Linux Netfilter development
 help / color / mirror / Atom feed
 messages from 2026-09-30 07:41:58 to 2026-10-08 23:29:32 UTC [more...]

[PATCH nf 0/1] netfilter: nf_ip6_checksum: validate checksum offset
 2026-10-08 23:29 UTC  (6+ messages)

[PATCH net] ipv4: validate checksum_start before completing checksum
 2026-10-08 18:40 UTC  (3+ messages)

[PATCH] netfilter: xt_dccp: handle reserved options as single-byte
 2026-10-08 18:38 UTC 

[iptables PATCH] extensions: libxt_conntrack: Fail on untranslatable state match
 2026-10-08 18:23 UTC 

[PATCH nf-next RFC] netfilter: nft_exthdr: add inner option type search for MPTCP
 2026-10-08 17:40 UTC 

[PATCH nf-next v2] netfilter: nf_conntrack_sip: only honour Via: port in original direction
 2026-10-08 15:28 UTC 

[iptables PATCH 1/3] extensions: libxt_conntrack: Fix inverted ctstate translation
 2026-10-08 13:28 UTC  (4+ messages)
` [iptables PATCH 2/3] extensions: libxt_conntrack: Fix for ignored ctstates in translation
` [iptables PATCH 3/3] xshared: fix crash when -4/-6 follows a restore command

[PATCH] netfilter: nft_set_pipapo: skip transaction elements during GC
 2026-10-08 11:18 UTC  (4+ messages)

[PATCH nf] netfilter: nft_set_rbtree: narrow down range completion to anonymous sets
 2026-10-08 10:52 UTC  (4+ messages)

[PATCH net v2] netfilter: ebtables: ebt_802_3: check the LLC fields before reading them
 2026-10-08 10:51 UTC  (2+ messages)

[PATCH nf v5 0/1] netfilter: x_tables: avoid holding mutex over faultable user copies
 2026-10-08 10:33 UTC  (2+ messages)
` [PATCH nf v5 1/1] "

[PATCH nf-next,v5] netfilter: flowtable: initial bridge support
 2026-10-08 10:32 UTC  (4+ messages)

[PATCH] netfilter: conntrack: wait for RCU readers before freeing the hash
 2026-10-08  7:28 UTC  (2+ messages)

[PATCH nf v6 0/1] netfilter: nf_dup: reject TEE and IPv4/IPv6/netdev nft dup in userns
 2026-10-08  7:08 UTC  (2+ messages)
` [PATCH nf v6 1/1] "

[PATCH v3] netfilter: nf_nat: Fix stale outer UDP checksum on VXLAN encapsulated packets
 2026-10-08  5:42 UTC 

[PATCH net] netfilter: nf_conntrack_reasm: avoid truncating header offset
 2026-10-08  5:02 UTC  (5+ messages)
` [PATCH net v2] netfilter: nf_conntrack_reasm: avoid truncating header offsets

[PATCH v3] netfilter: nf_nat: Fix stale outer UDP checksum on VXLAN encapsulated packets
 2026-09-22  6:23 UTC 

[PATCH v2] netfilter: nf_nat: Fix stale outer UDP checksum on VXLAN encapsulated packets
 2026-09-22  6:14 UTC  (2+ messages)

[PATCH] netfilter: ebtables: ebt_802_3: drop short frames before the match reads LLC
 2026-10-08  2:45 UTC  (3+ messages)

[PATCH nf] netfilter: nft_set_rbtree: reject expired interval ends
 2026-10-07 22:19 UTC  (6+ messages)

[PATCH nf,v3] netfilter: nf_reject: initialize IPCB at inet ingress
 2026-10-07 21:40 UTC 

[PATCH nf] netfilter: nf_conntrack_sip: only honour Via: port in original direction
 2026-10-07 19:58 UTC  (5+ messages)

[PATCH nf-next v3] netfilter: ip6t_NPT: ensure skb is writable before header modification
 2026-10-07 15:48 UTC 

[ebtables PATCH] include: drop bundled copy of linux/types.h
 2026-10-07 13:23 UTC  (2+ messages)

[PATCH nf-next] selftests: netfilter: fix return value in zone subtest
 2026-10-07 12:55 UTC  (3+ messages)

[PATCH nf-next] netfilter: nf_conntrack: limit expectation master chain depth
 2026-10-07 12:48 UTC 

[PATCH net v3] netfilter: conntrack: avoid recursive master destruction
 2026-10-07 11:45 UTC  (6+ messages)

[PATCH nft] tests: shell: add conntrack template attachment test
 2026-10-07 11:40 UTC  (2+ messages)

[PATCH nf-next] netfilter: nft_compat: restrict raw table targets/matches
 2026-10-07 11:29 UTC  (2+ messages)

Netfilter: match "tcp option" with the same type present multiple times
 2026-10-07 10:47 UTC  (11+ messages)

[PATCH nft v2] doc: add MPTCP subtypes documentation to man page
 2026-10-07  8:22 UTC  (3+ messages)

