Show patches with: Submitter = Florian Westphal       |    Archived = No       |   2595 patches
« 1 2 3 425 26 »
Patch Series A/F/R/T S/W/F Date Submitter Delegate State
[nft] evalute: don't BUG on unexpected base datatype [nft] evalute: don't BUG on unexpected base datatype - - - - --- 2025-06-13 Florian Westphal New
[v2,nft] src: move BASECHAIN flag toggle to netlink linearize code for device update [v2,nft] src: move BASECHAIN flag toggle to netlink linearize code for device update - 1 - - --- 2025-06-12 Florian Westphal New
[nft,v2,2/2] evaluate: restrict allowed subtypes of concatenations [nft,v2,1/2] evaluate: rename recursion counter to recursion.binop - - - - --- 2025-06-06 Florian Westphal New
[nft,v2,1/2] evaluate: rename recursion counter to recursion.binop [nft,v2,1/2] evaluate: rename recursion counter to recursion.binop - - - - --- 2025-06-06 Florian Westphal New
[nft] evaluate: fix crash when set name is null [nft] evaluate: fix crash when set name is null - - - - --- 2025-06-06 Florian Westphal New
[nft] src: move BASECHAIN flag toggle to netlink linearize code for device update [nft] src: move BASECHAIN flag toggle to netlink linearize code for device update - 1 - - --- 2025-06-05 Florian Westphal New
[nf-next,3/3] selftests: netfilter: nft_concat_range.sh: add datapath check for map fill bug netfilter: nf_set_pipapo_avx2: fix initial map fill - - - - --- 2025-05-23 Florian Westphal New
[nf-next,2/3] selftests: netfilter: nft_concat_range.sh: prefer per element counters for testing netfilter: nf_set_pipapo_avx2: fix initial map fill - - - - --- 2025-05-23 Florian Westphal New
[nf-next,1/3] netfilter: nf_set_pipapo_avx2: fix initial map fill netfilter: nf_set_pipapo_avx2: fix initial map fill - 1 - - --- 2025-05-23 Florian Westphal New
[libnftnl,v2] trace: add support for TRACE_CT information [libnftnl,v2] trace: add support for TRACE_CT information - - - - --- 2025-05-22 Florian Westphal New
[nf-next,v2,2/2] netfilter: nf_tables: add packets conntrack state to debug trace info netfilter: nf_tables: include conntrack state in trace messages - - - - --- 2025-05-22 Florian Westphal Accepted
[nf-next,v2,1/2] netfilter: conntrack: make nf_conntrack_id callable without a module dependency netfilter: nf_tables: include conntrack state in trace messages - - - - --- 2025-05-22 Florian Westphal Accepted
[nf-next,v2,5/5] selftests: netfilter: nft_fib.sh: add type and oif tests with and without VRFs netfilter: resolve fib+vrf issues - - - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,4/5] netfilter: nf_tables: nft_fib: consistent l3mdev handling netfilter: resolve fib+vrf issues - 1 - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,3/5] netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy netfilter: resolve fib+vrf issues - 1 - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,2/5] selftests: netfilter: move fib vrf test to nft_fib.sh netfilter: resolve fib+vrf issues - - - - --- 2025-05-21 Florian Westphal Accepted
[nf-next,v2,1/5] selftests: netfilter: nft_fib.sh: add 'type' mode tests netfilter: resolve fib+vrf issues - - - - --- 2025-05-21 Florian Westphal Accepted
[nf-next] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds [nf-next] netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds - 1 - - --- 2025-05-16 Florian Westphal Accepted
[nf-next,5/5] selftests: netfilter: nft_fib.sh: add type and oif tests with and without VRFs netfilter: resolve fib+vrf issues - - - - --- 2025-05-15 Florian Westphal Changes Requested
[nf-next,4/5] netfilter: nf_tables: nft_fib: consistent l3mdev handling netfilter: resolve fib+vrf issues - 1 - - --- 2025-05-15 Florian Westphal Changes Requested
[nf-next,3/5] netfilter: nf_tables: nft_fib_ipv6: fix VRF ipv4/ipv6 result discrepancy netfilter: resolve fib+vrf issues - 1 - - --- 2025-05-15 Florian Westphal Changes Requested
[nf-next,2/5] selftests: netfilter: move fib vrf test to nft_fib.sh netfilter: resolve fib+vrf issues - - - - --- 2025-05-15 Florian Westphal Changes Requested
[nf-next,1/5] selftests: netfilter: nft_fib.sh: add 'type' mode tests netfilter: resolve fib+vrf issues - - - - --- 2025-05-15 Florian Westphal Changes Requested
[nft] src: add conntrack information to trace monitor mode [nft] src: add conntrack information to trace monitor mode - - - - --- 2025-05-08 Florian Westphal New
