Toggle navigation
Patchwork
Netfilter Development
Patches
Bundles
About this project
Login
Register
Mail settings
Show patches with
: State =
Action Required
| Archived =
No
| 120 patches
Series
Submitter
State
any
Action Required
New
Under Review
Accepted
Rejected
RFC
Not Applicable
Changes Requested
Awaiting Upstream
Superseded
Deferred
Needs Review / ACK
Handled Elsewhere
Search
Archived
No
Yes
Both
Delegate
------
Nobody
jgarzik
arnd
ymano
smfrench
jlayton
tseliot
ogasawara
amitk
awhitcroft
mst
dayangkun
jwboyer
jwboyer
colinking
colinking
azummo
dwmw2
rtg
sconklin
smb
aliguori
bradf
demarchi
ms
bhundven
chbs
kengyu
kadlec
pdp
regit
jabk
laforge
laforge
tonyb
alai
zecke
zecke
__damien__
luka
luka
prafulla@marvell.com
cyrus
PeterHuewe
kiho
jow
jow
ypwong
nico
dedeckeh
dedeckeh
yousong
yousong
tomcwarren
mb
mrchuck
vineetg76
computersforpeace
patrick_delaunay
Noltari
Noltari
ee07b291
ldir
ldir
stefanct
zhouhan
carldani
blp
ffainelli
ffainelli
regXboi
bbrezillon
pravin
mkp
jpettit
mkresin
mkresin
thess
thess
fbarrat
fbarrat
phil
linville
jesse
tjaalton
esben
abrodkin
abrodkin
diproiettod
tbot
stephenfin
vriera
darball1
sammj
ajd
jogo
jogo
bhelgaas
blogic
blogic
oohal
russellb
ptomsich
agraf
tagr
tagr
tagr
joestringer
mwalle
naveen
pchotard
pepe2k
pepe2k
arj
arj
davem
davem
davem
andmur01
amitay
matttbe
pabeni
istokes
aparcar
Ansuel
goliath
martineau
tytso
danielschwierzeck
mariosix
dcaratti
aserdean
ovsrobot
ovsrobot
tpetazzoni
XiaoYang
hs
marex
khem
mkorpershoek
liwang
apritzel
danielhb
groug
robimarko
mmichelson
pareddja
npiggin
atishp
netdrv
mkubecek
stintel
stintel
jkicinski
cpitchen
maximeh
dsa
jstancek
pm215
bpf
jonhunter
shettyg
lorpie01
acelan
wigyori
wigyori
apopple
dja
alexhung
lynxis
lynxis
brgl
brgl
peda
akodanev
0andriy
981213
narmstrong
snowpatch_ozlabs
snowpatch_ozlabs
snowpatch_ozlabs
aivanov
atishp04
shemminger
blocktrron
vigneshr
monstr
mraynal
chunkeey
stewart
stewart
jacmet
kabel
kevery
horms
ivanhu
ehristev
rfried
sjg
metan
wsa
xypron
freenix
Jaehoon
rsalvaterra
adrianschmutzler
akumar
hegdevasant
hegdevasant
prom
ag
jagan
bmeng
rmilecki
rmilecki
ukleinek
ukleinek
arbab
trini
chleroy
apconole
wbx
rw
rw
pablo
pablo
legoater
legoater
legoater
svanheule
abelloni
bjonglez
ynezz
pevik
sbabic
sbabic
aik
xback
xback
richiejp
dangole
dangole
anuppatel
anuppatel
next_ghost
forty
acer
echaudron
benh
Hauke
Hauke
rgrimm
segher
pratyush
passgat
jms
jms
jms
mans0n
ruscur
jk
jk
jk
jk
festevam
xuyang
linusw
linusw
Andes
numans
jmberg
ymorin
ymorin
tambarus
kubu
matthias_bgg
conchuod
apalos
krzk
spectrum
strlen
strlen
pbrobinson
stroese
dceara
imaximets
cazzacarna
neocturne
aldot
TIENFONG
mpe
sfr
galak
ktraynor
arnout
anguy11
nbd
nbd
robh
paulus
calebccff
jm
Apply
«
1
2
»
Patch
Series
A/F/R/T
S/W/F
Date
Submitter
Delegate
State
[nf-next,v2,5/5] netfilter: nf_tables: allocate element update information dynamically
netfilter: nf_tables: reduce set element transaction size
- - - -
-
-
-
2024-10-11
Florian Westphal
New
[nf-next,v2,4/5] netfilter: nf_tables: switch trans_elem to real flex array
netfilter: nf_tables: reduce set element transaction size
- - - -
-
-
-
2024-10-11
Florian Westphal
New
[nf-next,v2,3/5] netfilter: nf_tables: prepare for multiple elements in nft_trans_elem structure
netfilter: nf_tables: reduce set element transaction size
- - - -
-
-
-
2024-10-11
Florian Westphal
New
[nf-next,v2,2/5] netfilter: nf_tables: add nft_trans_commit_list_add_elem helper
netfilter: nf_tables: reduce set element transaction size
