Toggle navigation
Patchwork
Netfilter Development
Patches
Bundles
About this project
Login
Register
Mail settings
Show patches with
: State =
Action Required
| Archived =
No
| 136 patches
Series
Submitter
State
any
Action Required
New
Under Review
Accepted
Rejected
RFC
Not Applicable
Changes Requested
Awaiting Upstream
Superseded
Deferred
Needs Review / ACK
Handled Elsewhere
Search
Archived
No
Yes
Both
Delegate
------
Nobody
jgarzik
arnd
ymano
smfrench
jlayton
tseliot
ogasawara
amitk
awhitcroft
mst
dayangkun
jwboyer
jwboyer
colinking
colinking
azummo
dwmw2
rtg
sconklin
smb
aliguori
bradf
demarchi
ms
bhundven
chbs
kengyu
kadlec
regit
jabk
laforge
laforge
tonyb
alai
zecke
zecke
__damien__
luka
luka
prafulla@marvell.com
cyrus
PeterHuewe
kiho
jow
jow
ypwong
nico
dedeckeh
dedeckeh
yousong
yousong
tomcwarren
mb
patrick_delaunay
mrchuck
vineetg76
computersforpeace
Noltari
Noltari
ee07b291
ldir
ldir
stefanct
zhouhan
carldani
blp
ffainelli
ffainelli
regXboi
bbrezillon
pravin
mkp
jpettit
mkresin
mkresin
thess
thess
fbarrat
fbarrat
phil
linville
jesse
tjaalton
esben
abrodkin
abrodkin
diproiettod
tbot
stephenfin
ajd
darball1
sammj
jogo
jogo
bhelgaas
blogic
blogic
tagr
tagr
oohal
russellb
ptomsich
agraf
joestringer
mwalle
naveen
pepe2k
pepe2k
pchotard
arj
arj
davem
davem
davem
jforissier
andmur01
amitay
matttbe
pabeni
istokes
aparcar
martineau
maddy
Ansuel
danielschwierzeck
goliath
mariosix
dcaratti
aserdean
ovsrobot
ovsrobot
tpetazzoni
marex
mkorpershoek
khem
XiaoYang
liwang
robimarko
apritzel
danielhb
groug
npiggin
mmichelson
pareddja
atishp
netdrv
mkubecek
stintel
stintel
jkicinski
cpitchen
dsa
jstancek
bpf
shettyg
lorpie01
acelan
wigyori
wigyori
pm215
apopple
dja
alexhung
lynxis
lynxis
brgl
brgl
peda
akodanev
0andriy
981213
narmstrong
snowpatch_ozlabs
snowpatch_ozlabs
snowpatch_ozlabs
aivanov
atishp04
shemminger
blocktrron
monstr
vigneshr
mraynal
chunkeey
stewart
stewart
jacmet
kabel
Jaehoon
metan
rfried
ag
kevery
horms
rsalvaterra
adrianschmutzler
hegdevasant
hegdevasant
akumar
sjg
arbab
jagan
ukleinek
ukleinek
prom
ehristev
freenix
rmilecki
rmilecki
wsa
bmeng
xypron
ivanhu
apconole
trini
wbx
legoater
legoater
legoater
abelloni
chleroy
rw
rw
juju
svanheule
pablo
pablo
bjonglez
ynezz
sbabic
sbabic
xback
xback
pevik
richiejp
dangole
dangole
jonhunter
aik
echaudron
forty
acer
next_ghost
amusil
Hauke
Hauke
anuppatel
anuppatel
benh
rgrimm
segher
passgat
pratyush
jms
jms
jms
Andes
mans0n
ruscur
ymorin
jmberg
numans
jk
jk
jk
jk
festevam
xuyang
linusw
linusw
tambarus
conchuod
kubu
tytso
matthias_bgg
ltpci
krzk
spectrum
imaximets
pbrobinson
strlen
strlen
stroese
dceara
apalos
cazzacarna
neocturne
aldot
TIENFONG
mpe
galak
sfr
ktraynor
arnout
robh
nbd
nbd
kcxt
anguy11
paulus
jm
mwilczynski
hs
Apply
«
1
2
»
Patch
Series
A/F/R/T
S/W/F
Date
Submitter
Delegate
State
[nf-next,v2] netfilter: conntrack: Add missing modification about data-race around ct->timeout
[nf-next,v2] netfilter: conntrack: Add missing modification about data-race around ct->timeout
- 1 - -
-
-
-
2025-11-19
Chenguang Zhao
New
[nf-next,2/2] netfilter: nfnetlink: bail out batch processing with EMLINK
[nf-next,1/2] netfilter: nf_tables: skip register jump/goto validation for non-base chain
- 1 - -
-
-
-
2025-11-18
Pablo Neira Ayuso
New
[nf-next,1/2] netfilter: nf_tables: skip register jump/goto validation for non-base chain
[nf-next,1/2] netfilter: nf_tables: skip register jump/goto validation for non-base chain
- 1 - -
-
-
-
2025-11-18
Pablo Neira Ayuso
New
[RFC,v4,19/19] landlock: Document socket rule type support
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,18/19] samples/landlock: Support socket protocol restrictions
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,17/19] selftests/landlock: Test socket creation denial log for audit
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,16/19] landlock: Log socket creation denials
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,15/19] lsm: Support logging socket common data
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,14/19] selftests/landlock: Test that accept(2) is not restricted
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,13/19] selftests/landlock: Test SCTP peeloff restriction
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,12/19] selftests/landlock: Test socketpair(2) restriction
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,11/19] selftests/landlock: Test protocol mappings
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,10/19] selftests/landlock: Test that kernel space sockets are not restricted
Support socket access-control
- - 1 -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,09/19] selftests/landlock: Test overlapped rulesets with rules of protocol ranges
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,08/19] selftests/landlock: Test network stack error code consistency
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,07/19] selftests/landlock: Test basic socket restriction
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,06/19] landlock: Add hook on socket creation
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,05/19] selftests/landlock: Test acceptable ranges of socket rule key
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,04/19] selftests/landlock: Testing adding rule with wildcard value
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,03/19] selftests/landlock: Test adding a socket rule
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,02/19] selftests/landlock: Test creating a ruleset with unknown access
Support socket access-control
- - 1 -
-
-
-
2025-11-18
Mikhail Ivanov
New
[RFC,v4,01/19] landlock: Support socket access-control
Support socket access-control
- - - -
-
-
-
2025-11-18
Mikhail Ivanov
New
[nf-next,3/3] netfilter: nft_set_rbtree: do not modifiy live tree
netfilter: nft_set_rbtree: use cloned tree for insertions and removal
- 1 - -
-
-
-
2025-11-18
Florian Westphal
New
[nf-next,2/3] netfilter: nft_set_rbtree: factor out insert helper
netfilter: nft_set_rbtree: use cloned tree for insertions and removal
- - - -
-
-
-
2025-11-18
Florian Westphal
New
[nf-next,1/3] netfilter: nft_set_rbtree: prepare for two rbtrees
netfilter: nft_set_rbtree: use cloned tree for insertions and removal
- - - -
-
-
-
2025-11-18
Florian Westphal
New
[nft,2/2] tests: shell: refer to python3 in json prettify script
[nft,1/2] tests: shell: add device to sets/0075tunnel_0 to support older kernels
- - - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[nft,1/2] tests: shell: add device to sets/0075tunnel_0 to support older kernels
[nft,1/2] tests: shell: add device to sets/0075tunnel_0 to support older kernels
- - - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,5.10,1/1] netfilter: nft_socket: fix sk refcount leaks
Netfilter fixes for -stable
- 1 - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,5.10,1/1] netfilter: nf_tables: reject duplicate device on updates
[-stable,5.10,1/1] netfilter: nf_tables: reject duplicate device on updates
- 2 - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,5.15,1/1] netfilter: nf_tables: reject duplicate device on updates
Netfilter fixes for -stable
- 2 - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,6.1,1/1] netfilter: nf_tables: reject duplicate device on updates
Netfilter fixes for -stable
- 2 - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,6.6,1/1] netfilter: nf_tables: reject duplicate device on updates
Netfilter fixes for -stable
- 2 - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,6.12,2/2] netfilter: nf_tables: reject duplicate device on updates
Netfilter fixes for -stable
- 2 - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[-stable,6.12,1/2] Revert "netfilter: nf_tables: Reintroduce shortened deletion notifications"
Netfilter fixes for -stable
- - - -
-
-
-
2025-11-17
Pablo Neira Ayuso
New
[linux] netfilter: conntrack: Add missing modification about data-race around ct->timeout
[linux] netfilter: conntrack: Add missing modification about data-race around ct->timeout
- 1 - -
-
-
-
2025-11-17
Chenguang Zhao
New
[nft,v2] src: add connlimit stateful object support
[nft,v2] src: add connlimit stateful object support
- - - -
-
-
-
2025-11-15
Fernando Fernandez Mancera
New
[v7,2/2] audit: include source and destination ports to NETFILTER_PKT
audit: improve NETFILTER_PKT records
- - - -
-
-
-
2025-11-14
Ricardo Robaina
New
[v7,1/2] audit: add audit_log_nf_skb helper function
audit: improve NETFILTER_PKT records
- - - -
-
-
-
2025-11-14
Ricardo Robaina
New
[nft,v2,11/11] utils: Introduce expr_print_debug()
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,10/11] tests: py: Update payload records
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,09/11] tests: py: tools: Add regen_payloads.sh
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,08/11] netlink: Make use of nftnl_{expr,set_elem}_set_imm()
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,07/11] netlink: Introduce struct nft_data_linearize::sizes
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,06/11] netlink: Introduce struct nft_data_linearize::byteorder
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,05/11] expression: Set range expression 'len' field
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,04/11] intervals: Convert byte order implicitly
Fix netlink debug output on Big Endian
- - - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,03/11] mergesort: Align concatenation sort order with Big Endian
Fix netlink debug output on Big Endian
- 1 - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,02/11] mergesort: Fix sorting of string values
Fix netlink debug output on Big Endian
- 1 - -
-
-
-
2025-11-14
Phil Sutter
New
[nft,v2,01/11] segtree: Fix range aggregation on Big Endian
Fix netlink debug output on Big Endian
- 1 - -
-
-
-
2025-11-14
Phil Sutter
New
[nf-next,v4] parser_json: support handle for rule positioning without breaking other objects
[nf-next,v4] parser_json: support handle for rule positioning without breaking other objects
- - - -
-
-
-
2025-11-13
Alexandre Knecht
New
[v2] tests: shell: add packetpath test for meta time expression.
