Toggle navigation
Patchwork
Netfilter Development
Patches
Bundles
About this project
Login
Register
Mail settings
Show patches with
: none
| 30066 patches
Series
Submitter
State
any
Action Required
New
Under Review
Accepted
Rejected
RFC
Not Applicable
Changes Requested
Awaiting Upstream
Superseded
Deferred
Needs Review / ACK
Handled Elsewhere
Search
Archived
No
Yes
Both
Delegate
------
Nobody
jgarzik
arnd
ymano
smfrench
jlayton
tseliot
ogasawara
amitk
awhitcroft
mst
dayangkun
jwboyer
jwboyer
colinking
colinking
azummo
dwmw2
rtg
sconklin
smb
aliguori
bradf
galak
galak
demarchi
ms
bhundven
chbs
kengyu
kadlec
pdp
regit
jabk
laforge
laforge
tonyb
sfr
alai
zecke
zecke
__damien__
luka
luka
prafulla@marvell.com
cyrus
PeterHuewe
kiho
jow
jow
ypwong
nico
dedeckeh
dedeckeh
yousong
yousong
tomcwarren
mb
mrchuck
vineetg76
computersforpeace
Noltari
Noltari
patrick_delaunay
ee07b291
ldir
ldir
stefanct
zhouhan
carldani
blp
ffainelli
ffainelli
regXboi
bbrezillon
pravin
mkp
jpettit
phil
mkresin
mkresin
thess
thess
fbarrat
fbarrat
linville
jesse
tjaalton
esben
abrodkin
abrodkin
diproiettod
tbot
stephenfin
vriera
darball1
sammj
ajd
jogo
jogo
bhelgaas
blogic
blogic
tagr
tagr
tagr
oohal
russellb
ptomsich
agraf
joestringer
davem
davem
davem
mwalle
naveen
pchotard
pepe2k
pepe2k
arj
arj
andmur01
amitay
matttbe
pabeni
istokes
aparcar
Ansuel
goliath
martineau
tytso
danielschwierzeck
mkorpershoek
mariosix
dcaratti
ovsrobot
ovsrobot
aserdean
XiaoYang
khem
hs
tpetazzoni
marex
liwang
robimarko
danielhb
groug
apritzel
mmichelson
npiggin
pareddja
atishp
netdrv
mkubecek
stintel
stintel
jkicinski
cpitchen
maximeh
dsa
jstancek
pm215
bpf
jonhunter
shettyg
lorpie01
acelan
wigyori
wigyori
apopple
dja
alexhung
lynxis
lynxis
brgl
brgl
peda
akodanev
narmstrong
981213
0andriy
chunkeey
snowpatch_ozlabs
snowpatch_ozlabs
snowpatch_ozlabs
aivanov
atishp04
shemminger
monstr
vigneshr
horms
mraynal
blocktrron
stewart
stewart
freenix
wsa
prom
rfried
ehristev
akumar
xypron
Jaehoon
jacmet
ivanhu
rsalvaterra
adrianschmutzler
sjg
hegdevasant
hegdevasant
metan
bmeng
jagan
ukleinek
ukleinek
ag
rmilecki
rmilecki
kevery
kabel
arbab
trini
rw
rw
apconole
pablo
pablo
abelloni
wbx
Hauke
Hauke
legoater
legoater
legoater
chleroy
svanheule
bjonglez
ynezz
aik
sbabic
sbabic
pevik
xback
xback
richiejp
dangole
dangole
forty
anuppatel
anuppatel
acer
echaudron
benh
rgrimm
next_ghost
segher
passgat
pratyush
jms
jms
jms
ymorin
ymorin
mans0n
ruscur
jk
jk
jk
jk
linusw
linusw
numans
xuyang
jmberg
Andes
festevam
matthias_bgg
tambarus
stroese
kubu
strlen
strlen
imaximets
apalos
dceara
pbrobinson
spectrum
cazzacarna
neocturne
aldot
TIENFONG
mpe
arnout
ktraynor
robh
nbd
nbd
anguy11
paulus
calebccff
jm
Apply
«
1
2
...
21
22
23
…
300
301
»
Patch
Series
A/F/R/T
S/W/F
Date
Submitter
Delegate
State
[nf-next,1/2] netfilter: nat: move repetitive nat port reserve loop to a helper
netfilter: nat: avoid long-running loops
- - - -
-
-
-
2022-09-06
Florian Westphal
pablo
Accepted
[nf] selftests: nft_concat_range: add socat support
[nf] selftests: nft_concat_range: add socat support
- - - -
-
-
-
2022-09-05
Florian Westphal
pablo
Accepted
[v2,nf] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers
[v2,nf] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers
- 1 - -
-
-
-
2022-09-05
Florian Westphal
pablo
Accepted
[nft,v2] json: fix empty statement list output in sets and maps
[nft,v2] json: fix empty statement list output in sets and maps
- 2 - -
-
-
-
2022-09-04
Fernando F. Mancera
pablo
Accepted
[nft] json: fix json schema version verification
[nft] json: fix json schema version verification
- 1 - -
-
-
-
2022-09-02
Fernando F. Mancera
pablo
Accepted
[nft] json: add table map statement support
[nft] json: add table map statement support
- - - -
-
-
-
2022-09-02
Fernando F. Mancera
pablo
Accepted
[nftables] rule: check address family in set collapse
[nftables] rule: check address family in set collapse
- 1 - -
-
-
-
2022-09-01
Derek Hageman
pablo
Accepted
[nft,v2] json: add set statement list support
[nft,v2] json: add set statement list support
- - - -
-
-
-
2022-09-01
Fernando F. Mancera
pablo
Accepted
[net,4/4] netfilter: nf_conntrack_irc: Fix forged IP logic
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
- 1 - -
-
-
-
2022-09-01
Florian Westphal
pablo
Accepted
[net,3/4] netfilter: nf_tables: clean up hook list when offload flags check fails
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
- 1 - -
-
-
-
2022-09-01
Florian Westphal
pablo
Accepted
[net,2/4] netfilter: br_netfilter: Drop dst references before setting.
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
1 1 - -
-
-
-
2022-09-01
Florian Westphal
pablo
Accepted
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
1 - - -
-
-
-
2022-09-01
Florian Westphal
pablo
Accepted
[net,0/4] netfilter: bug fixes for net
- - - -
-
-
-
2022-09-01
Florian Westphal
pablo
Accepted
[nft] tests/py: missing userdata in netlink payload
[nft] tests/py: missing userdata in netlink payload
- - - -
-
-
-
2022-08-31
Pablo Neira Ayuso
pablo
Accepted
[libnftnl] rule, set_elem: remove trailing \n in userdata snprintf
[libnftnl] rule, set_elem: remove trailing \n in userdata snprintf
- - - -
-
-
-
2022-08-31
Pablo Neira Ayuso
pablo
Accepted
[nft] json: add set statement list support
[nft] json: add set statement list support
- - - -
-
-
-
2022-08-31
Fernando F. Mancera
pablo
Accepted
[nf] netfilter: nf_tables: clean up hook list when offload flags check fails
[nf] netfilter: nf_tables: clean up hook list when offload flags check fails
- - - -
-
-
-
2022-08-31
Pablo Neira Ayuso
pablo
Accepted
[conntrack-tools] local: Avoid sockaddr_un::sun_path buffer overflow
[conntrack-tools] local: Avoid sockaddr_un::sun_path buffer overflow
- 1 - -
-
-
-
2022-08-31
Phil Sutter
pablo
Accepted
[bridge,v3] br_netfilter: Drop dst references before setting.
[bridge,v3] br_netfilter: Drop dst references before setting.
