get:
Show a patch.

patch:
Update a patch.

put:
Update a patch.

GET /api/1.1/patches/2230383/?format=api
HTTP 200 OK
Allow: GET, PUT, PATCH, HEAD, OPTIONS
Content-Type: application/json
Vary: Accept

{
    "id": 2230383,
    "url": "http://patchwork.ozlabs.org/api/1.1/patches/2230383/?format=api",
    "web_url": "http://patchwork.ozlabs.org/project/netfilter-devel/patch/20260429175613.1459342-2-tristmd@gmail.com/",
    "project": {
        "id": 26,
        "url": "http://patchwork.ozlabs.org/api/1.1/projects/26/?format=api",
        "name": "Netfilter Development",
        "link_name": "netfilter-devel",
        "list_id": "netfilter-devel.vger.kernel.org",
        "list_email": "netfilter-devel@vger.kernel.org",
        "web_url": null,
        "scm_url": null,
        "webscm_url": null
    },
    "msgid": "<20260429175613.1459342-2-tristmd@gmail.com>",
    "date": "2026-04-29T17:56:11",
    "name": "[1/2] netfilter: ip_tables: allocate hook ops before making table visible",
    "commit_ref": null,
    "pull_url": null,
    "state": "new",
    "archived": false,
    "hash": "08ca479003f7f9248a8869f634b056e89c23fdba",
    "submitter": {
        "id": 93179,
        "url": "http://patchwork.ozlabs.org/api/1.1/people/93179/?format=api",
        "name": "Tristan Madani",
        "email": "tristmd@gmail.com"
    },
    "delegate": null,
    "mbox": "http://patchwork.ozlabs.org/project/netfilter-devel/patch/20260429175613.1459342-2-tristmd@gmail.com/mbox/",
    "series": [
        {
            "id": 502119,
            "url": "http://patchwork.ozlabs.org/api/1.1/series/502119/?format=api",
            "web_url": "http://patchwork.ozlabs.org/project/netfilter-devel/list/?series=502119",
            "date": "2026-04-29T17:56:10",
            "name": "netfilter: fix NULL ops race in iptable lazy init",
            "version": 1,
            "mbox": "http://patchwork.ozlabs.org/series/502119/mbox/"
        }
    ],
    "comments": "http://patchwork.ozlabs.org/api/patches/2230383/comments/",
    "check": "pending",
    "checks": "http://patchwork.ozlabs.org/api/patches/2230383/checks/",
    "tags": {},
    "headers": {
        "Return-Path": "\n <netfilter-devel+bounces-12302-incoming=patchwork.ozlabs.org@vger.kernel.org>",
        "X-Original-To": [
            "incoming@patchwork.ozlabs.org",
            "netfilter-devel@vger.kernel.org"
        ],
        "Delivered-To": "patchwork-incoming@legolas.ozlabs.org",
        "Authentication-Results": [
            "legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256\n header.s=20251104 header.b=jYQAlbJM;\n\tdkim-atps=neutral",
            "legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=vger.kernel.org\n (client-ip=2600:3c15:e001:75::12fc:5321; helo=sin.lore.kernel.org;\n envelope-from=netfilter-devel+bounces-12302-incoming=patchwork.ozlabs.org@vger.kernel.org;\n receiver=patchwork.ozlabs.org)",
            "smtp.subspace.kernel.org;\n\tdkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=\"jYQAlbJM\"",
            "smtp.subspace.kernel.org;\n arc=none smtp.client-ip=209.85.128.45",