- - - -
-
-
-
2024-10-11
Florian Westphal
New
[nf-next,v2,1/5] netfilter: nf_tables: prefer nft_trans_elem_alloc helper
netfilter: nf_tables: reduce set element transaction size
- - - -
-
-
-
2024-10-11
Florian Westphal
New
[nft] tests: shell: fix spurious dump failure in vmap timeout test
[nft] tests: shell: fix spurious dump failure in vmap timeout test
- 1 - -
-
-
-
2024-10-11
Florian Westphal
New
[net] netfilter: nf_tables: Fix memory leak in nf_flow_offload_xdp_setup()
[net] netfilter: nf_tables: Fix memory leak in nf_flow_offload_xdp_setup()
- 1 - -
-
-
-
2024-10-10
Lorenzo Bianconi
New
[nf] netfilter: bpf: must hold reference on net namespace
[nf] netfilter: bpf: must hold reference on net namespace
- 1 - -
-
-
-
2024-10-10
Florian Westphal
New
[nft] doc: extend description of fib expression
[nft] doc: extend description of fib expression
- - - -
-
-
-
2024-10-10
Florian Westphal
New
[libnftnl] include: refresh nf_tables.h copy
[libnftnl] include: refresh nf_tables.h copy
- - - -
-
-
-
2024-10-10
Pablo Neira Ayuso
New
nf_conntrack_proto_udp: Set ASSURED for NAT_CLASH entries to avoid packets dropped
nf_conntrack_proto_udp: Set ASSURED for NAT_CLASH entries to avoid packets dropped
1 1 - -
-
-
-
2024-10-10
Yadan Fan
New
[net,3/3] selftests: netfilter: conntrack_vrf.sh: add fib test case
[net,1/3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed
- - - -
-
-
-
2024-10-09
Pablo Neira Ayuso
New
[net,2/3] netfilter: fib: check correct rtable in vrf setups
[net,1/3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed
- 1 - -
-
-
-
2024-10-09
Pablo Neira Ayuso
New
[net,1/3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed
[net,1/3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed
- 1 - -
-
-
-
2024-10-09
Pablo Neira Ayuso
New
[net,0/3] Netfilter fixes for net
- - - -
-
-
-
2024-10-09
Pablo Neira Ayuso
New
netfilter: Record uid and gid in xt_AUDIT
netfilter: Record uid and gid in xt_AUDIT
- - - -
-
-
-
2024-10-09
Richard Weinberger
New
[iptables,3/3] tests: shell: Test some commands involving rule numbers
[iptables,1/3] ebtables: Fix for -S with rule number
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,2/3] nft: Fix for -Z with bogus rule number
[iptables,1/3] ebtables: Fix for -S with rule number
- 1 - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,1/3] ebtables: Fix for -S with rule number
[iptables,1/3] ebtables: Fix for -S with rule number
- 1 - -
-
-
-
2024-10-09
Phil Sutter
New
[nft,v2] libnftables: remove set element uncollapse for error reporting
[nft,v2] libnftables: remove set element uncollapse for error reporting
- 1 - -
-
-
-
2024-10-09
Pablo Neira Ayuso
New
[iptables,v2,8/8] tests: iptables-test: Add nft-compat variant
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,7/8] nft: Embed compat extensions in rule userdata
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,6/8] nft: Pass nft_handle into add_{action,match}()
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,5/8] nft-ruleparse: Fallback to compat expressions in userdata
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,4/8] nft: Introduce UDATA_TYPE_COMPAT_EXT
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,3/8] nft: __add_{match,target}() can't fail
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,2/8] nft: ruleparse: Introduce nft_parse_rule_expr()
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,v2,1/8] nft: Make add_log() static
nft: Implement forward compat for future binaries
