Show patches with: Submitter = Florian Westphal       |   3419 patches
« 1 2 3 434 35 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[net-next] netlink: specs: nftables: allow decode of default firewalld ruleset [net-next] netlink: specs: nftables: allow decode of default firewalld ruleset - - 1 - --- 2024-09-02 Florian Westphal kadlec Changes Requested
[ipset,2/2] lib: don't segfault when ipset_data_get returns NULL - - - - --- 2014-02-12 Florian Westphal kadlec Superseded
[ipset,1/2] lib: fix ifname 'physdev:' prefix parsing - - - - --- 2014-02-12 Florian Westphal kadlec Accepted
[nftables] meta: iif/oifname should be host byte order - - - - --- 2013-09-20 Florian Westphal kadlec Accepted
[nf] netfilter: nf_tables: use kzalloc for hook allocation [nf] netfilter: nf_tables: use kzalloc for hook allocation - 1 - - --- 2024-02-21 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: set dormant flag on hook register failure [nf] netfilter: nf_tables: set dormant flag on hook register failure - 1 - - --- 2024-02-19 Florian Westphal pablo Accepted
[6.6.y,2/2] netfilter: nf_tables: split async and sync catchall in two functions netfilter: fix catchall element double-free - 1 - - --- 2023-11-21 Florian Westphal pablo Awaiting Upstream
[6.6.y,1/2] netfilter: nf_tables: remove catchall element in GC sync path netfilter: fix catchall element double-free - 1 - - --- 2023-11-21 Florian Westphal pablo Awaiting Upstream
[nf] netfilter: conntrack: fix extension size table [nf] netfilter: conntrack: fix extension size table - 1 - - --- 2023-09-12 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: don't fold port numbers into addresses before hashing [nf] netfilter: conntrack: don't fold port numbers into addresses before hashing - 1 - - --- 2023-07-04 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: gre: don't set assured flag for clash entries [nf] netfilter: conntrack: gre: don't set assured flag for clash entries - 1 - - --- 2023-07-03 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: limit allowed range via nla_policy [nf-next] netfilter: nf_tables: limit allowed range via nla_policy - - - - --- 2023-06-21 Florian Westphal pablo Accepted
[nf,v2] netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one [nf,v2] netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one - 1 1 - --- 2023-06-21 Florian Westphal pablo Accepted
[nf-next,v2] netfilter: snat: evict closing tcp entries on reply tuple collision [nf-next,v2] netfilter: snat: evict closing tcp entries on reply tuple collision - - - - --- 2023-06-06 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: permit update of set size [nf-next] netfilter: nf_tables: permit update of set size - - - - --- 2023-06-06 Florian Westphal pablo Accepted
[nf-next] netfilter: ipset: remove rcu_read_lock_bh pair from ip_set_test [nf-next] netfilter: ipset: remove rcu_read_lock_bh pair from ip_set_test - - - - --- 2023-06-06 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: relax set/map validation checks [nf-next] netfilter: nf_tables: relax set/map validation checks - - - - --- 2023-05-12 Florian Westphal pablo Accepted
[nf-next] netfilter: nf_tables: always increment set element count [nf-next] netfilter: nf_tables: always increment set element count - - - - --- 2023-05-11 Florian Westphal pablo Accepted
[nf] netfilter: nft_set_rbtree: fix null deref on element insertion [nf] netfilter: nft_set_rbtree: fix null deref on element insertion - 1 - - --- 2023-05-11 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: fix nft_trans type confusion [nf] netfilter: nf_tables: fix nft_trans type confusion - 1 - - --- 2023-05-11 Florian Westphal pablo Accepted
[nf] testing: selftests: nft_flowtable.sh: check ingress/egress chain too [nf] testing: selftests: nft_flowtable.sh: check ingress/egress chain too - - - - --- 2023-05-09 Florian Westphal pablo Accepted
[nf-next,3/3] netfilter: nf_tables: don't initialize registers in nft_do_chain() netfilter: nf_tables: reject loads from uninitialized registers - - - - --- 2023-05-05 Florian Westphal pablo Changes Requested
[nf-next,2/3] netfilter: nf_tables: validate register loads never access unitialised registers netfilter: nf_tables: reject loads from uninitialized registers - - - - --- 2023-05-05 Florian Westphal pablo Changes Requested
[nf-next,1/3] netfilter: nf_tables: pass context structure to nft_parse_register_load netfilter: nf_tables: reject loads from uninitialized registers - - - - --- 2023-05-05 Florian Westphal pablo Changes Requested
