Show patches with: Submitter = Pablo Neira Ayuso       |    Archived = No       |   9783 patches
« 1 2 3 497 98 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[net] netlink: validate length of NLA_{BE16,BE32} types [net] netlink: validate length of NLA_{BE16,BE32} types - 1 - - --- 2024-02-25 Pablo Neira Ayuso New
[net,5/5] netfilter: nf_tables: use kzalloc for hook allocation [net,1/5] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-22 Pablo Neira Ayuso Accepted
[net,4/5] netfilter: nf_tables: register hooks last when adding new chain/flowtable [net,1/5] netfilter: nf_tables: set dormant flag on hook register failure - 2 - - --- 2024-02-22 Pablo Neira Ayuso Accepted
[net,3/5] netfilter: nft_flow_offload: release dst in case direct xmit path is used [net,1/5] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-22 Pablo Neira Ayuso Accepted
[net,2/5] netfilter: nft_flow_offload: reset dst in route object after setting up flow [net,1/5] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-22 Pablo Neira Ayuso Accepted
[net,1/5] netfilter: nf_tables: set dormant flag on hook register failure [net,1/5] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-22 Pablo Neira Ayuso Accepted
[net,0/5] Netfilter fixes for net - - - - --- 2024-02-22 Pablo Neira Ayuso Accepted
[nf] netfilter: nf_tables: register hooks last when adding new chain/flowtable [nf] netfilter: nf_tables: register hooks last when adding new chain/flowtable - 2 - - --- 2024-02-21 Pablo Neira Ayuso pablo Accepted
[nf,2/2] netfilter: nft_flow_offload: release dst in case direct xmit path is used [nf,1/2] netfilter: nft_flow_offload: reset dst in route object after setting up flow - 1 - - --- 2024-02-21 Pablo Neira Ayuso pablo Accepted
[nf,1/2] netfilter: nft_flow_offload: reset dst in route object after setting up flow [nf,1/2] netfilter: nft_flow_offload: reset dst in route object after setting up flow - 1 - - --- 2024-02-21 Pablo Neira Ayuso pablo Accepted
[libnftnl] obj: ct_timeout: setter checks for timeout array boundaries [libnftnl] obj: ct_timeout: setter checks for timeout array boundaries - 1 - - --- 2024-02-20 Pablo Neira Ayuso New
[nft] expression: missing line in describe command with invalid expression [nft] expression: missing line in describe command with invalid expression - 1 - - --- 2024-02-13 Pablo Neira Ayuso Accepted
[nft,2/2] netlink_linearize: add assertion to catch for buggy byteorder [v2,nft,1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes - - - - --- 2024-02-08 Pablo Neira Ayuso Accepted
[v2,nft,1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes [v2,nft,1/2] evaluate: skip byteorder conversion for selector smaller than 2 bytes - 1 - - --- 2024-02-08 Pablo Neira Ayuso Accepted
[nft] evaluate: skip byteorder conversion for selector smaller than 2 bytes [nft] evaluate: skip byteorder conversion for selector smaller than 2 bytes - 1 - - --- 2024-02-07 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nf_tables: use timestamp to check for set element timeout [nf] netfilter: nf_tables: use timestamp to check for set element timeout - 1 - - --- 2024-02-07 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_ct: reject direction for ct id [nf] netfilter: nft_ct: reject direction for ct id - 1 - - --- 2024-02-05 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_compat: reject unused compat flag [nf] netfilter: nft_compat: reject unused compat flag - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_compat: restrict match/target protocol to u16 [nf] netfilter: nft_compat: restrict match/target protocol to u16 - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_compat: narrow down revision to unsigned 8-bits [nf] netfilter: nft_compat: narrow down revision to unsigned 8-bits - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_set_pipapo: remove static in nft_pipapo_get() [nf] netfilter: nft_set_pipapo: remove static in nft_pipapo_get() - 1 - - --- 2024-02-02 Pablo Neira Ayuso Accepted
[net,6/6] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - 1 - - --- 2024-01-31 Pablo Neira Ayuso Accepted
[net,5/6] netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - 1 - - --- 2024-01-31 Pablo Neira Ayuso Accepted
[net,4/6] netfilter: ipset: fix performance regression in swap operation [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - 1 - 1 --- 2024-01-31 Pablo Neira Ayuso Accepted
[net,3/6] netfilter: conntrack: check SCTP_CID_SHUTDOWN_ACK for vtag setting in sctp_new [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - - - - --- 2024-01-31 Pablo Neira Ayuso Accepted
[net,2/6] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - 1 - - --- 2024-01-31 Pablo Neira Ayuso Accepted
[net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN [net,1/6] netfilter: conntrack: correct window scaling with retransmitted SYN - 1 - - --- 2024-01-31 Pablo Neira Ayuso Accepted
[net,0/6] Netfilter fixes for net - - - - --- 2024-01-31 Pablo Neira Ayuso Accepted
[nf,v2] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations [nf,v2] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - 1 - - --- 2024-01-29 Pablo Neira Ayuso Accepted
[nf] netfilter: nft_ct: bail out if helper is not found for NFPROTO_{IPV4,IPV6} [nf] netfilter: nft_ct: bail out if helper is not found for NFPROTO_{IPV4,IPV6} - 1 - - --- 2024-01-29 Pablo Neira Ayuso Not Applicable
[nf,v2] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV [nf,v2] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV - 1 - - --- 2024-01-29 Pablo Neira Ayuso Accepted
