Show patches with: Submitter = Florian Westphal       |    Archived = No       |   2624 patches
« 1 2 3 426 27 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[v2,net-next,2/2] selftests: netfilter: add phony nft_offload test netdevsim: add fake FT/CLS_FLOWER offload - - - - --- 2026-06-12 Florian Westphal New
[v2,net-next,1/2] netdevsim: tc: allow to test nf_tables offload control plane code netdevsim: add fake FT/CLS_FLOWER offload - - - - --- 2026-06-12 Florian Westphal New
[nf-next] netfilter: conntrack: add deprecation warnings for irc and pptp trackers [nf-next] netfilter: conntrack: add deprecation warnings for irc and pptp trackers - - - - --- 2026-06-12 Florian Westphal New
[nf,v3] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test [nf,v3] selftests: netfilter: conntrack_sctp_collision.sh: Introduce SCTP INIT collision test 1 - - - --- 2026-06-11 Florian Westphal New
[v3,nf-next,3/3] netfilter: nftables: restrict checkum update offset netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-09 Florian Westphal New
[v3,nf-next,2/3] netfilter: nftables: restrict linklayer and network header writes netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-09 Florian Westphal New
[v3,nf-next,1/3] netfilter: nfnetlink_queue: restrict writes to network header netfilter: add restrictions/validations for packet rewrite - - - - --- 2026-06-09 Florian Westphal New
netfilter: x_tables: avoid leaking percpu counter pointers netfilter: add restrictions/validations for packet rewrite - 1 - - --- 2026-06-08 Florian Westphal New
[nf-next,v4,5/5] netfilter: nf_conncount: gc and rcu fixes netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,4/5] netfilter: nf_conncount: add sequence counter to detect tree modifications netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,3/5] netfilter: nf_conncount: split count_tree_node rbtree walk into helper netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,2/5] netfilter: nf_conncount: use per nf_conncount_data spinlocks netfilter: nf_conncount: fix gc and rbtree bugs - - - - --- 2026-06-05 Florian Westphal New
[nf-next,v4,1/5] netfilter: nf_conncount: callers must hold rcu read lock netfilter: nf_conncount: fix gc and rbtree bugs - 1 - - --- 2026-06-05 Florian Westphal New
[nf] selftests: nft_queue.sh: add a bridge queue test [nf] selftests: nft_queue.sh: add a bridge queue test - - - - --- 2026-06-02 Florian Westphal New
[v3,nf,9/8] netfilter: bridge: eb_tables: close module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-07 Florian Westphal Accepted
[v3,nf,8/8] netfilter: x_tables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 - - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,7/8] netfilter: ebtables: close dangling table module init race netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,6/8] netfilter: ebtables: move to two-stage removal scheme netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,5/8] netfilter: x_tables: add and use xtables_unregister_table_exit netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,4/8] netfilter: x_tables: unregister the templates first netfilter: xtables: fix module load and teardown races - 1 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,3/8] netfilter: x_tables: add and use xt_unregister_table_pre_exit netfilter: xtables: fix module load and teardown races - - 1 - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,2/8] netfilter: xtables: allocate hook ops while under mutex netfilter: xtables: fix module load and teardown races - 3 - - --- 2026-05-06 Florian Westphal Accepted
[v3,nf,1/8] netfilter: x_tables: allow initial table replace without emitting audit log message netfilter: xtables: fix module load and teardown races - - - - --- 2026-05-06 Florian Westphal Accepted
[nf] netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables [nf] netfilter: nf_tables: fix netdev hook allocation memleak with dormant tables - 1 - - --- 2026-04-29 Florian Westphal Accepted
[nf] netfilter: xt_CT: fix usersize for v1 and v2 revision [nf] netfilter: xt_CT: fix usersize for v1 and v2 revision - 1 - - --- 2026-04-28 Florian Westphal Accepted
