Show patches with: none      |   30066 patches
« 1 2 ... 21 22 23300 301 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf-next,1/2] netfilter: nat: move repetitive nat port reserve loop to a helper netfilter: nat: avoid long-running loops - - - - --- 2022-09-06 Florian Westphal pablo Accepted
[nf] selftests: nft_concat_range: add socat support [nf] selftests: nft_concat_range: add socat support - - - - --- 2022-09-05 Florian Westphal pablo Accepted
[v2,nf] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers [v2,nf] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers - 1 - - --- 2022-09-05 Florian Westphal pablo Accepted
[nft,v2] json: fix empty statement list output in sets and maps [nft,v2] json: fix empty statement list output in sets and maps - 2 - - --- 2022-09-04 Fernando F. Mancera pablo Accepted
[nft] json: fix json schema version verification [nft] json: fix json schema version verification - 1 - - --- 2022-09-02 Fernando F. Mancera pablo Accepted
[nft] json: add table map statement support [nft] json: add table map statement support - - - - --- 2022-09-02 Fernando F. Mancera pablo Accepted
[nftables] rule: check address family in set collapse [nftables] rule: check address family in set collapse - 1 - - --- 2022-09-01 Derek Hageman pablo Accepted
[nft,v2] json: add set statement list support [nft,v2] json: add set statement list support - - - - --- 2022-09-01 Fernando F. Mancera pablo Accepted
[net,4/4] netfilter: nf_conntrack_irc: Fix forged IP logic [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles - 1 - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,3/4] netfilter: nf_tables: clean up hook list when offload flags check fails [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles - 1 - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,2/4] netfilter: br_netfilter: Drop dst references before setting. [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles 1 1 - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles 1 - - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,0/4] netfilter: bug fixes for net - - - - --- 2022-09-01 Florian Westphal pablo Accepted
[nft] tests/py: missing userdata in netlink payload [nft] tests/py: missing userdata in netlink payload - - - - --- 2022-08-31 Pablo Neira Ayuso pablo Accepted
[libnftnl] rule, set_elem: remove trailing \n in userdata snprintf [libnftnl] rule, set_elem: remove trailing \n in userdata snprintf - - - - --- 2022-08-31 Pablo Neira Ayuso pablo Accepted
[nft] json: add set statement list support [nft] json: add set statement list support - - - - --- 2022-08-31 Fernando F. Mancera pablo Accepted
[nf] netfilter: nf_tables: clean up hook list when offload flags check fails [nf] netfilter: nf_tables: clean up hook list when offload flags check fails - - - - --- 2022-08-31 Pablo Neira Ayuso pablo Accepted
[conntrack-tools] local: Avoid sockaddr_un::sun_path buffer overflow [conntrack-tools] local: Avoid sockaddr_un::sun_path buffer overflow - 1 - - --- 2022-08-31 Phil Sutter pablo Accepted
[bridge,v3] br_netfilter: Drop dst references before setting. [bridge,v3] br_netfilter: Drop dst references before setting. 1 1 - - --- 2022-08-31 Harsh Modi pablo Accepted
[nft] src: allow burst 0 for byte ratelimit and use it as default [nft] src: allow burst 0 for byte ratelimit and use it as default 1 1 - - --- 2022-08-30 Pablo Neira Ayuso pablo Accepted
[nf,v3] netfilter: remove nf_conntrack_helper sysctl and modparam toggles [nf,v3] netfilter: remove nf_conntrack_helper sysctl and modparam toggles 1 - - - --- 2022-08-30 Pablo Neira Ayuso pablo Accepted
[nft] doc: nft.8: Add missing '-T' in synopsis [nft] doc: nft.8: Add missing '-T' in synopsis - 1 - - --- 2022-08-30 Phil Sutter pablo Accepted
[nft] erec: Dump locations' expressions only if set [nft] erec: Dump locations' expressions only if set - - - - --- 2022-08-30 Phil Sutter pablo Accepted
[nft,v2] optimize: expand implicit set element when merging into concatenation [nft,v2] optimize: expand implicit set element when merging into concatenation - - - - --- 2022-08-29 Pablo Neira Ayuso pablo Accepted
[libnftnl] rule, set_elem: fix printing of user data [libnftnl] rule, set_elem: fix printing of user data - - - - --- 2022-08-27 Jeremy Sowden pablo Accepted
[iptables] nft: Expand extended error reporting to nft_cmd, too [iptables] nft: Expand extended error reporting to nft_cmd, too - - - - --- 2022-08-26 Phil Sutter pablo Accepted
[v2,nf-next,4/4] netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst netfilter: conntrack: ignore overly delayed tcp packets - - - - --- 2022-08-26 Florian Westphal pablo Accepted
[v2,nf-next,3/4] netfilter: conntrack: remove unneeded indent level netfilter: conntrack: ignore overly delayed tcp packets - - - - --- 2022-08-26 Florian Westphal pablo Accepted
[v2,nf-next,2/4] netfilter: conntrack: ignore overly delayed tcp packets netfilter: conntrack: ignore overly delayed tcp packets - - - - --- 2022-08-26 Florian Westphal pablo Accepted
[v2,nf-next,1/4] netfilter: conntrack: prepare tcp_in_window for ternary return value netfilter: conntrack: ignore overly delayed tcp packets - - - - --- 2022-08-26 Florian Westphal pablo Accepted
