linux/net/netfilter
Linus Torvalds b85966adbf Networking changes for 7.2.
Core & protocols
 ----------------
 
  - Work on removing rtnl_lock protection throughout the stack continues.
    In this chapter:
     - don't use rtnl_lock for IPv6 multicast routing configuration
     - don't take rtnl_lock in ethtool for modern drivers
     - prepare Qdisc dump callbacks for rtnl_lock removal
 
  - Support dumping just ifindex + name of all interfaces, under RCU.
    It's a common operation for Netlink CLI tools (when translating
    names to ifindexes) and previously required full rtnl_lock.
 
  - Support dumping qdiscs and page pools for a specific netdev. Even tho
    user space wants a dump of all netdevs, most of the time, the OOO
    programming model results in repeating the dump for each netdev.
    Which, in absence of a cache, leads to a O(n^2) behavior.
 
  - Flush nexthops once on multi-nexthop removal (e.g. when device goes
    down), another O(n^2) -> O(n) improvement.
 
  - Rehash locally generated traffic to a different nexthop on retransmit
    timeout.
 
  - Honor oif when choosing nexthop for locally generated IPv6 traffic.
 
  - Convert TCP Auth Option to crypto library, and drop non-RFC algos.
 
  - Increase subflow limits in MPTCP to 64 and endpoint limit to 256.
 
  - Support MPTCP signaling of IPv6 address + port (ADD_ADDR). We need
    to selectively skip reporting of the standard TCP Timestamp option,
    because they won't fit into the header space together (12 + 30 > 40).
 
  - Support using bridge neighbor suppression, Duplicate Address
    Detection, Gratuitous ARP and unsolicited NA forwarding - in EVPN
    deployments, e.g. VXLAN fabrics (IPv4 and IPv6).
 
  - Improve link state reporting for upper netdevs (e.g. macvlan) over
    tunnel devices (again, mostly for EVPN deployments).
 
  - Support binding GENEVE tunnels to a local address.
 
  - Speed up UDP tunnel destruction (remove one synchronize_rcu()).
 
  - Support exponential field encoding in multicast (IGMPv3 and MLDv2).
 
  - Support attaching PSP crypto offload to containers (veth, netkit).
 
  - Add a new IPSec Netlink message XFRM_MSG_MIGRATE_STATE that allows
    migrating individual IPsec SAs independently of their policies.
    The existing XFRM_MSG_MIGRATE is tightly coupled to policy+SA
    migration, lacks SPI for unique SA identification, and cannot express
    reqid changes or migrate Transport mode selectors. The new interface
    identifies the SA via SPI and mark, supports reqid changes, address
    family changes, encap removal, and uses an atomic create+install
    flow under x->lock to prevent SN/IV reuse during AEAD SA migration.
 
  - Implement GRO/GSO support for PPPoE.
 
  - Convert sockopt callbacks in a number of protocols to iov_iter.
 
 Cross-tree stuff
 ----------------
 
  - Remove support for Crypto TFM cloning (unblocked after the TCP Auth
    Option rework). This feature regressed performance for all crypto API
    users, since it changed crypto transformation objects into reference-
    -counted objects.
 
  - Add FCrypt-PCBC implementation to rxrpc and remove it from the global
    crypto API as obsolete and insecure.
 
 Wireless
 --------
 
  - Major rework of station bandwidth handling, fixing issues with lower
    capability than AP.
 
  - Cleanups for EMLSR spec issues (drafts differed).
 
  - More Neighbor Awareness Networking (Wi-Fi Aware) work (multicast,
    schedule improvements, multi-station etc.)
 
  - Some Ultra High Reliability (UHR) / IEEE 802.11bn (D1.4) work
    (e.g. non-primary channel access, UHR DBE support).
 
  - Fine Timing Measurement ranging (i.e. distance measurement) APIs.
 
 Netfilter
 ---------
 
  - Use per-rule hash initval in nf_conncount. This avoids unnecessary
    lock contention with short keys (e.g. conntrack zones) in different
    namespaces.
 
  - Various safety improvements, both in packet parsing and object
    lifetimes. Notably add refcounts to conntrack timeout policy.
 