[nf,v3] netfilter: nf_conntrack_sip: don't use simple_strtoul [nf,v3] netfilter: nf_conntrack_sip: don't use simple_strtoul - 1 - - --- 2026-04-23 Florian Westphal Accepted
[nf] netfilter: nft_set_pipapo: don't return bogus extension pointer [nf] netfilter: nft_set_pipapo: don't return bogus extension pointer - 1 - - --- 2025-08-04 Florian Westphal Accepted
[nf,2/2] netfilter: ctnetlink: remove refcounting in expectation dumpers netfilter: ctnetlink: fix memory leak in ctnetlink dump - 2 - - --- 2025-08-01 Florian Westphal Accepted
[nf,1/2] netfilter: ctnetlink: fix refcount leak on table dump netfilter: ctnetlink: fix memory leak in ctnetlink dump - 1 - - --- 2025-08-01 Florian Westphal Accepted
[nf] netfilter: xt_nfacct: don't assume acct name is null-terminated [nf] netfilter: xt_nfacct: don't assume acct name is null-terminated - 1 - 1 --- 2025-07-18 Florian Westphal Accepted
[nf-next,v2,5/5] netfilter: nft_set_pipapo: prefer kvmalloc for scratch maps netfilter: nft_set updates - - 1 - --- 2025-07-09 Florian Westphal Accepted
[nf-next,v2,4/5] netfilter: nft_set_pipapo: merge pipapo_get/lookup netfilter: nft_set updates - - 1 - --- 2025-07-09 Florian Westphal Accepted
[nf-next,v2,3/5] netfilter: nft_set: remove indirection from update API call netfilter: nft_set updates - - - - --- 2025-07-09 Florian Westphal Accepted
[nf-next,v2,2/5] netfilter: nft_set: remove one argument from lookup and update functions netfilter: nft_set updates - - 1 - --- 2025-07-09 Florian Westphal Accepted
[nf-next,v2,1/5] netfilter: nft_set_pipapo: remove unused arguments netfilter: nft_set updates - - 1 - --- 2025-07-09 Florian Westphal Accepted
[nf] netfilter: nf_tables: hide clash bit from userspace [nf] netfilter: nf_tables: hide clash bit from userspace - 1 - - --- 2025-07-07 Florian Westphal Accepted
[nf] selftests: netfilter: nft_concat_range.sh: send packets to empty set [nf] selftests: netfilter: nft_concat_range.sh: send packets to empty set - - - - --- 2025-07-01 Florian Westphal Accepted
[nf,3/4] selftests: netfilter: conntrack_resize.sh: also use udpclash tool netfilter: conntrack: fix obscure confirmed race - - - - --- 2025-06-27 Florian Westphal Accepted
[nf,2/4] selftests: netfilter: add conntrack clash resolution test case netfilter: conntrack: fix obscure confirmed race - - - - --- 2025-06-27 Florian Westphal Accepted
[nf,1/4] selftests: netfilter: conntrack_resize.sh: extend resize test netfilter: conntrack: fix obscure confirmed race - - - - --- 2025-06-27 Florian Westphal Accepted
[nf-next,v2,2/2] netfilter: nf_tables: add packets conntrack state to debug trace info netfilter: nf_tables: include conntrack state in trace messages - - - - --- 2025-05-22 Florian Westphal Accepted
[nf-next,v2,1/2] netfilter: conntrack: make nf_conntrack_id callable without a module dependency netfilter: nf_tables: include conntrack state in trace messages - - - - --- 2025-05-22 Florian Westphal Accepted
[nf-next,v2,5/5] selftests: netfilter: nft_fib.sh: add type and oif tests with and without VRFs netfilter: resolve fib+vrf issues - - - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,4/5] netfilter: nf_tables: nft_fib: consistent l3mdev handling netfilter: resolve fib+vrf issues - 1 - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,3/5] netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy netfilter: resolve fib+vrf issues - 1 - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,2/5] selftests: netfilter: move fib vrf test to nft_fib.sh netfilter: resolve fib+vrf issues - - - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,1/5] selftests: netfilter: nft_fib.sh: add 'type' mode tests netfilter: resolve fib+vrf issues - - - - --- 2025-05-21 Florian Westphal Accepted
[nf-next] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds [nf-next] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds - 1 - - --- 2025-05-16 Florian Westphal Accepted
[nf-next] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation [nf-next] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation - - 1 - --- 2025-05-06 Florian Westphal Accepted
[nf-next] tools: selftests: prepare for non-default IP_TABLES_LEGACY [nf-next] tools: selftests: prepare for non-default IP_TABLES_LEGACY - - - - --- 2025-04-24 Florian Westphal Accepted
[nf-next] netfilter: nf_tables: fix debug splat when dumping pipapo avx2 set [nf-next] netfilter: nf_tables: fix debug splat when dumping pipapo avx2 set - 1 - - --- 2025-04-23 Florian Westphal Accepted
[nf-next] selftests: netfilter: nft_fib.sh: check lo packets bypass fib lookup [nf-next] selftests: netfilter: nft_fib.sh: check lo packets bypass fib lookup - - - - --- 2025-04-23 Florian Westphal Accepted
[v2,nf-next] netfilter: nf_conntrack: speed up reads from nf_conntrack proc file [v2,nf-next] netfilter: nf_conntrack: speed up reads from nf_conntrack proc file - - - - --- 2025-04-22 Florian Westphal Accepted
[nf-next] selftests: netfilter: add conntrack stress test [nf-next] selftests: netfilter: add conntrack stress test - - - - --- 2025-04-17 Florian Westphal Accepted
[nf] netfilter: conntrack: fix erronous removal of offload bit [nf] netfilter: conntrack: fix erronous removal of offload bit - 1 - - --- 2025-04-15 Florian Westphal Accepted
[v2,nf-next] netfilter: nf_tables: export set count and backend name to userspace [v2,nf-next] netfilter: nf_tables: export set count and backend name to userspace - - - - --- 2025-04-08 Florian Westphal Accepted
[v3,nf,2/3] selftests: netfilter: add test case for recent mismatch bug nft_set_pipapo: fix incorrect avx2 match of 5th field octet - - 1 - --- 2025-04-07 Florian Westphal Accepted
[v3,nf,1/3] nft_set_pipapo: fix incorrect avx2 match of 5th field octet nft_set_pipapo: fix incorrect avx2 match of 5th field octet - 1 1 - --- 2025-04-07 Florian Westphal Accepted
[nf] selftests: netfilter: skip br_netfilter queue tests if kernel is tainted [nf] selftests: netfilter: skip br_netfilter queue tests if kernel is tainted - - - - --- 2025-03-11 Florian Westphal Accepted
[nf-next] netfilter: fib: avoid lookup if socket is available [nf-next] netfilter: fib: avoid lookup if socket is available - - - - --- 2025-02-20 Florian Westphal Accepted
[nf] netfilter: nf_tables: do not defer rule destruction via call_rcu [nf] netfilter: nf_tables: do not defer rule destruction via call_rcu - 1 - - --- 2024-12-07 Florian Westphal Accepted
[nf-next] ipvs: speed up reads from ip_vs_conn proc file [nf-next] ipvs: speed up reads from ip_vs_conn proc file 1 - - - --- 2024-12-03 Florian Westphal Accepted
[nf-next,v5,5/5] netfilter: nf_tables: allocate element update information dynamically netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,4/5] netfilter: nf_tables: switch trans_elem to real flex array netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,3/5] netfilter: nf_tables: prepare nft audit for set element compaction netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,2/5] netfilter: nf_tables: prepare for multiple elements in nft_trans_elem structure netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,1/5] netfilter: nf_tables: add nft_trans_commit_list_add_elem helper netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v3,7/7] netfilter: nf_tables: must hold rcu read lock while iterating object type list netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,6/7] netfilter: nf_tables: must hold rcu read lock while iterating expression type list netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,5/7] netfilter: nf_tables: avoid false-positive lockdep splats with basechain hook netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,4/7] netfilter: nf_tables: avoid false-positive lockdep splats in set walker netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,3/7] netfilter: nf_tables: avoid false-positive lockdep splats with flowtables netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,2/7] netfilter: nf_tables: avoid false-positive lockdep splats with sets netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,1/7] netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - 1 --- 2024-11-04 Florian Westphal Accepted
[nft,v2] doc: extend description of fib expression [nft,v2] doc: extend description of fib expression - - 1 - --- 2024-10-30 Florian Westphal Accepted
