Show patches with: State = Action Required       |   134 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize [nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize - 1 - 1 --- 2026-05-13 Ren Wei kadlec Needs Review / ACK
netfilter: ipset: harden payload calculation in call_ad() netfilter: ipset: harden payload calculation in call_ad() 1 - - - --- 2026-03-13 David Baum kadlec Under Review
[iptables] nft: fix out-of-bounds read listing an old-revision match [iptables] nft: fix out-of-bounds read listing an old-revision match - 1 - - --- 2026-07-17 Omkhar Arasaratnam New
[iptables] nft: bridge: fix among buffer overflow when set has no size [iptables] nft: bridge: fix among buffer overflow when set has no size - 1 - - --- 2026-07-17 Omkhar Arasaratnam New
[nf,v3] netfilter: nf_tables: make nft_object rhltable per table [nf,v3] netfilter: nf_tables: make nft_object rhltable per table - 1 - - --- 2026-07-17 Pablo Neira Ayuso New
[nf-next] ipvs: use type-safe allocation helpers in ip_vs_rht_alloc [nf-next] ipvs: use type-safe allocation helpers in ip_vs_rht_alloc - - 1 - --- 2026-07-16 Subasri S New
[nft] tests: py: Fix --keep test runner option [nft] tests: py: Fix --keep test runner option - 1 - - --- 2026-07-15 Phil Sutter New
[nf] netfilter: conntrack: prevent helper extension relocation [nf] netfilter: conntrack: prevent helper extension relocation - 1 - - --- 2026-07-15 Jaeyeong Lee New
[nf,v2] netfilter: ip6tables: set hotdrop for malformed extension header matches [nf,v2] netfilter: ip6tables: set hotdrop for malformed extension header matches - - - - --- 2026-07-14 Zhixing Chen New
[nf] netfilter: nft_fib: bail out if input device is missing [nf] netfilter: nft_fib: bail out if input device is missing - 1 - - --- 2026-07-13 Xiang Mei New
[nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay [nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay - 1 - - --- 2026-07-13 Weiming Shi New
[nf-next,2/2] netfilter: nf_conntrack_expect: store event cache in expectation [nf-next,1/2] netfilter: conntrack_helper: pass master conntrack to helper functions - - - - --- 2026-07-13 Pablo Neira Ayuso New
[nf-next,1/2] netfilter: conntrack_helper: pass master conntrack to helper functions [nf-next,1/2] netfilter: conntrack_helper: pass master conntrack to helper functions - - - - --- 2026-07-13 Pablo Neira Ayuso New
[nf,v3] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() [nf,v3] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() - 1 - - --- 2026-07-13 Pablo Neira Ayuso New
[nf,v2] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests [nf,v2] selftests: netfilter: nft_flowtable.sh: fix offload counter verification for tunnel tests - 2 - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,6/6] selftests: netfilter: nft_flowtable.sh: add SIT flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,5/6] net: netfilter: add SIT tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,4/6] selftests: netfilter: nft_flowtable.sh: add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,3/6] net: netfilter: add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,2/6] net: netfilter: add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v6,1/6] net: netfilter: add ether_type to net_device_path_ctx Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-13 Lorenzo Bianconi New
[nf-next,v5] netfilter: flowtable: initial bridge support [nf-next,v5] netfilter: flowtable: initial bridge support - - - - --- 2026-07-13 Pablo Neira Ayuso New
[v2,2/2] ipvs: adjust double hashing when fwd method changes [v2,1/2] ipvs: do not propagate one-packet flag to synced conns - 1 - - --- 2026-07-13 Ren Wei New
[v2,1/2] ipvs: do not propagate one-packet flag to synced conns [v2,1/2] ipvs: do not propagate one-packet flag to synced conns 1 1 - - --- 2026-07-13 Ren Wei New