 Deletions
 ---------
 
  - Remove TLS + sockmap integration. TLS wants to pin user pages
    to avoid a copy, and sockmap wants to write to the input stream.
    More work on this integration is clearly needed, and we can't find
    any users (original author admitted that they never deployed it).
 
  - Remove support for TLS offload with TCP Offload Engine (the far
    more common opportunistic offload is retained). The locking looks
    unfixable (driver sleeps under TCP spin locks) and people from
    the vendor that added this are AWOL.
 
  - Remove more ATM code, trying to leave behind only what PPPoATM needs,
    AAL5 and br2684 with permanent circuits.
 
  - Remove AppleTalk. Let it join hamradio in our out of tree protocol
    graveyard, I mean, repository.
 
  - Disable 32-bit x_tables compatibility (32bit binaries on 64bit kernel)
    interface in user namespaces. To be deleted completely, soon.
 
  - Remove 5/10 MHz support from cfg80211/mac80211.
 
 Drivers
 -------
 
  - Software:
    - Support DEVMEM/DMABUF Tx over NETMEM_TX_NO_DMA devices (netkit).
    - bonding: add knob to strictly follow 802.3ad for link state.
 
  - New drivers:
    - Alibaba Elastic Ethernet Adaptor (cloud vNIC).
    - NXP NETC switch within i.MX94.
 
  - DPLL:
    - Add operational state to pins (implement in zl3073x).
    - Add generic DPLL type, for daisy-chaining DPLLs (implement in ice).
 
  - Ethernet high-speed NICs:
    - Huawei (hinic3):
      - enhance tc flow offload support with queue selection, tunnels
    - nVidia/Mellanox:
      - avoid over-copying payload to the skb's linear part (up to 60%
        win for LRO on slow CPUs like ARM64 V2)
      - expose more per-queue stats over the standard API
      - support additional, unprivileged PFs in the DPU configuration
      - support Socket Direct (multi-PF) with switchdev offloads
      - add a pool / frag allocator for DMA mapped buffers for control
        objects, save memory on systems with 64kB page size
      - take advantage of the ability to dynamically change RSS table
        size, even when table is configured by the user
      - increase the max RSS table size for even traffic distribution
 
  - Ethernet NICs:
    - Marvell/Aquantia:
      - AQC113 PTP support
    - Realtek USB (r8152):
      - support 10Gbit Link Speeds and Energy-Efficient Ethernet (EEE)
      - support firmware loaded (for RTL8157/RTL8159)
      - support for the RTL8159
    - Intel (ixgbe):
      - support Energy-Efficient Ethernet (EEE) on E610 devices
 
  - Ethernet switches:
    - Airoha:
      - support multiple netdevs on a single GDM block / port
    - Marvell (mv88e6xxx):
      - support SERDES of mv88e6321
    - Microchip (ksz8/9):
      - rework the driver callbacks to remove one indirection layer
    - Motorcomm (yt921x):
      - support port rate policing
      - support TBF qdisc offload
      - support ACL/flower offload
    - nVidia/Mellanox:
      - expose per-PG rx_discards
    - Realtek:
      - rtl8365mb: bridge offloading and VLAN support
 
  - Ethernet PHYs:
    - Airoha:
      - support Airoha AN8801R Gigabit PHYs.
    - Micrel:
      - implement 3 low-loss cable tunables
    - Realtek:
      - support MDI swapping for RTL8226-CG
      - support MDIO for RTL931x
    - Qualcomm:
      - at803x: Rx and Tx clock management for IPQ5018 PHY
    - Motorcomm:
      - support YT8522 100M RMII PHY
      - set drive strength in YT8531s RGMII
    - TI:
      - dp83822: add optional external PHY clock
 
  - Bluetooth:
    - hci_sync: add support for HCI_LE_Set_Host_Feature [v2]
    - SMP: use AES-CMAC library API
    - Intel:
      - support Product level reset
      - support smart trigger dump
    - Mediatek:
      - add event filter to filter specific event
    - Realtek:
      - fix RTL8761B/BU broken LE extended scan
 
