Show patches with: Submitter = Florian Westphal       |   4014 patches
« 1 2 3 440 41 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nf-next,2/2] netfilter: nftables: restrict linklayer and network header writes netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-05 Florian Westphal New
[nf-next,1/2] netfilter: nfnetlink_queue: restrict writes to network header netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,5/5] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,4/5] netfilter: nf_conncount: add sequence counter to detect tree modifications netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,3/5] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,2/5] netfilter: nf_conncount: use per nf_conncount_data spinlocks netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,1/5] netfilter: nf_conncount: callers must hold rcu read lock netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[1/1] netfilter: nf_tables_offload: drop device refcount on error [1/1] netfilter: nf_tables_offload: drop device refcount on error - 1 - - --- 2026-06-05 Florian Westphal New
[v3,nf-next,5/5] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-04 Florian Westphal Changes Requested
[v3,nf-next,4/5] netfilter: nf_conncount: add sequence counter to detect tree modifications netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-04 Florian Westphal Changes Requested
[v3,nf-next,3/5] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-04 Florian Westphal Changes Requested
[v3,nf-next,2/5] netfilter: nf_conncount: prepare for per-tree seqcount netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-04 Florian Westphal Changes Requested
[v3,nf-next,1/5] netfilter: nf_conncount: callers must hold rcu read lock netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-04 Florian Westphal Changes Requested
[v2,nf-next,4/4] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: fix gc and - 1 - - --- 2026-06-03 Florian Westphal Changes Requested
[v2,nf-next,3/4] netfilter: nf_conncount: add sequence counter to detect tree modifications netfilter: nf_conncount: fix gc and - - - - --- 2026-06-03 Florian Westphal Changes Requested
[v2,nf-next,2/4] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: fix gc and - - - - --- 2026-06-03 Florian Westphal Changes Requested
[v2,nf-next,1/4] netfilter: nf_conncount: prepare for per-tree seqcount netfilter: nf_conncount: fix gc and - - - - --- 2026-06-03 Florian Westphal Changes Requested
[nf-next,3/3] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: misc bug fixes - 1 - - --- 2026-06-03 Florian Westphal Changes Requested
[nf-next,2/3] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: misc bug fixes - - - - --- 2026-06-03 Florian Westphal Changes Requested
[nf-next,1/3] netfilter: nf_conncount: prepare for per-tree seqcount netfilter: nf_conncount: misc bug fixes - - - - --- 2026-06-03 Florian Westphal Changes Requested
[nf] netfilter: nf_queue: reinject must revalidate bridge ports [nf] netfilter: nf_queue: reinject must revalidate bridge ports - 1 - - --- 2026-06-02 Florian Westphal New
[nf] selftests: nft_queue.sh: add a bridge queue test [nf] selftests: nft_queue.sh: add a bridge queue test - - - - --- 2026-06-02 Florian Westphal New
[nf] netfilter: bridge: ebt_redirect: don't assume bridge port exists [nf] netfilter: bridge: ebt_redirect: don't assume bridge port exists - 1 - - --- 2026-06-01 Florian Westphal Under Review
[RFC,nf,2/2] netfilter: nftables: restrict linklayer and network header writes netfilter: add restrictions/validations for packet rewrites - - - - --- 2026-05-27 Florian Westphal New
[RFC,nf,1/2] netfilter: nfnetlink_queue: restrict writes to network header netfilter: add restrictions/validations for packet rewrites - - - - --- 2026-05-27 Florian Westphal New
[nf] netfilter: conntrack_irc: fix possible out-of-bounds read [nf] netfilter: conntrack_irc: fix possible out-of-bounds read - 1 1 - --- 2026-05-27 Florian Westphal Accepted
[net-next,11/11] netfilter: nf_conntrack_ftp: avoid u16 overflows [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-05-25 Florian Westphal Accepted
[net-next,10/11] netfilter: nft_set_pipapo_avx2: restore performance optimization [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - 1 - --- 2026-05-25 Florian Westphal Accepted
[net-next,09/11] netfilter: nf_conntrack_proto_tcp: fix typos in comments [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-05-25 Florian Westphal Accepted
[net-next,08/11] netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - 1 - - --- 2026-05-25 Florian Westphal Accepted
[net-next,07/11] netfilter: nfnl_cthelper: apply per-class values when updating policies [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - 1 - - --- 2026-05-25 Florian Westphal Accepted
[net-next,06/11] netfilter: nft_set_rbtree: remove dead conditional [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-05-25 Florian Westphal Accepted
[net-next,05/11] netfilter: ctnetlink: use nf_ct_exp_net() in expectation dump [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - 1 - - --- 2026-05-25 Florian Westphal Accepted
[net-next,04/11] netfilter: nf_conncount: use per-rule hash initval [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-05-25 Florian Westphal Accepted
[net-next,03/11] netfilter: allow nfnetlink built-in only [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - 1 - --- 2026-05-25 Florian Westphal Accepted
[net-next,02/11] netfilter: add option for GCOV profiling [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces 1 - - - --- 2026-05-25 Florian Westphal Accepted
[net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces [net-next,01/11] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-05-25 Florian Westphal Accepted
[net-next,00/11] netfilter: updates for net-next - - - - --- 2026-05-25 Florian Westphal Accepted
Followup needed for netfilter: nft_fib_ipv6: walk fib6_siblings under RCU? Followup needed for netfilter: nft_fib_ipv6: walk fib6_siblings under RCU? - - - - --- 2026-05-25 Florian Westphal RFC
[net,10/10] netfilter: nf_tables: fix dst corruption in same register operation [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check 1 1 - - --- 2026-05-22 Florian Westphal Accepted
[net,09/10] selftests: netfilter: add nft_fib_nexthop test [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - - - - --- 2026-05-22 Florian Westphal Accepted
[net,08/10] netfilter: nft_fib_ipv6: handle routes via external nexthop [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 - - --- 2026-05-22 Florian Westphal Accepted
[net,07/10] netfilter: nft_fib_ipv6: walk fib6_siblings under RCU [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 - - --- 2026-05-22 Florian Westphal Accepted
[net,06/10] netfilter: ebtables: fix OOB read in compat_mtw_from_user [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 1 - --- 2026-05-22 Florian Westphal Accepted
[net,05/10] netfilter: disable payload mangling in userns [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - - - 1 --- 2026-05-22 Florian Westphal Accepted
[net,04/10] netfilter: xt_cpu: prefer raw_smp_processor_id [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 1 - --- 2026-05-22 Florian Westphal Accepted
[net,03/10] netfilter: nf_conntrack_gre: fix gre keymap list corruption [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - - - - --- 2026-05-22 Florian Westphal Accepted
[net,02/10] netfilter: synproxy: refresh tcphdr after skb_ensure_writable [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 1 - --- 2026-05-22 Florian Westphal Accepted
[net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check [net,01/10] netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check - 1 - - --- 2026-05-22 Florian Westphal Accepted
[net,00/10] netfilter: updates for net - - - - --- 2026-05-22 Florian Westphal Not Applicable
[nf-next,5/5] netfilter: conntrack: add deprecation warnings for irc and pptp trackers netfilter: conntrack: remove some code - - - - --- 2026-05-22 Florian Westphal Changes Requested
[nf-next,4/5] netfilter: remove obsolete nf_ct_helper_init api netfilter: conntrack: remove some code - - - - --- 2026-05-22 Florian Westphal Changes Requested
[nf-next,3/5] netfilter: nf_conntrack: switch to static registration netfilter: conntrack: remove some code - - - - --- 2026-05-22 Florian Westphal Changes Requested
[nf-next,2/5] netfilter: conntrack: get rid of tuple in helper definitions netfilter: conntrack: remove some code - - - - --- 2026-05-22 Florian Westphal Changes Requested
[nf-next,1/5] netfilter: nf_conntrack_helper: do not hash by tuple netfilter: conntrack: remove some code - - - - --- 2026-05-22 Florian Westphal Changes Requested
[nf-next,v3] netfilter: add option for GCOV profiling [nf-next,v3] netfilter: add option for GCOV profiling 1 - - - --- 2026-05-21 Florian Westphal Accepted
[nft] tests: shell: add stateless nat test case [nft] tests: shell: add stateless nat test case - - - - --- 2026-05-21 Florian Westphal Accepted
[nf] netfilter: ebtables: fix OOB read in compat_mtw_from_user [nf] netfilter: ebtables: fix OOB read in compat_mtw_from_user 1 1 1 - --- 2026-05-20 Florian Westphal Accepted
[nf] netfilter: xt_cpu: prefer raw_smp_processor_id [nf] netfilter: xt_cpu: prefer raw_smp_processor_id - 1 - - --- 2026-05-19 Florian Westphal Accepted
[v2,nf] netfilter: nf_conntrack_gre: fix gre keymap list corruption [v2,nf] netfilter: nf_conntrack_gre: fix gre keymap list corruption - - - - --- 2026-05-19 Florian Westphal Accepted
[nf] netfilter: nf_conntrack_gre: fix gre keymap list corruption [nf] netfilter: nf_conntrack_gre: fix gre keymap list corruption - - - - --- 2026-05-15 Florian Westphal Changes Requested
[RFC] netfilter: disable payload mangling in userns [RFC] netfilter: disable payload mangling in userns - - - - --- 2026-05-15 Florian Westphal RFC
[nf-next,v2] netfilter: add option for GCOV profiling [nf-next,v2] netfilter: add option for GCOV profiling 1 - - - --- 2026-05-12 Florian Westphal strlen Superseded
[v3,nf-next] netfilter: nft_byteorder: remove multi-register support [v3,nf-next] netfilter: nft_byteorder: remove multi-register support - 1 - - --- 2026-05-12 Florian Westphal Accepted
[nf] netfilter: nft_inner: release local_lock before re-enabling softirqs [nf] netfilter: nft_inner: release local_lock before re-enabling softirqs - 1 1 - --- 2026-05-12 Florian Westphal Accepted
[conntrack-tools] tests: cli-test.sh: improve logging for CI pipelines [conntrack-tools] tests: cli-test.sh: improve logging for CI pipelines - - - - --- 2026-05-09 Florian Westphal strlen Accepted
[conntrack-tools] tests: bulk-load-stress.sh: return early if ct_max is reached [conntrack-tools] tests: bulk-load-stress.sh: return early if ct_max is reached - - - - --- 2026-05-09 Florian Westphal strlen Accepted
[nf] netfilter: nf_conntrack_helper: fix possible null deref during error log [nf] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-09 Florian Westphal Accepted
[nf-next] netfilter: add option for GCOV profiling [nf-next] netfilter: add option for GCOV profiling - - - - --- 2026-05-07 Florian Westphal strlen Changes Requested
[v3,nf,9/8] netfilter: bridge: eb_tables: close module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-07 Florian Westphal Accepted
[v3,nf,8/8] netfilter: x_tables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,7/8] netfilter: ebtables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,6/8] netfilter: ebtables: move to two-stage removal scheme netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,5/8] netfilter: x_tables: add and use xtables_unregister_table_exit netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,4/8] netfilter: x_tables: unregister the templates first netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,3/8] netfilter: x_tables: add and use xt_unregister_table_pre_exit netfilter: xtables: fix module load and teardown races - - 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,2/8] netfilter: xtables: allocate hook ops while under mutex netfilter: xtables: fix module load and teardown races - 3 - - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,1/8] netfilter: x_tables: allow initial table replace without emitting audit log message netfilter: xtables: fix module load and teardown races - - - - --- 2026-05-06 Florian Westphal Accepted
[nft] tests: shell: also test byte-based rate limiting [nft] tests: shell: also test byte-based rate limiting - - - - --- 2026-05-05 Florian Westphal strlen Accepted
[nft] scanner: enable verdicts in rate scope too [nft] scanner: enable verdicts in rate scope too - 1 - - --- 2026-05-05 Florian Westphal Superseded
[v2,nf,8/8] netfilter: x_tables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,7/8] netfilter: ebtables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,6/8] netfilter: ebtables: move to two-stage removal scheme netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,5/8] netfilter: x_tables: add and use xtables_unregister_table_exit netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,4/8] netfilter: x_tables: unregister the templates first netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,3/8] netfilter: x_tables: add and use xt_unregister_table_pre_exit netfilter: xtables: fix module load and teardown races - - - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,2/8] netfilter: xtables: allocate hook ops while under mutex netfilter: xtables: fix module load and teardown races - 3 - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[v2,nf,1/8] netfilter: x_tables: allow initial table replace without emitting audit log message netfilter: xtables: fix module load and teardown races - - - - --- 2026-05-04 Florian Westphal strlen Changes Requested
[nft] src: don't write to possible rodata location [nft] src: don't write to possible rodata location - - - - --- 2026-05-04 Florian Westphal strlen Accepted
[nft] tools: match_nomatch: fix spurious failure in nomatch test [nft] tools: match_nomatch: fix spurious failure in nomatch test - - - - --- 2026-05-04 Florian Westphal strlen Accepted
[nf,5/5] netfilter: ebtables: move to two-stage removal scheme netfilter: xtables: fix module unload and teardown races - 1 - - --- 2026-05-02 Florian Westphal Changes Requested
[nf,4/5] netfilter: x_tables: add and use xtables_unregister_table_exit netfilter: xtables: fix module unload and teardown races - 1 - - --- 2026-05-02 Florian Westphal Changes Requested
[nf,3/5] netfilter: x_tables: unregister the templates first netfilter: xtables: fix module unload and teardown races - 1 1 - --- 2026-05-02 Florian Westphal Changes Requested
[nf,2/5] netfilter: x_tables: add and use xt_unregister_table_pre_exit netfilter: xtables: fix module unload and teardown races - - - - --- 2026-05-02 Florian Westphal Changes Requested
[nf,1/5] netfilter: xtables: allocate hook ops while under mutex netfilter: xtables: fix module unload and teardown races - 3 - - --- 2026-05-02 Florian Westphal Changes Requested
[conntrack-tools] conntrackd-netns-test.sh: rework for CI pipelines [conntrack-tools] conntrackd-netns-test.sh: rework for CI pipelines - - - - --- 2026-04-29 Florian Westphal strlen Accepted
[conntrack-tools] tests: allow to run conntrackd-tests.py via unshare [conntrack-tools] tests: allow to run conntrackd-tests.py via unshare - - - - --- 2026-04-29 Florian Westphal strlen Accepted
[nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces [nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-04-29 Florian Westphal Accepted
[nf-next] netfilter: nf_conncount: use per-rule hash initval [nf-next] netfilter: nf_conncount: use per-rule hash initval - - - - --- 2026-04-29 Florian Westphal Accepted
[nf] netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables [nf] netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables - 1 - - --- 2026-04-29 Florian Westphal Accepted
« 1 2 3 440 41 »