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,5/5] xshared: iptables does not support '-b'
Some minor fixes
- 1 - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,4/5] gitignore: Ignore generated arptables-translate.8
Some minor fixes
- 1 - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,3/5] man: ebtables-nft.8: Note that --concurrent is a NOP
Some minor fixes
- 1 - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,2/5] man: xtables-legacy.8: Join two paragraphs
Some minor fixes
- - - -
-
-
-
2024-10-09
Phil Sutter
New
[iptables,1/5] tests: iptables-test: Append stderr output to log file
Some minor fixes
- - - -
-
-
-
2024-10-09
Phil Sutter
New
doc: don't suggest to disable GSO
doc: don't suggest to disable GSO
- 1 - -
-
-
-
2024-10-06
Ronan Pigott
New
[libnetfilter_queue] build: add missing backslash to build_man.sh
[libnetfilter_queue] build: add missing backslash to build_man.sh
- 1 - -
-
-
-
2024-10-04
Duncan Roe
New
[nft,9/9] monitor: Support NFT_MSG_(NEW|DEL)DEV events
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,8/9] tests: monitor: Support running external commands
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,7/9] tests: shell: Adjust to ifname-based flowtables
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,6/9] parser_bison: Accept ASTERISK_STRING in flowtable_expr_member
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,5/9] mnl: Support simple wildcards in netdev hooks
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,4/9] tests: monitor: Run in own netns
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,3/9] monitor: Recognize flowtable add/del events
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,2/9] tests: py: Fix for storing payload into missing file
Support wildcard netdev hooks and events
- 1 - -
-
-
-
2024-10-02
Phil Sutter
New
[nft,1/9] json: Support typeof in set and map types
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[libnftnl,4/4] device: Introduce nftnl_device
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[libnftnl,3/4] utils: Introduce nftnl_parse_str_attr()
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[libnftnl,2/4] utils: Add helpers for interface name wildcards
Support wildcard netdev hooks and events
- - - -
-
-
-
2024-10-02
Phil Sutter
New
[libnftnl,1/4] include: utils.h needs errno.h
Support wildcard netdev hooks and events
- 1 - -
-
-
-
2024-10-02
Phil Sutter
New
[nf-next,4/4] netfilter: nf_tables: use skb_drop_reason
netfilter: use skb_drop_reason in more places
- - - -
-
-
-
2024-10-02
Florian Westphal
New
[nf-next,3/4] netfilter: nf_nat: use skb_drop_reason
netfilter: use skb_drop_reason in more places
- - - -
-
-
-
2024-10-02
Florian Westphal
New
[nf-next,2/4] netfilter: xt_nat: drop packet earlier
netfilter: use skb_drop_reason in more places
- - - -
-
-
-
2024-10-02
Florian Westphal
New
[nf-next,1/4] netfilter: xt_nat: compact nf_nat_setup_info calls
netfilter: use skb_drop_reason in more places
- - - -
-
-
-
2024-10-02
Florian Westphal
New
[nf-next,v6] netfilter: Make legacy configs user selectable
[nf-next,v6] netfilter: Make legacy configs user selectable
- - - -
-
-
-
2024-09-30
Breno Leitao
New
nf_conntrack_proto_udp: do not accept packets with IPS_NAT_CLASH
nf_conntrack_proto_udp: do not accept packets with IPS_NAT_CLASH
- 1 - -
-
-
-
2024-09-30
Hannes Reinecke
New
[nf-next,v5,18/18] selftests: netfilter: Torture nftables netdev hooks
