Show patches with: State = Action Required       |   166 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
selftests: netfilter: fix nft_audit.sh auditd detection selftests: netfilter: fix nft_audit.sh auditd detection - - - - --- 2026-09-11 Jin Li New
selftests: netfilter: add functional test for nft ct timeout policies selftests: netfilter: add functional test for nft ct timeout policies - - - - --- 2026-08-05 Valery Borovsky New
netfilter: nft_synproxy: use the family-aware checksum helper netfilter: nft_synproxy: use the family-aware checksum helper - 1 - - --- 2026-09-10 Karl Mehltretter New
netfilter: nft_flow_offload: drop flowtable reference on init error path netfilter: nft_flow_offload: drop flowtable reference on init error path - 1 - - --- 2026-09-10 Aohan Mei New
netfilter: nf_conntrack_h323: fix OOB read in decode_enum() netfilter: nf_conntrack_h323: fix OOB read in decode_enum() - 1 - - --- 2026-09-07 Aamir Ahmed New
netfilter: nf_conntrack: validate template helper protocol netfilter: nf_conntrack: validate template helper protocol - 1 - - --- 2026-08-10 Kyle Zeng Under Review
netfilter: nf_conntrack: avoid truncating IPv6 nexthdr offset netfilter: nf_conntrack: avoid truncating IPv6 nexthdr offset - 1 - - --- 2026-08-22 Jérémy Jean New
netfilter: ipset: harden payload calculation in call_ad() netfilter: ipset: harden payload calculation in call_ad() 1 - - - --- 2026-03-13 David Baum kadlec Under Review
netfilter: flowtable: publish HW_DEAD after worker is done netfilter: flowtable: publish HW_DEAD after worker is done - 1 - - --- 2026-08-18 Jérémy Jean New
netfilter: flowtable: flush delete work after final GC netfilter: flowtable: flush delete work after final GC - 1 - - --- 2026-08-24 Chengfeng Ye New
netfilter: conntrack_irc: fix port value truncation in parse_dcc() netfilter: conntrack_irc: fix port value truncation in parse_dcc() - 1 - - --- 2026-09-06 Aamir Ahmed New
netfilter: conntrack_amanda: fix port value truncation netfilter: conntrack_amanda: fix port value truncation - 1 1 - --- 2026-09-06 Aamir Ahmed New
netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation netfilter: conntrack: fix nf_conntrack_expect_max default value in documentation - - - - --- 2026-08-20 Shaojie Sun New
net: netfilter: fix typo "specifiy" in comment net: netfilter: fix typo "specifiy" in comment - - - - --- 2026-09-04 Hemanth Selam New
ipvs: clear IPv4 options after rebasing tunnel ICMP errors ipvs: clear IPv4 options after rebasing tunnel ICMP errors - 1 - - --- 2026-07-31 David Lee New
[v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh [v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh - - - - --- 2026-05-12 Eric Woudstra New
[v4,nf,2/2] ipvs: bound LBLCR and LBLC cache growth ipvs: fix LBLC and LBLCR cache growth 1 1 - - --- 2026-09-10 Julian Anastasov New
[v4,nf,1/2] ipvs: fix missing counter decrement in lblc ipvs: fix LBLC and LBLCR cache growth - 1 - - --- 2026-09-10 Julian Anastasov New
[v20,nf-next,2/2] netfilter: bridge: Add conntrack double vlan and pppoe conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,1/2] netfilter: utils: nf_ip(6)_checksum(_partial) correct data!=networkheader conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v2,nf] ipvs: revalidate ihl before icmp_send [v2,nf] ipvs: revalidate ihl before icmp_send - 1 - - --- 2026-09-11 Julian Anastasov New
[v12,nf-next] netfilter: nft_flow_offload: Add DEV_PATH_MTK_WDMA to nft_dev_path_info() [v12,nf-next] netfilter: nft_flow_offload: Add DEV_PATH_MTK_WDMA to nft_dev_path_info() - - 1 - --- 2026-03-17 Eric Woudstra Needs Review / ACK
[v12,nf-next] bridge: Introduce DEV_PATH_BR_VLAN_KEEP_HW [v12,nf-next] bridge: Introduce DEV_PATH_BR_VLAN_KEEP_HW - - - - --- 2026-03-17 Eric Woudstra Needs Review / ACK
[nftables] include: fix for musl with iptables v1.8.11 [nftables] include: fix for musl with iptables v1.8.11 - - - - --- 2024-12-19 Alyssa Ross New
[nft] tests: shell: drop metainfo from the json dump comparison [nft] tests: shell: drop metainfo from the json dump comparison - - - - --- 2026-09-11 Avinash Duduskar New