[nf-next] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation [nf-next] selftests: netfilter: nft_concat_range.sh: add coverage for 4bit group representation - - 1 - --- 2025-05-06 Florian Westphal Accepted
[nf-next] tools: selftests: prepare for non-default IP_TABLES_LEGACY [nf-next] tools: selftests: prepare for non-default IP_TABLES_LEGACY - - - - --- 2025-04-24 Florian Westphal Accepted
[nf-next] netfilter: nf_tables: fix debug splat when dumping pipapo avx2 set [nf-next] netfilter: nf_tables: fix debug splat when dumping pipapo avx2 set - 1 - - --- 2025-04-23 Florian Westphal Accepted
[nf-next] selftests: netfilter: nft_fib.sh: check lo packets bypass fib lookup [nf-next] selftests: netfilter: nft_fib.sh: check lo packets bypass fib lookup - - - - --- 2025-04-23 Florian Westphal Accepted
[v2,nf-next] netfilter: nf_conntrack: speed up reads from nf_conntrack proc file [v2,nf-next] netfilter: nf_conntrack: speed up reads from nf_conntrack proc file - - - - --- 2025-04-22 Florian Westphal Accepted
[nf-next] selftests: netfilter: add conntrack stress test [nf-next] selftests: netfilter: add conntrack stress test - - - - --- 2025-04-17 Florian Westphal Accepted
[nf] netfilter: conntrack: fix erronous removal of offload bit [nf] netfilter: conntrack: fix erronous removal of offload bit - 1 - - --- 2025-04-15 Florian Westphal Accepted
[v2,nftables,4/4] tests: shell: add feature check for count output change src: print count variable in normal set listings - - - - --- 2025-04-08 Florian Westphal New
[v2,nftables,3/4] src: print count variable in normal set listings src: print count variable in normal set listings - - - - --- 2025-04-08 Florian Westphal New
[v2,nftables,2/4] debug: include kernel set information on cache fill src: print count variable in normal set listings - - - - --- 2025-04-08 Florian Westphal New
[v2,nftables,1/4] tests/py: prepare for set debug change src: print count variable in normal set listings - - - - --- 2025-04-08 Florian Westphal New
[v2,libnftnl] set: dump set backend name (hash, rbtree...) and elem count, if available [v2,libnftnl] set: dump set backend name (hash, rbtree...) and elem count, if available - - - - --- 2025-04-08 Florian Westphal New
[v2,nf-next] netfilter: nf_tables: export set count and backend name to userspace [v2,nf-next] netfilter: nf_tables: export set count and backend name to userspace - - - - --- 2025-04-08 Florian Westphal Accepted
[v3,nf,2/3] selftests: netfilter: add test case for recent mismatch bug nft_set_pipapo: fix incorrect avx2 match of 5th field octet - - 1 - --- 2025-04-07 Florian Westphal Accepted
[v3,nf,1/3] nft_set_pipapo: fix incorrect avx2 match of 5th field octet nft_set_pipapo: fix incorrect avx2 match of 5th field octet - 1 1 - --- 2025-04-07 Florian Westphal Accepted
[nft,2/2] evaluate: restrict allowed subtypes of concatenations [nft,1/2] evaluate: rename recursion counter to recursion.binop - - - - --- 2025-04-02 Florian Westphal New
[nft,1/2] evaluate: rename recursion counter to recursion.binop [nft,1/2] evaluate: rename recursion counter to recursion.binop - - - - --- 2025-04-02 Florian Westphal New
[nft] json: don't BUG when asked to list synproxies [nft] json: don't BUG when asked to list synproxies - - - - --- 2025-03-24 Florian Westphal Changes Requested
[nft] evaluate: tolerate empty concatenation [nft] evaluate: tolerate empty concatenation - - - - --- 2025-03-24 Florian Westphal Changes Requested
[nf] selftests: netfilter: skip br_netfilter queue tests if kernel is tainted [nf] selftests: netfilter: skip br_netfilter queue tests if kernel is tainted - - - - --- 2025-03-11 Florian Westphal Accepted
[nf-next] netfilter: fib: avoid lookup if socket is available [nf-next] netfilter: fib: avoid lookup if socket is available - - - - --- 2025-02-20 Florian Westphal Accepted
[nf] netfilter: nf_tables: do not defer rule destruction via call_rcu [nf] netfilter: nf_tables: do not defer rule destruction via call_rcu - 1 - - --- 2024-12-07 Florian Westphal Accepted
[nf-next] ipvs: speed up reads from ip_vs_conn proc file [nf-next] ipvs: speed up reads from ip_vs_conn proc file 1 - - - --- 2024-12-03 Florian Westphal Accepted