[2/2] netfilter: nf_conntrack_irc: Fix forged IP logic [1/2] netfilter: nf_conntrack_irc: Tighten matching on DCC message - 1 - - --- 2022-08-26 David Leadbeater pablo Accepted
[1/2] netfilter: nf_conntrack_irc: Tighten matching on DCC message [1/2] netfilter: nf_conntrack_irc: Tighten matching on DCC message - 1 - - --- 2022-08-26 David Leadbeater pablo Accepted
[iptables] xtables-restore: Extend failure error message [iptables] xtables-restore: Extend failure error message - - - - --- 2022-08-25 Phil Sutter pablo Accepted
[net,14/14] netfilter: nf_defrag_ipv6: allow nf_conntrack_frag6_high_thresh increases [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 2 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,13/14] netfilter: flowtable: fix stuck flows on cleanup due to pending work [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - 1 --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,12/14] netfilter: flowtable: add function to invoke garbage collection immediately [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - - - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,11/14] netfilter: nf_tables: disallow binding to already bound chain [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,10/14] netfilter: nft_tunnel: restrict it to netdev family [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,09/14] netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,08/14] netfilter: nf_tables: do not leave chain stats enabled on error [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,07/14] netfilter: nft_payload: do not truncate csum_offset and csum_type [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,06/14] netfilter: nft_payload: report ERANGE for too long offset and length [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,05/14] netfilter: nf_tables: make table handle allocation per-netns friendly [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 1 - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,04/14] netfilter: nf_tables: disallow updates of implicit chain [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,03/14] netfilter: nft_tproxy: restrict to prerouting hook [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,02/14] netfilter: conntrack: work around exceeded receive window [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - - - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points [net,01/14] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[net,00/14] Netfilter fixes for net - - - - --- 2022-08-24 Pablo Neira Ayuso pablo Accepted
[nf] netfilter: nf_defrag_ipv6: allow nf_conntrack_frag6_high_thresh increases [nf] netfilter: nf_defrag_ipv6: allow nf_conntrack_frag6_high_thresh increases - 1 - - --- 2022-08-23 Eric Dumazet pablo Accepted
[nft] expr: update EXPR_MAX and add missing comments [nft] expr: update EXPR_MAX and add missing comments - - - - --- 2022-08-23 Florian Westphal pablo Accepted
[nf,2/2] netfilter: flowtable: fix stuck flows on cleanup due to pending work [nf,1/2] netfilter: flowtable: add function to invoke garbage collection immediately - 1 - 1 --- 2022-08-22 Pablo Neira Ayuso pablo Accepted
[nf,1/2] netfilter: flowtable: add function to invoke garbage collection immediately [nf,1/2] netfilter: flowtable: add function to invoke garbage collection immediately - - - - --- 2022-08-22 Pablo Neira Ayuso pablo Accepted
[nf] netfilter: nf_tables: disallow binding to already bound chain [nf] netfilter: nf_tables: disallow binding to already bound chain - 1 - - --- 2022-08-22 Pablo Neira Ayuso pablo Accepted
[nf-next] netfilter: remove NFPROTO_DECNET [nf-next] netfilter: remove NFPROTO_DECNET - - - - --- 2022-08-22 Florian Westphal pablo Accepted
[nf,v3,2/2] netfilter: nft_payload: do not truncate csum_offset and csum_type Untitled series #314677 - 1 - - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf,3/3] netfilter: nft_tunnel: restrict it to netdev family [nf,1/3] netfilter: nft_dup: validate family and chains - 1 - - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf,2/3] netfilter: nft_osf: restrict osf to ipv4, ipv6 and inet families [nf,1/3] netfilter: nft_dup: validate family and chains - 1 - - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf] netfilter: nf_tables: do not leave chain stats enabled on error [nf] netfilter: nf_tables: do not leave chain stats enabled on error - 1 - - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf,v2,1/2] netfilter: nft_payload: report ERANGE for too long offset and length [nf,v2,1/2] netfilter: nft_payload: report ERANGE for too long offset and length - 1 - - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf] netfilter: nf_tables: make table handle allocation per-netns friendly [nf] netfilter: nf_tables: make table handle allocation per-netns friendly - 1 1 - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf] netfilter: nf_tables: disallow updates of implicit chain [nf] netfilter: nf_tables: disallow updates of implicit chain - 1 - - --- 2022-08-21 Pablo Neira Ayuso pablo Accepted
[nf] netfilter: ebtables: reject blobs that don't provide all entry points [nf] netfilter: ebtables: reject blobs that don't provide all entry points - 1 - - --- 2022-08-20 Florian Westphal pablo Accepted
