Show patches with: Archived = No       |   28564 patches
« 1 2 ... 110 111 112285 286 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[net,06/14] netfilter: nf_queue: remove excess nf_bridge variable [net,01/14] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,07/14] netfilter: propagate net to nf_bridge_get_physindev [net,01/14] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,08/14] netfilter: bridge: replace physindev with physinif in nf_bridge_info [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,09/14] netfilter: nf_tables: check if catch-all set element is active in next generation [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,10/14] netfilter: nf_tables: do not allow mismatch field size and set key length [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,11/14] netfilter: nf_tables: skip dead set elements in netlink dump [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,12/14] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,13/14] ipvs: avoid stat macros calls from preemptible context [net,01/14] netfilter: nf_tables: reject invalid set policy 2 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,14/14] netfilter: ipset: fix performance regression in swap operation [net,01/14] netfilter: nf_tables: reject invalid set policy - 2 - 2 --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family [nf] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family - - - - --- 2024-01-23 Pablo Neira Ayuso Changes Requested
[nf,v2] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family [nf,v2] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family - 7 - - --- 2024-01-24 Pablo Neira Ayuso Changes Requested
[RFC,1/1] netfilter: nat: restore default DNAT behavior netfilter: nat: restore default DNAT behavior - - - - --- 2024-01-26 Kyle Swenson Changes Requested
[nf] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations [nf] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - 1 - - --- 2024-01-29 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV [nf] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV - 1 - - --- 2024-01-29 Pablo Neira Ayuso Changes Requested
ipvs: generic netlink multicast event group ipvs: generic netlink multicast event group - - - - --- 2024-02-05 Terin Stock Changes Requested
[nf,1/3] netfilter: nft_set_pipapo: store index in scratch maps netfilter: nft_set_pipapo: map_index must be per set - 1 1 - --- 2024-02-06 Florian Westphal Changes Requested
[nf,2/3] netfilter: nft_set_pipapo: add helper to release pcpu scratch area netfilter: nft_set_pipapo: map_index must be per set - - 1 - --- 2024-02-06 Florian Westphal Changes Requested
[nf,3/3] netfilter: nft_set_pipapo: remove scratch_aligned pointer netfilter: nft_set_pipapo: map_index must be per set - 1 1 - --- 2024-02-06 Florian Westphal Changes Requested
[nft] evaluate: skip byteorder conversion for selector smaller than 2 bytes [nft] evaluate: skip byteorder conversion for selector smaller than 2 bytes - 1 - - --- 2024-02-07 Pablo Neira Ayuso Changes Requested
[v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate() [v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate() - 1 - - --- 2024-02-20 Ignat Korchagin Changes Requested
[nf,1/2] netfilter: nf_tables: disallow anonymous set with NFT_SET_{TIMEOUT,EVAL} flags [nf,1/2] netfilter: nf_tables: disallow anonymous set with NFT_SET_{TIMEOUT,EVAL} flags - 1 - - --- 2024-03-01 Pablo Neira Ayuso Changes Requested
[nf,2/2] netfilter: nf_tables: reject constant set with timeout [nf,1/2] netfilter: nf_tables: disallow anonymous set with NFT_SET_{TIMEOUT,EVAL} flags - 1 - - --- 2024-03-01 Pablo Neira Ayuso Changes Requested
[conntrack-tools,1/3] conntrackd: prevent memory loss if reallocation fails fix potential memory loss and exit codes - - - - --- 2024-03-01 Donald Yandt Changes Requested
[conntrack-tools,2/3] conntrackd: use size_t for element indices fix potential memory loss and exit codes - - - - --- 2024-03-01 Donald Yandt Changes Requested