[nf-next,v5,5/5] netfilter: nf_tables: allocate element update information dynamically netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,4/5] netfilter: nf_tables: switch trans_elem to real flex array netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,3/5] netfilter: nf_tables: prepare nft audit for set element compaction netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,2/5] netfilter: nf_tables: prepare for multiple elements in nft_trans_elem structure netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v5,1/5] netfilter: nf_tables: add nft_trans_commit_list_add_elem helper netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-13 Florian Westphal Accepted
[nf-next,v4,5/5] netfilter: nf_tables: allocate element update information dynamically netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-07 Florian Westphal Changes Requested
[nf-next,v4,4/5] netfilter: nf_tables: switch trans_elem to real flex array netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-07 Florian Westphal Changes Requested
[nf-next,v4,3/5] netfilter: nf_tables: preemptive fix for audit selftest failure netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-07 Florian Westphal Changes Requested
[nf-next,v4,2/5] netfilter: nf_tables: prepare for multiple elements in nft_trans_elem structure netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-07 Florian Westphal Changes Requested
[nf-next,v4,1/5] netfilter: nf_tables: add nft_trans_commit_list_add_elem helper netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-11-07 Florian Westphal Changes Requested
[net-next] selftests: netfilter: nft_queue.sh: fix warnings with socat 1.8.0.0 [net-next] selftests: netfilter: nft_queue.sh: fix warnings with socat 1.8.0.0 - - - - --- 2024-11-04 Florian Westphal Awaiting Upstream
[net-next] selftests: netfilter: run conntrack_dump_flush in netns [net-next] selftests: netfilter: run conntrack_dump_flush in netns - - - - --- 2024-11-04 Florian Westphal Awaiting Upstream
[nf-next,v3,7/7] netfilter: nf_tables: must hold rcu read lock while iterating object type list netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,6/7] netfilter: nf_tables: must hold rcu read lock while iterating expression type list netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,5/7] netfilter: nf_tables: avoid false-positive lockdep splats with basechain hook netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,4/7] netfilter: nf_tables: avoid false-positive lockdep splats in set walker netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,3/7] netfilter: nf_tables: avoid false-positive lockdep splats with flowtables netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,2/7] netfilter: nf_tables: avoid false-positive lockdep splats with sets netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-11-04 Florian Westphal Accepted
[nf-next,v3,1/7] netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - 1 --- 2024-11-04 Florian Westphal Accepted
[nft,v2] doc: extend description of fib expression [nft,v2] doc: extend description of fib expression - - 1 - --- 2024-10-30 Florian Westphal Accepted
[nf-next,v2] netfilter: conntrack: collect start time as early as possible [nf-next,v2] netfilter: conntrack: collect start time as early as possible - 1 - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,7/7] netfilter: nf_tables: must hold rcu read lock while iterating object type list netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,6/7] netfilter: nf_tables: must hold rcu read lock while iterating expression type list netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,5/7] netfilter: nf_tables: avoid false-positive lockdep splats with basechain hook netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,4/7] netfilter: nf_tables: avoid false-positive lockdep splats in set walker netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,3/7] netfilter: nf_tables: avoid false-positive lockdep splats with flowtables netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,2/7] netfilter: nf_tables: avoid false-positive lockdep splats with sets netfilter: nf_tables: avoid PROVE_RCU_LIST splats - - - - --- 2024-10-30 Florian Westphal Changes Requested
[v2,nf-next,1/7] netfilter: nf_tables: avoid false-positive lockdep splat on rule deletion netfilter: nf_tables: avoid PROVE_RCU_LIST splats - 1 - 1 --- 2024-10-30 Florian Westphal Changes Requested