[PATCH v6 nf-next 0/3] ipvs: add per-service secure_tcp
 2026-10-07  3:52 UTC  (5+ messages)
` [PATCH v6 nf-next 1/3] ipvs: add flags for per-service secure TCP state table
` [PATCH v6 nf-next 2/3] ipvs: tcp: enable per-connection secure_tcp in state machine
` [PATCH v6 nf-next 3/3] selftests: netfilter: ipvs: add per-service secure_tcp test

[PATCH net] netfilter: conntrack: avoid recursive master destruction
 2026-10-07  1:33 UTC  (11+ messages)
` [PATCH v2 net] netfilter: conntrack: reject nested ctnetlink master chains

[PATCH nf-next] netfilter: nft_ct: validate hook and priority for ct zone set
 2026-10-06 23:12 UTC 

[PATCH nft] doc: add MPTCP subtypes documentation to man page
 2026-10-06 20:40 UTC  (5+ messages)

[RFC PATCH net-next] netfilter: nf_conntrack: add ct expression support for netdev egress chains
 2026-10-06 14:04 UTC  (3+ messages)

hardware flows are left behind when a flowtable is deleted (nf_tables unbinds the offload block at commit time)
 2026-10-06 11:28 UTC  (2+ messages)

[nft PATCH v2] Fix for warnings when compiling for 32bit arch
 2026-10-06  9:30 UTC  (3+ messages)

[PATCH nf-next v2 0/2] netfilter: nf_conntrack_h323: fixes for NAT bypass and ASN.1 decode
 2026-10-06  6:54 UTC  (3+ messages)
` [PATCH nf-next v2 1/2] netfilter: nf_conntrack_h323: do not bypass NAT helpers when tuple source matches reply destination
` [PATCH nf-next v2 2/2] netfilter: nf_conntrack_h323: check extension bitmap before decoding components

[PATCH net 0/2] netfilter: nf_conntrack_h323: fixes for NAT bypass and ASN.1 decode
 2026-10-06  3:57 UTC  (8+ messages)

[PATCH nf-next v3 3/3] selftests: netfilter: nft_flowtable.sh: check the priority a flow carries
 2026-10-05 21:20 UTC 

[PATCH nf-next v3 2/3] netfilter: flowtable: carry a priority into the offload
 2026-10-05 21:19 UTC 

[PATCH net-next 00/11] Netfilter updates for net-next
 2026-10-05 20:53 UTC  (7+ messages)
` [PATCH net-next 01/11] netfilter: synproxy: fix reset of ct seqadj when reopening a connection

[PATCH nf v6 0/3] ipvs: avoid stack overflow from recursive connection expiration
 2026-10-05 15:25 UTC  (5+ messages)
` [PATCH nf v6 1/3] ipvs: fix problems during connection deletion
` [PATCH nf v6 2/3] ipvs: avoid stack overflow from recursive connection expiration
` [PATCH nf v6 3/3] ipvs: reject FTP control ports as data ports

[PATCH nf] netfilter: nft_synproxy: only handle pure SYN and ACK packets
 2026-10-05 15:21 UTC  (4+ messages)
` [PATCH nf-next v2] "

[PATCH nf-next] netfilter: nf_nat: replace u_int16_t with u16
 2026-10-05 12:09 UTC  (2+ messages)

[PATCH nf] netfilter: flowtable: set on NF_FLOW_HW once flow has been offloaded
 2026-10-04 22:17 UTC 

[PATCH nf v2 0/2] netfilter: preserve bridge egress VLAN tags
 2026-10-04 21:42 UTC  (5+ messages)
` [PATCH nf v2 1/2] netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets
` [PATCH nf v2 2/2] netfilter: br_netfilter: clear stale VLAN tag on refragmented packets

[PATCH libnftnl] set: Check array boundary when parsing NFTA_SET_DESC_CONCAT
 2026-10-04 19:59 UTC 

[PATCH nf v2 0/2] netfilter: flowtable: correct and advertise the vlan match
 2026-10-04 17:24 UTC  (2+ messages)

[PATCH nf-next v3 0/3] netfilter: flowtable: carry a priority into the offload
 2026-10-04 17:16 UTC  (4+ messages)
` [PATCH nf-next v3 1/3] net/mlx5e: Ignore FLOW_ACTION_PRIORITY on flowtable offload
` [PATCH nf-next v3 2/3] netfilter: flowtable: carry a priority into the offload
` [PATCH nf-next v3 3/3] selftests: netfilter: nft_flowtable.sh: check the priority a flow carries

[PATCH nf-next v2 0/4] netfilter: offload a TCP flow whose reply is never seen
 2026-10-04 17:16 UTC  (5+ messages)
` [PATCH nf-next v2 1/4] netfilter: conntrack: pick up a TCP flow whose SYN was never answered
` [PATCH nf-next v2 2/4] netfilter: flowtable: promote a flow offloaded in one direction only
` [PATCH nf-next v2 3/4] netfilter: nft_flow_offload: offload a TCP flow that has no reply
` [PATCH nf-next v2 4/4] selftests: netfilter: cover a TCP flow whose reply is never seen