[conntrack-tools,3/3] conntrackd: exit with failure status fix potential memory loss and exit codes - - - - --- 2024-03-01 Donald Yandt Changes Requested
[conntrack-tools,v2,2/3] conntrackd: use size_t for element indices fix potential memory loss and exit codes - - - - --- 2024-03-02 Donald Yandt Changes Requested
[nf] netfilter: nf_tables: mark set as dead when deactivating anonymous set [nf] netfilter: nf_tables: mark set as dead when deactivating anonymous set - 1 - - --- 2024-03-04 Pablo Neira Ayuso Changes Requested
[nf,v2] netfilter: nf_tables: mark set as dead when deactivating anonymous set with timeout [nf,v2] netfilter: nf_tables: mark set as dead when deactivating anonymous set with timeout - 1 - - --- 2024-03-04 Pablo Neira Ayuso Changes Requested
[nft] evaluate: translate meter into dynamic set [nft] evaluate: translate meter into dynamic set - - - - --- 2024-03-06 Pablo Neira Ayuso Changes Requested
[net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb [net-next] netfilter: conntrack: avoid sending RST to reply out-of-window skb - - - - --- 2024-03-07 Jason Xing Changes Requested
iptables-nft: Wrong payload merge of rule filter - "! --sport xx ! --dport xx" iptables-nft: Wrong payload merge of rule filter - "! --sport xx ! --dport xx" 1 - - - --- 2024-03-08 Sriram Rajagopalan Changes Requested
[net-next] netfilter: conntrack: dccp: try not to drop skb in conntrack [net-next] netfilter: conntrack: dccp: try not to drop skb in conntrack - - - - --- 2024-03-08 Jason Xing Changes Requested
[net-next] netfilter: conntrack: using NF_DROP in test statement in nf_conntrack_in() [net-next] netfilter: conntrack: using NF_DROP in test statement in nf_conntrack_in() - - - - --- 2024-03-08 Jason Xing Changes Requested
[v2,nf-next,1/2] netfilter: nf_tables: use struct nlattr * to store userdata for nft_table [v2,nf-next,1/2] netfilter: nf_tables: use struct nlattr * to store userdata for nft_table - - - - --- 2024-03-10 Quan Tian Changes Requested
[v2,nf-next,2/2] netfilter: nf_tables: support updating userdata for nft_table [v2,nf-next,1/2] netfilter: nf_tables: use struct nlattr * to store userdata for nft_table - - - - --- 2024-03-10 Quan Tian Changes Requested
[nf] netfilter: nf_tables: fix updating/deleting devices in an existing netdev chain [nf] netfilter: nf_tables: fix updating/deleting devices in an existing netdev chain - 2 - - --- 2024-03-10 Pablo Neira Ayuso Changes Requested
[nf] netfilter: flowtable: infer TCP state and timeout before flow teardown [nf] netfilter: flowtable: infer TCP state and timeout before flow teardown - 1 - - --- 2024-03-18 Pablo Neira Ayuso Changes Requested
[nf,2/2] netfilter: flowtable: use UDP timeout after flow teardown Untitled series #399383 - 1 - - --- 2024-03-18 Pablo Neira Ayuso Changes Requested
[net,0/3] Netfilter fixes for net - - - - --- 2024-03-21 Pablo Neira Ayuso Changes Requested
[net,1/3] netfilter: nft_set_pipapo: release elements in clone only from destroy path [net,1/3] netfilter: nft_set_pipapo: release elements in clone only from destroy path - 1 - - --- 2024-03-21 Pablo Neira Ayuso Changes Requested
[net,2/3] netfilter: nf_tables: do not compare internal table flags on updates [net,1/3] netfilter: nft_set_pipapo: release elements in clone only from destroy path - 1 - - --- 2024-03-21 Pablo Neira Ayuso Changes Requested
[net,3/3] netfilter: nf_tables: Fix a memory leak in nf_tables_updchain [net,1/3] netfilter: nft_set_pipapo: release elements in clone only from destroy path - 1 - - --- 2024-03-21 Pablo Neira Ayuso Changes Requested
[iptables] libxtables: Fix xtables_ipaddr_to_numeric calls with xtables_ipmask_to_numeric [iptables] libxtables: Fix xtables_ipaddr_to_numeric calls with xtables_ipmask_to_numeric - - - - --- 2024-03-23 Vitaly Chikunov Changes Requested
[nftables] evaluate: add support for variables in map expressions [nftables] evaluate: add support for variables in map expressions - - - - --- 2024-03-24 Jeremy Sowden Changes Requested
