lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <20251030121954.29175-1-fw@strlen.de>
Date: Thu, 30 Oct 2025 13:19:51 +0100
From: Florian Westphal <fw@...len.de>
To: <netdev@...r.kernel.org>
Cc: Paolo Abeni <pabeni@...hat.com>,
	"David S. Miller" <davem@...emloft.net>,
	Eric Dumazet <edumazet@...gle.com>,
	Jakub Kicinski <kuba@...nel.org>,
	<netfilter-devel@...r.kernel.org>,
	pablo@...filter.org
Subject: [PATCH net-next 0/3] netfilter: updates for net-next

Hi,

The following patchset contains Netfilter fixes for *net-next*:

1) Convert nf_tables 'nft_set_iter' usage to use C99 struct
   initialization, from Fernando Fernandez Mancera.
2) Disallow nf_conntrack_max=0.  This was an (undocumented)
   historic inheritance from ip_conntrack (ipv4 only nf_conntrack
   predecessor).  Doing so will simplify future changes to make this
   pernet-tuneable.
3) Fix a typo in conntrack.h comment, from Weibiao Tu.

Please, pull these changes from:
The following changes since commit ea7d0d60ebc9bddf3ad768557dfa1495bc032bf6:

  Merge branch 'add-cn20k-nix-and-npa-contexts' (2025-10-30 10:44:12 +0100)

are available in the Git repository at:

  https://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf-next.git tags/nf-next-25-10-30

for you to fetch changes up to 57347d58a4011551e7d0e030f2f12e4d1a28feb6:

  netfilter: fix typo in nf_conntrack_l4proto.h comment (2025-10-30 12:52:45 +0100)

----------------------------------------------------------------
netfilter pull request nf-next-25-10-30

----------------------------------------------------------------
Fernando Fernandez Mancera (1):
      netfilter: nf_tables: use C99 struct initializer for nft_set_iter

Florian Westphal (1):
      netfilter: conntrack: disable 0 value for conntrack_max setting

caivive (Weibiao Tu) (1):
      netfilter: fix typo in nf_conntrack_l4proto.h comment

 include/net/netfilter/nf_conntrack_l4proto.h |  2 +-
 net/netfilter/nf_conntrack_core.c            |  2 +-
 net/netfilter/nf_conntrack_standalone.c      |  4 ++--
 net/netfilter/nf_tables_api.c                | 34 +++++++++++++---------------
 net/netfilter/nft_lookup.c                   | 13 ++++-------
 5 files changed, 25 insertions(+), 30 deletions(-)
# WARNING: skip 0001-netfilter-nf_tables-use-C99-struct-initializer-for-n.patch, no "Fixes" tag!
# WARNING: skip 0002-netfilter-conntrack-disable-0-value-for-conntrack_ma.patch, no "Fixes" tag!
# WARNING: skip 0003-netfilter-fix-typo-in-nf_conntrack_l4proto.h-comment.patch, no "Fixes" tag!

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