[PATCH nf-next 0/3] netfilter: flowtable: update upper device stats in the fast path
 2026-10-04 17:16 UTC  (4+ messages)
` [PATCH nf-next 1/3] 8021q: add vlan_dev_sw_netstats_rx_add() and vlan_dev_sw_netstats_tx_add()
` [PATCH nf-next 2/3] netfilter: flowtable: update upper device stats in the fast path
` [PATCH nf-next 3/3] selftests: netfilter: nft_flowtable.sh: check upper device counters

[PATCH nf-next v6 0/2] netfilter: flowtable: tear down bridged flows on layer 2 roaming
 2026-10-04 17:16 UTC  (3+ messages)
` [PATCH nf-next v6 1/2] netfilter: flowtable: tear down direct xmit flows when the fdb entry moves
` [PATCH nf-next v6 2/2] selftests: netfilter: nft_flowtable.sh: roam a host between two bridge ports

[PATCH 1/2 nf-next] netfilter: nft_exthdr: remove redundant op parsing in tcp_set_init
 2026-10-04  1:41 UTC  (2+ messages)
` [PATCH 2/2 nf-next] netfilter: nft_exthdr: avoid 60 bytes stack buffer in TCP option mangling

[PATCH net v6 0/2] net: prevent partial checksums from modifying network headers
 2026-10-03 19:10 UTC  (10+ messages)
` [PATCH net v6 1/2] net: validate virtio checksum start after network header

[nft PATCH 1/2] doc: nft.8: Describe nftables transactions and their limitations
 2026-10-03 11:10 UTC  (3+ messages)
` [nft PATCH 2/2] doc: nft.8: Document caveats when mixing clients

[PATCH nf] ipvs: do not create conns from packets with port 0
 2026-10-03  9:50 UTC 

[PATCH nf 0/2] ipvs: keep templates and cport 0 conns away from packet lookups
 2026-10-02 23:04 UTC  (3+ messages)

[PATCH 6.6 6.1 1/2] netfilter: nf_tables: Tolerate chains with no remaining hooks
 2026-10-02 21:44 UTC  (7+ messages)
` [PATCH 6.1] netfilter: nf_tables: fix UAF in nf_tables_netdev_event walker
    ` [PATCH 6.1 1/2] netfilter: nf_tables: allow to create netdev chain without device
      ` [PATCH 6.1 2/2] netfilter: nf_tables: support for adding new devices to an existing netdev chain

[syzbot] Monthly netfilter report (Oct 2026)
 2026-10-02 20:33 UTC 

[PATCH nf-next] netfilter: nfnetlink_log: collapse both dev log blocks
 2026-10-02 17:38 UTC  (2+ messages)

[PATCH nf] netfilter: flowtable: use the vlan id, not the full tci, in the tuple key
 2026-10-02  8:42 UTC 

[PATCH nf 0/2] ipvs: fix OOB write when NATing ICMPv6 errors quoting non-first fragments
 2026-10-01 16:10 UTC  (5+ messages)

[PATCH nf] netfilter: br_netfilter: restore VLAN tag on refragmented IPv6 packets
 2026-10-01 12:19 UTC  (5+ messages)

[PATCH nf-next 0/2] netfilter: do not assume skb->sk is inet sk
 2026-10-01 12:06 UTC  (3+ messages)
` [PATCH nf-next 1/2] netfilter: add nf_skb_sk helper and use it
` [PATCH nf-next 2/2] netfilter: add nf_sk_to_full_sk "

[PATCH net,v2 00/10] Netfilter/IPVS fixes for net
 2026-10-01 10:20 UTC  (11+ messages)
` [PATCH net 01/10] netfilter: ipset: do not update comments from kernel-side adds
` [PATCH net 03/10] ipvs: fix missing counter decrement in lblc
` [PATCH net 05/10] ipvs: do not create invisible templates
` [PATCH net 06/10] ipvs: filter some flags received in the backup server
` [PATCH net 07/10] netfilter: nft_set_rbtree: skip transaction elements during GC
` [PATCH net 08/10] netfilter: bpf: reject invalid NAT manipulation types
` [PATCH net 09/10] netfilter: flowtable: generalize pending status bit
` [PATCH net 10/10] netfilter: flowtable: restore ieee80211 forward path

[PATCH nf-next v2] netfilter: ip6t_NPT: ensure skb is writable before header modification
 2026-09-30 20:54 UTC 

[PATCH net] netfilter: ip6t_NPT: ensure skb is writable before header modification
 2026-09-30 20:49 UTC  (2+ messages)

[PATCH net] ipvs: fix protocol data lifetime during namespace teardown
 2026-09-30 17:21 UTC  (2+ messages)

[PATCH net] ipvs: prevent LBLCR destination leak after entry expiry
 2026-09-30 15:38 UTC  (3+ messages)

[PATCH 01/16 net-next v3] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack
 2026-09-30 13:52 UTC  (2+ messages)
` [PATCH 12/16 net-next v3] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4

[PATCH nf-next v5 0/4] netfilter: conntrack: shared port parser for helpers
 2026-09-30  9:57 UTC  (2+ messages)


This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox