Hi Pablo,
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Wednesday, March 29, 2017 6:44 PM
> To: Gao Feng <gfree.w...@foxmail.com>
> Cc: netfilter-devel@vger.kernel.org; 'Gao Feng' <f...@ikuai8.com>
> Subject: Re: [P
Hi Pablo,
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Wednesday, March 29, 2017 6:08 PM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf-next v2 1/1] n
g;
netfilter-devel@vger.kernel.org;
> gfree.w...@foxmail.com; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf v4 1/1] netfilter: snmp: Fix one possible panic
when
> snmp_trap_helper fail to register
>
> Hi Gao,
>
> [auto build test WARNING on nf/master]
>
> url:
&g
; Subject: Re: [PATCH nf-next 1/1] netfilter: Use bool type instead of int
as the
> return value of nf_conntrack_tuple_taken and nf_nat_used_tuple
>
> On Tue, Mar 07, 2017 at 12:28:55PM +0800, f...@ikuai8.com wrote:
> > From: Gao Feng <f...@ikuai8.com>
> >
> &g
value
> comparison of the func nf_nat_mangle_udp_packet
>
> On Fri, Mar 17, 2017 at 02:47:19PM +0800, f...@ikuai8.com wrote:
> > From: Gao Feng <f...@ikuai8.com>
> >
> > The return value of nf_nat_mangle_udp_packet actually is 1 and 0 as
> > bool type. But the a
Hi Liping,
> -Original Message-
> From: Liping Zhang [mailto:zlpnob...@gmail.com]
> Sent: Saturday, March 25, 2017 4:17 PM
> To: gfree.w...@foxmail.com
> Cc: Pablo Neira Ayuso <pa...@netfilter.org>; Netfilter Developer Mailing List
> <netfilter-devel@vg
ubject: Re: [PATCH nf v3 1/1] netfilter: snmp: Fix one possible panic
when
> snmp_trap_helper fail to register
>
> On Tue, Mar 21, 2017 at 08:22:29AM +0800, f...@ikuai8.com wrote:
> > From: Gao Feng <f...@ikuai8.com>
> >
> > In the commit 93557f53e1fb (
Hi Pablo,
> -Original Message-
> From: Pablo Neira Ayuso [mailto:pa...@netfilter.org]
> Sent: Friday, March 24, 2017 7:43 PM
> To: gfree.w...@foxmail.com
> Cc: netfilter-devel@vger.kernel.org; Gao Feng <f...@ikuai8.com>
> Subject: Re: [PATCH nf 1/1] netf
, 2017 at 08:22:29AM +0800, f...@ikuai8.com wrote:
> > > From: Gao Feng <f...@ikuai8.com>
> > >
> > > In the commit 93557f53e1fb ("netfilter: nf_conntrack: nf_conntrack
> > > snmp helper"), the snmp_helper is replaced by nf_nat_snmp_hook. So
> &
Hi Pablo,
> -Original Message-
> From: netfilter-devel-ow...@vger.kernel.org
> [mailto:netfilter-devel-ow...@vger.kernel.org] On Behalf Of Gao Feng
> Sent: Wednesday, March 22, 2017 9:37 AM
> To: pa...@netfilter.org; netfilter-devel@vger.kernel.org
> Cc: 'Gao Feng
nel.org;
> gfree.w...@foxmail.com
> Cc: Gao Feng <f...@ikuai8.com>
> Subject: [PATCH RESENT nf 1/1] netfilter: ctlink: Fix one possible
use-after-free
> in ctnetlink_create_expect
>
> From: Gao Feng <f...@ikuai8.com>
>
> There is no rcu_read_lock during ctlink gets the
@126.com
> Subject: Re: [PATCH nf v3 2/2] netfilter: helper: Fix possible panic
caused by
> invoking expectfn unloaded
>
> On Tue, Mar 21, 2017 at 02:06:26PM +0800, f...@ikuai8.com wrote:
> > From: Gao Feng <f...@ikuai8.com>
> >
> > Because the conntrack NAT module
On Mon, Mar 20, 2017 at 9:11 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Mon, Mar 20, 2017 at 09:06:22PM +0800, Gao Feng wrote:
>> On Mon, Mar 20, 2017 at 8:50 PM, Pablo Neira Ayuso <pa...@netfilter.org>
>> wrote:
>> > On Mon, Mar 20, 2017 at 11:44
On Mon, Mar 20, 2017 at 8:50 PM, Pablo Neira Ayuso wrote:
> On Mon, Mar 20, 2017 at 11:44:42AM +0100, Pablo Neira Ayuso wrote:
>> > diff --git a/net/netfilter/nf_conntrack_helper.c
>> > b/net/netfilter/nf_conntrack_helper.c
>> > index 6dc44d9..6c840af 100644
>> > ---
On Mon, Mar 20, 2017 at 6:44 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Sat, Mar 18, 2017 at 03:40:45PM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> The helper module could register one helper expectfn by the function
>&g
Hi Pablo,
On Fri, Mar 17, 2017 at 10:09 PM, Gao Feng <f...@ikuai8.com> wrote:
> Hi Pablo,
>
> On Fri, Mar 17, 2017 at 9:08 PM, Pablo Neira Ayuso <pa...@netfilter.org>
> wrote:
>> On Tue, Mar 14, 2017 at 02:26:06PM +0800, f...@ikuai8.com wrote:
>&
Hi Pablo,
On Fri, Mar 17, 2017 at 9:08 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Tue, Mar 14, 2017 at 02:26:06PM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> The helper module permits the helper modules register
Hi Pablo,
On Wed, Mar 15, 2017 at 9:07 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Tue, Mar 14, 2017 at 02:26:06PM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> The helper module permits the helper modules register
Hi Pablo,
On Fri, Mar 3, 2017 at 5:30 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Fri, Mar 03, 2017 at 09:58:52AM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> When memory is exhausted, nf_ct_nat_ext_add may re
Hi Liping,
On Thu, Mar 2, 2017 at 7:18 PM, Liping Zhang <zlpnob...@gmail.com> wrote:
> Hi,
> 2017-03-02 18:18 GMT+08:00 Gao Feng <f...@ikuai8.com>:
> [...]
>> The expect class is NF_CT_EXPECT_CLASS_DEFAULT, and proto is
>> IPPROTO_UDP at the function "
Hi Pablo,
On Thu, Jan 12, 2017 at 7:11 PM, Pablo Neira Ayuso wrote:
> On Thu, Jan 12, 2017 at 06:37:54PM +0800, f...@ikuai8.com wrote:
>> From: Feng
>>
>> The rcu lock protect is added 3 years ago with the commit
>> e688a7f8c6cb7a18aae7e55ccdd175f0ad9e69c0.
Hi Pablo,
On Thu, Jan 12, 2017 at 7:21 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Wed, Jan 11, 2017 at 09:32:15AM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> The return value of nf_tables_table_lookup is valid pointer or on
On Fri, Nov 25, 2016 at 12:11 PM, Eric Dumazet <eric.duma...@gmail.com> wrote:
> On Fri, 2016-11-25 at 11:58 +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> I lost one test case in the commit for xt_multiport.
>> For example, the r
Hi Liping,
On Tue, Sep 27, 2016 at 1:49 PM, Liping Zhang <zlpnob...@gmail.com> wrote:
> Hi Feng,
>
> 2016-09-27 12:39 GMT+08:00 <f...@ikuai8.com>:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> Current xt_osf codes use memcmp to check if two user fingers
On Tue, Sep 27, 2016 at 8:39 AM, Florian Westphal <f...@strlen.de> wrote:
> Gao Feng <f...@ikuai8.com> wrote:
>> >> diff --git a/net/netfilter/xt_nfacct.c b/net/netfilter/xt_nfacct.c
>> >> index cf32759..7abb5b5 100644
>> >> --- a/net/netfilte
Hi Florian,
On Mon, Sep 26, 2016 at 11:17 PM, Florian Westphal wrote:
> f...@ikuai8.com wrote:
>> 1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/net/netfilter/xt_nfacct.c b/net/netfilter/xt_nfacct.c
>> index cf32759..7abb5b5 100644
>> ---
Hi Pablo,
On Tue, Sep 6, 2016 at 10:54 PM, Gao Feng <f...@ikuai8.com> wrote:
> inline
>
> On Tue, Sep 6, 2016 at 10:51 PM, Florian Westphal <f...@strlen.de> wrote:
>> f...@ikuai8.com <f...@ikuai8.com> wrote:
>>> From: Gao Feng <f...
Hi Pablo,
On Tue, Sep 6, 2016 at 6:17 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Tue, Sep 06, 2016 at 09:57:23AM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> When memory is exhausted, nfct_seqadj_ext_add may fa
inline
On Tue, Sep 6, 2016 at 10:51 PM, Florian Westphal <f...@strlen.de> wrote:
> f...@ikuai8.com <f...@ikuai8.com> wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> When memory is exhausted, nfct_seqadj_ext_add may fail to add the seqadj
>> extensio
inline
On Tue, Sep 6, 2016 at 6:17 PM, Pablo Neira Ayuso <pa...@netfilter.org> wrote:
> On Tue, Sep 06, 2016 at 09:57:23AM +0800, f...@ikuai8.com wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> When memory is exhausted, nfct_seqadj_ext_add may fa
Hi Florian,
On Fri, Sep 2, 2016 at 2:59 PM, Florian Westphal <f...@strlen.de> wrote:
> f...@ikuai8.com <f...@ikuai8.com> wrote:
>> From: Gao Feng <f...@ikuai8.com>
>>
>> When memory is exhausted, nfct_seqadj_ext_add may fail to add the seqadj
>>
55 matches
Mail list logo