[nft] src: release scope symbols by reference count [nft] src: release scope symbols by reference count - 1 - - --- 2026-09-11 Avinash Duduskar New
[nft] payload: restore is_raw flag for th expressions parsed from udata [nft] payload: restore is_raw flag for th expressions parsed from udata - - - - --- 2026-08-25 Adrian Moisey New
[nft] limit: Support arbitrary unit values [nft] limit: Support arbitrary unit values - - - - --- 2024-04-13 Phil Sutter New
[nft] json: output set/map element count [nft] json: output set/map element count - - - - --- 2026-04-19 Niklas Fiekas New
[nft] datatype: Accept IPv4 addresses for ip6addr_type [nft] datatype: Accept IPv4 addresses for ip6addr_type - - - - --- 2025-12-10 Phil Sutter New
[nft] cache: Fix for multiple commands in a single batch [nft] cache: Fix for multiple commands in a single batch - 1 - - --- 2026-03-11 Phil Sutter New
[nft,v3] src: add connlimit stateful object support [nft,v3] src: add connlimit stateful object support - - 1 - --- 2025-11-24 Fernando Fernandez Mancera New
[nft,v3] evaluate: reject negative values for unsigned datatypes [nft,v3] evaluate: reject negative values for unsigned datatypes - 1 - - --- 2026-09-11 Avinash Duduskar New
[nft,v2] src: Convert ip {s,d}addr to IPv4-mapped as needed [nft,v2] src: Convert ip {s,d}addr to IPv4-mapped as needed - - - - --- 2025-12-10 Phil Sutter New
[nft,v2] evaluate: reject negative values for unsigned datatypes [nft,v2] evaluate: reject negative values for unsigned datatypes - 1 - - --- 2026-08-14 Avinash Duduskar New
[nft,v2,5/5] libnftables: support for several reset commands support for several list and reset commands - 1 - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,4/5] src: allow reset commands in batch with list and get commands only support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,3/5] libnftables: use nft_run_cmds() in nft_run_cmd_from_filename() support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,2/5] libnftables: split nft_run_cmd_from_buffer() in helper functions support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,v2,1/5] libnftables: add nft_run_cmd_release() helper and use it support for several list and reset commands - - - - --- 2026-06-23 Pablo Neira Ayuso New
[nft,2/2] tests: shell: add JSON delete test for ct stateful objects parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nft,2/2] parser_bison: Accept non-constant binop on LHS of relationals A bit of non-constant binop follow-up - - - - --- 2026-04-02 Phil Sutter New
[nft,1/2] parser_json: fix CMD_OBJ/NFT_OBJECT mismatch in delete path parser_json: fix JSON delete of ct stateful objects - - - - --- 2026-08-11 Gergely Palotas New
[nft,1/2] parser_json: Accept non-RHS expressions in binop RHS A bit of non-constant binop follow-up - 1 - - --- 2026-04-02 Phil Sutter New
[nf] netfilter: nf_tables: skip expired catchall elements in dedup walk [nf] netfilter: nf_tables: skip expired catchall elements in dedup walk - 1 - - --- 2026-09-08 Aohan Mei New
[nf] netfilter: nf_tables: Fix netdev hook sanity checks [nf] netfilter: nf_tables: Fix netdev hook sanity checks - 1 - - --- 2026-08-27 Phil Sutter New
[nf] netfilter: ipset: do not update comments from kernel-side adds [nf] netfilter: ipset: do not update comments from kernel-side adds - 1 - - --- 2026-09-04 Florian Westphal New
[nf] netfilter: flowtable: advertise the vlan match in used_keys [nf] netfilter: flowtable: advertise the vlan match in used_keys - 1 - - --- 2026-09-06 Julius Bairaktaris New
[nf] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter [nf] netfilter: ctnetlink: fix inverted IPv6 address match in dump filter - 1 - - --- 2026-09-09 Piotr Kubik New
[nf] netfilter: conntrack: correct sequence on reinitialized TCP connection [nf] netfilter: conntrack: correct sequence on reinitialized TCP connection - 1 - - --- 2025-02-20 Pablo Neira Ayuso New
[nf] net/sched: act_ct: set net pointer before publishing flowtable [nf] net/sched: act_ct: set net pointer before publishing flowtable - 1 1 - --- 2026-09-09 Qingfang Deng New
[nf] ipvs: read the seq_mask only once on sync [nf] ipvs: read the seq_mask only once on sync - 1 - - --- 2026-09-09 Julian Anastasov New
[nf] ipvs: fix more races around the overload flag [nf] ipvs: fix more races around the overload flag - 1 - - --- 2026-09-07 Julian Anastasov New
[nf] ipvs: fix buffer overflow when sending sync messages [nf] ipvs: fix buffer overflow when sending sync messages - 1 - - --- 2026-09-09 Julian Anastasov New
[nf] ipvs: filter some flags received in the backup server [nf] ipvs: filter some flags received in the backup server - 1 - - --- 2026-09-11 Julian Anastasov New
[nf-next] netfilter: flowtable: remove inline segmentation [nf-next] netfilter: flowtable: remove inline segmentation - - - - --- 2026-06-03 Qingfang Deng New
[nf-next] netfilter: flowtable: check namespace before iterating flows [nf-next] netfilter: flowtable: check namespace before iterating flows - - - - --- 2026-09-09 Qingfang Deng New
[nf-next] netfilter: conntrack: sctp: validate vtag before state changes [nf-next] netfilter: conntrack: sctp: validate vtag before state changes - - - - --- 2026-07-31 Yizhou Zhao New
[nf-next] netfilter: conntrack: prevent nf_conntrack_buckets race condition [nf-next] netfilter: conntrack: prevent nf_conntrack_buckets race condition - 1 - - --- 2026-09-11 Fernando Fernandez Mancera New
[nf-next] netfilter: conntrack: make filtering by zone discoverable [nf-next] netfilter: conntrack: make filtering by zone discoverable - - - - --- 2026-09-04 Ilya Maximets New
[nf-next,v5] netfilter: flowtable: initial bridge support [nf-next,v5] netfilter: flowtable: initial bridge support - - - - --- 2026-07-13 Pablo Neira Ayuso New
[nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers [nf-next,v4] netfilter: ip6tables: hotdrop malformed hbh/dst and srh headers - - - - --- 2026-08-07 Zhixing Chen New
[nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay [nf-next,v3] netfilter: ipset: skip extension destroy on hash resize replay - 1 - - --- 2026-07-13 Weiming Shi New
[nf-next,v3,8/8] netfilter: ipset: use GFP_KERNEL_ACCOUNT [nf-next,v3,1/8] netfilter: x_tables: use GFP_KERNEL_ACCOUNT in match/target - - - - --- 2026-09-07 Pablo Neira Ayuso New
[nf-next,v2] netfilter: osf: remove unreachable break in nf_osf_ttl() [nf-next,v2] netfilter: osf: remove unreachable break in nf_osf_ttl() - - - - --- 2026-08-21 Linkui Xiao New
[nf-next,v2] netfilter: conntrack: make filtering by zone discoverable [nf-next,v2] netfilter: conntrack: make filtering by zone discoverable - - - - --- 2026-09-10 Ilya Maximets New
[nf-next,v2,6/6] net: netfilter: nf_flow_table: unify tunnel push for IPv4 and IPv6 net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,5/6] net: netfilter: nf_flow_table: refactor MTU check for tunnel offload net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,4/6] net: netfilter: add encap_proto to flow_offload_tunnel net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,3/6] net: netfilter: nf_flow_table: populate tunnel tuple regardless of inner protocol net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,3/3] selftests: netfilter: fix typo "adress" in comment netfilter: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[nf-next,v2,2/6] net: netfilter: nf_flow_table: set inner protocol when popping tunnel header net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,2/3] netfilter: ipset: fix typo "artifical" in comment netfilter: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[nf-next,v2,2/2] selftests: netfilter: nft_flowtable.sh: check the priority a flow carries [nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload - - - - --- 2026-09-02 Julius Bairaktaris New
[nf-next,v2,2/2] net: dsa: update net_device stats with HW offloaded flows stats Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nf-next,v2,1/6] net: netfilter: nf_flow_table: recognize IPv4/IPv6 in tunnel proto matching net: netfilter: preliminary support for IPv4 over IPv6 and SIT flowtable offload - - - - --- 2026-09-07 Lorenzo Bianconi New
