Show patches with: Submitter = Florian Westphal       |    Archived = No       |   2482 patches
« 1 2 ... 4 5 624 25 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf-next,v2,1/2] netfilter: conntrack: tag conntracks picked up in local out hook nat: force port remap to prevent shadowing well-known ports - - - - --- 2021-12-15 Florian Westphal pablo Accepted
[nf] netfilter: ctnetlink: remove expired entries first [nf] netfilter: ctnetlink: remove expired entries first - - - - --- 2021-12-09 Florian Westphal pablo Accepted
[nft,2/2] src: propagate key datatype for anonymous sets mptcp: add mptcp subtype mnemonics - - - - --- 2021-12-09 Florian Westphal pablo Deferred
[nft,1/2] tcpopt: add phony mptcp suboption datatype mptcp: add mptcp subtype mnemonics - - - - --- 2021-12-09 Florian Westphal pablo Deferred
[nf] selftests: netfilter: switch zone stress to socat [nf] selftests: netfilter: switch zone stress to socat - - - - --- 2021-12-03 Florian Westphal pablo Accepted
[nft,3/3] netlink_delinearize: binop: make accesses to expr->left/right conditional netlink_delinearize cleanups - - - - --- 2021-12-01 Florian Westphal pablo Accepted
[nft,2/3] netlink_delinearize: rename misleading variable netlink_delinearize cleanups - - - - --- 2021-12-01 Florian Westphal pablo Accepted
[nft,1/3] netlink_delinearize: use correct member type netlink_delinearize cleanups - - - - --- 2021-12-01 Florian Westphal pablo Accepted
[nf] netfilter: nat: force port remap to prevent shadowing well-known ports [nf] netfilter: nat: force port remap to prevent shadowing well-known ports - - - - --- 2021-11-29 Florian Westphal pablo Changes Requested
[nf] netfilter: nfnetlink_queue: silence bogus compiler warning [nf] netfilter: nfnetlink_queue: silence bogus compiler warning - - - - --- 2021-11-26 Florian Westphal pablo Accepted
[nf] netfilter: bridge: add support for ppoe filtering [nf] netfilter: bridge: add support for ppoe filtering - 1 - - --- 2021-11-23 Florian Westphal pablo Accepted
[nft,8/8] tests: py: add tcp subtype match test cases mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,7/8] exthdr: fix tcpopt_find_template to use length after mask adjustment mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,6/8] mptcp: add subtype matching mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,5/8] tests: py: add test cases for md5sig, fastopen and mptcp mnemonics mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,4/8] tcpopt: add md5sig, fastopen and mptcp options mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,3/8] parser: split tcp option rules mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,2/8] scanner: add tcp flex scope mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft,1/8] tcpopt: remove KIND keyword mptcp subtype option match support - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_queue: remove leftover synchronize_rcu [nf-next] netfilter: nf_queue: remove leftover synchronize_rcu - - - - --- 2021-11-19 Florian Westphal pablo Accepted
[nft] monitor: do not call interval_map_decompose() for concat intervals [nft] monitor: do not call interval_map_decompose() for concat intervals - - - - --- 2021-11-17 Florian Westphal pablo Accepted
[nf-next,2/2] netfilter: conntrack: speed up netns cleanup netfilter: conntrack: speed up netns dismantle - - - - --- 2021-11-17 Florian Westphal pablo Deferred
[nf-next,1/2] netfilter: conntrack: split nf_conntrack_cleanup_net_list netfilter: conntrack: speed up netns dismantle - - - - --- 2021-11-17 Florian Westphal pablo Deferred
[nf] selftests: nft_nat: switch port shadow test cases to socat [nf] selftests: nft_nat: switch port shadow test cases to socat - - - - --- 2021-11-11 Florian Westphal pablo Accepted
[nft] doc: update ct timeout section with the state names [nft] doc: update ct timeout section with the state names - - - - --- 2021-10-28 Florian Westphal pablo Accepted
[v2,net-next,2/2] vrf: run conntrack only in context of lower/physdev for locally generated packets vrf: rework interaction with netfilter/conntrack 1 - - - --- 2021-10-25 Florian Westphal pablo Awaiting Upstream