  - WiFi:
    - Broadcom (b43):
      - new support for a 11n device
    - MediaTek (mt76):
      - support mt7927
      - mt792x: broken usb transport detection
      - mt7921: regulatory improvements
    - Qualcomm (ath9k):
      - GPIO interface improvements
    - Qualcomm (ath12k):
      - WDS support
      - replace dynamic memory allocation in WMI Rx path
      - thermal throttling/cooling device support
      - 6 GHz incumbent interference detection
      - channel 177 in 5 GHz
    - Realtek (rt89):
      - RTL8922AU support
      - USB 3 mode switch for performance
      - better monitor radiotap support
      - RTL8922DE preparations
 
 Signed-off-by: Jakub Kicinski <kuba@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQIzBAABCgAdFiEE6jPA+I1ugmIBA4hXMUZtbf5SIrsFAmox1O4ACgkQMUZtbf5S
 Irve7hAAgvCYRFvQ/1dvL+PORg2KqVW4rWXMvNrEWaMVAEXJIIPJoxen6zn6a/72
 aRs2Ord/wVM/Uh291TOrARwtv1U0oOvOvnbrVM2u06o/EqjtxRAZSF9quTlPdm6Q
 RvlkR5X9XXM2MwbDc1zYNTITfhVv80YDCFmYGI7O8dyhLuyspX2eU0SiW33Twl4f
 y6RLcn12gyUbDpa6vt+tari6cFCO/X2zot/uwaDY38b+kwsMHunrj3/PSfJzeYIU
 5mD7jG+xsPxQlEskMYGOjVT5VeMdRquhb9UGwoostZpuEPYZfzTdFtphC1qZqIPk
 8O8ngAW1yYNIY9TTMPF3Y3LMpOiyZq6/P4KY+tksbeDw8vvTYJzEgw3VpwurZQLM
 vfHKDj1kM6VLNekeCI+2cip06flVH3jtIkN0KOERwzTSS8NUbs6PuoEP0HLdjafj
 cr/pgSSTQPUsQkpS5R5Ld3bwpnKea56CQ36p2E8JvU2akwK5RnvqiZiTAfz2z2Tg
 M0NVlTsJ07ucNBxsO4l7osDtRTnzUqo+ZeTo+zR5l0cGRXPd9nJByk257z4IAlcQ
 2MHrJmCZ+ZFKhmkUNUPBdFBATbRgOZHzA/iiiThBrT2hDvWQ2kygO9+IkJBS/WYx
 eQz7G9hb6Xn1ifWVvPVD0oDL3DKKTotQIN90PZCzvObQFWMc1Vk=
 =oNfE
 -----END PGP SIGNATURE-----

Merge tag 'net-next-7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next

Pull networking updates from Jakub Kicinski:
 "Core & protocols:

   - Work on removing rtnl_lock protection throughout the stack
     continues. In this chapter:
       - don't use rtnl_lock for IPv6 multicast routing configuration
       - don't take rtnl_lock in ethtool for modern drivers
       - prepare Qdisc dump callbacks for rtnl_lock removal

   - Support dumping just ifindex + name of all interfaces, under RCU.
     It's a common operation for Netlink CLI tools (when translating
     names to ifindexes) and previously required full rtnl_lock.

   - Support dumping qdiscs and page pools for a specific netdev. Even
     tho user space wants a dump of all netdevs, most of the time, the
     OOO programming model results in repeating the dump for each
     netdev. Which, in absence of a cache, leads to a O(n^2) behavior.

   - Flush nexthops once on multi-nexthop removal (e.g. when device goes
     down), another O(n^2) -> O(n) improvement.

   - Rehash locally generated traffic to a different nexthop on
     retransmit timeout.

   - Honor oif when choosing nexthop for locally generated IPv6 traffic.

   - Convert TCP Auth Option to crypto library, and drop non-RFC algos.

   - Increase subflow limits in MPTCP to 64 and endpoint limit to 256.

   - Support MPTCP signaling of IPv6 address + port (ADD_ADDR). We need
     to selectively skip reporting of the standard TCP Timestamp option,
     because they won't fit into the header space together (12 + 30 >
     40).

