Show patches with: Submitter = Florian Westphal       |   3954 patches
« 1 2 3 439 40 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[RFC] netfilter: disable payload mangling in userns [RFC] netfilter: disable payload mangling in userns - - - - --- 2026-05-15 Florian Westphal New
[nf-next,v2] netfilter: add option for GCOV profiling [nf-next,v2] netfilter: add option for GCOV profiling 1 - - - --- 2026-05-12 Florian Westphal New
[v3,nf-next] netfilter: nft_byteorder: remove multi-register support [v3,nf-next] netfilter: nft_byteorder: remove multi-register support - 1 - - --- 2026-05-12 Florian Westphal New
[nf] netfilter: nft_inner: release local_lock before re-enabling softirqs [nf] netfilter: nft_inner: release local_lock before re-enabling softirqs - 1 1 - --- 2026-05-12 Florian Westphal New
[nf] netfilter: nf_conntrack_helper: fix possible null deref during error log [nf] netfilter: nf_conntrack_helper: fix possible null deref during error log - 1 - - --- 2026-05-09 Florian Westphal New
[nft] tests: shell: also test byte-based rate limiting [nft] tests: shell: also test byte-based rate limiting - - - - --- 2026-05-05 Florian Westphal New
[nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces [nf-next] netfilter: x_tables: disable 32bit compat interface in user namespaces - - - - --- 2026-04-29 Florian Westphal New
[nf-next] netfilter: nf_conncount: use per-rule hash initval [nf-next] netfilter: nf_conncount: use per-rule hash initval - - - - --- 2026-04-29 Florian Westphal New
[nf-next,v2] netfilter: nft_set_rbtree: remove dead conditional [nf-next,v2] netfilter: nft_set_rbtree: remove dead conditional - - - - --- 2026-04-11 Florian Westphal New
[v2,nf-next] netfilter: nft_set_pipapo_avx2: restore performance optimization [v2,nf-next] netfilter: nft_set_pipapo_avx2: restore performance optimization - - 1 - --- 2026-04-11 Florian Westphal New
[nf-next,2/2] netfilter: nf_tables: add netlink policy based cap on registers [nf-next,1/2] netfilter: add more netlink-based policy range checks - - - - --- 2026-03-16 Florian Westphal Under Review
[nf-next,1/2] netfilter: add more netlink-based policy range checks [nf-next,1/2] netfilter: add more netlink-based policy range checks - - - - --- 2026-03-16 Florian Westphal Under Review
[conntrack-tools] tests: cli-test.sh: improve logging for CI pipelines [conntrack-tools] tests: cli-test.sh: improve logging for CI pipelines - - - - --- 2026-05-09 Florian Westphal strlen Accepted
[conntrack-tools] tests: bulk-load-stress.sh: return early if ct_max is reached [conntrack-tools] tests: bulk-load-stress.sh: return early if ct_max is reached - - - - --- 2026-05-09 Florian Westphal strlen Accepted
[v3,nf,9/8] netfilter: bridge: eb_tables: close module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-07 Florian Westphal Accepted
[v3,nf,8/8] netfilter: x_tables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,7/8] netfilter: ebtables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,6/8] netfilter: ebtables: move to two-stage removal scheme netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,5/8] netfilter: x_tables: add and use xtables_unregister_table_exit netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,4/8] netfilter: x_tables: unregister the templates first netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,3/8] netfilter: x_tables: add and use xt_unregister_table_pre_exit netfilter: xtables: fix module load and teardown races - - 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,2/8] netfilter: xtables: allocate hook ops while under mutex netfilter: xtables: fix module load and teardown races - 3 - - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,1/8] netfilter: x_tables: allow initial table replace without emitting audit log message netfilter: xtables: fix module load and teardown races - - - - --- 2026-05-06 Florian Westphal Accepted
[nft] src: don't write to possible rodata location [nft] src: don't write to possible rodata location - - - - --- 2026-05-04 Florian Westphal strlen Accepted