[v2,net-next,1/2] netfilter: conntrack: skip confirmation and nat hooks in postrouting for vrf vrf: rework interaction with netfilter/conntrack - - - - --- 2021-10-25 Florian Westphal pablo Awaiting Upstream
[net-next,2/2] vrf: run conntrack only in context of lower/physdev for locally generated packets vrf: rework interaction with netfilter/conntrack - - - - --- 2021-10-21 Florian Westphal pablo Changes Requested
[net-next,1/2] netfilter: conntrack: skip confirmation and nat hooks in postrouting for vrf vrf: rework interaction with netfilter/conntrack - - - - --- 2021-10-21 Florian Westphal pablo Changes Requested
[nf] selftests: netfilter: extend nfqueue tests to cover vrf device [nf] selftests: netfilter: extend nfqueue tests to cover vrf device - - - - --- 2021-10-20 Florian Westphal pablo Accepted
[nf] netfilter: nfnetlink_queue: fix OOB when mac header was cleared [nf] netfilter: nfnetlink_queue: fix OOB when mac header was cleared - 1 - - --- 2021-10-20 Florian Westphal pablo Accepted
[nf] selftests: netfilter: add a vrf+conntrack testcase [nf] selftests: netfilter: add a vrf+conntrack testcase - - - - --- 2021-10-18 Florian Westphal pablo Accepted
[nft] main: _exit() if setuid [nft] main: _exit() if setuid - - - - --- 2021-10-16 Florian Westphal pablo Accepted
[RFC,nf-next,9/9] netfilter: hook_jit: add prog cache netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,8/9] netfilter: ingress: switch to invocation via bpf netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,7/9] netfilter: core: do not rebuild bpf program on dying netns netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,6/9] netfilter: add bpf base hook program generator netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,5/9] netfilter: reduce allowed hook count to 32 netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,4/9] netfilter: make hook functions accept only one argument netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,3/9] netfilter: remove hook index from nf_hook_slow arguments netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,2/9] netfilter: nat: split nat hook iteration into a helper netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[RFC,nf-next,1/9] netfilter: nf_queue: carry index in hook state [RFC,nf-next,1/9] netfilter: nf_queue: carry index in hook state - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[1/1] netfilter: add bpf base hook program generator netfilter: bpf base hook program generator - - - - --- 2021-10-14 Florian Westphal pablo Changes Requested
[nf-next,v2,4/4] netfilter: ipvs: merge ipv4 + ipv6 icmp reply handlers netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Accepted
[nf-next,v2,3/4] netfilter: ipvs: remove unneeded input wrappers netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Accepted
[nf-next,v2,2/4] netfilter: ipvs: remove unneeded output wrappers netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Accepted
[nf-next,v2,1/4] netfilter: ipvs: prepare for hook function reduction netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Accepted
[nf] selftests: netfilter: remove stray bash debug line [nf] selftests: netfilter: remove stray bash debug line - 1 - - --- 2021-10-12 Florian Westphal pablo Accepted
[nf-next,4/4] netfilter: ipvs: merge ipv4 + ipv6 icmp reply handlers netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Changes Requested
[nf-next,3/4] netfilter: ipvs: remove unneeded input wrappers netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Changes Requested
[nf-next,2/4] netfilter: ipvs: remove unneeded output wrappers netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Changes Requested
[nf-next,1/4] netfilter: ipvs: prepare for hook function reduction netfilter: ipvs: remove unneeded hook wrappers - - - - --- 2021-10-12 Florian Westphal pablo Changes Requested
[nf-next,4/4] netfilter: ebtables: allow use of ebt_do_table as hookfn netfilter: remove obsolete hook wrappers - - - - --- 2021-10-11 Florian Westphal pablo Accepted
[nf-next,3/4] netfilter: ip6tables: allow use of ip6t_do_table as hookfn netfilter: remove obsolete hook wrappers - - - - --- 2021-10-11 Florian Westphal pablo Accepted