   - Support using bridge neighbor suppression, Duplicate Address
     Detection, Gratuitous ARP and unsolicited NA forwarding - in EVPN
     deployments, e.g. VXLAN fabrics (IPv4 and IPv6).

   - Improve link state reporting for upper netdevs (e.g. macvlan) over
     tunnel devices (again, mostly for EVPN deployments).

   - Support binding GENEVE tunnels to a local address.

   - Speed up UDP tunnel destruction (remove one synchronize_rcu()).

   - Support exponential field encoding in multicast (IGMPv3 and MLDv2).

   - Support attaching PSP crypto offload to containers (veth, netkit).

   - Add a new IPSec Netlink message XFRM_MSG_MIGRATE_STATE that allows
     migrating individual IPsec SAs independently of their policies.

     The existing XFRM_MSG_MIGRATE is tightly coupled to policy+SA
     migration, lacks SPI for unique SA identification, and cannot
     express reqid changes or migrate Transport mode selectors.

     The new interface identifies the SA via SPI and mark, supports
     reqid changes, address family changes, encap removal, and uses an
     atomic create+install flow under x->lock to prevent SN/IV reuse
     during AEAD SA migration.

   - Implement GRO/GSO support for PPPoE.

   - Convert sockopt callbacks in a number of protocols to iov_iter.

  Cross-tree stuff:

   - Remove support for Crypto TFM cloning (unblocked after the TCP Auth
     Option rework). This feature regressed performance for all crypto
     API users, since it changed crypto transformation objects into
     reference-counted objects.

   - Add FCrypt-PCBC implementation to rxrpc and remove it from the
     global crypto API as obsolete and insecure.

  Wireless:

   - Major rework of station bandwidth handling, fixing issues with
     lower capability than AP.

   - Cleanups for EMLSR spec issues (drafts differed).

   - More Neighbor Awareness Networking (Wi-Fi Aware) work (multicast,
     schedule improvements, multi-station etc.)

   - Some Ultra High Reliability (UHR) / IEEE 802.11bn (D1.4) work
     (e.g. non-primary channel access, UHR DBE support).

   - Fine Timing Measurement ranging (i.e. distance measurement) APIs.

  Netfilter:

   - Use per-rule hash initval in nf_conncount. This avoids unnecessary
     lock contention with short keys (e.g. conntrack zones) in different
     namespaces.

   - Various safety improvements, both in packet parsing and object
     lifetimes. Notably add refcounts to conntrack timeout policy.

  Deletions:

   - Remove TLS + sockmap integration. TLS wants to pin user pages to
     avoid a copy, and sockmap wants to write to the input stream. More
     work on this integration is clearly needed, and we can't find any
     users (original author admitted that they never deployed it).

   - Remove support for TLS offload with TCP Offload Engine (the far
     more common opportunistic offload is retained). The locking looks
     unfixable (driver sleeps under TCP spin locks) and people from the
     vendor that added this are AWOL.

   - Remove more ATM code, trying to leave behind only what PPPoATM
     needs, AAL5 and br2684 with permanent circuits.

   - Remove AppleTalk. Let it join hamradio in our out of tree protocol
     graveyard, I mean, repository.

   - Disable 32-bit x_tables compatibility (32bit binaries on 64bit
     kernel) interface in user namespaces. To be deleted completely,
     soon.

   - Remove 5/10 MHz support from cfg80211/mac80211.

  Drivers:

   - Software:
       - Support DEVMEM/DMABUF Tx over NETMEM_TX_NO_DMA devices (netkit)
       - bonding: add knob to strictly follow 802.3ad for link state

   - New drivers:
       - Alibaba Elastic Ethernet Adaptor (cloud vNIC).
       - NXP NETC switch within i.MX94.

   - DPLL:
       - Add operational state to pins (implement in zl3073x).
       - Add generic DPLL type, for daisy-chaining DPLLs (implement in ice).