[nf-next,v2,1/3] netfilter: arp_tables: fix typo "alignement" in comment netfilter: fix typos in comments - - - - --- 2026-09-07 Hemanth Selam New
[nf-next,v2,1/2] netfilter: flowtable: update netdev stats with HW_OFFLOAD flows Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload [nf-next,v2,1/2] netfilter: flowtable: carry a priority into the offload - - - - --- 2026-09-02 Julius Bairaktaris New
[nf-next,4/4] selftests: netfilter: cover a TCP flow whose reply is never seen netfilter: offload a TCP flow whose reply is never seen - - - - --- 2026-09-10 Julius Bairaktaris New
[nf-next,4/4] netfilter: conntrack: Improve invalid packet stats netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,3/4] netfilter: nft_flow_offload: offload a TCP flow that has no reply netfilter: offload a TCP flow whose reply is never seen - - - - --- 2026-09-10 Julius Bairaktaris New
[nf-next,3/4] netfilter: conntrack: nf_ct_seq_adjust to return error cause netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,2/4] netfilter: flowtable: promote a flow offloaded in one direction only netfilter: offload a TCP flow whose reply is never seen - - - - --- 2026-09-10 Julius Bairaktaris New
[nf-next,2/4] netfilter: conntrack: Untangle drop and invalid counters netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,2/2] netfilter: nf_tables: add netlink policy based cap on registers [nf-next,1/2] netfilter: add more netlink-based policy range checks - - - - --- 2026-03-16 Florian Westphal Under Review
[nf-next,1/4] netfilter: conntrack: pick up a TCP flow whose SYN was never answered netfilter: offload a TCP flow whose reply is never seen - - - 1 --- 2026-09-10 Julius Bairaktaris New
[nf-next,1/4] netfilter: conntrack: Untangle insert_failed counter from others netfilter: Conntrack counter review - - - - --- 2026-09-08 Phil Sutter New
[nf-next,1/2] netfilter: add more netlink-based policy range checks [nf-next,1/2] netfilter: add more netlink-based policy range checks - - - - --- 2026-03-16 Florian Westphal Under Review
[nf,v4] netfilter: nfnetlink: Fix for interrupted hook dumps [nf,v4] netfilter: nfnetlink: Fix for interrupted hook dumps - 2 - - --- 2026-09-09 Phil Sutter New
[nf,v3] netfilter: nft_payload: restrict checksum offsets to known values [nf,v3] netfilter: nft_payload: restrict checksum offsets to known values - 1 - - --- 2026-09-05 Florian Westphal New
[nf,v3] netfilter: disable br_netfilter in user namespaces [nf,v3] netfilter: disable br_netfilter in user namespaces - - 1 - --- 2026-08-31 Florian Westphal New
[nf,v3,RESEND,2/2] netfilter: nfnetlink: Fix for interrupted hook dumps [nf,v3,RESEND,1/2] netfilter: nf_nat: unregister and release hooks on error - 2 - - --- 2026-09-09 Pablo Neira Ayuso New
[nf,v2] netfilter: nf_tables: skip expired catchall elements on insert and delete [nf,v2] netfilter: nf_tables: skip expired catchall elements on insert and delete - 1 - - --- 2026-09-10 Aohan Mei New
[nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress [nf,v2] netfilter: nf_reject: initialize IPCB at inet ingress - 1 - - --- 2026-08-10 David Lee New
[nf,v2] netfilter: ip6t_rpfilter: reject routes without inet6_dev [nf,v2] netfilter: ip6t_rpfilter: reject routes without inet6_dev - 1 - - --- 2026-09-06 Weiming Shi New
[nf,v2] netfilter: flowtable: hold reference on ct until flow is released [nf,v2] netfilter: flowtable: hold reference on ct until flow is released - 1 - - --- 2026-09-11 Pablo Neira Ayuso New
[nf,v2] ipvs: make destination flags atomic [nf,v2] ipvs: make destination flags atomic - 1 - - --- 2026-07-08 Yizhou Zhao Needs Review / ACK
[nf,v2,1/1] netfilter: x_tables: avoid holding mutex over faultable user copies netfilter: x_tables: avoid holding mutex over faultable user copies - 1 - - --- 2026-09-09 Zihan Xi New
[nf,v2,1/1] netfilter: nf_dup: disable duplication in user namespaces netfilter: nf_dup: disable duplication in user namespaces - 1 - - --- 2026-09-03 Zihan Xi New
« 1 2 »