[net-next,1/3] netfilter: using NF_DROP in test statement in nf_conntrack_in() netfilter: use NF_DROP instead of -NF_DROP - - - - --- 2024-03-25 Jason Xing Changes Requested
[net-next,2/3] netfilter: use NF_DROP in iptable_filter_table_init() netfilter: use NF_DROP instead of -NF_DROP - - - - --- 2024-03-25 Jason Xing Changes Requested
[net-next,3/3] netfilter: use NF_DROP in ip6table_filter_table_init() netfilter: use NF_DROP instead of -NF_DROP - - - - --- 2024-03-25 Jason Xing Changes Requested
[bpf-next] net: netfilter: Make ct zone id configurable for bpf ct helper functions [bpf-next] net: netfilter: Make ct zone id configurable for bpf ct helper functions - - - - --- 2024-03-29 Brad Cowie Changes Requested
[nft] netfilter: nf_tables: Fix pertential data-race in __nft_flowtable_type_get() [nft] netfilter: nf_tables: Fix pertential data-race in __nft_flowtable_type_get() - - - - --- 2024-04-01 Ziyang Xuan Changes Requested
[nf,1/3] netfilter: nf_tables: release batch on table validation from abort path [nf,1/3] netfilter: nf_tables: release batch on table validation from abort path - 1 - - --- 2024-04-01 Pablo Neira Ayuso Changes Requested
[nf,2/3] netfilter: nf_tables: release mutex after nft_gc_seq_end from abort path [nf,1/3] netfilter: nf_tables: release batch on table validation from abort path - 1 - - --- 2024-04-01 Pablo Neira Ayuso Changes Requested
[nf,3/3] netfilter: nf_tables: flush pending destroy work before exit_net release [nf,1/3] netfilter: nf_tables: release batch on table validation from abort path - 1 - - --- 2024-04-01 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nf_tables: discard table flag update with pending basechain deletion [nf] netfilter: nf_tables: discard table flag update with pending basechain deletion - 1 - - --- 2024-04-03 Pablo Neira Ayuso Changes Requested
[nf] netfilter: flowtable: validate PPPoe header [nf] netfilter: flowtable: validate PPPoe header - 1 - - --- 2024-04-09 Pablo Neira Ayuso Changes Requested
[nf,v2] netfilter: flowtable: validate PPPoe header [nf,v2] netfilter: flowtable: validate PPPoe header - 1 - - --- 2024-04-09 Pablo Neira Ayuso Changes Requested
[net-next,v2,1/3] doc/netlink/specs: Add draft nftables spec netlink: Add nftables spec w/ multi messages - - - - --- 2024-04-10 Donald Hunter Changes Requested
[net-next,v2,2/3] netfilter: nfnetlink: Handle ACK flags for batch messages netlink: Add nftables spec w/ multi messages - - - - --- 2024-04-10 Donald Hunter Changes Requested
[net-next,v2,3/3] tools/net/ynl: Add multi message support to ynl netlink: Add nftables spec w/ multi messages - - - - --- 2024-04-10 Donald Hunter Changes Requested
[nf] netfilter: flowtable: incorrect pppoe tuple in reply direction [nf] netfilter: flowtable: incorrect pppoe tuple in reply direction - 1 - - --- 2024-04-10 Pablo Neira Ayuso Changes Requested
[net-next] ipvs: allow some sysctls in non-init user namespaces [net-next] ipvs: allow some sysctls in non-init user namespaces - - - - --- 2024-04-16 Aleksandr Mikhalitsyn Changes Requested
[net-next,v2,1/2] ipvs: add READ_ONCE barrier for ipvs->sysctl_amemthresh [net-next,v2,1/2] ipvs: add READ_ONCE barrier for ipvs->sysctl_amemthresh - - - - --- 2024-04-18 Aleksandr Mikhalitsyn Changes Requested
[net-next,v2,2/2] ipvs: allow some sysctls in non-init user namespaces [net-next,v2,1/2] ipvs: add READ_ONCE barrier for ipvs->sysctl_amemthresh - - - - --- 2024-04-18 Aleksandr Mikhalitsyn Changes Requested
ipvs: Fix checksumming on GSO of SCTP packets ipvs: Fix checksumming on GSO of SCTP packets - 1 - 1 --- 2024-04-18 Ismael Luceno Changes Requested
netfilter: mark racy access on ext->gen_id netfilter: mark racy access on ext->gen_id 1 - - - --- 2024-04-23 linke li Changes Requested
[v3] ipvs: Fix checksumming on GSO of SCTP packets [v3] ipvs: Fix checksumming on GSO of SCTP packets - 1 - 1 --- 2024-04-25 Ismael Luceno Changes Requested
adjust __net_exit - - - - --- 2012-03-08 Jan Beulich Not Applicable
`iptables -m tcp --syn` doesn't do what the man says - - - - --- 2012-03-30 Eric Dumazet Not Applicable
a possible bug in netfilter - - - - --- 2012-04-07 Florian Westphal Not Applicable
[5/9] ipvs: use adaptive pause in master thread - - - - --- 2012-04-08 Julian Anastasov Not Applicable
[xt-addons] xt_psd: avoid crash due to curr->next corruption - - - - --- 2012-04-18 Florian Westphal Not Applicable
[net-next] netfilter: remove two dropwatch false positives - - - - --- 2012-05-02 Eric Dumazet Not Applicable
[19/25] ipvs: optimize the use of flags in ip_vs_bind_dest - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[01/25] netfilter: nf_ct_ecache: refactor notifier registration - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[02/25] netfilter: nf_ct_helper: allow to disable automatic helper assignment - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[03/25] netfilter: nf_conntrack: use this_cpu_inc() - - 1 - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[04/25] netfilter: bridge: optionally set indev to vlan 1 - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[04/25] netfilter: bridge: optionally set indev to vlan 1 - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[05/25] ipvs: timeout tables do not need GFP_ATOMIC allocation - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[06/25] ipvs: LBLC scheduler does not need GFP_ATOMIC allocation on init - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[07/25] ipvs: DH scheduler does not need GFP_ATOMIC allocation - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[08/25] ipvs: WRR scheduler does not need GFP_ATOMIC allocation - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[10/25] ipvs: SH scheduler does not need GFP_ATOMIC allocation - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[11/25] ipvs: use GFP_KERNEL allocation where possible 1 - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[12/25] ipvs: ignore IP_VS_CONN_F_NOOUTPUT in backup server - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[13/25] ipvs: remove check for IP_VS_CONN_F_SYNC from ip_vs_bind_dest - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[14/25] ipvs: fix ip_vs_try_bind_dest to rebind app and transmitter - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[15/25] ipvs: always update some of the flags bits in backup - - - 1 --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[16/25] ipvs: wakeup master thread - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[17/25] ipvs: reduce sync rate with time thresholds - - - 1 --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[18/25] ipvs: add support for sync threads - - - 1 --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[19/25] ipvs: optimize the use of flags in ip_vs_bind_dest - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[20/25] ipvs: ip_vs_ftp: local functions should not be exposed globally - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[21/25] ipvs: ip_vs_proto: local functions should not be exposed globally - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[22/25] net: export sysctl_[r|w]mem_max symbols needed by ip_vs_sync 1 - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[23/25] netfilter: nf_ct_expect: partially implement ctnetlink_change_expect - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[24/25] netfilter: nf_conntrack: fix explicit helper attachment and NAT - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[25/25] netfilter: remove ip_queue support - - - - --- 2012-05-08 Pablo Neira Ayuso Not Applicable
[04/13] bridge: netfilter: Convert compare_ether_addr to ether_addr_equal 1 - - - --- 2012-05-09 Joe Perches Not Applicable
[10/13] netfilter: Convert compare_ether_addr to ether_addr_equal - - - - --- 2012-05-09 Joe Perches Not Applicable
[ANNOUNCE] ipset 6.12 released - - - - --- 2012-05-10 Jozsef Kadlecsik Not Applicable
« 1 2 ... 110 111 112285 286 »