1 1 - -
-
-
-
2022-08-31
Harsh Modi
pablo
Accepted
[nft] src: allow burst 0 for byte ratelimit and use it as default
[nft] src: allow burst 0 for byte ratelimit and use it as default
1 1 - -
-
-
-
2022-08-30
Pablo Neira Ayuso
pablo
Accepted
[nf,v3] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
[nf,v3] netfilter: remove nf_conntrack_helper sysctl and modparam toggles
1 - - -
-
-
-
2022-08-30
Pablo Neira Ayuso
pablo
Accepted
[nft] doc: nft.8: Add missing '-T' in synopsis
[nft] doc: nft.8: Add missing '-T' in synopsis
- 1 - -
-
-
-
2022-08-30
Phil Sutter
pablo
Accepted
[nft] erec: Dump locations' expressions only if set
[nft] erec: Dump locations' expressions only if set
- - - -
-
-
-
2022-08-30
Phil Sutter
pablo
Accepted
[nft,v2] optimize: expand implicit set element when merging into concatenation
[nft,v2] optimize: expand implicit set element when merging into concatenation
- - - -
-
-
-
2022-08-29
Pablo Neira Ayuso
pablo
Accepted
[libnftnl] rule, set_elem: fix printing of user data
[libnftnl] rule, set_elem: fix printing of user data
- - - -
-
-
-
2022-08-27
Jeremy Sowden
pablo
Accepted
[iptables] nft: Expand extended error reporting to nft_cmd, too
[iptables] nft: Expand extended error reporting to nft_cmd, too
- - - -
-
-
-
2022-08-26
Phil Sutter
pablo
Accepted
[v2,nf-next,4/4] netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst
netfilter: conntrack: ignore overly delayed tcp packets
- - - -
-
-
-
2022-08-26
Florian Westphal
pablo
Accepted
[v2,nf-next,3/4] netfilter: conntrack: remove unneeded indent level
netfilter: conntrack: ignore overly delayed tcp packets
- - - -
-
-
-
2022-08-26
Florian Westphal
pablo
Accepted
[v2,nf-next,2/4] netfilter: conntrack: ignore overly delayed tcp packets
netfilter: conntrack: ignore overly delayed tcp packets
- - - -
-
-
-
2022-08-26
Florian Westphal
pablo
Accepted
[v2,nf-next,1/4] netfilter: conntrack: prepare tcp_in_window for ternary return value
netfilter: conntrack: ignore overly delayed tcp packets
- - - -
-
-
-
2022-08-26
Florian Westphal
pablo
Accepted
[2/2] netfilter: nf_conntrack_irc: Fix forged IP logic
[1/2] netfilter: nf_conntrack_irc: Tighten matching on DCC message
- 1 - -
-
-
-
2022-08-26
David Leadbeater
pablo
Accepted
[1/2] netfilter: nf_conntrack_irc: Tighten matching on DCC message
[1/2] netfilter: nf_conntrack_irc: Tighten matching on DCC message
- 1 - -
-
-
-
2022-08-26
David Leadbeater
pablo
Accepted
[iptables] xtables-restore: Extend failure error message
[iptables] xtables-restore: Extend failure error message
- - - -
-
-
-
2022-08-25
Phil Sutter
pablo
Accepted
[net,14/14] netfilter: nf_defrag_ipv6: allow nf_conntrack_frag6_high_thresh increases
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 2 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,13/14] netfilter: flowtable: fix stuck flows on cleanup due to pending work
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - 1
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,12/14] netfilter: flowtable: add function to invoke garbage collection immediately
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- - - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,11/14] netfilter: nf_tables: disallow binding to already bound chain
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,10/14] netfilter: nft_tunnel: restrict it to netdev family
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,09/14] netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,08/14] netfilter: nf_tables: do not leave chain stats enabled on error
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,07/14] netfilter: nft_payload: do not truncate csum_offset and csum_type
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,06/14] netfilter: nft_payload: report ERANGE for too long offset and length
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,05/14] netfilter: nf_tables: make table handle allocation per-netns friendly
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 1 -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,04/14] netfilter: nf_tables: disallow updates of implicit chain
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,03/14] netfilter: nft_tproxy: restrict to prerouting hook
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,02/14] netfilter: conntrack: work around exceeded receive window