[nf] nefilter: nft_tproxy: restrict to prerouting hook [nf] nefilter: nft_tproxy: restrict to prerouting hook - 1 - - --- 2022-08-20 Florian Westphal pablo Accepted
[nft,v3] src: Don't parse string as verdict in map [nft,v3] src: Don't parse string as verdict in map - 1 - - --- 2022-08-19 Xiao Liang Accepted
[nf] netfilter: conntrack: work around exceeded receive window [nf] netfilter: conntrack: work around exceeded receive window - - - - --- 2022-08-18 Florian Westphal pablo Accepted
netfilter: move from strlcpy with unused retval to strscpy netfilter: move from strlcpy with unused retval to strscpy - - 1 - --- 2022-08-18 Wolfram Sang pablo Accepted
[net,17/17] testing: selftests: nft_flowtable.sh: rework test to detect offload failure [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,16/17] testing: selftests: nft_flowtable.sh: use random netns names [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,15/17] netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,14/17] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,13/17] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,12/17] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,11/17] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,10/17] netfilter: nf_tables: really skip inactive sets when allocating name [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,09/17] netfilter: nfnetlink: re-enable conntrack expectation events [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,08/17] netfilter: nf_tables: fix scheduling-while-atomic splat [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,07/17] netfilter: nf_ct_irc: cap packet search space to 4k [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,06/17] netfilter: nf_ct_ftp: prefer skb_linearize [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,05/17] netfilter: nf_ct_h323: cap packet size at 64k [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,04/17] netfilter: nf_ct_sane: remove pseudo skb linearization [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,03/17] netfilter: nf_tables: possible module reference underflow in error path [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,02/17] netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERVAL_END flag [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,00/17] netfilter: conntrack and nf_tables bug fixes - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[nf,2/2] testing: selftests: nft_flowtable.sh: rework test to detect offload failure testing: selftests: nft_flowtable.sh: unbreak test script - - - - --- 2022-08-16 Florian Westphal pablo Accepted
[nf,1/2] testing: selftests: nft_flowtable.sh: use random netns names testing: selftests: nft_flowtable.sh: unbreak test script - - - - --- 2022-08-16 Florian Westphal pablo Accepted
[nf,v2] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified [nf,v2] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified - 1 - - --- 2022-08-15 Pablo Neira Ayuso pablo Accepted
[nf,v4,2/2] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags Untitled series #313871 - 1 - - --- 2022-08-15 Pablo Neira Ayuso pablo Accepted
netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y - - - - --- 2022-08-15 Geert Uytterhoeven pablo Accepted
[nf] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END [nf] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END - 1 - - --- 2022-08-13 Pablo Neira Ayuso pablo Accepted
[nf,1/2] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag [nf,1/2] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag - 1 - - --- 2022-08-12 Pablo Neira Ayuso pablo Accepted
ipset-translate: allow invoking with a path name ipset-translate: allow invoking with a path name - - - - --- 2022-08-11 Quentin Armitage pablo Accepted
[nf] netfilter: nf_tables: fix scheduling-while-atomic splat [nf] netfilter: nf_tables: fix scheduling-while-atomic splat - 1 - - --- 2022-08-11 Florian Westphal pablo Accepted
[nft] tests: shell: check for a tainted kernel [nft] tests: shell: check for a tainted kernel - - - - --- 2022-08-11 Florian Westphal Accepted
[nft] evaluate: allow implicit ether -> vlan dep [nft] evaluate: allow implicit ether -> vlan dep - - - - --- 2022-08-11 Florian Westphal pablo Accepted
[net,8/8] netfilter: nf_tables: fix null deref due to zeroed list head [net,1/8] netfilter: nf_tables: validate variable length element extension - 1 - - --- 2022-08-09 Pablo Neira Ayuso pablo Accepted
[net,7/8] netfilter: nf_tables: disallow jump to implicit chain from set element [net,1/8] netfilter: nf_tables: validate variable length element extension - 1 - - --- 2022-08-09 Pablo Neira Ayuso pablo Accepted
[net,6/8] netfilter: nf_tables: upfront validation of data via nft_data_init() [net,1/8] netfilter: nf_tables: validate variable length element extension - - - - --- 2022-08-09 Pablo Neira Ayuso pablo Accepted
[net,5/8] netfilter: ip6t_LOG: Fix a typo in a comment [net,1/8] netfilter: nf_tables: validate variable length element extension - - - - --- 2022-08-09 Pablo Neira Ayuso pablo Accepted
[net,4/8] netfilter: nf_tables: do not allow RULE_ID to refer to another chain [net,1/8] netfilter: nf_tables: validate variable length element extension - 2 - - --- 2022-08-09 Pablo Neira Ayuso pablo Accepted
« 1 2 ... 21 22 23300 301 »