Show patches with: Archived = No       |   28137 patches
« 1 2 3 4281 282 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate() [v2] netfilter: nf_tables: allow NFPROTO_INET in nft_(match/target)_validate() - 1 - - --- 2024-02-20 Ignat Korchagin New
[libnftnl] obj: ct_timeout: setter checks for timeout array boundaries [libnftnl] obj: ct_timeout: setter checks for timeout array boundaries - 1 - - --- 2024-02-20 Pablo Neira Ayuso New
Add protection for bmp length out of range Add protection for bmp length out of range - - - - --- 2024-02-20 Lena Wang (王娜) New
[nf] netfilter: nf_tables: set dormant flag on hook register failure [nf] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-19 Florian Westphal New
[nf-next] netfilter: nft_byteorder: remove multi-register support [nf-next] netfilter: nft_byteorder: remove multi-register support - 1 - - --- 2024-02-14 Florian Westphal New
[libnetfilter_queue,1/1] Convert libnetfilter_queue to use entirely libmnl functions Convert libnetfilter_queue to use entirely libmnl functions - - - - --- 2024-02-13 Duncan Roe New
[1/1] tests: use common shebang in "packetpath/flowtables" test [1/1] tests: use common shebang in "packetpath/flowtables" test - - - - --- 2024-02-09 Thomas Haller New
ipvs: generic netlink multicast event group ipvs: generic netlink multicast event group - - - - --- 2024-02-05 Terin Stock New
[nft] rule: do not crash if to-be-printed flowtable lacks priority [nft] rule: do not crash if to-be-printed flowtable lacks priority - - - - --- 2024-01-12 Florian Westphal New
[nft,v3] src: do not merge a set with a erroneous one [nft,v3] src: do not merge a set with a erroneous one - - - - --- 2024-01-12 Florian Westphal New
[RFC,libnetfilter_queue,1/1] utils/nfqnl_test runs without libnfnetlink libnfnetlink dependency elimination - - - - --- 2023-12-31 Duncan Roe New
[v3,nft] support for afl++ (american fuzzy lop++) fuzzer [v3,nft] support for afl++ (american fuzzy lop++) fuzzer - - - - --- 2023-12-19 Florian Westphal New
[libnftnl,6/6] expr: Enforce attr_policy compliance in nftnl_expr_set() Attribute policies for expressions - - - - --- 2023-12-15 Phil Sutter New
[libnftnl,5/6] expr: Introduce struct expr_ops::attr_policy Attribute policies for expressions - - - - --- 2023-12-15 Phil Sutter New
[libnftnl,4/6] include: Sync nf_log.h with kernel headers Attribute policies for expressions - - - - --- 2023-12-15 Phil Sutter New
[libnftnl,3/6] expr: Call expr_ops::set with legal types only Attribute policies for expressions - - - - --- 2023-12-15 Phil Sutter New
[libnftnl,2/6] expr: Repurpose struct expr_ops::max_attr field Attribute policies for expressions - - - - --- 2023-12-15 Phil Sutter New
[libnftnl,1/6] tests: Fix objref test case Attribute policies for expressions - 1 - - --- 2023-12-15 Phil Sutter New
ulogd / JSON output / enhancement proposal ulogd / JSON output / enhancement proposal - - - - --- 2023-12-14 Gérald Colangelo New
Bug in ulogd2 when destroying a stack that failed to start (with fix attached) Bug in ulogd2 when destroying a stack that failed to start (with fix attached) - - - - --- 2023-12-14 Gérald Colangelo New
[libnetfilter_queue,1/1] src: add nfq_socket_sendto() - send config request and check response src: add nfq_socket_sendto() - send config request and check response - - - - --- 2023-12-11 Duncan Roe New
[ulogd] log NAT events using IPFIX [ulogd] log NAT events using IPFIX - - - - --- 2023-12-10 Tomasz Pala New
[nft,2/2,v2] tests/shell: have .json-nft dumps prettified to wrap lines Untitled series #385629 - - - - --- 2023-12-07 Thomas Haller New
[nft,v2,5/5] tests/unit: add unit tests for libnftables add infrastructure for unit tests - - - - --- 2023-11-05 Thomas Haller New
[nft,v2,4/5] build: cleanup if-blocks for conditional compilation in "Makefile.am" add infrastructure for unit tests - - - - --- 2023-11-05 Thomas Haller New
[nft,v2,3/5] build: add `make check-tree` to check consistency of source tree add infrastructure for unit tests - - - - --- 2023-11-05 Thomas Haller New
[nft,v2,2/5] build: add `make check-build` to run `./tests/build/run-tests.sh` add infrastructure for unit tests - - - - --- 2023-11-05 Thomas Haller New
[nft,v2,1/5] build: add basic "check-{local,more,all}" and "build-all" make targets add infrastructure for unit tests - - - - --- 2023-11-05 Thomas Haller New
[nft,4/5] datatype: extend set_datatype_alloc() to change size more various cleanups related to struct datatype - - - - --- 2023-09-27 Thomas Haller New
[nft,3/5] datatype: don't clone datatype in set_datatype_alloc() if byteorder already matches more various cleanups related to struct datatype - - - - --- 2023-09-27 Thomas Haller New
[nft,2/5] datatype: don't clone static name/desc strings for datatype more various cleanups related to struct datatype - - - - --- 2023-09-27 Thomas Haller New
[nft,1/5] datatype: make "flags" field of datatype struct simple booleans more various cleanups related to struct datatype - - - - --- 2023-09-27 Thomas Haller New
netfilter: x_tables: Use unsafe_memcpy() for 0-sized destination netfilter: x_tables: Use unsafe_memcpy() for 0-sized destination - - 1 - --- 2024-02-16 Kees Cook Under Review
[nf-next] netfilter: nft_set_pipapo: use GFP_KERNEL for insertions [nf-next] netfilter: nft_set_pipapo: use GFP_KERNEL for insertions - - - - --- 2024-02-15 Florian Westphal strlen Under Review
[nf-next] netfilter: move nf_reinject into nfnetlink_queue modules [nf-next] netfilter: move nf_reinject into nfnetlink_queue modules - - - - --- 2024-02-14 Florian Westphal strlen Under Review
[v2,nf-next,4/4] netfilter: nft_set_pipapo: speed up bulk element insertions netfilter: nft_set_pipapo: speed up bulk element insertions - - - - --- 2024-02-13 Florian Westphal strlen Under Review
[v2,nf-next,3/4] netfilter: nft_set_pipapo: shrink data structures netfilter: nft_set_pipapo: speed up bulk element insertions - - - - --- 2024-02-13 Florian Westphal strlen Under Review
[v2,nf-next,2/4] netfilter: nft_set_pipapo: do not rely on ZERO_SIZE_PTR netfilter: nft_set_pipapo: speed up bulk element insertions - - - - --- 2024-02-13 Florian Westphal strlen Under Review
[v2,nf-next,1/4] netfilter: nft_set_pipapo: constify lookup fn args where possible netfilter: nft_set_pipapo: speed up bulk element insertions - - - - --- 2024-02-13 Florian Westphal strlen Under Review
[nf-next] netfilter: xtables: fix up kconfig dependencies [nf-next] netfilter: xtables: fix up kconfig dependencies 1 2 - 1 --- 2024-02-06 Florian Westphal strlen Under Review
[nf-next] netfilter: nft_osf: simplify init path [nf-next] netfilter: nft_osf: simplify init path - - - - --- 2024-01-29 Pablo Neira Ayuso strlen Under Review
[nf-next,2/2] netfilter: nf_log: validate nf_logger_find_get() [nf-next,1/2] netfilter: nf_log: consolidate check for NULL logger in lookup function - - - - --- 2024-01-29 Pablo Neira Ayuso strlen Under Review
[nf-next,1/2] netfilter: nf_log: consolidate check for NULL logger in lookup function [nf-next,1/2] netfilter: nf_log: consolidate check for NULL logger in lookup function - - - - --- 2024-01-29 Pablo Neira Ayuso strlen Under Review
[nf-next] netfilter: expect: Simplify the allocation of slab caches in nf_conntrack_expect_init [nf-next] netfilter: expect: Simplify the allocation of slab caches in nf_conntrack_expect_init - - - - --- 2024-01-24 Kunwu Chan strlen Under Review
[nft,v5,8/8] tests: add tests for binops with variable RHS operands Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,7/8] parser_json: allow RHS mark and payload expressions Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,6/8] evaluate: allow binop expressions with variable right-hand operands Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,5/8] evaluate: preserve existing binop properties Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,4/8] evaluate: prevent nested byte-order conversions Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,3/8] netlink_delinearize: add support for processing variable payload statement arguments Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,2/8] netlink_delinearize: refactor stmt_payload_binop_postprocess Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nft,v5,1/8] netlink: support (de)linearization of new bitwise boolean operations Bitwise boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[libnftnl,v3,5/5] tests: bitwise: add tests for new boolean operations bitwise: support for boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[libnftnl,v3,4/5] tests: bitwise: refactor shift tests bitwise: support for boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[libnftnl,v3,3/5] expr: bitwise: add support for kernel space AND, OR and XOR operations bitwise: support for boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[libnftnl,v3,2/5] expr: bitwise: rename some boolean operation functions bitwise: support for boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[libnftnl,v3,1/5] include: add new bitwise boolean attributes to nf_tables.h bitwise: support for boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nf-next,v4,2/2] netfilter: bitwise: add support for doing AND, OR and XOR directly netfilter: bitwise: support boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nf-next,v4,1/2] netfilter: bitwise: rename some boolean operation functions netfilter: bitwise: support boolean operations with variable RHS operands - - - - --- 2023-05-28 Jeremy Sowden Under Review
[nftables] Allow resetting the include search path [nftables] Allow resetting the include search path - - - - --- 2022-06-27 Daniel Gröber pablo Under Review
[nf-next,v2,3/3] selftests: netfilter: flowtable vlan filtering bridge support [nf-next,v2,1/3] nf_flow_table_offload: offload the vlan encap in the flowtable - - - - --- 2022-05-26 wenxu@chinatelecom.cn pablo Under Review
[nft] expression: missing line in describe command with invalid expression [nft] expression: missing line in describe command with invalid expression - 1 - - --- 2024-02-13 Pablo Neira Ayuso Accepted
[nft] cache: Always set NFT_CACHE_TERSE for list cmd with --terse [nft] cache: Always set NFT_CACHE_TERSE for list cmd with --terse - - - - --- 2024-02-08 Phil Sutter Accepted
[nft,2/2] netlink_linearize: add assertion to catch for buggy byteorder [v2,nft,1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes - - - - --- 2024-02-08 Pablo Neira Ayuso Accepted
[v2,nft,1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes [v2,nft,1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes - 1 - - --- 2024-02-08 Pablo Neira Ayuso Accepted
[nf,v2,3/3] netfilter: nft_set_pipapo: remove scratch_aligned pointer netfilter: nft_set_pipapo: nft_set_pipapo: map_index must be per set - 1 1 - --- 2024-02-07 Florian Westphal Accepted
[nf,v2,2/3] netfilter: nft_set_pipapo: add helper to release pcpu scratch area netfilter: nft_set_pipapo: nft_set_pipapo: map_index must be per set - - 1 - --- 2024-02-07 Florian Westphal Accepted
[nf,v2,1/3] netfilter: nft_set_pipapo: store index in scratch maps netfilter: nft_set_pipapo: nft_set_pipapo: map_index must be per set - 1 1 - --- 2024-02-07 Florian Westphal Accepted
[nft] cache: Optimize caching for 'list tables' command [nft] cache: Optimize caching for 'list tables' command - - - - --- 2024-02-07 Phil Sutter Accepted
[nft,v3] evaluate: fix check for unknown in cmd_op_to_name [nft,v3] evaluate: fix check for unknown in cmd_op_to_name - 1 - - --- 2024-02-07 谢致邦 (XIE Zhibang) Accepted
[nf] netfilter: nf_tables: use timestamp to check for set element timeout [nf] netfilter: nf_tables: use timestamp to check for set element timeout - 1 - - --- 2024-02-07 Pablo Neira Ayuso Accepted
Makefile.am: don't silence -Wimplicit-function-declaration Makefile.am: don't silence -Wimplicit-function-declaration - - - - --- 2024-02-07 Sam James Accepted
[nf] netfilter: nfnetlink_queue: un-break NF_REPEAT [nf] netfilter: nfnetlink_queue: un-break NF_REPEAT - 1 - - --- 2024-02-06 Florian Westphal Accepted
[nf] netfilter: nft_ct: reject direction for ct id [nf] netfilter: nft_ct: reject direction for ct id - 1 - - --- 2024-02-05 Pablo Neira Ayuso Accepted
[net] net: ctnetlink: fix filtering for zone 0 [net] net: ctnetlink: fix filtering for zone 0 - 1 - - --- 2024-02-05 Felix Huettner Accepted
[1/1] netfilter: ipset: Missing gc cancellations fixed [1/1] netfilter: ipset: Missing gc cancellations fixed - 1 - 2 --- 2024-02-04 Jozsef Kadlecsik Accepted
[iptables,12/12] libxtables: xtoptions: Respect min/max values when completing ranges Range value related fixes/improvements - - - - --- 2024-02-02 Phil Sutter Accepted
[iptables,11/12] extensions: tcp/udp: Save/xlate inverted full ranges Range value related fixes/improvements - 2 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,10/12] nft: Do not omit full ranges if inverted Range value related fixes/improvements - 1 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,09/12] extensions: ipcomp: Save inverted full ranges Range value related fixes/improvements - 1 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,08/12] extensions: esp: Save/xlate inverted full ranges Range value related fixes/improvements - 1 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,07/12] extensions: rt: Save/xlate inverted full ranges Range value related fixes/improvements - 1 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,06/12] extensions: mh: Save/xlate inverted full ranges Range value related fixes/improvements - 1 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,05/12] extensions: frag: Save/xlate inverted full ranges Range value related fixes/improvements - 1 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,04/12] extensions: ah: Save/xlate inverted full ranges Range value related fixes/improvements - 2 - - --- 2024-02-02 Phil Sutter Accepted
[iptables,03/12] libxtables: Reject negative port ranges Range value related fixes/improvements - - - - --- 2024-02-02 Phil Sutter Accepted
[iptables,02/12] libxtables: xtoptions: Assert ranges are monotonic increasing Range value related fixes/improvements - - - - --- 2024-02-02 Phil Sutter Accepted
[iptables,01/12] extensions: *.t/*.txlate: Test range corner-cases Range value related fixes/improvements - - - - --- 2024-02-02 Phil Sutter Accepted
[nf] netfilter: nft_compat: reject unused compat flag [nf] netfilter: nft_compat: reject unused compat flag - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_compat: restrict match/target protocol to u16 [nf] netfilter: nft_compat: restrict match/target protocol to u16 - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_compat: narrow down revision to unsigned 8-bits [nf] netfilter: nft_compat: narrow down revision to unsigned 8-bits - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_set_pipapo: remove static in nft_pipapo_get() [nf] netfilter: nft_set_pipapo: remove static in nft_pipapo_get() - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[iptables,7/7] ebtables: Fix for memleak with change counters command A number of ASAN-identified fixes - 1 - - --- 2024-02-01 Phil Sutter Accepted
[iptables,6/7] xshared: Introduce xtables_clear_args() Untitled series #393160 - 1 - - --- 2024-02-01 Phil Sutter Accepted
[iptables,5/7] xshared: Fix for memleak in option merging with ebtables A number of ASAN-identified fixes - 1 - - --- 2024-02-01 Phil Sutter Accepted
[iptables,4/7] xtables-eb: Eliminate 'opts' define A number of ASAN-identified fixes - - - - --- 2024-02-01 Phil Sutter Accepted
[iptables,3/7] libxtables: Fix memleak of matches' udata A number of ASAN-identified fixes - 1 - - --- 2024-02-01 Phil Sutter Accepted
[iptables,2/7] nft: ruleparse: Add missing braces around ternary A number of ASAN-identified fixes - 1 - - --- 2024-02-01 Phil Sutter Accepted
[iptables,1/7] tests: iptables-test: Increase non-fast mode strictness A number of ASAN-identified fixes - - - - --- 2024-02-01 Phil Sutter Accepted
[net,6/6] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - 1 - - --- 2024-01-31 Pablo Neira Ayuso Accepted
« 1 2 3 4281 282 »