            "smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com",
            "smtp.subspace.kernel.org;\n spf=pass smtp.mailfrom=gmail.com"
        ],
        "Received": [
            "from sin.lore.kernel.org (sin.lore.kernel.org\n [IPv6:2600:3c15:e001:75::12fc:5321])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519 server-signature ECDSA (secp384r1) server-digest SHA384)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4g5Q4R3kKKz1yK5\n\tfor <incoming@patchwork.ozlabs.org>; Thu, 30 Apr 2026 03:57:27 +1000 (AEST)",
            "from smtp.subspace.kernel.org (conduit.subspace.kernel.org\n [100.90.174.1])\n\tby sin.lore.kernel.org (Postfix) with ESMTP id EA24830131BD\n\tfor <incoming@patchwork.ozlabs.org>; Wed, 29 Apr 2026 17:56:36 +0000 (UTC)",
            "from localhost.localdomain (localhost.localdomain [127.0.0.1])\n\tby smtp.subspace.kernel.org (Postfix) with ESMTP id 2842D41C2F5;\n\tWed, 29 Apr 2026 17:56:20 +0000 (UTC)",
            "from mail-wm1-f45.google.com (mail-wm1-f45.google.com\n [209.85.128.45])\n\t(using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))\n\t(No client certificate requested)\n\tby smtp.subspace.kernel.org (Postfix) with ESMTPS id 5C0A43B961D\n\tfor <netfilter-devel@vger.kernel.org>; Wed, 29 Apr 2026 17:56:17 +0000 (UTC)",
            "by mail-wm1-f45.google.com with SMTP id\n 5b1f17b1804b1-483487335c2so308635e9.2\n        for <netfilter-devel@vger.kernel.org>;\n Wed, 29 Apr 2026 10:56:17 -0700 (PDT)",
            "from debian.. ([2001:41d0:303:db6b::])\n        by smtp.gmail.com with ESMTPSA id\n ffacd0b85a97d-447b3d48517sm6183750f8f.5.2026.04.29.10.56.14\n        (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);\n        Wed, 29 Apr 2026 10:56:14 -0700 (PDT)"
        ],
        "ARC-Seal": "i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116;\n\tt=1777485379; cv=none;\n b=SJQc3h1kQJ4/1fydCHUl4H2cfTAKJCJzUq9HipkKeurIjQ/dBAj5UY4OEaBHijiMIuqvb2DTkGCL0EWMBOA1t2PMwLkm1rLjGsULbLdD3JHnfzAoAxrO5PwkrkJhDYjlbNhqJmH7fOqk2/QmYCsRamXlQa9SPufJPbISAilboEg=",
        "ARC-Message-Signature": "i=1; a=rsa-sha256; d=subspace.kernel.org;\n\ts=arc-20240116; t=1777485379; c=relaxed/simple;\n\tbh=eDBirYq4pCbL+nEUiEp7cl5+N06I9yeNRMJUvi0dUZs=;\n\th=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References:\n\t MIME-Version;\n b=gE31Z0K3UsqPV/DKu+zeukwFoMnQkqvzoB5u5pnIPO5eEtSPQp0FP4VtWzmjQS1psLHitm784z2GXVXbnKVdfGWmBFEsG4N5JvtYcB/R1BnID29Uoa5XdqT2DThZRA+0LhE+KSI7E2sTdi0rOpaXYT0/ceCvWQIwMLj1yiNPW5E=",
        "ARC-Authentication-Results": "i=1; smtp.subspace.kernel.org;\n dmarc=pass (p=none dis=none) header.from=gmail.com;\n spf=pass smtp.mailfrom=gmail.com;\n dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com\n header.b=jYQAlbJM; arc=none smtp.client-ip=209.85.128.45",