[nf] netfilter: fix possible bug_on with enable_hooks=1 [nf] netfilter: fix possible bug_on with enable_hooks=1 - 1 - - --- 2023-05-04 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: always release netdev hooks from notifier [nf] netfilter: nf_tables: always release netdev hooks from notifier - 1 - - --- 2023-05-04 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: fix ct untracked match breakage [nf] netfilter: nf_tables: fix ct untracked match breakage - 1 - - --- 2023-05-03 Florian Westphal pablo Accepted
[nf] netfilter: nf_tables: fix ifdef to also consider nf_tables=m [nf] netfilter: nf_tables: fix ifdef to also consider nf_tables=m - 1 - - --- 2023-04-17 Florian Westphal pablo Accepted
[nf-next,4/4] netfilter: nf_tables: do not store rule in traceinfo structure netfilter: nf_tables: shrink stack usage a bit more - - - - --- 2023-04-14 Florian Westphal pablo Accepted
[nf-next,3/4] netfilter: nf_tables: do not store verdict in traceinfo structure netfilter: nf_tables: shrink stack usage a bit more - - - - --- 2023-04-14 Florian Westphal pablo Accepted
[nf-next,2/4] netfilter: nf_tables: do not store pktinfo in traceinfo structure netfilter: nf_tables: shrink stack usage a bit more - - - - --- 2023-04-14 Florian Westphal pablo Accepted
[nf-next,1/4] netfilter: nf_tables: remove unneeded conditional netfilter: nf_tables: shrink stack usage a bit more - - - - --- 2023-04-14 Florian Westphal pablo Accepted
[nf-next,2/2] netfilter: nf_tables: make validation state per table netfilter: nf_tables: move ruleset validation state to table - - - - --- 2023-04-13 Florian Westphal pablo Accepted
[nf-next,1/2] netfilter: nf_tables: don't write table validation state without mutex netfilter: nf_tables: move ruleset validation state to table - 1 - - --- 2023-04-13 Florian Westphal pablo Accepted
[nf-next,3/3] netfilter: nf_tables: don't store chain address on jump netfilter: nf_tables: shrink jump stack size - - - - --- 2023-04-11 Florian Westphal pablo Accepted
[nf-next,2/3] netfilter: nf_tables: don't store address of last rule on jump netfilter: nf_tables: shrink jump stack size - - - - --- 2023-04-11 Florian Westphal pablo Accepted
[nf-next,1/3] netfilter: nf_tables: merge nft_rules_old structure and end of ruleblob marker netfilter: nf_tables: shrink jump stack size - - - - --- 2023-04-11 Florian Westphal pablo Accepted
[nf] netfilter: br_netfilter: fix recent physdev match breakage [nf] netfilter: br_netfilter: fix recent physdev match breakage - 1 - - --- 2023-04-03 Florian Westphal pablo Accepted
[nf-next] xtables: move icmp/icmpv6 logic to xt_tcpudp [nf-next] xtables: move icmp/icmpv6 logic to xt_tcpudp - - - - --- 2023-03-16 Florian Westphal pablo Accepted
[nf-next] netfilter: xtables: disable 32bit compat interface by default [nf-next] netfilter: xtables: disable 32bit compat interface by default - - - - --- 2023-03-16 Florian Westphal pablo Accepted
[nft] meta: don't crash if meta key isn't known [nft] meta: don't crash if meta key isn't known - - - - --- 2023-03-15 Florian Westphal pablo Accepted
[net-next,9/9] netfilter: nat: fix indentation of function arguments [net-next,1/9] netfilter: bridge: introduce broute meta statement - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,8/9] netfilter: conntrack: fix typo [net-next,1/9] netfilter: bridge: introduce broute meta statement - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,7/9] selftests: add a selftest for big tcp [net-next,1/9] netfilter: bridge: introduce broute meta statement - - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,6/9] netfilter: use nf_ip6_check_hbh_len in nf_ct_skb_network_trim [net-next,1/9] netfilter: bridge: introduce broute meta statement - - 3 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,5/9] netfilter: move br_nf_check_hbh_len to utils [net-next,1/9] netfilter: bridge: introduce broute meta statement - - 3 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,4/9] netfilter: bridge: move pskb_trim_rcsum out of br_nf_check_hbh_len [net-next,1/9] netfilter: bridge: introduce broute meta statement 1 - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,3/9] netfilter: bridge: check len before accessing more nh data [net-next,1/9] netfilter: bridge: introduce broute meta statement 1 - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,2/9] netfilter: bridge: call pskb_may_pull in br_nf_check_hbh_len [net-next,1/9] netfilter: bridge: introduce broute meta statement 1 - 2 - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,1/9] netfilter: bridge: introduce broute meta statement [net-next,1/9] netfilter: bridge: introduce broute meta statement - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[net-next,0/9] Netfilter updates for net-next - - - - --- 2023-03-08 Florian Westphal pablo Accepted