   - Ethernet high-speed NICs:
       - Huawei (hinic3):
           - enhance tc flow offload support with queue selection,
             tunnels
       - nVidia/Mellanox:
           - avoid over-copying payload to the skb's linear part (up to
             60% win for LRO on slow CPUs like ARM64 V2)
           - expose more per-queue stats over the standard API
           - support additional, unprivileged PFs in the DPU
             configuration
           - support Socket Direct (multi-PF) with switchdev offloads
           - add a pool / frag allocator for DMA mapped buffers for
             control objects, save memory on systems with 64kB page size
           - take advantage of the ability to dynamically change RSS
             table size, even when table is configured by the user
           - increase the max RSS table size for even traffic
             distribution

   - Ethernet NICs:
       - Marvell/Aquantia:
           - AQC113 PTP support
       - Realtek USB (r8152):
           - support 10Gbit Link Speeds and Energy-Efficient Ethernet
             (EEE)
           - support firmware loaded (for RTL8157/RTL8159)
           - support for the RTL8159
       - Intel (ixgbe):
           - support Energy-Efficient Ethernet (EEE) on E610 devices

   - Ethernet switches:
       - Airoha:
           - support multiple netdevs on a single GDM block / port
       - Marvell (mv88e6xxx):
           - support SERDES of mv88e6321
       - Microchip (ksz8/9):
           - rework the driver callbacks to remove one indirection layer
       - Motorcomm (yt921x):
           - support port rate policing
           - support TBF qdisc offload
           - support ACL/flower offload
       - nVidia/Mellanox:
           - expose per-PG rx_discards
       - Realtek:
           - rtl8365mb: bridge offloading and VLAN support

   - Ethernet PHYs:
       - Airoha:
           - support Airoha AN8801R Gigabit PHYs.
       - Micrel:
           - implement 3 low-loss cable tunables
       - Realtek:
           - support MDI swapping for RTL8226-CG
           - support MDIO for RTL931x
       - Qualcomm:
           - at803x: Rx and Tx clock management for IPQ5018 PHY
       - Motorcomm:
           - support YT8522 100M RMII PHY
           - set drive strength in YT8531s RGMII
       - TI:
           - dp83822: add optional external PHY clock

   - Bluetooth:
       - hci_sync: add support for HCI_LE_Set_Host_Feature [v2]
       - SMP: use AES-CMAC library API
       - Intel:
           - support Product level reset
           - support smart trigger dump
       - Mediatek:
           - add event filter to filter specific event
       - Realtek:
           - fix RTL8761B/BU broken LE extended scan

   - WiFi:
       - Broadcom (b43):
           - new support for a 11n device
       - MediaTek (mt76):
           - support mt7927
           - mt792x: broken usb transport detection
           - mt7921: regulatory improvements
       - Qualcomm (ath9k):
           - GPIO interface improvements
       - Qualcomm (ath12k):
           - WDS support
           - replace dynamic memory allocation in WMI Rx path
           - thermal throttling/cooling device support
           - 6 GHz incumbent interference detection
           - channel 177 in 5 GHz
       - Realtek (rt89):
           - RTL8922AU support
           - USB 3 mode switch for performance
           - better monitor radiotap support
           - RTL8922DE preparations"

* tag 'net-next-7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next: (1778 commits)
  ipv4: fib_rule: Move fib4_rules_exit() to ->exit().
  net: serialize netif_running() check in enqueue_to_backlog()
  net: skmsg: preserve sg.copy across SG transforms
  appletalk: move the protocol out of tree
  appletalk: stop storing per-interface state in struct net_device
  selftests/bpf: test that TLS crypto is rejected on a sockmap socket
  selftests/bpf: drop the unused kTLS program from test_sockmap
  selftests/bpf: remove sockmap + ktls tests
  tls: remove dead sockmap (psock) handling from the SW path
  tls: reject the combination of TLS and sockmap
  atm: remove orphaned uAPI for deleted drivers, protocols and SVCs
  atm: remove unused ATM PHY operations
  atm: remove the unused pre_send and send_bh device operations
  atm: remove the unused change_qos device operation
  atm: remove SVC socket support and the signaling daemon interface
  atm: remove the local ATM (NSAP) address registry
  atm: remove dead SONET PHY ioctls
  atm: remove the unused send_oam / push_oam callbacks
  atm: remove AAL3/4 transport support
  net: dsa: sja1105: fix lastused timestamp in flower stats
  ...
2026-06-17 08:17:00 +01:00
..
ipset netfilter: add option for GCOV profiling 2026-05-24 22:55:47 +02:00
ipvs ipvs: Replace use of system_unbound_wq with system_dfl_long_wq 2026-06-14 12:49:32 +02:00
core.c netfilter: remove nf_ipv6_ops and use direct function calls 2026-03-29 11:21:24 -07:00
Kconfig netfilter: allow nfnetlink built-in only 2026-05-24 22:55:47 +02:00
Makefile netfilter: allow nfnetlink built-in only 2026-05-24 22:55:47 +02:00
nf_bpf_link.c netfilter: bpf: defer hook memory release until rcu readers are done 2026-03-19 10:26:31 +01:00
nf_conncount.c netfilter: nf_conncount: gc and rcu fixes 2026-06-14 12:51:55 +02:00
nf_conntrack_acct.c
nf_conntrack_amanda.c netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper 2026-06-05 13:25:18 +02:00
nf_conntrack_bpf.c Networking changes for 7.0 2026-02-11 19:31:52 -08:00
nf_conntrack_broadcast.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_core.c netfilter: conntrack: call nf_ct_gre_keymap_destroy() if master helper is pptp 2026-06-05 16:21:38 +02:00
nf_conntrack_ecache.c netfilter: ctnetlink: ensure safe access to master conntrack 2026-03-26 13:18:32 +01:00
nf_conntrack_expect.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_extend.c netfilter: conntrack: revert ct extension genid infrastructure 2026-06-05 16:16:44 +02:00
nf_conntrack_ftp.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_h323_asn1.c netfilter: nf_conntrack_h323: Correct indentation when H323_TRACE defined 2026-04-08 07:51:31 +02:00
nf_conntrack_h323_main.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_h323_types.c
nf_conntrack_helper.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-06-11 14:33:35 -07:00
nf_conntrack_irc.c netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper 2026-06-05 13:25:18 +02:00
nf_conntrack_labels.c netfilter: conntrack: switch connlabels to atomic_t 2023-10-24 13:16:30 +02:00
nf_conntrack_netbios_ns.c netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper 2026-06-05 13:25:18 +02:00
nf_conntrack_netlink.c netfilter: nf_conntrack_helper: add refcounting from datapath 2026-06-05 16:16:44 +02:00
nf_conntrack_ovs.c netfilter: nf_conntrack_helper: add refcounting from datapath 2026-06-05 16:16:44 +02:00
nf_conntrack_pptp.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_proto_generic.c netfilter: nf_conntrack: Add allow_clash to generic protocol handler 2026-01-20 16:23:37 +01:00
nf_conntrack_proto_gre.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_proto_icmp.c netfilter: nf_conntrack: enable icmp clash support 2026-01-20 16:23:37 +01:00
nf_conntrack_proto_icmpv6.c netfilter: nf_conntrack: enable icmp clash support 2026-01-20 16:23:37 +01:00
nf_conntrack_proto_sctp.c netfilter: skip recording stale or retransmitted INIT 2026-04-28 17:52:19 -07:00
nf_conntrack_proto_tcp.c netfilter: nf_conntrack: use get_unaligned_be32() in tcp_sack() 2026-06-07 11:13:47 +02:00
nf_conntrack_proto_udp.c netfilter: conntrack: remove UDP-Lite conntrack support 2026-04-10 12:16:26 +02:00
nf_conntrack_proto.c netfilter: nf_conntrack_helper: add refcounting from datapath 2026-06-05 16:16:44 +02:00
nf_conntrack_sane.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_seqadj.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_sip.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nf_conntrack_snmp.c netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper 2026-06-05 13:25:18 +02:00
nf_conntrack_standalone.c netfilter: conntrack: remove UDP-Lite conntrack support 2026-04-10 12:16:26 +02:00
nf_conntrack_tftp.c netfilter: nf_conntrack_helper: dynamically allocate struct nf_conntrack_helper 2026-06-05 13:25:18 +02:00
nf_conntrack_timeout.c netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount 2026-06-05 13:11:55 +02:00
nf_conntrack_timestamp.c
nf_dup_netdev.c netfilter pull request 26-06-14 2026-06-15 14:09:57 -07:00
nf_flow_table_bpf.c bpf: Remove redundant KF_TRUSTED_ARGS flag from all kfuncs 2026-01-02 12:04:28 -08:00
nf_flow_table_core.c netfilter: flowtable: fix inline pppoe encapsulation in xmit path 2026-05-01 01:24:01 +02:00
nf_flow_table_inet.c net: netfilter: move nf flowtable bpf initialization in nf_flow_table_module_init() 2024-09-12 15:41:03 +02:00
nf_flow_table_ip.c netfilter: flowtable: use skb_pull_rcsum() to pop vlan/pppoe header 2026-05-01 12:39:23 +02:00
nf_flow_table_offload.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-04-02 11:03:13 -07:00
nf_flow_table_path.c netfilter: flowtable: bail out if forward path cannot be discovered 2026-06-14 12:51:55 +02:00
nf_flow_table_procfs.c
nf_flow_table_xdp.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
nf_hooks_lwtunnel.c sysctl: treewide: constify the ctl_table argument of proc_handlers 2024-07-24 20:59:29 +02:00
nf_internals.h netfilter: move the sysctl nf_hooks_lwtunnel into the netfilter core 2024-06-19 18:41:59 +02:00
nf_log_syslog.c netfilter: nf_log: validate MAC header was set before dumping it 2026-06-10 18:00:01 +02:00
nf_log.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
nf_nat_amanda.c netfilter: conntrack: remove sprintf usage 2026-04-20 23:27:46 +02:00
nf_nat_bpf.c bpf: Remove redundant KF_TRUSTED_ARGS flag from all kfuncs 2026-01-02 12:04:28 -08:00
nf_nat_core.c netfilter: nf_conntrack: destroy stale expectfn expectations on unregister 2026-06-10 17:58:39 +02:00
nf_nat_ftp.c
nf_nat_helper.c
nf_nat_irc.c
nf_nat_masquerade.c netfilter: remove nf_ipv6_ops and use direct function calls 2026-03-29 11:21:24 -07:00
nf_nat_ovs.c netfilter: nf_conntrack: don't rely on implicit includes 2026-01-20 16:23:37 +01:00
nf_nat_proto.c netfilter: conntrack: remove UDP-Lite conntrack support 2026-04-10 12:16:26 +02:00
nf_nat_redirect.c netfilter: nat: fix ipv6 nat redirect with mapped and scoped addresses 2023-11-08 16:40:30 +01:00
nf_nat_sip.c netfilter pull request 26-06-14 2026-06-15 14:09:57 -07:00
nf_nat_tftp.c
nf_queue.c netfilter: nf_queue: hold bridge skb->dev while queued 2026-05-16 13:23:01 +02:00
nf_sockopt.c
nf_synproxy_core.c netfilter: synproxy: fix unaligned memory access in timestamp adjustment 2026-06-05 13:11:55 +02:00
nf_tables_api.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nf_tables_core.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nf_tables_offload.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nf_tables_trace.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nfnetlink_acct.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nfnetlink_cthelper.c netfilter: conntrack: check NULL when retrieving ct extension 2026-06-14 12:51:55 +02:00
nfnetlink_cttimeout.c netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount 2026-06-05 13:11:55 +02:00
nfnetlink_hook.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nfnetlink_log.c netfilter: revalidate bridge ports 2026-06-10 17:58:20 +02:00
nfnetlink_osf.c netfilter: nfnetlink_osf: fix mss parsing on big-endian architectures 2026-06-05 13:11:54 +02:00
nfnetlink_queue.c netfilter: revalidate bridge ports 2026-06-10 17:58:20 +02:00
nfnetlink.c net: Add SPDX ids to some source files 2026-03-09 18:32:45 -07:00
nft_bitwise.c netfilter: nf_tables: fix dst corruption in same register operation 2026-05-22 12:28:46 +02:00
nft_byteorder.c netfilter: nft_byteorder: remove multi-register support 2026-06-01 13:43:53 +02:00
nft_chain_filter.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-03-12 12:53:34 -07:00
nft_chain_nat.c netfilter: add missing module descriptions 2023-11-08 13:52:32 +01:00
nft_chain_route.c
nft_cmp.c netfilter: nf_tables: add netlink policy based cap on registers 2026-04-08 07:51:31 +02:00