        "DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=gmail.com; s=20251104; t=1777485376; x=1778090176;\n darn=vger.kernel.org;\n        h=content-transfer-encoding:mime-version:references:in-reply-to\n         :message-id:date:subject:cc:to:from:from:to:cc:subject:date\n         :message-id:reply-to;\n        bh=ZAVLe7MO2A1MyrDF6a2t4MvPRiDZqS4DmH+U/JOcnYM=;\n        b=jYQAlbJMAUmgBX14wyxFlZBhXAKj3S+TKPLSDiohw7yy20edVzYsqczSigBf0J6CcC\n         ktDQiI+MWNeYMkIasiq6Qa6I8khKvtNF5t2q33GMs9LFFsuSvZuUIy88OuGlTYUP4IkD\n         WPkh/d+tsh2lw6msVv4Q+TiPhfofGlpslXAeSx/2MpTgu6SLSRqstfmuT/4zkVjdmJOL\n         FOo889lSGnqyx97fziO/SI+wjyWY2ZOWYsmPwZ9UTjf4w/BYKexvsrhONblzXMIHeHEd\n         FmQL/73zTpBwt2H6vWHOIHk9wYs0vqoo7ffG7R2+fu40Cx1svYsuGwplU06b9E4pzZCy\n         uO4g==",
        "X-Google-DKIM-Signature": "v=1; a=rsa-sha256; c=relaxed/relaxed;\n        d=1e100.net; s=20251104; t=1777485376; x=1778090176;\n        h=content-transfer-encoding:mime-version:references:in-reply-to\n         :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from\n         :to:cc:subject:date:message-id:reply-to;\n        bh=ZAVLe7MO2A1MyrDF6a2t4MvPRiDZqS4DmH+U/JOcnYM=;\n        b=YzCd9kQ0iqkn0gv+G6kA5rRHPC5KPFkAyI8fXj89NBqlV4QpNLMKlxhmwEOobiZm9M\n         uTgjz8W7d+6N/zrp0jOoXY0VB73dm9Bm11wuLeW12oXjMwCINpJ6oXSOBjNZijm0w0XD\n         XPeLVkXoSxcOKxUow302BvCfDPWt90fvM+tVc0Eqgy7cTRT7WICSkZFI4rMYyfC4xKds\n         2zvvNzhH3FhmJWfp8ks9xx5PaBbxLdg770b56N2qTkKv2v3vxuvmAdVum7bJ8S/r5/4p\n         KaUOw/rjJJSg0DbuL1NNmyiZXFBt0Rp0JORIEFDHxlSuvs//CdB5SCaMfFo+VkiXXr+/\n         0tyQ==",
        "X-Forwarded-Encrypted": "i=1;\n AFNElJ8RmU5W7F8y1Tdl5jU6+N9imzDUXcrrZMkeYvUmpuX5RiiNHPhR4V2DEV+brbmEsqXNXyJVvVY16hsN9qiONyM=@vger.kernel.org",
        "X-Gm-Message-State": "AOJu0Yw/TlCcQNgRS4f06Ul7s/zuqLOOGAjL1aeec8Bf4T3VEtZhHuQC\n\tEbiSBrq4kULkxyctpyKLpyuK3LjTJuekHku4gCqEV6BPmVKTQneZy/u1S8Nq",
        "X-Gm-Gg": "AeBDietFomk/62++6Imfm7hL7dYjp6TaQQDBvZwDv0YKzyU2P748jyaRRxAOBPSI3zv\n\trsiztbu424q/lX+jziievEDI8HXvHHVaJu9kJeyIvu76aBkJ62KCp5N43OEIaq8isHw5MSR4qoL\n\tuUX/0Ga5fa7OVjJiqIcCg5si0+6L8TrMUcH6LfgXAyKDUVwwMdH2iUR53ZrO+hpyTIIC3yYVrl7\n\t5LkWRbq9i54tYrgvsMyrUj0w2pndhcTut6oE+OvxFT4yYBnF453ceNS5NoWdSyr2SnwzG1AdHpE\n\tye1f8cgEigCnM3Xnsy0Fs3I/8uS+89iEf6NhvzYUGjC+IOkD62HK73E3m3lnBp65hwI2Z9to683\n\txbcAjVRVIVhjFzVUlNw9mmuTjvwj8kwY6Nlsaq2wo/5rkEk3qNvFFaxBcSnhSzkT1W70+BPaZox\n\tEttSM=",
        "X-Received": "by 2002:a05:600c:c048:b0:485:39b2:a47c with SMTP id\n 5b1f17b1804b1-48a77b22dedmr99590625e9.25.1777485375550;\n        Wed, 29 Apr 2026 10:56:15 -0700 (PDT)",
        "From": "Tristan Madani <tristmd@gmail.com>",
        "To": "Pablo Neira Ayuso <pablo@netfilter.org>",
        "Cc": "Florian Westphal <fw@strlen.de>,\n\tPhil Sutter <phil@nwl.cc>,\n\tnetfilter-devel@vger.kernel.org,\n\tnetdev@vger.kernel.org,\n\tstable@vger.kernel.org,\n\tlinux-kernel@vger.kernel.org,\n\tTristan Madani <tristan@talencesecurity.com>",
        "Subject": "[PATCH 1/2] netfilter: ip_tables: allocate hook ops before making\n table visible",
        "Date": "Wed, 29 Apr 2026 17:56:11 +0000",
        "Message-ID": "<20260429175613.1459342-2-tristmd@gmail.com>",
        "X-Mailer": "git-send-email 2.47.3",
        "In-Reply-To": "<20260429175613.1459342-1-tristmd@gmail.com>",
        "References": "<20260429175613.1459342-1-tristmd@gmail.com>",
        "Precedence": "bulk",
        "X-Mailing-List": "netfilter-devel@vger.kernel.org",
        "List-Id": "<netfilter-devel.vger.kernel.org>",