[nf-next,2/4] netfilter: arp_tables: allow use of arpt_do_table as hookfn netfilter: remove obsolete hook wrappers - - - - --- 2021-10-11 Florian Westphal pablo Accepted
[nf-next,1/4] netfilter: ipv4: allow use of ipt_do_table as hookfn [nf-next,1/4] netfilter: ipv4: allow use of ipt_do_table as hookfn - - - - --- 2021-10-11 Florian Westphal pablo Superseded
[nf-next,1/4] netfilter: iptables: allow use of ipt_do_table as hookfn netfilter: remove obsolete hook wrappers - - - - --- 2021-10-11 Florian Westphal pablo Accepted
[nf] netfilter: nftables: skip netdev events generated on netns removal [nf] netfilter: nftables: skip netdev events generated on netns removal - 1 - - --- 2021-10-06 Florian Westphal pablo Accepted
[nft] netlink: dynset: set compound expr dtype based on set key definition [nft] netlink: dynset: set compound expr dtype based on set key definition - - - - --- 2021-09-28 Florian Westphal pablo Accepted
[nft] payload: don't adjust offsets of autogenerated dependency expressions [nft] payload: don't adjust offsets of autogenerated dependency expressions - - - - --- 2021-09-28 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: fix boot failure with nf_conntrack.enable_hooks=1 [nf] netfilter: conntrack: fix boot failure with nf_conntrack.enable_hooks=1 - 2 - - --- 2021-09-23 Florian Westphal pablo Accepted
[RFC,2/2] netfilter: nf_nat: don't allow source ports that shadow local port [nf,1/2] selftests: nft_nat: add udp hole punch test case - - - - --- 2021-09-23 Florian Westphal pablo RFC
[nf,1/2] selftests: nft_nat: add udp hole punch test case [nf,1/2] selftests: nft_nat: add udp hole punch test case - - - - --- 2021-09-23 Florian Westphal pablo Accepted
[nf] netfilter: log: work around missing softdep backend module [nf] netfilter: log: work around missing softdep backend module - 2 - - --- 2021-09-17 Florian Westphal pablo Accepted
[nf] netfilter: iptable_raw: drop bogus net_init annotation [nf] netfilter: iptable_raw: drop bogus net_init annotation - 1 - - --- 2021-09-17 Florian Westphal pablo Accepted
[nf,2/2] netfilter: nf_nat_masquerade: defer conntrack walk to work queue netfilter: nf_nat_masquerade: don't block rtnl lock - - - - --- 2021-09-15 Florian Westphal pablo Accepted
[nf,1/2] netfilter: nf_nat_masquerade: make async masq_inet6_event handling generic netfilter: nf_nat_masquerade: don't block rtnl lock - - - - --- 2021-09-15 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: unlink table before deleting it [nf] netfilter: nf_tables: unlink table before deleting it - 1 - - --- 2021-09-13 Florian Westphal pablo Accepted
[5.10.y,3/3] netfilter: nftables: clone set element expression template netfilter: nf_tables fixes for 5.10.y - 1 - - --- 2021-09-09 Florian Westphal pablo Awaiting Upstream
[5.10.y,2/3] netfilter: nf_tables: initialize set before expression setup netfilter: nf_tables fixes for 5.10.y - 1 - - --- 2021-09-09 Florian Westphal pablo Awaiting Upstream
[5.10.y,1/3] netfilter: nftables: avoid potential overflows on 32bit arches netfilter: nf_tables fixes for 5.10.y - 1 - - --- 2021-09-09 Florian Westphal pablo Awaiting Upstream
[nf,5/5] selftests: netfilter: add zone stress test with colliding tuples netfilter: conntrack: make zone id part of conntrack hash - - - - --- 2021-09-08 Florian Westphal pablo Accepted
[nf,4/5] selftests: netfilter: add selftest for directional zone support netfilter: conntrack: make zone id part of conntrack hash - - - - --- 2021-09-08 Florian Westphal pablo Accepted
[nf,3/5] netfilter: nat: include zone id in nat table hash again netfilter: conntrack: make zone id part of conntrack hash - - - - --- 2021-09-08 Florian Westphal pablo Accepted
[nf,2/5] netfilter: conntrack: include zone id in tuple hash again netfilter: conntrack: make zone id part of conntrack hash - - - - --- 2021-09-08 Florian Westphal pablo Accepted
[nf,1/5] netfilter: conntrack: make max chain length random [nf,1/5] netfilter: conntrack: make max chain length random - - - - --- 2021-09-08 Florian Westphal pablo Accepted
[nf,1/5] netfilter: conntrack: make connection tracking table less predictable netfilter: conntrack: make zone id part of conntrack hash - - - - --- 2021-09-08 Florian Westphal pablo Superseded