[nft] tools: match_nomatch: fix spurious failure in nomatch test [nft] tools: match_nomatch: fix spurious failure in nomatch test - - - - --- 2026-05-04 Florian Westphal strlen Accepted
[conntrack-tools] conntrackd-netns-test.sh: rework for CI pipelines [conntrack-tools] conntrackd-netns-test.sh: rework for CI pipelines - - - - --- 2026-04-29 Florian Westphal strlen Accepted
[conntrack-tools] tests: allow to run conntrackd-tests.py via unshare [conntrack-tools] tests: allow to run conntrackd-tests.py via unshare - - - - --- 2026-04-29 Florian Westphal strlen Accepted
[nf] netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables [nf] netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables - 1 - - --- 2026-04-29 Florian Westphal Accepted
[conntrack-tools] tests: nfct: make it suitable for CI pipeline [conntrack-tools] tests: nfct: make it suitable for CI pipeline - - - - --- 2026-04-28 Florian Westphal strlen Accepted
[nf] netfilter: xt_CT: fix usersize for v1 and v2 revision [nf] netfilter: xt_CT: fix usersize for v1 and v2 revision - 1 - - --- 2026-04-28 Florian Westphal Accepted
[nft] tests: shell: add test case for netdev + dormant table [nft] tests: shell: add test case for netdev + dormant table - - - - --- 2026-04-26 Florian Westphal strlen Accepted
[nf,v3] netfilter: nf_conntrack_sip: don't use simple_strtoul [nf,v3] netfilter: nf_conntrack_sip: don't use simple_strtoul - 1 - - --- 2026-04-23 Florian Westphal Accepted
[nft] evaluate: zap useless 0-shifts [nft] evaluate: zap useless 0-shifts - - 1 - --- 2026-04-22 Florian Westphal strlen Accepted
[iptables] tests: shell: add test case for checkentry hook validations [iptables] tests: shell: add test case for checkentry hook validations - - - - --- 2026-04-19 Florian Westphal strlen Accepted
[nft] tests: shell: add fwd to/fwd ip to test cases [nft] tests: shell: add fwd to/fwd ip to test cases - - - - --- 2026-04-17 Florian Westphal strlen Accepted
[nf,1/2] netfilter: conntrack: remove sprintf usage [nf,1/2] netfilter: conntrack: remove sprintf usage - 1 - - --- 2026-04-14 Florian Westphal strlen Accepted
[nft] tests: py: don't use a fixed filename [nft] tests: py: don't use a fixed filename - - - - --- 2026-04-09 Florian Westphal strlen Accepted
[nft] doc: ct count should be restricted via new [nft] doc: ct count should be restricted via new - - 1 - --- 2026-04-09 Florian Westphal Accepted
[nf-next] netfilter: nft_fwd_netdev: check ttl/hl before forwarding [nf-next] netfilter: nft_fwd_netdev: check ttl/hl before forwarding - 1 - - --- 2026-04-09 Florian Westphal Accepted
[nf-next] netfilter: x_physdev: reject empty or not-nul terminated device names [nf-next] netfilter: x_physdev: reject empty or not-nul terminated device names - - - - --- 2026-04-09 Florian Westphal Accepted
[net,7/7] selftests: nft_queue.sh: add a parallel stress test [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path - - - - --- 2026-04-08 Florian Westphal Accepted
[net,6/7] netfilter: nfnetlink_queue: make hash table per queue [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path - 1 - - --- 2026-04-08 Florian Westphal Accepted
[net,5/7] netfilter: nft_ct: fix use-after-free in timeout object destroy [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path - 1 - - --- 2026-04-08 Florian Westphal Accepted
[net,4/7] netfilter: ip6t_eui64: reject invalid MAC header for all packets [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path - 1 - 1 --- 2026-04-08 Florian Westphal Accepted
[net,3/7] netfilter: xt_multiport: validate range encoding in checkentry [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path - 1 - 1 --- 2026-04-08 Florian Westphal Accepted
[net,2/7] netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path - 1 - - --- 2026-04-08 Florian Westphal Accepted
[net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path [net,1/7] ipvs: fix NULL deref in ip_vs_add_service error path 2 1 - - --- 2026-04-08 Florian Westphal Accepted
[net,0/7] netfilter updates for net - - - - --- 2026-04-08 Florian Westphal Accepted
[GIT,PULL,v2,net-next] netfilter: updates for net-next [GIT,PULL,v2,net-next] netfilter: updates for net-next - - - - --- 2026-04-08 Florian Westphal Accepted