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,17/18] netfilter: nf_tables: Add notications for hook changes
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,16/18] netfilter: nf_tables: Support wildcard netdev hook specs
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,15/18] netfilter: nf_tables: Handle NETDEV_CHANGENAME events
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,14/18] netfilter: nf_tables: Wrap netdev notifiers
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,13/18] netfilter: nf_tables: flowtable: Respect NETDEV_REGISTER events
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,12/18] netfilter: nf_tables: chain: Respect NETDEV_REGISTER events
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,11/18] netfilter: nf_tables: Have a list of nf_hook_ops in nft_hook
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,10/18] netfilter: nf_tables: Drop __nft_unregister_flowtable_net_hooks()
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,09/18] netfilter: nf_tables: Introduce nft_register_flowtable_ops()
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,08/18] netfilter: nf_tables: Introduce nft_hook_find_ops()
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,07/18] netfilter: nf_tables: Introduce functions freeing nft_hook objects
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,06/18] netfilter: nf_tables: Simplify chain netdev notifier
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,05/18] netfilter: nf_tables: Tolerate chains with no remaining hooks
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,04/18] netfilter: nf_tables: Compare netdev hooks based on stored name
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,03/18] netfilter: nf_tables: Use stored ifname in netdev hook dumps
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,02/18] netfilter: nf_tables: Store user-defined hook ifname
Dynamic hook interface binding
- - - -
-
-
-
2024-09-26
Phil Sutter
New
[nf-next,v5,01/18] netfilter: nf_tables: Flowtable hook's pf value never varies
Dynamic hook interface binding
- 1 - -
-
-
-
2024-09-26
Phil Sutter
New
[v4] net/bridge: Optimizing read-write locks in ebtables.c
[v4] net/bridge: Optimizing read-write locks in ebtables.c
- - - -
-
-
-
2024-09-25
yushengjin
New
[nf-next,7/7] netfilter: nft_flow_offload: do not remove flowtable entry for fin packets
netfilter: rework conntrack/flowtable interaction
- - - -
-
-
-
2024-09-24
Florian Westphal
New
[nf-next,6/7] netfilter: nft_flow_offload: never grow the timeout when moving packets back to slowp…
netfilter: rework conntrack/flowtable interaction
- - - -
-
-
-
2024-09-24
Florian Westphal
New
[nf-next,5/7] netfilter: conntrack: rework offload nf_conn timeout extension logic
netfilter: rework conntrack/flowtable interaction
- - - -
-
-
-
2024-09-24
Florian Westphal
New
[nf-next,4/7] netfilter: flowtable: prefer plain nf_ct_refresh for setting initial timeout
netfilter: rework conntrack/flowtable interaction
- - - -
-
-
-
2024-09-24
Florian Westphal
New
[nf-next,3/7] netfilter: conntrack: remove skb argument from nf_ct_refresh
netfilter: rework conntrack/flowtable interaction
- - - -
-
-
-
2024-09-24
Florian Westphal
New
[nf-next,2/7] netfilter: nft_flow_offload: update tcp state flags under lock
netfilter: rework conntrack/flowtable interaction
- 1 - -
-
-
-
2024-09-24
Florian Westphal
New
[nf-next,1/7] netfilter: nft_flow_offload: clear tcp MAXACK flag before moving to slowpath
netfilter: rework conntrack/flowtable interaction
- - - -
-
-
-
