Show patches with: State = Action Required       |    Archived = No       |   123 patches
« 1 2 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nft] limit: Support arbitrary unit values [nft] limit: Support arbitrary unit values - - - - --- 2024-04-13 Phil Sutter New
[nftables] include: fix for musl with iptables v1.8.11 [nftables] include: fix for musl with iptables v1.8.11 - - - - --- 2024-12-19 Alyssa Ross New
[nf] netfilter: conntrack: correct sequence on reinitialized TCP connection [nf] netfilter: conntrack: correct sequence on reinitialized TCP connection - 1 - - --- 2025-02-20 Pablo Neira Ayuso New
[V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl [V6] netfilter: netns nf_conntrack: per-netns net.netfilter.nf_conntrack_max sysctl - - - - --- 2025-04-15 lvxiafei Under Review
[libnftnl] src: add connlimit stateful object support [libnftnl] src: add connlimit stateful object support - - - - --- 2025-11-04 Fernando Fernandez Mancera New
[nft,v3] src: add connlimit stateful object support [nft,v3] src: add connlimit stateful object support - - 1 - --- 2025-11-24 Fernando Fernandez Mancera New
[nft,v2] src: Convert ip {s,d}addr to IPv4-mapped as needed [nft,v2] src: Convert ip {s,d}addr to IPv4-mapped as needed - - - - --- 2025-12-10 Phil Sutter New
[nft] datatype: Accept IPv4 addresses for ip6addr_type [nft] datatype: Accept IPv4 addresses for ip6addr_type - - - - --- 2025-12-10 Phil Sutter New
[nft] cache: Fix for multiple commands in a single batch [nft] cache: Fix for multiple commands in a single batch - 1 - - --- 2026-03-11 Phil Sutter New
netfilter: ipset: harden payload calculation in call_ad() netfilter: ipset: harden payload calculation in call_ad() 1 - - - --- 2026-03-13 David Baum kadlec Under Review
[v12,nf-next] netfilter: nft_flow_offload: Add DEV_PATH_MTK_WDMA to nft_dev_path_info() [v12,nf-next] netfilter: nft_flow_offload: Add DEV_PATH_MTK_WDMA to nft_dev_path_info() - - 1 - --- 2026-03-17 Eric Woudstra Needs Review / ACK
[v12,nf-next] bridge: Introduce DEV_PATH_BR_VLAN_KEEP_HW [v12,nf-next] bridge: Introduce DEV_PATH_BR_VLAN_KEEP_HW - - - - --- 2026-03-17 Eric Woudstra Needs Review / ACK
[nf-next,v2] netfilter: nfnetlink_hook: Dump nat type chains [nf-next,v2] netfilter: nfnetlink_hook: Dump nat type chains - - - - --- 2026-03-20 Phil Sutter Under Review
[nf-next,v2,1/2] netfilter: flowtable: update netdev stats with HW_OFFLOAD flows Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nf-next,v2,2/2] net: dsa: update net_device stats with HW offloaded flows stats Update (DSA) netdev stats with offloaded flows - - - - --- 2026-03-24 Ahmed Zaki Needs Review / ACK
[nft,1/2] parser_json: Accept non-RHS expressions in binop RHS A bit of non-constant binop follow-up - 1 - - --- 2026-04-02 Phil Sutter New
[nft,2/2] parser_bison: Accept non-constant binop on LHS of relationals A bit of non-constant binop follow-up - - - - --- 2026-04-02 Phil Sutter New
[nft,2/5] libnftables: add nft_run_cmd_release() helper and use it support for several list and reset commands - - - - --- 2026-04-08 Pablo Neira Ayuso New
[nft,3/5] libnftables: consolidate evaluation and netlink run support for several list and reset commands - - - - --- 2026-04-08 Pablo Neira Ayuso New
[nft,4/5] libnftables: use nft_eval_run_cmds() in nft_run_cmd_from_filename() support for several list and reset commands - - - - --- 2026-04-08 Pablo Neira Ayuso New
[nft,5/5] libnftables: support for several list and reset commands support for several list and reset commands - - - - --- 2026-04-08 Pablo Neira Ayuso New
[RFC,net-next,1/4] net: flow_offload: let drivers report byte counter semantics improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC,net-next,2/4] nf_flow_table: track sub-interface and bridge ifindex in flow tuple improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC,net-next,3/4] nf_flow_table: convert hw byte counts and update sub-interface stats improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
[RFC,net-next,4/4] net: ethernet: mtk_eth_soc: report INGRESS_L2 byte_type in flow stats improve hw flow offload byte accounting - - - - --- 2026-04-09 Daniel Golle New
netfilter module-autoload: duplicate request for netfilter module netfilter module-autoload: duplicate request for netfilter module - - - - --- 2026-04-14 Zhe Zhao New
[nft] json: output set/map element count [nft] json: output set/map element count - - - - --- 2026-04-19 Niklas Fiekas New
[nf-next,v5] netfilter: nf_tables: add math expression support [nf-next,v5] netfilter: nf_tables: add math expression support - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[libnftnl,v4] expr: add support to math expression [libnftnl,v4] expr: add support to math expression - - - - --- 2026-04-21 Fernando Fernandez Mancera New