[nf] netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger [nf] netfilter: nf_log: replace BUG_ON by WARN_ON_ONCE when putting logger - 1 - - --- 2024-01-29 Pablo Neira Ayuso Accepted
[nf] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV [nf] netfilter: nf_tables: restrict tunnel object to NFPROTO_NETDEV - 1 - - --- 2024-01-29 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations [nf] netfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations - 1 - - --- 2024-01-29 Pablo Neira Ayuso Changes Requested
[nf,v3] netfilter: nf_tables: validate NFPROTO_* family [nf,v3] netfilter: nf_tables: validate NFPROTO_* family - 7 - - --- 2024-01-24 Pablo Neira Ayuso Accepted
[nf,v2] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family [nf,v2] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family - 7 - - --- 2024-01-24 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family [nf] netfilter: nf_tables: validate NFPROTO_{IPV4,IPV6,INET} family - - - - --- 2024-01-23 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain [nf] netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,13/13] ipvs: avoid stat macros calls from preemptible context [net,01/13] netfilter: nf_tables: reject invalid set policy 2 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,12/13] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,11/13] netfilter: nf_tables: skip dead set elements in netlink dump [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,10/13] netfilter: nf_tables: do not allow mismatch field size and set key length [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,09/13] netfilter: nf_tables: check if catch-all set element is active in next generation [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,08/13] netfilter: bridge: replace physindev with physinif in nf_bridge_info [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,07/13] netfilter: propagate net to nf_bridge_get_physindev [net,01/13] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,06/13] netfilter: nf_queue: remove excess nf_bridge variable [net,01/13] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,05/13] netfilter: nfnetlink_log: use proper helper for fetching physinif [net,01/13] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,04/13] netfilter: nft_limit: do not ignore unsupported flags [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,03/13] netfilter: nf_tables: bail out if stateful expression provides no .clone [net,01/13] netfilter: nf_tables: reject invalid set policy - - - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,02/13] netfilter: nf_tables: validate .maxattr at expression registration [net,01/13] netfilter: nf_tables: reject invalid set policy - - - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,01/13] netfilter: nf_tables: reject invalid set policy [net,01/13] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,v2,00/13] Netfilter fixes for net - - - - --- 2024-01-18 Pablo Neira Ayuso Accepted
[net,14/14] netfilter: ipset: fix performance regression in swap operation [net,01/14] netfilter: nf_tables: reject invalid set policy - 2 - 2 --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,13/14] ipvs: avoid stat macros calls from preemptible context [net,01/14] netfilter: nf_tables: reject invalid set policy 2 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,12/14] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,11/14] netfilter: nf_tables: skip dead set elements in netlink dump [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,10/14] netfilter: nf_tables: do not allow mismatch field size and set key length [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,09/14] netfilter: nf_tables: check if catch-all set element is active in next generation [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,08/14] netfilter: bridge: replace physindev with physinif in nf_bridge_info [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,07/14] netfilter: propagate net to nf_bridge_get_physindev [net,01/14] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,06/14] netfilter: nf_queue: remove excess nf_bridge variable [net,01/14] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,05/14] netfilter: nfnetlink_log: use proper helper for fetching physinif [net,01/14] netfilter: nf_tables: reject invalid set policy - - 1 - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,04/14] netfilter: nft_limit: do not ignore unsupported flags [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,03/14] netfilter: nf_tables: bail out if stateful expression provides no .clone [net,01/14] netfilter: nf_tables: reject invalid set policy - - - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,02/14] netfilter: nf_tables: validate .maxattr at expression registration [net,01/14] netfilter: nf_tables: reject invalid set policy - - - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,01/14] netfilter: nf_tables: reject invalid set policy [net,01/14] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[net,00/14] Netfilter fixes for net - - - - --- 2024-01-17 Pablo Neira Ayuso Changes Requested
[nf] netfilter: nf_tables: skip dead set elements in netlink dump [nf] netfilter: nf_tables: skip dead set elements in netlink dump - 1 - - --- 2024-01-15 Pablo Neira Ayuso Accepted
[nf] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description [nf] netfilter: nf_tables: reject NFT_SET_CONCAT with not field length description - 1 - - --- 2024-01-15 Pablo Neira Ayuso Accepted