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- - - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[net,00/14] Netfilter fixes for net
- - - -
-
-
-
2022-08-24
Pablo Neira Ayuso
pablo
Accepted
[nf] netfilter: nf_defrag_ipv6: allow nf_conntrack_frag6_high_thresh increases
[nf] netfilter: nf_defrag_ipv6: allow nf_conntrack_frag6_high_thresh increases
- 1 - -
-
-
-
2022-08-23
Eric Dumazet
pablo
Accepted
[nft] expr: update EXPR_MAX and add missing comments
[nft] expr: update EXPR_MAX and add missing comments
- - - -
-
-
-
2022-08-23
Florian Westphal
pablo
Accepted
[nf,2/2] netfilter: flowtable: fix stuck flows on cleanup due to pending work
[nf,1/2] netfilter: flowtable: add function to invoke garbage collection immediately
- 1 - 1
-
-
-
2022-08-22
Pablo Neira Ayuso
pablo
Accepted
[nf,1/2] netfilter: flowtable: add function to invoke garbage collection immediately
[nf,1/2] netfilter: flowtable: add function to invoke garbage collection immediately
- - - -
-
-
-
2022-08-22
Pablo Neira Ayuso
pablo
Accepted
[nf] netfilter: nf_tables: disallow binding to already bound chain
[nf] netfilter: nf_tables: disallow binding to already bound chain
- 1 - -
-
-
-
2022-08-22
Pablo Neira Ayuso
pablo
Accepted
[nf-next] netfilter: remove NFPROTO_DECNET
[nf-next] netfilter: remove NFPROTO_DECNET
- - - -
-
-
-
2022-08-22
Florian Westphal
pablo
Accepted
[nf,v3,2/2] netfilter: nft_payload: do not truncate csum_offset and csum_type
Untitled series #314677
- 1 - -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf,3/3] netfilter: nft_tunnel: restrict it to netdev family
[nf,1/3] netfilter: nft_dup: validate family and chains
- 1 - -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf,2/3] netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families
[nf,1/3] netfilter: nft_dup: validate family and chains
- 1 - -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf] netfilter: nf_tables: do not leave chain stats enabled on error
[nf] netfilter: nf_tables: do not leave chain stats enabled on error
- 1 - -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf,v2,1/2] netfilter: nft_payload: report ERANGE for too long offset and length
[nf,v2,1/2] netfilter: nft_payload: report ERANGE for too long offset and length
- 1 - -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf] netfilter: nf_tables: make table handle allocation per-netns friendly
[nf] netfilter: nf_tables: make table handle allocation per-netns friendly
- 1 1 -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf] netfilter: nf_tables: disallow updates of implicit chain
[nf] netfilter: nf_tables: disallow updates of implicit chain
- 1 - -
-
-
-
2022-08-21
Pablo Neira Ayuso
pablo
Accepted
[nf] netfilter: ebtables: reject blobs that don't provide all entry points
[nf] netfilter: ebtables: reject blobs that don't provide all entry points
- 1 - -
-
-
-
2022-08-20
Florian Westphal
pablo
Accepted
[nf] nefilter: nft_tproxy: restrict to prerouting hook
[nf] nefilter: nft_tproxy: restrict to prerouting hook
- 1 - -
-
-
-
2022-08-20
Florian Westphal
pablo
Accepted
[nft,v3] src: Don't parse string as verdict in map
[nft,v3] src: Don't parse string as verdict in map
- 1 - -
-
-
-
2022-08-19
Xiao Liang
Accepted
[nf] netfilter: conntrack: work around exceeded receive window
[nf] netfilter: conntrack: work around exceeded receive window
- - - -
-
-
-
2022-08-18
Florian Westphal
pablo
Accepted
netfilter: move from strlcpy with unused retval to strscpy
netfilter: move from strlcpy with unused retval to strscpy
- - 1 -
-
-
-
2022-08-18
Wolfram Sang
pablo
Accepted
[net,17/17] testing: selftests: nft_flowtable.sh: rework test to detect offload failure
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- - - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,16/17] testing: selftests: nft_flowtable.sh: use random netns names
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- - - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,15/17] netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- - - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,14/17] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,13/17] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,12/17] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,11/17] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,10/17] netfilter: nf_tables: really skip inactive sets when allocating name