[nf] netfilter: tproxy: fix deadlock due to missing BH disable [nf] netfilter: tproxy: fix deadlock due to missing BH disable - 1 - - --- 2023-03-03 Florian Westphal pablo Accepted
[RFC,v2,bpf-next,3/3] bpf: minimal support for programs hooked into netfilter framework bpf: add netfilter program type - - - - --- 2023-03-02 Florian Westphal pablo RFC
[RFC,v2,bpf-next,2/3] libbpf: sync header file, add nf prog section name bpf: add netfilter program type - - - - --- 2023-03-02 Florian Westphal pablo RFC
[RFC,v2,bpf-next,1/3] bpf: add bpf_link support for BPF_NETFILTER programs bpf: add netfilter program type - - - - --- 2023-03-02 Florian Westphal pablo RFC
[nf] netfilter: ctnetlink: make event listener tracking global [nf] netfilter: ctnetlink: make event listener tracking global - 1 - - --- 2023-02-20 Florian Westphal pablo Accepted
[nf] ebtables: fix table blob use-after-free [nf] ebtables: fix table blob use-after-free - 1 - - --- 2023-02-17 Florian Westphal pablo Accepted
[nf,v2] netfilter: conntrack: fix rmmod double-free race [nf,v2] netfilter: conntrack: fix rmmod double-free race - 1 - - --- 2023-02-14 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: fix rmmod double-free race [nf] netfilter: conntrack: fix rmmod double-free race - 1 - - --- 2023-02-13 Florian Westphal pablo Changes Requested
[RFC,nf-next,3/3] bpf: minimal support for programs hooked into netfilter framework bpf, netfilter: minimal support for bpf progs - - - - --- 2023-02-08 Florian Westphal pablo RFC
[RFC,nf-next,2/3] libbpf: sync header file, add nf prog section name bpf, netfilter: minimal support for bpf progs - - - - --- 2023-02-08 Florian Westphal pablo RFC
[RFC,nf-next,1/3] bpf: add bpf_link support for BPF_NETFILTER programs bpf, netfilter: minimal support for bpf progs - - - - --- 2023-02-08 Florian Westphal pablo RFC
[nf-next] netfilter: let reset rules clean out conntrack entries [nf-next] netfilter: let reset rules clean out conntrack entries - - - - --- 2023-02-01 Florian Westphal pablo Accepted
[RFC] bpf: add bpf_link support for BPF_NETFILTER programs [RFC] bpf: add bpf_link support for BPF_NETFILTER programs - - - - --- 2023-01-30 Florian Westphal pablo RFC
[nf] netfilter: br_netfilter: disable sabotage_in hook after first suppression [nf] netfilter: br_netfilter: disable sabotage_in hook after first suppression - 1 - - --- 2023-01-30 Florian Westphal pablo Accepted
[nf] Revert "netfilter: conntrack: fix bug in for_each_sctp_chunk" [nf] Revert "netfilter: conntrack: fix bug in for_each_sctp_chunk" - 1 - - --- 2023-01-26 Florian Westphal pablo Accepted
[nft] evaluate: set eval ctx for add/update statements with integer constants [nft] evaluate: set eval ctx for add/update statements with integer constants - - - - --- 2023-01-24 Florian Westphal pablo Accepted
[nf-next] netfilter: conntrack: udp: fix seen-reply test [nf-next] netfilter: conntrack: udp: fix seen-reply test - 1 1 - --- 2023-01-23 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: handle tcp challenge acks during connection reuse [nf] netfilter: conntrack: handle tcp challenge acks during connection reuse - 1 - - --- 2023-01-11 Florian Westphal pablo Accepted
[nf-next] netfilter: remove clusterip target [nf-next] netfilter: remove clusterip target - - - - --- 2023-01-05 Florian Westphal pablo Accepted
[nf] selftests: netfilter: fix transaction test script timeout handling [nf] selftests: netfilter: fix transaction test script timeout handling - 1 - - --- 2023-01-04 Florian Westphal pablo Accepted
[nf-next,3/3] netfilter: nf_tables: avoid retpoline overhead for some ct expression calls netfilter: nf_tables: extend retpoline workarounds - - - - --- 2023-01-03 Florian Westphal pablo Accepted
[nf-next,2/3] netfilter: nf_tables: avoid retpoline overhead for objref calls netfilter: nf_tables: extend retpoline workarounds - - - - --- 2023-01-03 Florian Westphal pablo Accepted
