summaryrefslogtreecommitdiff
path: root/net/netfilter
AgeCommit message (Expand)AuthorFilesLines
6 daysMerge tag 'bpf-fixes' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpfLinus Torvalds1-22/+13
9 daysnetfilter: nf_conntrack_helper: cap maximum number of expectation at helper r...Pablo Neira Ayuso2-4/+8
9 daysnetfilter: nft_ct: expectation timeouts are passed in millisecondsFlorian Westphal1-3/+18
9 daysnetfilter: nf_conntrack_expect: run expectation eviction with no helperPablo Neira Ayuso1-0/+7
9 daysnetfilter: nf_conntrack_expect: store master_tuple in expectationPablo Neira Ayuso3-6/+7
9 daysnetfilter: conntrack: add deprecation warnings for irc and pptp trackersFlorian Westphal3-5/+10
9 daysnetfilter: ctnetlink: do not allow to reset helper on existing conntrackPablo Neira Ayuso1-13/+0
9 daysnetfilter: nft_compat: ebtables emulation must reject non-bridge targetsFlorian Westphal1-3/+21
9 daysnetfilter: nft_synproxy: stop bypassing the priv->info snapshotRunyu Xiao1-5/+4
9 daysnetfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto()Lorenzo Bianconi1-3/+5
9 daysnetfilter: nf_conncount: prevent connlimit drops for early confirmed ctFernando Fernandez Mancera1-6/+5
9 daysnetfilter: nf_nat: avoid invalid nat_net pointer use on failed nf_nat_init()Mathias Krause1-0/+10
9 daysbpf: Guard conntrack opts error writesYiyang Chen1-22/+13
11 daysnetfilter: nf_conntrack_expect: use conntrack GC to reap expectationsPablo Neira Ayuso7-105/+125
11 daysnetfilter: nft_flow_offload: zero device address for non-ether caseFlorian Westphal1-1/+3
11 daysnetfilter: nft_meta_bridge: add validate callback for get operationsFlorian Westphal1-2/+3
11 daysnetfilter: nft_payload: reject offsets exceeding 65535 bytesFlorian Westphal1-3/+13
11 daysnetfilter: ipset: make sure gc is properly stoppedJozsef Kadlecsik1-1/+1
11 daysnetfilter: ipset: fix order of kfree_rcu() and rcu_assign_pointer()Jozsef Kadlecsik1-2/+2
11 daysnetfilter: ipset: Don't use test_bit() in lockless RCU readers in bitmap typesJozsef Kadlecsik4-4/+6
11 daysnetfilter: ipset: Don't use test_bit() in lockless RCU readers in hash typesJozsef Kadlecsik1-5/+5
13 daysnetfilter: flowtable: fix and simplify IP6IP6 tunnel handlingLorenzo Bianconi1-61/+19
13 daysnetfilter: xt_cluster: reject template conntracks in hash matchWyatt Feng1-1/+1
13 daysnetfilter: nf_queue: pin bridge device while NFQUEUE holds fake dstHaoze Xie2-0/+17
13 daysnetfilter: flowtable: fix offloaded ct timeout never being extendedAdrian Bente1-4/+9
2026-06-17Merge tag 'net-next-7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/net...Linus Torvalds63-746/+1016
2026-06-16Merge tag 'nf-next-26-06-14' of git://git.kernel.org/pub/scm/linux/kernel/git...Jakub Kicinski39-212/+424
2026-06-15Merge tag 'timers-core-2026-06-13' of gitolite.kernel.org:pub/scm/linux/kerne...Linus Torvalds1-6/+18
2026-06-14netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use themPablo Neira Ayuso2-14/+18
2026-06-14netfilter: flowtable: bail out if forward path cannot be discoveredPablo Neira Ayuso1-35/+46
2026-06-14netfilter: conntrack: check NULL when retrieving ct extensionPablo Neira Ayuso11-23/+134
2026-06-14netfilter: nf_conncount: gc and rcu fixesFlorian Westphal1-22/+32
2026-06-14netfilter: nf_conncount: add sequence counter to detect tree modificationsFlorian Westphal1-0/+19
2026-06-14netfilter: nf_conncount: split count_tree_node rbtree walk into helperFlorian Westphal1-40/+62
2026-06-14netfilter: nf_conncount: use per nf_conncount_data spinlocksFlorian Westphal1-29/+34
2026-06-14netfilter: nf_conncount: callers must hold rcu read lockFlorian Westphal1-3/+3
2026-06-14netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control pathsFernando Fernandez Mancera22-46/+76
2026-06-14ipvs: Replace use of system_unbound_wq with system_dfl_long_wqMarco Crivellari2-7/+7
2026-06-12Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/netJakub Kicinski9-16/+112
2026-06-10netfilter: nft_fib: fix stale stack leak via the OIFNAME registerDavide Ornaghi1-0/+6
2026-06-10netfilter: nft_exthdr: fix register tracking for F_PRESENT flagFlorian Westphal1-0/+3
2026-06-10netfilter: nf_log: validate MAC header was set before dumping itXiang Mei1-2/+2
2026-06-10netfilter: nf_conntrack: destroy stale expectfn expectations on unregisterWeiming Shi3-0/+22
2026-06-10netfilter: nf_tables_offload: drop device refcount on errorFlorian Westphal1-2/+4
2026-06-10netfilter: revalidate bridge portsFlorian Westphal2-12/+75
2026-06-07netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack()Rosen Penev1-5/+5
2026-06-07netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untagDavid Carlier1-1/+2
2026-06-05netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptpPablo Neira Ayuso1-2/+16
2026-06-05netfilter: conntrack: revert ct extension genid infrastructurePablo Neira Ayuso2-91/+2
2026-06-05netfilter: nf_conntrack_helper: add refcounting from datapathPablo Neira Ayuso8-59/+68