[nf] netfilter: ipset: do not update comments from kernel-side hash adds [nf] netfilter: ipset: do not update comments from kernel-side hash adds 1 1 - - --- 2026-07-13 David Lee New
[nf,v3,2/2] ipvs: use bitops for destination overload state ipvs: fix destination overload state updates - 1 - - --- 2026-07-13 Yizhou Zhao New
[nf,v3,1/2] ipvs: properly update the overload flag on dest edit ipvs: fix destination overload state updates - 1 - - --- 2026-07-13 Yizhou Zhao New
[nf-next,v4] netfilter: flowtable: initial bridge support [nf-next,v4] netfilter: flowtable: initial bridge support - - - - --- 2026-07-13 Pablo Neira Ayuso New
[nf] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() [nf] netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() - 1 - - --- 2026-07-12 Xiang Mei New
[nf,v2] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() [nf,v2] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() - 1 - - --- 2026-07-12 Pablo Neira Ayuso New
[nf-next,v3] netfilter: flowtable: initial bridge support [nf-next,v3] netfilter: flowtable: initial bridge support - - - - --- 2026-07-12 Pablo Neira Ayuso New
[nf,v3] netfilter: flowtable: initial bridge support [nf,v3] netfilter: flowtable: initial bridge support - - - - --- 2026-07-12 Pablo Neira Ayuso New
[nf] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() [nf] netfilter: nf_conntrack_expect: add and use nf_ct_expect_related_pair() - 1 - - --- 2026-07-12 Pablo Neira Ayuso New
[nf,v2,2/2] netfilter: nf_conntrack_expect: reject reinsertion of DEAD expectations [nf,v2,1/2] netfilter: nf_nat: stop reusing DEAD RTP expectations - 1 - - --- 2026-07-12 Jaeyeong Lee New
[nf,v2,1/2] netfilter: nf_nat: stop reusing DEAD RTP expectations [nf,v2,1/2] netfilter: nf_nat: stop reusing DEAD RTP expectations - 1 - - --- 2026-07-12 Jaeyeong Lee New
[12/13,RFC,net-next] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 [01/13,RFC,net-next] net: ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack - - - - --- 2026-07-12 Fernando Fernandez Mancera New
[01/13,RFC,net-next] net: ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack [01/13,RFC,net-next] net: ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack - - - - --- 2026-07-12 Fernando Fernandez Mancera New
[nf] netfilter: nf_nat: do not reuse an unexpected expectation on RTCP clash [nf] netfilter: nf_nat: do not reuse an unexpected expectation on RTCP clash - 1 - - --- 2026-07-11 Jaeyeong Lee New
[nf] selftests: netfilter: nft_flowtable.sh: check offload counters for IP6IP6 tunnel test [nf] selftests: netfilter: nft_flowtable.sh: check offload counters for IP6IP6 tunnel test - 1 - - --- 2026-07-11 Lorenzo Bianconi New
[nf-next,v3,4/4] netfilter: nfnetlink_hook: Fix for concurrent NAT hooks dump and change Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,3/4] netfilter: nfnetlink_hook: Handle multipart NAT hook dumps Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,2/4] netfilter: nfnetlink_hook: Address hook ops using READ_ONCE() Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-10 Phil Sutter New
[nf-next,v3,1/4] netfilter: nfnetlink_hook: Pass cb object to nfnl_hook_dump_nat() Address Sashiko review of NAT hook dump code - - - - --- 2026-07-10 Phil Sutter New
[net,v3] netfilter: nf_nat: recalculate TCP TS offset after SNAT port rewrite [net,v3] netfilter: nf_nat: recalculate TCP TS offset after SNAT port rewrite - 1 - - --- 2026-07-10 xietangxin New
[nf-next,v2,3/3] netfilter: flowtable: initial bridge support initial flowtable bridge support - - - - --- 2026-07-10 Pablo Neira Ayuso New
[nf-next,v2,2/3] net: expose dev_fwd_path() helper via static inline initial flowtable bridge support - - - - --- 2026-07-10 Pablo Neira Ayuso New
[nf-next,v2,1/3] net: pass net_device_path_ctx struct to dev_fill_forward_path() initial flowtable bridge support - - - - --- 2026-07-10 Pablo Neira Ayuso New