2024-09-24
Florian Westphal
New
netfilter: conntrack: tcp: do not lower timeout to CLOSE for in-window RSTs
netfilter: conntrack: tcp: do not lower timeout to CLOSE for in-window RSTs
- - - -
-
-
-
2024-07-05
yyxRoy
Under Review
[nf] netfilter: restore default behavior for nf_conntrack_events
[nf] netfilter: restore default behavior for nf_conntrack_events
- 1 - -
-
-
-
2024-06-04
Nicolas Dichtel
New
[nft] limit: Support arbitrary unit values
[nft] limit: Support arbitrary unit values
- - - -
-
-
-
2024-04-13
Phil Sutter
New
[nf,2/2] netfilter: flowtable: use UDP timeout after flow teardown
[nf,1/2] netfilter: flowtable: infer TCP state and timeout before flow teardown
- 1 - -
-
-
-
2024-03-20
Pablo Neira Ayuso
New
[nf,1/2] netfilter: flowtable: infer TCP state and timeout before flow teardown
[nf,1/2] netfilter: flowtable: infer TCP state and timeout before flow teardown
- 1 - -
-
-
-
2024-03-20
Pablo Neira Ayuso
New
[nf] netfilter: nf_tables: do not reject dormant flag update for table with owner
[nf] netfilter: nf_tables: do not reject dormant flag update for table with owner
- 1 - -
-
-
-
2024-03-15
Quan Tian
New
[nf] netfilter: nf_tables: fix consistent table updates being rejected
[nf] netfilter: nf_tables: fix consistent table updates being rejected
- 1 - -
-
-
-
2024-03-13
Quan Tian
New
[v3,nf-next,2/2] netfilter: nf_tables: support updating userdata for nft_table
[v3,nf-next,1/2] netfilter: nf_tables: use struct nlattr * to store userdata for nft_table
- - - -
-
-
-
2024-03-11
Quan Tian
New
[v3,nf-next,1/2] netfilter: nf_tables: use struct nlattr * to store userdata for nft_table
[v3,nf-next,1/2] netfilter: nf_tables: use struct nlattr * to store userdata for nft_table
- - - -
-
-
-
2024-03-11
Quan Tian
New
[nf-next] netfilter: nft_byteorder: remove multi-register support
[nf-next] netfilter: nft_byteorder: remove multi-register support
- 1 - -
-
-
-
2024-02-14
Florian Westphal
New
[v3,nft] support for afl++ (american fuzzy lop++) fuzzer
[v3,nft] support for afl++ (american fuzzy lop++) fuzzer
- - - -
-
-
-
2023-12-19
Florian Westphal
New
ulogd / JSON output / enhancement proposal
ulogd / JSON output / enhancement proposal
- - - -
-
-
-
2023-12-14
Gérald Colangelo
New
Bug in ulogd2 when destroying a stack that failed to start (with fix attached)
Bug in ulogd2 when destroying a stack that failed to start (with fix attached)
- - - -
-
-
-
2023-12-14
Gérald Colangelo
New
[libnetfilter_queue,1/1] src: add nfq_socket_sendto() - send config request and check response
src: add nfq_socket_sendto() - send config request and check response
- - - -
-
-
-
2023-12-11
Duncan Roe
New
[ulogd] log NAT events using IPFIX
[ulogd] log NAT events using IPFIX
- - - -
-
-
-
2023-12-10
Tomasz Pala
New
[nft,2/2,v2] tests/shell: have .json-nft dumps prettified to wrap lines
Untitled series #385629
- - - -
-
-
-
2023-12-07
Thomas Haller
New
[nft,v2,5/5] tests/unit: add unit tests for libnftables
add infrastructure for unit tests
- - - -
-
-
-
2023-11-05
Thomas Haller
New
[nft,v2,4/5] build: cleanup if-blocks for conditional compilation in "Makefile.am"
add infrastructure for unit tests
- - - -
-
-
-
2023-11-05
Thomas Haller
New
[nft,v2,3/5] build: add `make check-tree` to check consistency of source tree
add infrastructure for unit tests
- - - -
-
-
-
2023-11-05
Thomas Haller
New
[nft,v2,2/5] build: add `make check-build` to run `./tests/build/run-tests.sh`
add infrastructure for unit tests
- - - -
-
-
-
2023-11-05
Thomas Haller
New
«
1
2
»