        "List-Subscribe": "<mailto:netfilter-devel+subscribe@vger.kernel.org>",
        "List-Unsubscribe": "<mailto:netfilter-devel+unsubscribe@vger.kernel.org>",
        "MIME-Version": "1.0",
        "Content-Transfer-Encoding": "8bit"
    },
    "content": "From: Tristan Madani <tristan@talencesecurity.com>\n\nipt_register_table() adds the table to the per-netns list via\nxt_register_table() before allocating the per-netns hook ops copy\nvia kmemdup_array().  This leaves a window where the table is\nvisible in the list with ops=NULL.\n\nIf cleanup_net() runs during this window (e.g. due to concurrent\nnetns teardown with failslab-induced allocation failures), the\npre_exit callback finds the table via xt_find_table() and passes\nthe NULL ops pointer to nf_unregister_net_hooks(), causing a NULL\npointer dereference:\n\n  general protection fault in nf_unregister_net_hooks+0xbc/0x150\n  RIP: nf_unregister_net_hooks (net/netfilter/core.c:613)\n  Call Trace:\n    ipt_unregister_table_pre_exit\n    iptable_mangle_net_pre_exit\n    ops_pre_exit_list\n    cleanup_net\n\nFix by moving the ops allocation before xt_register_table() so\nthe table is never in the list without valid ops.\n\nFixes: ae689334225f (\"netfilter: ip_tables: pass table pointer via nf_hook_ops\")\nCc: stable@vger.kernel.org\nSigned-off-by: Tristan Madani <tristan@talencesecurity.com>\n---\n net/ipv4/netfilter/ip_tables.c | 31 ++++++++++++++++---------------\n 1 file changed, 16 insertions(+), 15 deletions(-)",
    "diff": "diff --git a/net/ipv4/netfilter/ip_tables.c b/net/ipv4/netfilter/ip_tables.c\nindex 23c8deff8095a..c47bc776eb4f2 100644\n--- a/net/ipv4/netfilter/ip_tables.c\n+++ b/net/ipv4/netfilter/ip_tables.c\n@@ -1745,6 +1745,21 @@ int ipt_register_table(struct net *net, const struct xt_table *table,\n \t\treturn ret;\n \t}\n \n+\tif (template_ops) {\n+\t\tnum_ops = hweight32(table->valid_hooks);\n+\t\tif (num_ops == 0) {\n+\t\t\txt_free_table_info(newinfo);\n+\t\t\treturn -EINVAL;\n+\t\t}\n+\n+\t\tops = kmemdup_array(template_ops, num_ops, sizeof(*ops),\n+\t\t\t\t    GFP_KERNEL);\n+\t\tif (!ops) {\n+\t\t\txt_free_table_info(newinfo);\n+\t\t\treturn -ENOMEM;\n+\t\t}\n+\t}\n+\n \tnew_table = xt_register_table(net, table, &bootstrap, newinfo);\n \tif (IS_ERR(new_table)) {\n \t\tstruct ipt_entry *iter;\n@@ -1752,27 +1767,13 @@ int ipt_register_table(struct net *net, const struct xt_table *table,\n \t\txt_entry_foreach(iter, loc_cpu_entry, newinfo->size)\n \t\t\tcleanup_entry(iter, net);\n \t\txt_free_table_info(newinfo);\n+\t\tkfree(ops);\n \t\treturn PTR_ERR(new_table);\n \t}\n \n-\t/* No template? No need to do anything. This is used by 'nat' table, it registers\n-\t * with the nat core instead of the netfilter core.\n-\t */\n \tif (!template_ops)\n \t\treturn 0;\n \n-\tnum_ops = hweight32(table->valid_hooks);\n-\tif (num_ops == 0) {\n-\t\tret = -EINVAL;\n-\t\tgoto out_free;\n-\t}\n-\n-\tops = kmemdup_array(template_ops, num_ops, sizeof(*ops), GFP_KERNEL);\n-\tif (!ops) {\n-\t\tret = -ENOMEM;\n-\t\tgoto out_free;\n-\t}\n-\n \tfor (i = 0; i < num_ops; i++)\n \t\tops[i].priv = new_table;\n \n",
    "prefixes": [
        "1/2"
    ]
}