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,09/17] netfilter: nfnetlink: re-enable conntrack expectation events
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,08/17] netfilter: nf_tables: fix scheduling-while-atomic splat
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,07/17] netfilter: nf_ct_irc: cap packet search space to 4k
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 2 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,06/17] netfilter: nf_ct_ftp: prefer skb_linearize
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 2 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,05/17] netfilter: nf_ct_h323: cap packet size at 64k
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 2 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,04/17] netfilter: nf_ct_sane: remove pseudo skb linearization
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 2 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,03/17] netfilter: nf_tables: possible module reference underflow in error path
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,02/17] netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERVAL_END flag
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access
- 1 - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[net,00/17] netfilter: conntrack and nf_tables bug fixes
- - - -
-
-
-
2022-08-17
Florian Westphal
pablo
Accepted
[nf,2/2] testing: selftests: nft_flowtable.sh: rework test to detect offload failure
testing: selftests: nft_flowtable.sh: unbreak test script
- - - -
-
-
-
2022-08-16
Florian Westphal
pablo
Accepted
[nf,1/2] testing: selftests: nft_flowtable.sh: use random netns names
testing: selftests: nft_flowtable.sh: unbreak test script
- - - -
-
-
-
2022-08-16
Florian Westphal
pablo
Accepted
[nf,v2] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified
[nf,v2] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified
- 1 - -
-
-
-
2022-08-15
Pablo Neira Ayuso
pablo
Accepted
[nf,v4,2/2] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags
Untitled series #313871
- 1 - -
-
-
-
2022-08-15
Pablo Neira Ayuso
pablo
Accepted
netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y
netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y
- - - -
-
-
-
2022-08-15
Geert Uytterhoeven
pablo
Accepted
[nf] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END
[nf] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END
- 1 - -
-
-
-
2022-08-13
Pablo Neira Ayuso
pablo
Accepted
[nf,1/2] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag
[nf,1/2] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag
- 1 - -
-
-
-
2022-08-12
Pablo Neira Ayuso
pablo
Accepted
ipset-translate: allow invoking with a path name
ipset-translate: allow invoking with a path name
- - - -
-
-
-
2022-08-11
Quentin Armitage
pablo
Accepted
[nf] netfilter: nf_tables: fix scheduling-while-atomic splat
[nf] netfilter: nf_tables: fix scheduling-while-atomic splat
- 1 - -
-
-
-
2022-08-11
Florian Westphal
pablo
Accepted
[nft] tests: shell: check for a tainted kernel
[nft] tests: shell: check for a tainted kernel
- - - -
-
-
-
2022-08-11
Florian Westphal
Accepted
[nft] evaluate: allow implicit ether -> vlan dep
[nft] evaluate: allow implicit ether -> vlan dep
- - - -
-
-
-
2022-08-11
Florian Westphal
pablo
Accepted
[net,8/8] netfilter: nf_tables: fix null deref due to zeroed list head
[net,1/8] netfilter: nf_tables: validate variable length element extension
- 1 - -
-
-
-
2022-08-09
Pablo Neira Ayuso
pablo
Accepted
[net,7/8] netfilter: nf_tables: disallow jump to implicit chain from set element
[net,1/8] netfilter: nf_tables: validate variable length element extension
- 1 - -
-
-
-
2022-08-09
Pablo Neira Ayuso
pablo
Accepted
[net,6/8] netfilter: nf_tables: upfront validation of data via nft_data_init()
[net,1/8] netfilter: nf_tables: validate variable length element extension
- - - -
-
-
-
2022-08-09
Pablo Neira Ayuso
pablo
Accepted
[net,5/8] netfilter: ip6t_LOG: Fix a typo in a comment
[net,1/8] netfilter: nf_tables: validate variable length element extension
- - - -
-
-
-
2022-08-09
Pablo Neira Ayuso
pablo
Accepted
[net,4/8] netfilter: nf_tables: do not allow RULE_ID to refer to another chain
[net,1/8] netfilter: nf_tables: validate variable length element extension
- 2 - -
-
-
-
2022-08-09
Pablo Neira Ayuso
pablo
Accepted
«
1
2
...
21
22
23
…
300
301
»