[v2] tests: shell: add packetpath test for meta time expression.
- - 1 -
-
-
-
2025-11-13
Yi Chen
New
[6/6,nf-next,v3] netfilter: nft_connlimit: update the count if add was skipped
netfilter: rework conncount API to receive sk_buff directly
- 1 - -
-
-
-
2025-11-12
Fernando Fernandez Mancera
New
[5/6,nf-next,v3] netfilter: nf_conncount: make nf_conncount_gc_list() to disable BH
netfilter: rework conncount API to receive sk_buff directly
- - - -
-
-
-
2025-11-12
Fernando Fernandez Mancera
New
[4/6,nf-next,v3] netfilter: nf_conncount: pass the sk_buff down to __nf_conncount_add()
netfilter: rework conncount API to receive sk_buff directly
- 1 - -
-
-
-
2025-11-12
Fernando Fernandez Mancera
New
[3/6,nf-next,v3] openvswitch: use nf_conncount_count_skb() directly
netfilter: rework conncount API to receive sk_buff directly
- - - -
-
-
-
2025-11-12
Fernando Fernandez Mancera
New
[2/6,nf-next,v3] netfilter: xt_connlimit: use nf_conncount_count_skb() directly
netfilter: rework conncount API to receive sk_buff directly
- - - -
-
-
-
2025-11-12
Fernando Fernandez Mancera
New
[1/6,nf-next,v3] netfilter: nf_conncount: introduce new nf_conncount_count_skb() API
netfilter: rework conncount API to receive sk_buff directly
- - - -
-
-
-
2025-11-12
Fernando Fernandez Mancera
New
[v17,nf-next,4/4] netfilter: nft_chain_filter: Add bridge double vlan and pppoe
conntrack: bridge: add double vlan, pppoe and pppoe-in-q
- - - -
-
-
-
2025-11-09
Eric Woudstra
New
[v17,nf-next,3/4] netfilter: nft_set_pktinfo_ipv4/6_validate: Add nhoff argument
conntrack: bridge: add double vlan, pppoe and pppoe-in-q
- - - -
-
-
-
2025-11-09
Eric Woudstra
New
[v17,nf-next,2/4] netfilter: bridge: Add conntrack double vlan and pppoe
conntrack: bridge: add double vlan, pppoe and pppoe-in-q
- - - -
-
-
-
2025-11-09
Eric Woudstra
New
[v17,nf-next,1/4] netfilter: utils: nf_checksum(_partial) correct data!=networkheader
conntrack: bridge: add double vlan, pppoe and pppoe-in-q
- - - -
-
-
-
2025-11-09
Eric Woudstra
New
[nf-next,v9,3/3] selftests: netfilter: nft_flowtable.sh: Add IPIP flowtable selftest
Add IPIP flowtable SW acceleration
- - - -
-
-
-
2025-11-07
Lorenzo Bianconi
New
[nf-next,v9,2/3] net: netfilter: Add IPIP flowtable tx sw acceleration
Add IPIP flowtable SW acceleration
- - - -
-
-
-
2025-11-07
Lorenzo Bianconi
New
[nf-next,v9,1/3] net: netfilter: Add IPIP flowtable rx sw acceleration
Add IPIP flowtable SW acceleration
- - - -
-
-
-
2025-11-07
Lorenzo Bianconi
New
[nf,v3,2/2] doc: clarify JSON rule positioning with handle field
Untitled series #481127
1 - - -
-
-
-
2025-11-06
Alexandre Knecht
New
[nf-next] netfilter: nft_connlimit: add support to object update operation
[nf-next] netfilter: nft_connlimit: add support to object update operation
- - - -
-
-
-
2025-11-04
Fernando Fernandez Mancera
New
[libnftnl] src: add connlimit stateful object support
[libnftnl] src: add connlimit stateful object support
- - - -
-
-
-
2025-11-04
Fernando Fernandez Mancera
New
[v4,nf-next] selftests: netfilter: Add bridge_fastpath.sh
[v4,nf-next] selftests: netfilter: Add bridge_fastpath.sh
- - - -
-
-
-
2025-11-04
Eric Woudstra
New
[nf-next,v1,2/2] selftests: netfilter: add test for nf_tables_jumps_max_netns sysctl
[nf-next,1/2] netfilter: nf_tables: limit maximum number of jumps/gotos per netns
- - - -
-
-
-
2025-11-03
Pablo Neira Ayuso
New
[nf-next,1/2] netfilter: nf_tables: limit maximum number of jumps/gotos per netns
[nf-next,1/2] netfilter: nf_tables: limit maximum number of jumps/gotos per netns
- - - -
-
-
-
2025-11-03
Pablo Neira Ayuso
New
[nf-next,v2] netfilter: nf_tables: add math expression support
[nf-next,v2] netfilter: nf_tables: add math expression support
- - - -
-
-
-
2025-11-03
Fernando Fernandez Mancera
New
[libnftnl,v2] expr: add support to math expression
[libnftnl,v2] expr: add support to math expression
- - - -
-
-
-
2025-11-03
Fernando Fernandez Mancera
New
[net-next] netfilter: ip6t_srh: fix UAPI kernel-doc comments format
[net-next] netfilter: ip6t_srh: fix UAPI kernel-doc comments format
- - - -
-
-
-
2025-11-01
Randy Dunlap
Under Review
[net-next] netfilter: nf_tables: improve UAPI kernel-doc comments
[net-next] netfilter: nf_tables: improve UAPI kernel-doc comments
- - - -
-
-
-
2025-11-01
Randy Dunlap
Under Review
[v3,2/2] tests: shell: Added SNAT/DNAT only cases for nat_ftp
tests: shell: nat_ftp SNAT/DNAT only testcases
- - - -
-
-
-
2025-10-30
Andrii Melnychenko
Under Review
[v3,1/2] tests: shell: Refactored nat_ftp, added rulesets and testcase functions
tests: shell: nat_ftp SNAT/DNAT only testcases
- - - -
-
-
-
2025-10-30
Andrii Melnychenko
Under Review
[libnftnl,9/9] udata: Store u32 udata values in Big Endian
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,8/9] data_reg: Support concatenated data
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,7/9] data_reg: Respect data byteorder when printing
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,6/9] Introduce nftnl_{expr,set_elem}_set_imm()
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,5/9] data_reg: Introduce struct nftnl_data_reg::sizes array
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,4/9] data_reg: Introduce struct nftnl_data_reg::byteorder field
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,3/9] expr: Pass byteorder to struct expr_ops::set callback
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,2/9] expr: data_reg: Avoid extra whitespace
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[libnftnl,1/9] set_elem: Review debug output
Fix for debug output on Big Endian
- - - -
-
-
-
2025-10-23
Phil Sutter
New
[PATCHv6,net-next,14/14] ipvs: add conn_lfactor and svc_lfactor sysctl vars
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,13/14] ipvs: add ip_vs_status info
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,12/14] ipvs: use more keys for connection hashing
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,11/14] ipvs: no_cport and dropentry counters can be per-net
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,10/14] ipvs: show the current conn_tab size to users
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,09/14] ipvs: switch to per-net connection table
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,08/14] ipvs: use resizable hash table for services
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,07/14] ipvs: add resizable hash tables
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,06/14] ipvs: use more counters to avoid service lookups
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,05/14] ipvs: do not keep dest_dst after dest is removed
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,04/14] ipvs: use single svc table
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,03/14] ipvs: some service readers can use RCU
ipvs: per-net tables and optimizations
- - 1 -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,02/14] ipvs: make ip_vs_svc_table and ip_vs_svc_fwm_table per netns
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[PATCHv6,net-next,01/14] rculist_bl: add hlist_bl_for_each_entry_continue_rcu
ipvs: per-net tables and optimizations
- - - -
-
-
-
2025-10-19
Julian Anastasov
New
[nf-next,5/5] netfilter: flowtable: remove hw_ifidx
flowtable: consolidate xmit path
- - - -
-
-
-
2025-10-10
Pablo Neira Ayuso
New
«
1
2
»