[nf-next,1/3] netfilter: nf_tables: add static key to skip retpoline workarounds netfilter: nf_tables: extend retpoline workarounds - - - - --- 2023-01-03 Florian Westphal pablo Accepted
[nf-next,3/3] netfilter: conntrack: avoid reload of ct->status netfilter: conntrack: cleanups - - - - --- 2023-01-02 Florian Westphal pablo Accepted
[nf-next,2/3] netfilter: conntrack: remove pr_debug calls netfilter: conntrack: cleanups - - - - --- 2023-01-02 Florian Westphal pablo Accepted
[nf-next,1/3] netfilter: conntrack: sctp: use nf log infrastructure for invalid packets netfilter: conntrack: cleanups - - - - --- 2023-01-02 Florian Westphal pablo Accepted
[nf-next] netfilter: conntrack: move rcu read lock to nf_conntrack_find_get [nf-next] netfilter: conntrack: move rcu read lock to nf_conntrack_find_get - - - - --- 2022-12-16 Florian Westphal pablo Accepted
[nf] netfilter: conntrack: fix ipv6 exthdr error check [nf] netfilter: conntrack: fix ipv6 exthdr error check - 1 - - --- 2022-12-15 Florian Westphal pablo Accepted
[nft] doc: add/update can be used with maps too [nft] doc: add/update can be used with maps too - - - - --- 2022-12-13 Florian Westphal pablo Accepted
[iptables-nft] extensions: add xt_statistics random mode translation [iptables-nft] extensions: add xt_statistics random mode translation - - - - --- 2022-12-01 Florian Westphal pablo Accepted
[RFC,ebtables-nft] unify ether type and meta protocol decoding [RFC,ebtables-nft] unify ether type and meta protocol decoding - - - - --- 2022-11-30 Florian Westphal pablo RFC
[ebtables-nft] nft-bridge: work around recent "among" decode breakage [ebtables-nft] nft-bridge: work around recent "among" decode breakage 1 1 - - --- 2022-11-30 Florian Westphal pablo Accepted
[v3,iptables-nft,3/3] xlate-test: avoid shell entanglements remove escape_quotes support - - - - --- 2022-11-30 Florian Westphal pablo Accepted
[v3,iptables-nft,2/3] extensions: change expected output for new format remove escape_quotes support - - - - --- 2022-11-30 Florian Westphal pablo Accepted
[v3,iptables-nft,1/3] xlate: get rid of escape_quotes remove escape_quotes support - - - - --- 2022-11-30 Florian Westphal pablo Accepted
[v2,iptables-nft,3/3] xlate-test: avoid shell entanglements remove escape_quotes support - - - - --- 2022-11-29 Florian Westphal pablo Changes Requested
[v2,iptables-nft,2/3] extensions: change expected output for new format remove escape_quotes support - - - - --- 2022-11-29 Florian Westphal pablo Changes Requested
[v2,iptables-nft,1/3] xlate: get rid of escape_quotes remove escape_quotes support - - - - --- 2022-11-29 Florian Westphal pablo Changes Requested
[iptables-nft,3/3] extensions: remove trailing spaces remove escape_quotes support - - - - --- 2022-11-24 Florian Westphal pablo Superseded
[iptables-nft,2/3] extensions: change expected output for new format remove escape_quotes support - - - - --- 2022-11-24 Florian Westphal pablo Superseded
[iptables-nft,1/3] xlate: get rid of escape_quotes remove escape_quotes support - - - - --- 2022-11-24 Florian Westphal pablo Superseded
[iptables-nft] iptables-nft: exit nonzero when iptables-save cannot decode all expressions [iptables-nft] iptables-nft: exit nonzero when iptables-save cannot decode all expressions 1 - - - --- 2022-11-23 Florian Westphal pablo Accepted
[v2,nf] netfilter: conntrack: set icmpv6 redirects as RELATED [v2,nf] netfilter: conntrack: set icmpv6 redirects as RELATED 1 - - - --- 2022-11-23 Florian Westphal pablo Accepted
[iptables-nft,RFC,5/5] generic.xlate: make one replay test case work update iptables-nft dissector - - - - --- 2022-11-21 Florian Westphal pablo RFC
[iptables-nft,RFC,4/5] xlate-test: extra-escape of '"' for replay mode update iptables-nft dissector - - - - --- 2022-11-21 Florian Westphal pablo RFC
[iptables-nft,RFC,3/5] nft: check for unknown meta keys update iptables-nft dissector - - - - --- 2022-11-21 Florian Westphal pablo RFC
[iptables-nft,RFC,2/5] iptables-nft: do not refuse to decode table with unsupported expressions update iptables-nft dissector - - - - --- 2022-11-21 Florian Westphal pablo RFC
[iptables-nft,RFC,1/5] nft-shared: dump errors on stdout to garble output update iptables-nft dissector - - - - --- 2022-11-21 Florian Westphal pablo RFC
[nf-next] netfilter: conntrack: add __force annotation to silence harmless warning [nf-next] netfilter: conntrack: add __force annotation to silence harmless warning - 1 - - --- 2022-11-14 Florian Westphal pablo Accepted
« 1 2 3 434 35 »