[nf] netfilter: nfnetlink_queue: make hash table per queue [nf] netfilter: nfnetlink_queue: make hash table per queue - 1 - - --- 2026-04-07 Florian Westphal Accepted
[net-next,13/13] netfilter: ctnetlink: restrict expectfn to helper [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,12/13] netfilter: nf_tables_offload: add nft_flow_action_entry_next() and use it [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,11/13] netfilter: nf_conntrack_h323: Correct indentation when H323_TRACE defined [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - 1 - --- 2026-04-07 Florian Westphal Accepted
[net-next,10/13] netfilter: nft_meta: add double-tagged vlan and pppoe support [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,09/13] netfilter: nft_set_pipapo_avx2: remove redundant loop in lookup_slow [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - 1 - --- 2026-04-07 Florian Westphal Accepted
[net-next,08/13] netfilter: nft_set_pipapo: increment data in one step [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - 1 - --- 2026-04-07 Florian Westphal Accepted
[net-next,07/13] netfilter: nf_tables: add netlink policy based cap on registers [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,06/13] netfilter: add more netlink-based policy range checks [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,05/13] netfilter: nf_conntrack_h323: remove unreliable debug code in decode_octstr [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,04/13] netfilter: add deprecation warning for dccp support [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,03/13] netfilter: nf_conntrack_sip: remove net variable shadowing [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,02/13] netfilter: nf_tables: Fix typo in enum description [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers [net-next,01/13] netfilter: use function typedefs for __rcu NAT helper hook pointers - - - - --- 2026-04-07 Florian Westphal Accepted
[net-next,00/13] netfilter: updates for net-next - - - - --- 2026-04-07 Florian Westphal Accepted
[nf-next] netfilter: xt_socket: enable defrag after all other checks [nf-next] netfilter: xt_socket: enable defrag after all other checks - 1 - - --- 2026-04-04 Florian Westphal Accepted
[v2,nf] netfilter: x_tables: ensure names are nul-terminated [v2,nf] netfilter: x_tables: ensure names are nul-terminated - 1 - - --- 2026-03-31 Florian Westphal Accepted
[nf] netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr [nf] netfilter: ipset: use nla_strcmp for IPSET_ATTR_NAME attr - 1 - - --- 2026-03-30 Florian Westphal Accepted
[nf] netfilter: nfnetlink_log: account for netlink header size [nf] netfilter: nfnetlink_log: account for netlink header size - 1 - - --- 2026-03-26 Florian Westphal Accepted
[net,3/3] nfnetlink_osf: validate individual option lengths in fingerprints [net,1/3] netfilter: bpf: defer hook memory release until rcu readers are done - 1 - - --- 2026-03-19 Florian Westphal Accepted
[net,2/3] netfilter: nf_tables: release flowtable after rcu grace period on error [net,1/3] netfilter: bpf: defer hook memory release until rcu readers are done - 1 - - --- 2026-03-19 Florian Westphal Accepted
[net,1/3] netfilter: bpf: defer hook memory release until rcu readers are done [net,1/3] netfilter: bpf: defer hook memory release until rcu readers are done - 1 - - --- 2026-03-19 Florian Westphal Accepted
[net,0/3] netfilter: updates for net - - - - --- 2026-03-19 Florian Westphal Accepted
[nf-next] netfilter: nft_set_pipapo_avx2: remove redundant loop in lookup_slow [nf-next] netfilter: nft_set_pipapo_avx2: remove redundant loop in lookup_slow - - 1 - --- 2026-03-18 Florian Westphal Accepted
[nf-next] netfilter: nft_set_pipapo: increment data in one step [nf-next] netfilter: nft_set_pipapo: increment data in one step - - 1 - --- 2026-03-18 Florian Westphal Accepted
[nf,2/2] selftests: netfilter: nft_concat_range.sh: add check for flush+reload bug netfilter: nft_set_pipapo_avx2: don't return non-matching entry - - 1 - --- 2026-03-18 Florian Westphal Accepted