[nf,v2] netfilter: flowtable: tear down flow entries with stale dst from GC [nf,v2] netfilter: flowtable: tear down flow entries with stale dst from GC - - - - --- 2026-07-10 Pablo Neira Ayuso New
[nf-next] netfilter: flowtable: tear down flow entries with stale dst from GC [nf-next] netfilter: flowtable: tear down flow entries with stale dst from GC - - - - --- 2026-07-10 Pablo Neira Ayuso New
[nf] ipvs: fix the checksum validations [nf] ipvs: fix the checksum validations - 1 - - --- 2026-07-09 Julian Anastasov New
[nf-next,v2,5/5] netfilter: nfnetlink_hook: Fix for concurrent NAT hooks dump and change Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-09 Phil Sutter New
[nf-next,v2,4/5] netfilter: nfnetlink_hook: Handle multipart NAT hook dumps Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-09 Phil Sutter New
[nf-next,v2,3/5] netfilter: nfnetlink_hook: Address hook ops using READ_ONCE() Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-09 Phil Sutter New
[nf-next,v2,2/5] netfilter: nfnetlink_hook: Pass cb object to nfnl_hook_dump_nat() Address Sashiko review of NAT hook dump code - - - - --- 2026-07-09 Phil Sutter New
[nf-next,v2,1/5] netfilter: nfnetlink_hook: Fix for EINTR due to index too large Address Sashiko review of NAT hook dump code - 1 - - --- 2026-07-09 Phil Sutter New
[nft] mnl: support RLIMIT_NOFILE soft limit > FD_SETSIZE [nft] mnl: support RLIMIT_NOFILE soft limit > FD_SETSIZE - - - - --- 2026-07-09 Cory Snider New
[nf-next,v5,6/6] selftests: netfilter: nft_flowtable.sh: add SIT flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-09 Lorenzo Bianconi New
[nf-next,v5,5/6] net: netfilter: add SIT tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-09 Lorenzo Bianconi New
[nf-next,v5,4/6] selftests: netfilter: nft_flowtable.sh: add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-09 Lorenzo Bianconi New
[nf-next,v5,3/6] net: netfilter: add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-09 Lorenzo Bianconi New
[nf-next,v5,2/6] net: netfilter: add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-09 Lorenzo Bianconi New
[nf-next,v5,1/6] net: netfilter: add ether_type to net_device_path_ctx Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-07-09 Lorenzo Bianconi New
[nf,v2] ipvs: make destination flags atomic [nf,v2] ipvs: make destination flags atomic - 1 - - --- 2026-07-08 Yizhou Zhao Needs Review / ACK
[nf-next,2/4] netfilter: nf_conntrack_sip: replace u_int16_t with u16 netfilter: replace u_int*_t with kernel int types (batch 3) - - - - --- 2026-07-07 Carlos Grillet New
[nf-next,1/4] netfilter: ip_vs_core: replace u_int32_t with u32 netfilter: replace u_int*_t with kernel int types (batch 3) - - - - --- 2026-07-07 Carlos Grillet New
[v12,nf-next,7/7] netfilter: nft_flow_offload: Add bridgeflow to nft_flow_offload_eval() netfilter: Add bridge-fastpath - - - - --- 2026-07-07 Eric Woudstra New
[v12,nf-next,6/7] netfilter: nft_flow_offload: Add NFPROTO_BRIDGE to validate netfilter: Add bridge-fastpath - - 1 - --- 2026-07-07 Eric Woudstra New
[v12,nf-next,5/7] netfilter: nft_flow_offload: nft_flow_offload_eval: check thoff==0 netfilter: Add bridge-fastpath - - - - --- 2026-07-07 Eric Woudstra New
[v12,nf-next,4/7] netfilter: nf_flow_table_inet: Add nf_flowtable_type flowtable_bridge netfilter: Add bridge-fastpath - - 1 - --- 2026-07-07 Eric Woudstra New
[v12,nf-next,3/7] netfilter: nf_flow_table_offload: Add nf_flow_rule_bridge() netfilter: Add bridge-fastpath - - 1 - --- 2026-07-07 Eric Woudstra New
[v12,nf-next,2/7] net: core: dev: Add dev_fill_bridge_path() netfilter: Add bridge-fastpath - - 1 - --- 2026-07-07 Eric Woudstra New
[v12,nf-next,1/7] bridge: Add filling forward path from port to port netfilter: Add bridge-fastpath 1 - - - --- 2026-07-07 Eric Woudstra New