[nft] src: allow to map key to nfqueue number [nft] src: allow to map key to nfqueue number - - - - --- 2024-10-25 Florian Westphal Accepted
[nf-next,v2,5/5] netfilter: nf_tables: allocate element update information dynamically netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-10-11 Florian Westphal Changes Requested
[nf-next,v2,4/5] netfilter: nf_tables: switch trans_elem to real flex array netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-10-11 Florian Westphal Changes Requested
[nf-next,v2,3/5] netfilter: nf_tables: prepare for multiple elements in nft_trans_elem structure netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-10-11 Florian Westphal Changes Requested
[nf-next,v2,2/5] netfilter: nf_tables: add nft_trans_commit_list_add_elem helper netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-10-11 Florian Westphal Changes Requested
[nf-next,v2,1/5] netfilter: nf_tables: prefer nft_trans_elem_alloc helper netfilter: nf_tables: reduce set element transaction size - - - - --- 2024-10-11 Florian Westphal Changes Requested
[nf] netfilter: bpf: must hold reference on net namespace [nf] netfilter: bpf: must hold reference on net namespace - 1 1 - --- 2024-10-10 Florian Westphal Accepted
[nf,2/2] selftests: netfilter: conntrack_vrf.sh: add fib test case [nf,1/2] netfilter: fib: check correct rtable in vrf setups - - - - --- 2024-10-09 Florian Westphal Accepted
[nf,1/2] netfilter: fib: check correct rtable in vrf setups [nf,1/2] netfilter: fib: check correct rtable in vrf setups - 1 - - --- 2024-10-09 Florian Westphal Accepted
[nf,v3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed [nf,v3] netfilter: xtables: avoid NFPROTO_UNSPEC where needed - 1 - - --- 2024-10-07 Florian Westphal Accepted
[nf-next,4/4] netfilter: nf_tables: use skb_drop_reason netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf-next,3/4] netfilter: nf_nat: use skb_drop_reason netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf-next,2/4] netfilter: xt_nat: drop packet earlier netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf-next,1/4] netfilter: xt_nat: compact nf_nat_setup_info calls netfilter: use skb_drop_reason in more places - - - - --- 2024-10-02 Florian Westphal Accepted
[nf] kselftest: add test for nfqueue induced conntrack race [nf] kselftest: add test for nfqueue induced conntrack race - - - - --- 2024-09-18 Florian Westphal Accepted
[nf] netfilter: nfnetlink_queue: remove old clash resolution logic [nf] netfilter: nfnetlink_queue: remove old clash resolution logic - - - 1 --- 2024-09-18 Florian Westphal Accepted
[nf-next,3/3] selftests: netfilter: add reverse-clash resolution test case netfilter: conntrack: clash resolution for reverse collisions - - - - --- 2024-09-10 Florian Westphal Accepted
[nf-next,2/3] netfilter: conntrack: add clash resolution for reverse collisions netfilter: conntrack: clash resolution for reverse collisions - - - - --- 2024-09-10 Florian Westphal Accepted
[nf-next,1/3] netfilter: nf_nat: don't try nat source port reallocation for reverse dir clash netfilter: conntrack: clash resolution for reverse collisions - - - - --- 2024-09-10 Florian Westphal Accepted
[nf,v2,2/2] netfilter: nft_socket: make cgroupsv2 matching work with namespaces Untitled series #422862 - 1 - - --- 2024-09-07 Florian Westphal Accepted
[nf,1/2] netfilter: nft_socket: fix sk refcount leaks [nf,1/2] netfilter: nft_socket: fix sk refcount leaks - 1 - - --- 2024-09-05 Florian Westphal Accepted
[net-next] netlink: specs: nftables: allow decode of default firewalld ruleset [net-next] netlink: specs: nftables: allow decode of default firewalld ruleset - - 1 - --- 2024-09-02 Florian Westphal kadlec Changes Requested
[nf-next] netfilter: nf_tables: drop unused 3rd argument from validate callback ops [nf-next] netfilter: nf_tables: drop unused 3rd argument from validate callback ops - - - - --- 2024-08-28 Florian Westphal Accepted
[net-next] selftests: netfilter: nft_queue.sh: reduce test file size for debug build [net-next] selftests: netfilter: nft_queue.sh: reduce test file size for debug build 1 1 - - --- 2024-08-27 Florian Westphal Awaiting Upstream
[nf-next,3/3] netfilter: nf_tables: don't initialize registers in nft_do_chain() netfilter: nf_tables: reject loads from - - - - --- 2024-08-20 Florian Westphal Accepted
« 1 2 3 425 26 »