[nft] src: allow to map key to nfqueue number [nft] src: allow to map key to nfqueue number - - - - --- 2024-10-25 Florian Westphal Accepted
[nf] netfilter: bpf: must hold reference on net namespace [nf] netfilter: bpf: must hold reference on net namespace - 1 1 - --- 2024-10-10 Florian Westphal Accepted
[nf,2/2] selftests: netfilter: conntrack_vrf.sh: add fib test case [nf,1/2] netfilter: fib: check correct rtable in vrf setups - - - - --- 2024-10-09 Florian Westphal Accepted
[nf,1/2] netfilter: fib: check correct rtable in vrf setups [nf,1/2] netfilter: fib: check correct rtable in vrf setups - 1 - - --- 2024-10-09 Florian Westphal Accepted
[nf,v3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed [nf,v3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed - 1 - - --- 2024-10-07 Florian Westphal Accepted
[nf-next,4/4] netfilter: nf_tables: use skb_drop_reason netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf-next,3/4] netfilter: nf_nat: use skb_drop_reason netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf-next,2/4] netfilter: xt_nat: drop packet earlier netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf-next,1/4] netfilter: xt_nat: compact nf_nat_setup_info calls netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf] kselftest: add test for nfqueue induced conntrack race [nf] kselftest: add test for nfqueue induced conntrack race - - - - --- 2024-09-18 Florian Westphal Accepted
[nf] netfilter: nfnetlink_queue: remove old clash resolution logic [nf] netfilter: nfnetlink_queue: remove old clash resolution logic - - - 1 --- 2024-09-18 Florian Westphal Accepted
[nf-next,3/3] selftests: netfilter: add reverse-clash resolution test case netfilter: conntrack: clash resolution for reverse collisions - - - - --- 2024-09-10 Florian Westphal Accepted
[nf-next,2/3] netfilter: conntrack: add clash resolution for reverse collisions netfilter: conntrack: clash resolution for reverse collisions - - - - --- 2024-09-10 Florian Westphal Accepted
[nf-next,1/3] netfilter: nf_nat: don't try nat source port reallocation for reverse dir clash netfilter: conntrack: clash resolution for reverse collisions - - - - --- 2024-09-10 Florian Westphal Accepted
[nf,v2,2/2] netfilter: nft_socket: make cgroupsv2 matching work with namespaces Untitled series #422862 - 1 - - --- 2024-09-07 Florian Westphal Accepted
[nf,1/2] netfilter: nft_socket: fix sk refcount leaks [nf,1/2] netfilter: nft_socket: fix sk refcount leaks - 1 - - --- 2024-09-05 Florian Westphal Accepted
[nf-next] netfilter: nf_tables: drop unused 3rd argument from validate callback ops [nf-next] netfilter: nf_tables: drop unused 3rd argument from validate callback ops - - - - --- 2024-08-28 Florian Westphal Accepted
[nf-next,3/3] netfilter: nf_tables: don't initialize registers in nft_do_chain() netfilter: nf_tables: reject loads from - - - - --- 2024-08-20 Florian Westphal Accepted
[nf-next,2/3] netfilter: nf_tables: allow loads only when register is initialized netfilter: nf_tables: reject loads from - - - - --- 2024-08-20 Florian Westphal Accepted
[nf-next,1/3] netfilter: nf_tables: pass context structure to nft_parse_register_load netfilter: nf_tables: reject loads from - - - - --- 2024-08-20 Florian Westphal Accepted
[nf] selftests: netfilter: add test case for recent mismatch bug [nf] selftests: netfilter: add test case for recent mismatch bug - - 1 - --- 2024-07-15 Florian Westphal Accepted
[nf] netfilter: nf_set_pipapo: fix initial map fill [nf] netfilter: nf_set_pipapo: fix initial map fill - 1 1 - --- 2024-07-15 Florian Westphal Accepted
[nf-next] netfilter: nf_tables: store new sets in dedicated list [nf-next] netfilter: nf_tables: store new sets in dedicated list - 1 - - --- 2024-07-10 Florian Westphal Accepted
[nf] netfilter: nf_tables: unconditionally flush pending work before notifier [nf] netfilter: nf_tables: unconditionally flush pending work before notifier - 1 - - --- 2024-07-02 Florian Westphal Accepted
[nf-next] selftests: netfilter: nft_queue.sh: sctp coverage [nf-next] selftests: netfilter: nft_queue.sh: sctp coverage - - - - --- 2024-07-02 Florian Westphal Accepted
« 1 2 3 426 27 »