[nf,3/3] netfilter: refuse insertion if chain has grown too large Untitled series #259761 - - - - --- 2021-08-26 Florian Westphal pablo Accepted
[nf,3/3] netfilter: conntrack: refuse insertion if chain has grown too large netfilter: conntrack: switch to siphash - - - - --- 2021-08-26 Florian Westphal pablo Superseded
[nf,2/3] netfilter: conntrack: switch to siphash netfilter: conntrack: switch to siphash - - - - --- 2021-08-26 Florian Westphal pablo Accepted
[nf,1/3] netfilter: conntrack: sanitize table size default settings netfilter: conntrack: switch to siphash - - - - --- 2021-08-26 Florian Westphal pablo Accepted
[nft] parser: permit symbolic defines for 'queue num' again [nft] parser: permit symbolic defines for 'queue num' again - 1 - - --- 2021-08-20 Florian Westphal pablo Accepted
[v2,iptables] iptables-nft: allow removal of empty builtin chains [v2,iptables] iptables-nft: allow removal of empty builtin chains - - - - --- 2021-08-17 Florian Westphal pablo Accepted
[nf-next,5/5] netfilter: ecache: remove nf_exp_event_notifier structure netfilter: ecache: simplify event registration - - - - --- 2021-08-16 Florian Westphal pablo Accepted
[nf-next,4/5] netfilter: ecache: prepare for event notifier merge netfilter: ecache: simplify event registration - - - - --- 2021-08-16 Florian Westphal pablo Accepted
[nf-next,3/5] netfilter: ecache: add common helper for nf_conntrack_eventmask_report netfilter: ecache: simplify event registration - - - - --- 2021-08-16 Florian Westphal pablo Accepted
[nf-next,2/5] netfilter: ecache: remove another indent level netfilter: ecache: simplify event registration - - - - --- 2021-08-16 Florian Westphal pablo Accepted
[nf-next,1/5] netfilter: ecache: remove one indent level netfilter: ecache: simplify event registration - - - - --- 2021-08-16 Florian Westphal pablo Accepted
[iptabes-nft] iptables-nft: allow removal of empty builtin chains [iptabes-nft] iptables-nft: allow removal of empty builtin chains - - - - --- 2021-08-14 Florian Westphal pablo Changes Requested
[nf-next,v2] netfilter: nf_queue: move hookfn registration out of struct net [nf-next,v2] netfilter: nf_queue: move hookfn registration out of struct net - - - - --- 2021-08-05 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_queue: move hookfn registration out of struct net [nf-next] netfilter: nf_queue: move hookfn registration out of struct net - - - - --- 2021-08-05 Florian Westphal Superseded
[v2,nf] netfilter: conntrack: remove offload_pickup sysctl again [v2,nf] netfilter: conntrack: remove offload_pickup sysctl again - - 2 - --- 2021-08-04 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: remove offload_pickup sysctl again [nf] netfilter: conntrack: remove offload_pickup sysctl again - - - - --- 2021-08-04 Florian Westphal pablo Changes Requested
[nf-next] x_tables: never register tables by default [nf-next] x_tables: never register tables by default - - - - --- 2021-08-03 Florian Westphal pablo Accepted
[conntrack-tools,4/4] conntrack: add shorthand mnemonic for UNREPLIED [lnf-conntrack,1/4] include: sync uapi header with nf-next - - - - --- 2021-08-02 Florian Westphal pablo Accepted
[conntrack-tools,3/4] conntrack: enable kernel-based status filtering with -L -u STATUS [lnf-conntrack,1/4] include: sync uapi header with nf-next - - - - --- 2021-08-02 Florian Westphal pablo Accepted
[lnf-conntrack,2/4] src: add support for status dump filter [lnf-conntrack,1/4] include: sync uapi header with nf-next - - - - --- 2021-08-02 Florian Westphal pablo Accepted
[lnf-conntrack,1/4] include: sync uapi header with nf-next [lnf-conntrack,1/4] include: sync uapi header with nf-next - - - - --- 2021-08-02 Florian Westphal pablo Accepted
[nf-next,2/2] netfilter: ctnetlink: allow to filter dump by status bits netfilter: ctnetlink: allow to filter dumps via ct->status - - - - --- 2021-07-30 Florian Westphal pablo Accepted
[nf-next,1/2] netfilter: ctnetlink: add and use a helper for mark parsing netfilter: ctnetlink: allow to filter dumps via ct->status - - - - --- 2021-07-30 Florian Westphal pablo Accepted
« 1 2 ... 4 5 624 25 »