Show patches with: Submitter = Florian Westphal       |    Archived = No       |   2473 patches
« 1 2 3 424 25 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[ipset,2/2] lib: don't segfault when ipset_data_get returns NULL - - - - --- 2014-02-12 Florian Westphal kadlec Superseded
[ipset,1/2] lib: fix ifname 'physdev:' prefix parsing - - - - --- 2014-02-12 Florian Westphal kadlec Accepted
[nftables] meta: iif/oifname should be host byte order - - - - --- 2013-09-20 Florian Westphal kadlec Accepted
[nf] netfilter: nf_tables: use kzalloc for hook allocation [nf] netfilter: nf_tables: use kzalloc for hook allocation - 1 - - --- 2024-02-21 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: set dormant flag on hook register failure [nf] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-19 Florian Westphal pablo Accepted
[6.6.y,2/2] netfilter: nf_tables: split async and sync catchall in two functions netfilter: fix catchall element double-free - 1 - - --- 2023-11-21 Florian Westphal pablo Awaiting Upstream
[6.6.y,1/2] netfilter: nf_tables: remove catchall element in GC sync path netfilter: fix catchall element double-free - 1 - - --- 2023-11-21 Florian Westphal pablo Awaiting Upstream
[nf] netfilter: conntrack: fix extension size table [nf] netfilter: conntrack: fix extension size table - 1 - - --- 2023-09-12 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: don't fold port numbers into addresses before hashing [nf] netfilter: conntrack: don't fold port numbers into addresses before hashing - 1 - - --- 2023-07-04 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: gre: don't set assured flag for clash entries [nf] netfilter: conntrack: gre: don't set assured flag for clash entries - 1 - - --- 2023-07-03 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: limit allowed range via nla_policy [nf-next] netfilter: nf_tables: limit allowed range via nla_policy - - - - --- 2023-06-21 Florian Westphal pablo Accepted
[nf,v2] netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one [nf,v2] netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one - 1 1 - --- 2023-06-21 Florian Westphal pablo Accepted
[nf-next,v2] netfilter: snat: evict closing tcp entries on reply tuple collision [nf-next,v2] netfilter: snat: evict closing tcp entries on reply tuple collision - - - - --- 2023-06-06 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: permit update of set size [nf-next] netfilter: nf_tables: permit update of set size - - - - --- 2023-06-06 Florian Westphal pablo Accepted
[nf-next] netfilter: ipset: remove rcu_read_lock_bh pair from ip_set_test [nf-next] netfilter: ipset: remove rcu_read_lock_bh pair from ip_set_test - - - - --- 2023-06-06 Florian Westphal pablo Accepted
[nf] testing: selftests: nft_flowtable.sh: check ingress/egress chain too [nf] testing: selftests: nft_flowtable.sh: check ingress/egress chain too - - - - --- 2023-05-09 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: fix ct untracked match breakage [nf] netfilter: nf_tables: fix ct untracked match breakage - 1 - - --- 2023-05-03 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: fix ifdef to also consider nf_tables=m [nf] netfilter: nf_tables: fix ifdef to also consider nf_tables=m - 1 - - --- 2023-04-17 Florian Westphal pablo Accepted
[nf] netfilter: br_netfilter: fix recent physdev match breakage [nf] netfilter: br_netfilter: fix recent physdev match breakage - 1 - - --- 2023-04-03 Florian Westphal pablo Accepted
[net-next,9/9] netfilter: nat: fix indentation of function arguments [net-next,1/9] netfilter: bridge: introduce broute meta statement - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,8/9] netfilter: conntrack: fix typo [net-next,1/9] netfilter: bridge: introduce broute meta statement - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,7/9] selftests: add a selftest for big tcp [net-next,1/9] netfilter: bridge: introduce broute meta statement - - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,6/9] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim [net-next,1/9] netfilter: bridge: introduce broute meta statement - - 3 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,5/9] netfilter: move br_nf_check_hbh_len to utils [net-next,1/9] netfilter: bridge: introduce broute meta statement - - 3 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,4/9] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len [net-next,1/9] netfilter: bridge: introduce broute meta statement 1 - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,3/9] netfilter: bridge: check len before accessing more nh data [net-next,1/9] netfilter: bridge: introduce broute meta statement 1 - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,2/9] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len [net-next,1/9] netfilter: bridge: introduce broute meta statement 1 - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,1/9] netfilter: bridge: introduce broute meta statement [net-next,1/9] netfilter: bridge: introduce broute meta statement - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,0/9] Netfilter updates for net-next - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[nf] netfilter: tproxy: fix deadlock due to missing BH disable [nf] netfilter: tproxy: fix deadlock due to missing BH disable - 1 - - --- 2023-03-03 Florian Westphal pablo Accepted
[nf] netfilter: ctnetlink: make event listener tracking global [nf] netfilter: ctnetlink: make event listener tracking global - 1 - - --- 2023-02-20 Florian Westphal pablo Accepted
[nf] ebtables: fix table blob use-after-free [nf] ebtables: fix table blob use-after-free - 1 - - --- 2023-02-17 Florian Westphal pablo Accepted
[nf,v2] netfilter: conntrack: fix rmmod double-free race [nf,v2] netfilter: conntrack: fix rmmod double-free race - 1 - - --- 2023-02-14 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: fix rmmod double-free race [nf] netfilter: conntrack: fix rmmod double-free race - 1 - - --- 2023-02-13 Florian Westphal pablo Changes Requested
[RFC,nf-next,3/3] bpf: minimal support for programs hooked into netfilter framework bpf, netfilter: minimal support for bpf progs - - - - --- 2023-02-08 Florian Westphal pablo RFC
[RFC,nf-next,2/3] libbpf: sync header file, add nf prog section name bpf, netfilter: minimal support for bpf progs - - - - --- 2023-02-08 Florian Westphal pablo RFC
[RFC,nf-next,1/3] bpf: add bpf_link support for BPF_NETFILTER programs bpf, netfilter: minimal support for bpf progs - - - - --- 2023-02-08 Florian Westphal pablo RFC
[nf-next] netfilter: let reset rules clean out conntrack entries [nf-next] netfilter: let reset rules clean out conntrack entries - - - - --- 2023-02-01 Florian Westphal pablo Accepted
[RFC] bpf: add bpf_link support for BPF_NETFILTER programs [RFC] bpf: add bpf_link support for BPF_NETFILTER programs - - - - --- 2023-01-30 Florian Westphal pablo RFC
[nf] netfilter: br_netfilter: disable sabotage_in hook after first suppression [nf] netfilter: br_netfilter: disable sabotage_in hook after first suppression - 1 - - --- 2023-01-30 Florian Westphal pablo Accepted
[nf] Revert "netfilter: conntrack: fix bug in for_each_sctp_chunk" [nf] Revert "netfilter: conntrack: fix bug in for_each_sctp_chunk" - 1 - - --- 2023-01-26 Florian Westphal pablo Accepted
[nf-next] netfilter: conntrack: udp: fix seen-reply test [nf-next] netfilter: conntrack: udp: fix seen-reply test - 1 1 - --- 2023-01-23 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: handle tcp challenge acks during connection reuse [nf] netfilter: conntrack: handle tcp challenge acks during connection reuse - 1 - - --- 2023-01-11 Florian Westphal pablo Accepted
[nf] selftests: netfilter: fix transaction test script timeout handling [nf] selftests: netfilter: fix transaction test script timeout handling - 1 - - --- 2023-01-04 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: fix ipv6 exthdr error check [nf] netfilter: conntrack: fix ipv6 exthdr error check - 1 - - --- 2022-12-15 Florian Westphal pablo Accepted
[nft] doc: add/update can be used with maps too [nft] doc: add/update can be used with maps too - - - - --- 2022-12-13 Florian Westphal pablo Accepted
[RFC,ebtables-nft] unify ether type and meta protocol decoding [RFC,ebtables-nft] unify ether type and meta protocol decoding - - - - --- 2022-11-30 Florian Westphal pablo RFC
[v3,iptables-nft,3/3] xlate-test: avoid shell entanglements remove escape_quotes support - - - - --- 2022-11-30 Florian Westphal pablo Accepted
[v3,iptables-nft,2/3] extensions: change expected output for new format remove escape_quotes support - - - - --- 2022-11-30 Florian Westphal pablo Accepted
[v3,iptables-nft,1/3] xlate: get rid of escape_quotes remove escape_quotes support - - - - --- 2022-11-30 Florian Westphal pablo Accepted
[iptables-nft,3/3] extensions: remove trailing spaces remove escape_quotes support - - - - --- 2022-11-24 Florian Westphal pablo Superseded
[iptables-nft,2/3] extensions: change expected output for new format remove escape_quotes support - - - - --- 2022-11-24 Florian Westphal pablo Superseded
[iptables-nft,1/3] xlate: get rid of escape_quotes remove escape_quotes support - - - - --- 2022-11-24 Florian Westphal pablo Superseded
[iptables-nft] iptables-nft: exit nonzero when iptables-save cannot decode all expressions [iptables-nft] iptables-nft: exit nonzero when iptables-save cannot decode all expressions 1 - - - --- 2022-11-23 Florian Westphal pablo Accepted
[nf-next] netfilter: conntrack: add __force annotation to silence harmless warning [nf-next] netfilter: conntrack: add __force annotation to silence harmless warning - 1 - - --- 2022-11-14 Florian Westphal pablo Accepted
[nf-next] netfilter: merge ipv4+ipv6 confirm functions [nf-next] netfilter: merge ipv4+ipv6 confirm functions - - - - --- 2022-11-09 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: avoid access to free'd chain info in nft_commit_release [nf] netfilter: nf_tables: avoid access to free'd chain info in nft_commit_release - 1 - - --- 2022-10-24 Florian Westphal pablo Superseded
[nf-next] netfilter: nf_tables: nft_objref: make it builtin [nf-next] netfilter: nf_tables: nft_objref: make it builtin - - - - --- 2022-10-21 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: reduce nft_pktinfo by 8 bytes [nf-next] netfilter: nf_tables: reduce nft_pktinfo by 8 bytes - - - - --- 2022-10-14 Florian Westphal pablo Accepted
[nf-next] netfilter: conntrack: use siphash_4u64 [nf-next] netfilter: conntrack: use siphash_4u64 - - - - --- 2022-10-14 Florian Westphal pablo Changes Requested
[iptables-nft] iptables-nft: must withdraw PAYLOAD flag after parsing [iptables-nft] iptables-nft: must withdraw PAYLOAD flag after parsing - 1 - - --- 2022-09-19 Florian Westphal pablo Changes Requested
[net,4/4] netfilter: nfnetlink_osf: fix possible bogus match in nf_osf_find() [net,1/4] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers - 1 - - --- 2022-09-08 Florian Westphal pablo Accepted
