Show patches with: none      |   35169 patches
« 1 2 3 4351 352 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[net-next,2/2] selftests: netfilter: add phony nft_offload test netdevsim: add fake FT/CLS_FLOWER offload - - - - --- 2026-06-10 Florian Westphal New
[net-next,1/2] netdevsim: tc: allow to test nf_tables offload control plane code netdevsim: add fake FT/CLS_FLOWER offload - - - - --- 2026-06-10 Florian Westphal New
[net,8/8] netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,7/8] netfilter: nft_fib: fix stale stack leak via the OIFNAME register [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,6/8] netfilter: nft_exthdr: fix register tracking for F_PRESENT flag [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,5/8] netfilter: nf_log: validate MAC header was set before dumping it [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,4/8] netfilter: x_tables: avoid leaking percpu counter pointers [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,3/8] netfilter: nf_conntrack: destroy stale expectfn expectations on unregister [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,2/8] netfilter: nf_tables_offload: drop device refcount on error [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,1/8] netfilter: revalidate bridge ports [net,1/8] netfilter: revalidate bridge ports - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[net,0/8] Netfilter fixes for net - - - - --- 2026-06-10 Pablo Neira Ayuso New
[libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols [libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols [libnetfilter_conntrack,v2] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[nft] profiling: Include unistd.h to avoid compiler warnings [nft] profiling: Include unistd.h to avoid compiler warnings - 1 - - --- 2026-06-10 Phil Sutter New
[nft] parser_bison: Fix for bison < 3.6 [nft] parser_bison: Fix for bison < 3.6 - 1 - - --- 2026-06-10 Phil Sutter New
[nf-next,v3] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them [nf-next,v3] netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them - 2 - - --- 2026-06-10 Pablo Neira Ayuso New
[nf-next,v3] netfilter: conntrack: check NULL when retrieving ct extension [nf-next,v3] netfilter: conntrack: check NULL when retrieving ct extension - - - - --- 2026-06-10 Pablo Neira Ayuso New
[v2,2/2] netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register netfilter: fix two remaining stale-stack register leaks - 1 - - --- 2026-06-10 Davide Ornaghi New
[v2,1/2] netfilter: nft_fib: fix stale stack leak via the OIFNAME register netfilter: fix two remaining stale-stack register leaks - 1 - - --- 2026-06-10 Davide Ornaghi New
[libnetfilter_conntrack] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols [libnetfilter_conntrack] objopt: restrict NFCT_GOPT_IS_{S,D}PAT to supported layer 4 protocols - 1 - - --- 2026-06-10 Pablo Neira Ayuso New
[nf-next,v2] netfilter: flowtable: bail out if forward path cannot be discovered [nf-next,v2] netfilter: flowtable: bail out if forward path cannot be discovered - - - - --- 2026-06-10 Pablo Neira Ayuso New
[nf-next] netfilter: ebtables: bound num_counters like nentries in do_replace() [nf-next] netfilter: ebtables: bound num_counters like nentries in do_replace() - - - - --- 2026-06-10 Jiayuan Chen New
[net,v2] netfilter: nf_log: validate MAC header was set before dumping it [net,v2] netfilter: nf_log: validate MAC header was set before dumping it - 1 - - --- 2026-06-09 Xiang Mei New
[v3,nf] netfilter: nft_exthdr: fix register tracking for F_PRESENT flag [v3,nf] netfilter: nft_exthdr: fix register tracking for F_PRESENT flag - 1 - - --- 2026-06-09 Florian Westphal New
[v3,nf-next,3/3] netfilter: nftables: restrict checkum update offset netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-09 Florian Westphal New
[v3,nf-next,2/3] netfilter: nftables: restrict linklayer and network header writes netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-09 Florian Westphal New
[v3,nf-next,1/3] netfilter: nfnetlink_queue: restrict writes to network header netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-09 Florian Westphal New
[v2,9/9] netfilter: ipset: rework cidr bookkeeping netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,8/9] netfilter: ipset: fix potential torn read in reuse/forceadd cases netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,7/9] netfilter: ipset: make sure gc is properly stopped netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,6/9] netfilter: ipset: fix potential double free at resize/del netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,5/9] netfilter: ipset: exlude gc when resize is in progress netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,4/9] netfilter: ipset: Extend the rcu locked area properly netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,3/9] netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,2/9] netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[v2,1/9] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types netfilter: ipset fixes, second batch - - - - --- 2026-06-09 Jozsef Kadlecsik New
