)]}'
{
  "commit": "855404efae0d449cc491978d54ea5d117a3cb271",
  "tree": "3c44948365a77058d8b1f2ed6e6683bfc52ef256",
  "parents": [
    "a1d4b03a076d95edc88d070f7627a73ab80abddc",
    "82a37132f300ea53bdcd812917af5a6329ec80c3"
  ],
  "author": {
    "name": "David S. Miller",
    "email": "davem@davemloft.net",
    "time": "Sun Jan 05 20:18:50 2014 -0500"
  },
  "committer": {
    "name": "David S. Miller",
    "email": "davem@davemloft.net",
    "time": "Sun Jan 05 20:18:50 2014 -0500"
  },
  "message": "Merge git://git.kernel.org/pub/scm/linux/kernel/git/pablo/nf-next\n\nPablo Neira Ayuso says:\n\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\nnetfilter/IPVS updates for net-next\n\nThe following patchset contains Netfilter updates for your net-next tree,\nthey are:\n\n* Add full port randomization support. Some crazy researchers found a way\n  to reconstruct the secure ephemeral ports that are allocated in random mode\n  by sending off-path bursts of UDP packets to overrun the socket buffer of\n  the DNS resolver to trigger retransmissions, then if the timing for the\n  DNS resolution done by a client is larger than usual, then they conclude\n  that the port that received the burst of UDP packets is the one that was\n  opened. It seems a bit aggressive method to me but it seems to work for\n  them. As a result, Daniel Borkmann and Hannes Frederic Sowa came up with a\n  new NAT mode to fully randomize ports using prandom.\n\n* Add a new classifier to x_tables based on the socket net_cls set via\n  cgroups. These includes two patches to prepare the field as requested by\n  Zefan Li. Also from Daniel Borkmann.\n\n* Use prandom instead of get_random_bytes in several locations of the\n  netfilter code, from Florian Westphal.\n\n* Allow to use the CTA_MARK_MASK in ctnetlink when mangling the conntrack\n  mark, also from Florian Westphal.\n\n* Fix compilation warning due to unused variable in IPVS, from Geert\n  Uytterhoeven.\n\n* Add support for UID/GID via nfnetlink_queue, from Valentina Giusti.\n\n* Add IPComp extension to x_tables, from Fan Du.\n\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\u003d\n\nSigned-off-by: David S. Miller \u003cdavem@davemloft.net\u003e\n",
  "tree_diff": []
}