[nf,1/2] netfilter: nft_set_pipapo_avx2: don't return non-matching entry on expiry netfilter: nft_set_pipapo_avx2: don't return non-matching entry - - 1 - --- 2026-03-18 Florian Westphal Accepted
[nf] netfilter: bpf: defer hook memory release until rcu readers are done [nf] netfilter: bpf: defer hook memory release until rcu readers are done - 1 - - --- 2026-03-17 Florian Westphal Accepted
[net,11/11] netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - 1 --- 2026-03-13 Florian Westphal Accepted
[net,10/11] netfilter: xt_time: use unsigned int for monthday bit shift [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - 1 --- 2026-03-13 Florian Westphal Accepted
[net,09/11] netfilter: xt_CT: drop pending enqueued packets on template removal [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,08/11] netfilter: nft_ct: drop pending enqueued packets on removal [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,07/11] nf_tables: nft_dynset: fix possible stateful expression memleak in error path [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,06/11] netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,05/11] netfilter: nf_flow_table_ip: reset mac header before vlan push [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() 1 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,04/11] netfilter: revert nft_set_rbtree: validate open interval overlap [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() 1 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,03/11] netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,02/11] netfilter: conntrack: add missing netlink policy validations [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 2 - - --- 2026-03-13 Florian Westphal Accepted
[net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() [net,01/11] netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() - 1 - - --- 2026-03-13 Florian Westphal Accepted
[net,00/11] netfilter: updates for net - - - - --- 2026-03-13 Florian Westphal Accepted
[nf-next] netfilter: add deprecation warning for dccp support [nf-next] netfilter: add deprecation warning for dccp support - - - - --- 2026-03-12 Florian Westphal Accepted
[nf-next] netfilter: nf_conntrack_sip: remove net variable shadowing [nf-next] netfilter: nf_conntrack_sip: remove net variable shadowing - - - - --- 2026-03-12 Florian Westphal Accepted
[nf-next] netfilter: nf_conntrack_h323: remove unreliable debug code in decode_octstr [nf-next] netfilter: nf_conntrack_h323: remove unreliable debug code in decode_octstr - - - - --- 2026-03-12 Florian Westphal Accepted
[nft] parser_bison: add range check for synproxy wscale [nft] parser_bison: add range check for synproxy wscale - - - - --- 2026-03-11 Florian Westphal Accepted
[nf] netfilter: revert nft_set_rbtree: validate open interval overlap [nf] netfilter: revert nft_set_rbtree: validate open interval overlap 1 1 - - --- 2026-03-11 Florian Westphal Accepted
[nf] netfilter: conntrack: add missing netlink policy validations [nf] netfilter: conntrack: add missing netlink policy validations - 2 - - --- 2026-03-10 Florian Westphal Accepted
[libnetfilter_conntrack] tests: add a wrapper for the filter test case [libnetfilter_conntrack] tests: add a wrapper for the filter test case - - - - --- 2026-03-09 Florian Westphal Accepted
[libnetfilter_conntrack] tests: test_api: expose return value and fix various bugs [libnetfilter_conntrack] tests: test_api: expose return value and fix various bugs - - - - --- 2026-03-09 Florian Westphal Accepted
[nft] tests: shell: add rbtree reload test case [nft] tests: shell: add rbtree reload test case - - - - --- 2026-03-09 Florian Westphal Accepted
[nf] netfilter: nf_tables: always walk all pending catchall elements [nf] netfilter: nf_tables: always walk all pending catchall elements - 1 - - --- 2026-03-05 Florian Westphal Accepted
[v2,nf] netfilter: nft_set_pipapo: split gc in unlink and reclaim phase [v2,nf] netfilter: nft_set_pipapo: split gc in unlink and reclaim phase - 1 - - --- 2026-03-04 Florian Westphal Accepted
« 1 2 3 439 40 »