[net,3/4] netfilter: nf_conntrack_irc: Tighten matching on DCC message [net,1/4] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers - 1 - - --- 2022-09-08 Florian Westphal pablo Accepted
[net,2/4] selftests: nft_concat_range: add socat support [net,1/4] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers - - - - --- 2022-09-08 Florian Westphal pablo Accepted
[net,1/4] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers [net,1/4] netfilter: nf_conntrack_sip: fix ct_sip_walk_headers - 1 - - --- 2022-09-08 Florian Westphal pablo Accepted
[net,0/4] netfilter: bugfixes for net - - - - --- 2022-09-08 Florian Westphal pablo Accepted
[net-next,8/8] netfilter: nat: avoid long-running port range loop [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,7/8] netfilter: nat: move repetitive nat port reserve loop to a helper [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,6/8] netfilter: move from strlcpy with unused retval to strscpy [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - 1 - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,5/8] netfilter: remove NFPROTO_DECNET [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,4/8] netfilter: conntrack: reduce timeout when receiving out-of-window fin or rst [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,3/8] netfilter: conntrack: remove unneeded indent level [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,2/8] netfilter: conntrack: ignore overly delayed tcp packets [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value [net-next,1/8] netfilter: conntrack: prepare tcp_in_window for ternary return value - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[net-next,0/8] netfilter: patches for net-next - - - - --- 2022-09-07 Florian Westphal pablo Accepted
[nf-next,2/2] netfilter: nat: avoid long-running port range loop netfilter: nat: avoid long-running loops - - - - --- 2022-09-06 Florian Westphal pablo Accepted
[nf-next,1/2] netfilter: nat: move repetitive nat port reserve loop to a helper netfilter: nat: avoid long-running loops - - - - --- 2022-09-06 Florian Westphal pablo Accepted
[net,4/4] netfilter: nf_conntrack_irc: Fix forged IP logic [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles - 1 - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,3/4] netfilter: nf_tables: clean up hook list when offload flags check fails [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles - 1 - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,2/4] netfilter: br_netfilter: Drop dst references before setting. [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles 1 1 - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles [net,1/4] netfilter: remove nf_conntrack_helper sysctl and modparam toggles 1 - - - --- 2022-09-01 Florian Westphal pablo Accepted
[net,0/4] netfilter: bug fixes for net - - - - --- 2022-09-01 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: add ebpf expression [nf-next] netfilter: nf_tables: add ebpf expression - - - - --- 2022-08-31 Florian Westphal pablo Changes Requested
[nft] expr: update EXPR_MAX and add missing comments [nft] expr: update EXPR_MAX and add missing comments - - - - --- 2022-08-23 Florian Westphal pablo Accepted
[net,17/17] testing: selftests: nft_flowtable.sh: rework test to detect offload failure [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,16/17] testing: selftests: nft_flowtable.sh: use random netns names [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,15/17] netfilter: conntrack: NF_CONNTRACK_PROCFS should no longer default to y [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - - - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,14/17] netfilter: nf_tables: check NFT_SET_CONCAT flag if field_count is specified [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,13/17] netfilter: nf_tables: disallow NFT_SET_ELEM_CATCHALL and NFT_SET_ELEM_INTERVAL_END [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,12/17] netfilter: nf_tables: NFTA_SET_ELEM_KEY_END requires concat and interval flags [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,11/17] netfilter: nf_tables: validate NFTA_SET_ELEM_OBJREF based on NFT_SET_OBJECT flag [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,10/17] netfilter: nf_tables: really skip inactive sets when allocating name [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,09/17] netfilter: nfnetlink: re-enable conntrack expectation events [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,08/17] netfilter: nf_tables: fix scheduling-while-atomic splat [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,07/17] netfilter: nf_ct_irc: cap packet search space to 4k [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,06/17] netfilter: nf_ct_ftp: prefer skb_linearize [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,05/17] netfilter: nf_ct_h323: cap packet size at 64k [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,04/17] netfilter: nf_ct_sane: remove pseudo skb linearization [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 2 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,03/17] netfilter: nf_tables: possible module reference underflow in error path [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
[net,02/17] netfilter: nf_tables: disallow NFTA_SET_ELEM_KEY_END with NFT_SET_ELEM_INTERVAL_END flag [net,01/17] netfilter: nf_tables: use READ_ONCE and WRITE_ONCE for shared generation id access - 1 - - --- 2022-08-17 Florian Westphal pablo Accepted
« 1 2 3 424 25 »