[net-next] ipvs: fix doc syntax for conn_max sysctl [net-next] ipvs: fix doc syntax for conn_max sysctl - 1 - - --- 2026-06-08 Julian Anastasov New
[nf] netfilter: flowtable: use pskb_may_pull() in nf_flow_ip6_tunnel_proto() [nf] netfilter: flowtable: use pskb_may_pull() in nf_flow_ip6_tunnel_proto() - 1 - - --- 2026-06-08 Lorenzo Bianconi New
netfilter: x_tables: avoid leaking percpu counter pointers netfilter: add restrictions/validations for packet rewrite - 1 - - --- 2026-06-08 Florian Westphal New
[nf,v2] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() [nf,v2] netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() - 1 - - --- 2026-06-08 Lorenzo Bianconi New
[nf-next] netfilter: nf_reject_ipv6: do not reject ICMPv6 Redirect with an ICMPv6 error [nf-next] netfilter: nf_reject_ipv6: do not reject ICMPv6 Redirect with an ICMPv6 error - - - - --- 2026-06-08 Sayooj K Karun New
[net-next] net/netfilter/nfnetlink_cttimeout: Use strscpy() to copy strings into arrays [net-next] net/netfilter/nfnetlink_cttimeout: Use strscpy() to copy strings into arrays - - - - --- 2026-06-08 David Laight New
[nf,v5,1/1] bridge: br_netfilter: pin bridge device while NFQUEUE holds fake dst [nf,v5,1/1] bridge: br_netfilter: pin bridge device while NFQUEUE holds fake dst - 1 - - --- 2026-06-08 Ren Wei New
[nf] netfilter: nf_log: validate MAC header was set before dumping it [nf] netfilter: nf_log: validate MAC header was set before dumping it - 1 - - --- 2026-06-08 Xiang Mei New
[net-next] net/netfilter/xt_recent: Use strscpy() to copy device name [net-next] net/netfilter/xt_recent: Use strscpy() to copy device name - - - - --- 2026-06-06 David Laight New
[nf-next,v4,5/5] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,4/5] netfilter: nf_conncount: add sequence counter to detect tree modifications netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,3/5] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,2/5] netfilter: nf_conncount: use per nf_conncount_data spinlocks netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,1/5] netfilter: nf_conncount: callers must hold rcu read lock netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[1/1] netfilter: nf_tables_offload: drop device refcount on error [1/1] netfilter: nf_tables_offload: drop device refcount on error - 1 - - --- 2026-06-05 Florian Westphal New
[nf] netfilter: flowtable: fix IP6IP6 tunnel offset double-count with vlan/pppoe encap [nf] netfilter: flowtable: fix IP6IP6 tunnel offset double-count with vlan/pppoe encap 1 1 - - --- 2026-06-04 David Carlier New
[nf,1/1] netfilter: nf_flow_table: separate tunnel route state from direct xmit [nf,1/1] netfilter: nf_flow_table: separate tunnel route state from direct xmit - 1 - - --- 2026-06-04 Ren Wei New
[nft,6/6] netlink: Call tunnel getters unconditionally Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,5/6] src: Avoid variable declarations in switch cases Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,4/6] rule: Introduce tunnel_obj_print_data() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,3/6] rule: Turn obj_print_comment() into obj_print_header() Eliminate variable declarations in switch cases - - - - --- 2026-06-03 Phil Sutter New
[nft,2/6] parser_json: Introduce json_parse_tunnel() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft,1/6] json: Introduce tunnel_obj_print_json() Eliminate variable declarations in switch cases - 1 - - --- 2026-06-03 Phil Sutter New
[nft] intervals: Fix for inconsistent union field use [nft] intervals: Fix for inconsistent union field use - 1 - - --- 2026-06-03 Phil Sutter New
[nf] netfilter: nf_conntrack: destroy stale expectfn expectations on unregister [nf] netfilter: nf_conntrack: destroy stale expectfn expectations on unregister - 1 - - --- 2026-06-03 Weiming Shi New
[nf-next] netfilter: flowtable: remove inline segmentation [nf-next] netfilter: flowtable: remove inline segmentation - - - - --- 2026-06-03 Qingfang Deng New
[nf] netfilter: nf_queue: reinject must revalidate bridge ports [nf] netfilter: nf_queue: reinject must revalidate bridge ports - 1 - - --- 2026-06-02 Florian Westphal New
[nf] selftests: nft_queue.sh: add a bridge queue test [nf] selftests: nft_queue.sh: add a bridge queue test - - - - --- 2026-06-02 Florian Westphal New
[conntrack-tools] conntrackd: remove redundant retry checks [conntrack-tools] conntrackd: remove redundant retry checks - - - - --- 2026-06-02 Denis Ozhigov New
[9/9,nf-next] netfilter: conncount: use DEBUG_NET_WARN_ON_ONCE on reaching count limit netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[8/9,nf-next] netfilter: flowtable: use DEBUG_NET_WARN_ON_ONCE in offload path netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[7/9,nf-next] netfilter: bpf: use DEBUG_NET_WARN_ON_ONCE for missing BTF structures netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[6/9,nf-next] netfilter: tproxy: use DEBUG_NET_WARN_ON_ONCE for protocol fallbacks netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[5/9,nf-next] netfilter: nat: use DEBUG_NET_WARN_ON_ONCE in core and helper paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[4/9,nf-next] netfilter: conntrack: use DEBUG_NET_WARN_ON_ONCE on packet paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[3/9,nf-next] netfilter: nfnetlink: use DEBUG_NET_WARN_ON_ONCE for attribute validation netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[2/9,nf-next] netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[1/9,nf-next] netfilter: xtables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths netfilter: replace raw warnings with - - - - --- 2026-06-01 Fernando Fernandez Mancera New
[nf-next,v3,6/6] selftests: netfilter: nft_flowtable.sh: Add SIT flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,5/6] net: netfilter: Add SIT tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,4/6] selftests: netfilter: nft_flowtable.sh: Add IPv4 over IPv6 flowtable selftest Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,3/6] net: netfilter: Add IPv4 over IPv6 tunnel flowtable acceleration Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,2/6] net: netfilter: Add encap_proto to flow_offload_tunnel Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[nf-next,v3,1/6] net: netfilter: Add ether_type to net_device_path_ctx Add IPv4 over IPv6 and SIT flowtable SW acceleration - - - - --- 2026-05-31 Lorenzo Bianconi New
[v2] netfilter: TCPMSS: fix dropped packets when MSS option is unaligned [v2] netfilter: TCPMSS: fix dropped packets when MSS option is unaligned - - - - --- 2026-05-28 Kacper Kokot New
[v2,net] netfilter: flowtable: fix offloaded ct timeout never being extended [v2,net] netfilter: flowtable: fix offloaded ct timeout never being extended - 1 - - --- 2026-05-28 Adrian Bente New
[v3] ipvs: Replace use of system_unbound_wq with system_dfl_long_wq [v3] ipvs: Replace use of system_unbound_wq with system_dfl_long_wq 1 - - - --- 2026-05-27 Marco Crivellari New
[nf,v2,1/1] bridge: br_netfilter: move fake rtable off struct net_bridge [nf,v2,1/1] bridge: br_netfilter: move fake rtable off struct net_bridge - 1 - - --- 2026-05-26 Ren Wei New
netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() - - 1 - --- 2026-05-25 Rosen Penev New
netfilter: flowtable: resolve LAG slave for direct HW offload netfilter: flowtable: resolve LAG slave for direct HW offload - - - - --- 2026-05-25 Jihong Min New
[v3,nf-next] ipvs: add conn_max sysctl to limit connections [v3,nf-next] ipvs: add conn_max sysctl to limit connections - - - - --- 2026-05-25 Julian Anastasov New
[6/6] netfilter: ipset: add comment how cidr bookkeeping is working netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[5/6] netfilter: ipset: fix potential torn read in reuse/forceadd cases netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[4/6] netfilter: ipset: skip gc when resize is in progress netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[3/6] netfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer() netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[2/6] netfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap types netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[1/6] netfilter: ipset: Don't use test_bit() in lockless RCU readers in hash types netfilter: ipset fixes, second batch - - - - --- 2026-05-23 Jozsef Kadlecsik New
[4/3,nf,v4] netfilter: nf_conntrack_helper: call .destroy() when helper is unregistered Untitled series #504819 - 1 - - --- 2026-05-18 Pablo Neira Ayuso New
[nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct [nf,v2] netfilter: nf_conncount: prevent connlimit drops for early confirmed ct - 1 - - --- 2026-05-14 Fernando Fernandez Mancera New
[v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh [v5,nf-next] selftests: netfilter: Add bridge_fastpath.sh - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,2/2] netfilter: bridge: Add conntrack double vlan and pppoe conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[v20,nf-next,1/2] netfilter: utils: nf_ip(6)_checksum(_partial) correct data!=networkheader conntrack: bridge: add double vlan, pppoe and pppoe-in-q - - - - --- 2026-05-12 Eric Woudstra New
[nft] cache: honor -c/--check for reset commands [nft] cache: honor -c/--check for reset commands - 1 - - --- 2026-05-11 Pablo Neira Ayuso New
[net,8/8] sched/isolation: Make HK_TYPE_KTHREAD an alias of HK_TYPE_DOMAIN [net,1/8] ipvs: fixes for the new ip_vs_status info - 1 - - --- 2026-05-05 Pablo Neira Ayuso New
« 1 2 3 4351 352 »