[nf-next] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet [nf-next] netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet - 1 - - --- 2026-07-06 Florian Westphal New
[nf] netfilter: nf_conncount: fix zone comparison in tuple dedup [nf] netfilter: nf_conncount: fix zone comparison in tuple dedup - 2 - - --- 2026-07-06 Yizhou Zhao New
[nf-next] netfilter: xt_tcpmss: extend checkentry to ipv6 [nf-next] netfilter: xt_tcpmss: extend checkentry to ipv6 - 1 - - --- 2026-07-04 Florian Westphal New
[nf] netfilter: ipset: skip extension destroy on hash resize replay [nf] netfilter: ipset: skip extension destroy on hash resize replay - 1 - - --- 2026-07-04 Weiming Shi Needs Review / ACK
[nf,1/1] netfilter: xt_time: reject pre-epoch calendar matching [nf,1/1] netfilter: xt_time: reject pre-epoch calendar matching - 1 2 - --- 2026-07-03 Ren Wei New
[v2,nf-next] ipvs: Move defense_work and est_reload_work to system_dfl_long_wq [v2,nf-next] ipvs: Move defense_work and est_reload_work to system_dfl_long_wq 1 - - - --- 2026-07-02 Ismael Luceno New
[nft,v2,5/5] libnftables: support for several reset commands support for several list and reset commands - 1 - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,4/5] src: allow reset commands in batch with list and get commands only support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,3/5] libnftables: use nft_run_cmds() in nft_run_cmd_from_filename() support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,2/5] libnftables: split nft_run_cmd_from_buffer() in helper functions support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,1/5] libnftables: add nft_run_cmd_release() helper and use it support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nf,v3,2/2] selftests: netfilter: add bridge tunnel flowtable regression [nf,v3,1/2] netfilter: nf_flow_table: separate tunnel route state from direct xmit - - - - --- 2026-06-22 Ren Wei New
[nft,v2] parser_bison: Fix for bison < 3.6 [nft,v2] parser_bison: Fix for bison < 3.6 - 1 - - --- 2026-06-11 Phil Sutter New
[nft,6/6] netlink: Call tunnel getters unconditionally Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,5/6] src: Avoid variable declarations in switch cases Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,4/6] rule: Introduce tunnel_obj_print_data() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,3/6] rule: Turn obj_print_comment() into obj_print_header() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,2/6] parser_json: Introduce json_parse_tunnel() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,1/6] json: Introduce tunnel_obj_print_json() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nf-next] netfilter: flowtable: remove inline segmentation [nf-next] netfilter: flowtable: remove inline segmentation - - - - --- 2026-06-03 Qingfang Deng New
[9/9,nf-next] netfilter: conncount: use DEBUG_NET_WARN_ON_ONCE on reaching count limit netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[8/9,nf-next] netfilter: flowtable: use DEBUG_NET_WARN_ON_ONCE in offload path netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[7/9,nf-next] netfilter: bpf: use DEBUG_NET_WARN_ON_ONCE for missing BTF structures netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[6/9,nf-next] netfilter: tproxy: use DEBUG_NET_WARN_ON_ONCE for protocol fallbacks netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[5/9,nf-next] netfilter: nat: use DEBUG_NET_WARN_ON_ONCE in core and helper paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[4/9,nf-next] netfilter: conntrack: use DEBUG_NET_WARN_ON_ONCE on packet paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[3/9,nf-next] netfilter: nfnetlink: use DEBUG_NET_WARN_ON_ONCE for attribute validation netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[1/9,nf-next] netfilter: xtables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
« 1 2 »