[BUG] KASAN: slab-use-after-free in hash_ipportip6_resize [BUG] KASAN: slab-use-after-free in hash_ipportip6_resize - - - - --- 2026-04-23 Eulgyu Kim New
[net] netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() [net] netfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init() - 1 - - --- 2026-04-28 Mathias Krause New
[nf-next] netfilter: flowtable_offload: propagate CT mark to hardware offload path [nf-next] netfilter: flowtable_offload: propagate CT mark to hardware offload path - - - - --- 2026-04-29 Lorenzo Bianconi New
[net-next,v3,1/4] netfilter: conntrack: add shared port and uint parsers for helpers netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 Rahul New
[net-next,v3,2/4] netfilter: nf_conntrack_irc: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 Rahul New
[net-next,v3,3/4] netfilter: nf_conntrack_amanda: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - 1 - - --- 2026-05-03 Rahul New
[net-next,v3,4/4] netfilter: nf_conntrack_sip: use nf_ct_helper_parse_port() netfilter: conntrack: shared port parser for helpers - - - - --- 2026-05-03 Rahul New
[v20,nf-next,1/2] netfilter: utils: nf_ip(6)_checksum(_partial) correct data!=networkheader conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,2/2] netfilter: bridge: Add conntrack double vlan and pppoe conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh [v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh - - - - --- 2026-05-12 Eric Woudstra New
[nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize [nf,1/1] netfilter: ipset: fix comment extension lifetime during hash resize - 1 - 1 --- 2026-05-13 Ren Wei kadlec Needs Review / ACK
[nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct [nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct - 1 - - --- 2026-05-14 Fernando Fernandez Mancera New
[4/3,nf,v4] netfilter: nf_conntrack_helper: call .destroy() when helper is unregistered Untitled series #504819 - 1 - - --- 2026-05-18 Pablo Neira Ayuso New
[1/6] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[2/6] netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[3/6] netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[4/6] netfilter: ipset: skip gc when resize is in progress netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[5/6] netfilter: ipset: fix potential torn read in reuse/forceadd cases netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[6/6] netfilter: ipset: add comment how cidr bookkeeping is working netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[v3,nf-next] ipvs: add conn_max sysctl to limit connections [v3,nf-next] ipvs: add conn_max sysctl to limit connections - - - - --- 2026-05-25 Julian Anastasov New
netfilter: flowtable: resolve LAG slave for direct HW offload netfilter: flowtable: resolve LAG slave for direct HW offload - - - - --- 2026-05-25 Jihong Min New
[nf,v2,1/1] bridge: br_netfilter: move fake rtable off struct net_bridge [nf,v2,1/1] bridge: br_netfilter: move fake rtable off struct net_bridge - 1 - - --- 2026-05-26 Ren Wei New
[v3] ipvs: Replace use of system_unbound_wq with system_dfl_long_wq [v3] ipvs: Replace use of system_unbound_wq with system_dfl_long_wq 1 - - - --- 2026-05-27 Marco Crivellari New
[v2,net] netfilter: flowtable: fix offloaded ct timeout never being extended [v2,net] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-05-28 Adrian Bente New
[v2] netfilter: TCPMSS: fix dropped packets when MSS option is unaligned [v2] netfilter: TCPMSS: fix dropped packets when MSS option is unaligned - - - - --- 2026-05-28 Kacper Kokot New
[nf-next,v3,1/6] net: netfilter: Add ether_type to net_device_path_ctx Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,2/6] net: netfilter: Add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,3/6] net: netfilter: Add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,4/6] selftests: netfilter: nft_flowtable.sh: Add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,5/6] net: netfilter: Add SIT tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,6/6] selftests: netfilter: nft_flowtable.sh: Add SIT flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[1/9,nf-next] netfilter: xtables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[2/9,nf-next] netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[3/9,nf-next] netfilter: nfnetlink: use DEBUG_NET_WARN_ON_ONCE for attribute validation netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[4/9,nf-next] netfilter: conntrack: use DEBUG_NET_WARN_ON_ONCE on packet paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[5/9,nf-next] netfilter: nat: use DEBUG_NET_WARN_ON_ONCE in core and helper paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[6/9,nf-next] netfilter: tproxy: use DEBUG_NET_WARN_ON_ONCE for protocol fallbacks netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[7/9,nf-next] netfilter: bpf: use DEBUG_NET_WARN_ON_ONCE for missing BTF structures netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[8/9,nf-next] netfilter: flowtable: use DEBUG_NET_WARN_ON_ONCE in offload path netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[9/9,nf-next] netfilter: conncount: use DEBUG_NET_WARN_ON_ONCE on reaching count limit netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[nf] selftests: nft_queue.sh: add a bridge queue test [nf] selftests: nft_queue.sh: add a bridge queue test - - - - --- 2026-06-02 Florian Westphal New
[nf-next] netfilter: flowtable: remove inline segmentation [nf-next] netfilter: flowtable: remove inline segmentation - - - - --- 2026-06-03 Qingfang Deng New
[nft] intervals: Fix for inconsistent union field use [nft] intervals: Fix for inconsistent union field use - 1 - - --- 2026-06-03 Phil Sutter New
[nft,1/6] json: Introduce tunnel_obj_print_json() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,2/6] parser_json: Introduce json_parse_tunnel() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,3/6] rule: Turn obj_print_comment() into obj_print_header() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,4/6] rule: Introduce tunnel_obj_print_data() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,5/6] src: Avoid variable declarations in switch cases Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,6/6] netlink: Call tunnel getters unconditionally Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nf,1/1] netfilter: nf_flow_table: separate tunnel route state from direct xmit [nf,1/1] netfilter: nf_flow_table: separate tunnel route state from direct xmit - 1 - - --- 2026-06-04 Ren Wei New
[nf] netfilter: flowtable: fix IP6IP6 tunnel offset double-count with vlan/pppoe encap [nf] netfilter: flowtable: fix IP6IP6 tunnel offset double-count with vlan/pppoe encap 1 1 - - --- 2026-06-04 David Carlier New
[nf-next,v4,1/5] netfilter: nf_conncount: callers must hold rcu read lock netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,2/5] netfilter: nf_conncount: use per nf_conncount_data spinlocks netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,3/5] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,4/5] netfilter: nf_conncount: add sequence counter to detect tree modifications netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,5/5] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[net-next] net/netfilter/xt_recent: Use strscpy() to copy device name [net-next] net/netfilter/xt_recent: Use strscpy() to copy device name - - - - --- 2026-06-06 David Laight New
[nf,v5,1/1] bridge: br_netfilter: pin bridge device while NFQUEUE holds fake dst [nf,v5,1/1] bridge: br_netfilter: pin bridge device while NFQUEUE holds fake dst - 1 - - --- 2026-06-08 Ren Wei Under Review
[net-next] net/netfilter/nfnetlink_cttimeout: Use strscpy() to copy strings into arrays [net-next] net/netfilter/nfnetlink_cttimeout: Use strscpy() to copy strings into arrays - - - - --- 2026-06-08 David Laight New
[nf-next] netfilter: nf_reject_ipv6: do not reject ICMPv6 Redirect with an ICMPv6 error [nf-next] netfilter: nf_reject_ipv6: do not reject ICMPv6 Redirect with an ICMPv6 error - - - - --- 2026-06-08 Sayooj K Karun New
[nf,v2] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() [nf,v2] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() - 1 - - --- 2026-06-08 Lorenzo Bianconi New
netfilter: x_tables: avoid leaking percpu counter pointers netfilter: add restrictions/validations for packet rewrite - 1 - - --- 2026-06-08 Florian Westphal New
[nf] netfilter: flowtable: use pskb_may_pull() in nf_flow_ip6_tunnel_proto() [nf] netfilter: flowtable: use pskb_may_pull() in nf_flow_ip6_tunnel_proto() - 1 - - --- 2026-06-08 Lorenzo Bianconi New
[net-next] ipvs: fix doc syntax for conn_max sysctl [net-next] ipvs: fix doc syntax for conn_max sysctl - 1 - - --- 2026-06-08 Julian Anastasov New
[v2,1/9] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,2/9] netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,3/9] netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,4/9] netfilter: ipset: Extend the rcu locked area properly netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,5/9] netfilter: ipset: exlude gc when resize is in progress netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,6/9] netfilter: ipset: fix potential double free at resize/del netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,7/9] netfilter: ipset: make sure gc is properly stopped netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
« 1 2 »