[nf] netfilter: nf_tables: do not allow mismatch field size and set key length [nf] netfilter: nf_tables: do not allow mismatch field size and set key length - 1 - - --- 2024-01-15 Pablo Neira Ayuso Accepted
[nf] netfilter: nf_tables: check if catch-all set element is active in next generation [nf] netfilter: nf_tables: check if catch-all set element is active in next generation - 1 - - --- 2024-01-12 Pablo Neira Ayuso Accepted
[libnftnl,v3] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA} [libnftnl,v3] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA} - - - - --- 2024-01-12 Pablo Neira Ayuso Accepted
[libnftnl] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA} [libnftnl] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA} - - - - --- 2024-01-12 Pablo Neira Ayuso Changes Requested
[libnftnl] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA} [libnftnl] set_elem: use nftnl_data_cpy() in NFTNL_SET_ELEM_{KEY,KEY_END,DATA} - - - - --- 2024-01-12 Pablo Neira Ayuso Changes Requested
[libnftnl] set: buffer overflow in NFTNL_SET_DESC_CONCAT setter [libnftnl] set: buffer overflow in NFTNL_SET_DESC_CONCAT setter - 1 - - --- 2024-01-11 Pablo Neira Ayuso Accepted
[nft,2/2] evaluate: release mpz type in expr_evaluate_list() error path memleak fixes for tests/shell/testcases/bogons/nft-f/ - 1 - - --- 2024-01-11 Pablo Neira Ayuso Accepted
[nft,1/2] evaluate: release key expression in error path of implicit map with unknown datatype memleak fixes for tests/shell/testcases/bogons/nft-f/ - 1 - - --- 2024-01-11 Pablo Neira Ayuso Accepted
[nft,v2] evaluate: bail out if anonymous concat set defines a non concat expression [nft,v2] evaluate: bail out if anonymous concat set defines a non concat expression - - - - --- 2024-01-11 Pablo Neira Ayuso Accepted
[nft,4/4] Revert "datatype: do not assert when value exceeds expected width" assorted fixes - - - - --- 2024-01-10 Pablo Neira Ayuso Not Applicable
[nft,3/4] evaluate: bail out if anonymous concat set defines a non concat expression assorted fixes - - - - --- 2024-01-10 Pablo Neira Ayuso Changes Requested
[nft,2/4] evaluate: do not fetch next expression on runaway number of concatenation components assorted fixes - 1 - - --- 2024-01-10 Pablo Neira Ayuso Accepted
[nft,1/4] evaluate: skip anonymous set optimization for concatenations assorted fixes - 1 - - --- 2024-01-10 Pablo Neira Ayuso Accepted
[nft] doc: incorrect datatype description for icmpv6_type and icmpvx_code [nft] doc: incorrect datatype description for icmpv6_type and icmpvx_code - - - - --- 2024-01-09 Pablo Neira Ayuso Accepted
[nf-next] netfilter: nf_tables: bail out if stateful expression provides no .clone [nf-next] netfilter: nf_tables: bail out if stateful expression provides no .clone - - - - --- 2024-01-08 Pablo Neira Ayuso Accepted
[nf-next] netfilter: nf_tables: validate .maxattr at expression registration [nf-next] netfilter: nf_tables: validate .maxattr at expression registration - - - - --- 2024-01-08 Pablo Neira Ayuso Accepted
[nft] tests: shell: extend coverage for netdevice removal [nft] tests: shell: extend coverage for netdevice removal - - - - --- 2024-01-08 Pablo Neira Ayuso Accepted
[nf-next] netfilter: nf_tables: pass flags to set backend selection routine [nf-next] netfilter: nf_tables: pass flags to set backend selection routine - - - - --- 2024-01-04 Pablo Neira Ayuso strlen Accepted
[nf] netfilter: nf_tables: reject invalid set policy [nf] netfilter: nf_tables: reject invalid set policy - 1 - - --- 2024-01-04 Pablo Neira Ayuso Accepted
[libnftnl] object: define nftnl_obj_unset() [libnftnl] object: define nftnl_obj_unset() - 1 - - --- 2024-01-02 Pablo Neira Ayuso Accepted
[net-next,8/8] netfilter: nf_tables: validate chain type update if available [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - 1 - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,7/8] netfilter: ctnetlink: support filtering by zone [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - - - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,6/8] netfilter: nf_tables: mark newset as dead on transaction abort [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - 1 - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,5/8] netfilter: flowtable: reorder nf_flowtable struct members [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - - - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,4/8] netfilter: nft_set_pipapo: prefer gfp_kernel allocation [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - 1 - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,3/8] netfilter: nf_tables: Add locking for NFT_MSG_GETSETELEM_RESET requests [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - - - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,2/8] netfilter: nf_tables: Introduce nft_set_dump_ctx_init() [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - - - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem [net-next,1/8] netfilter: nf_tables: Pass const set to nft_get_set_elem - - - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net-next,0/8] Netfilter updates for net-next - - - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net,2/2] netfilter: nf_tables: skip set commit for deleted/destroyed sets [net,1/2] netfilter: nf_tables: set transport offset from mac header for netdev/egress - 1 - - --- 2023-12-22 Pablo Neira Ayuso Accepted
[net,1/2] netfilter: nf_tables: set transport offset from mac header for netdev/egress [net,1/2] netfilter: nf_tables: set transport offset from mac header for netdev/egress - 1 - - --- 2023-12-22 Pablo Neira Ayuso Accepted
« 1 2 3 497 98 »