nft_compat.c netfilter: nft_compat: run xt_check_hooks_{match,target}() from .validate 2026-04-30 08:03:22 +02:00
nft_connlimit.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_counter.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_ct_fast.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_ct.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_dup_netdev.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_dynset.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_exthdr.c netfilter pull request 26-06-14 2026-06-15 14:09:57 -07:00
nft_fib_inet.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_fib_netdev.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_fib.c netfilter pull request 26-06-14 2026-06-15 14:09:57 -07:00
nft_flow_offload.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_fwd_netdev.c netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them 2026-06-14 13:07:03 +02:00
nft_hash.c netfilter: nf_tables: add netlink policy based cap on registers 2026-04-08 07:51:31 +02:00
nft_immediate.c netfilter: nf_tables_offload: add nft_flow_action_entry_next() and use it 2026-04-08 07:51:31 +02:00
nft_inner.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_last.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-02-26 10:23:00 -08:00
nft_limit.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_log.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_lookup.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_masq.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_meta.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_nat.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_numgen.c netfilter: nf_tables: add netlink policy based cap on registers 2026-04-08 07:51:31 +02:00
nft_objref.c netfilter: nf_tables: add netlink policy based cap on registers 2026-04-08 07:51:31 +02:00
nft_osf.c netfilter: nf_tables: skip L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
nft_payload.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_queue.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_quota.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_range.c netfilter: nf_tables: add netlink policy based cap on registers 2026-04-08 07:51:31 +02:00
nft_redir.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_reject_inet.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_reject_netdev.c netfilter: nf_tables: remove register tracking infrastructure 2026-02-25 19:36:26 -08:00
nft_reject.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_rt.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_set_bitmap.c netfilter: nft_set_bitmap: fix lockdep splat due to missing annotation 2025-09-10 20:28:24 +02:00
nft_set_hash.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_set_pipapo_avx2.c netfilter: nft_set_pipapo_avx2: restore performance optimization 2026-05-24 22:55:48 +02:00
nft_set_pipapo_avx2.h netfilter: nft_set_pipapo: use avx2 algorithm for insertions too 2025-08-20 13:52:37 +02:00
nft_set_pipapo.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_set_pipapo.h netfilter: nft_set_pipapo: increment data in one step 2026-04-08 07:51:31 +02:00
nft_set_rbtree.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_socket.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_synproxy.c netfilter: add more netlink-based policy range checks 2026-04-08 07:51:30 +02:00
nft_tproxy.c netfilter: nf_tables: skip L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
nft_tunnel.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
nft_xfrm.c netfilter: nf_tables: use DEBUG_NET_WARN_ON_ONCE in packet and control paths 2026-06-14 12:50:01 +02:00
utils.c netfilter: remove nf_ipv6_ops and use direct function calls 2026-03-29 11:21:24 -07:00
x_tables.c netfilter: x_tables: add and use xtables_unregister_table_exit 2026-05-08 01:30:16 +02:00
xt_addrtype.c netfilter: x_tables: add .check_hooks to matches and targets 2026-04-30 08:03:22 +02:00
xt_AUDIT.c audit: add audit_log_nf_skb helper function 2025-12-16 11:04:14 -05:00
xt_bpf.c
xt_cgroup.c netfilter: x_tables: ensure names are nul-terminated 2026-04-01 11:55:29 +02:00
xt_CHECKSUM.c netfilter: xtables: avoid NFPROTO_UNSPEC where needed 2024-10-09 23:20:46 +02:00
xt_CLASSIFY.c netfilter: xtables: avoid NFPROTO_UNSPEC where needed 2024-10-09 23:20:46 +02:00
xt_cluster.c netfilter: xtables: avoid NFPROTO_UNSPEC where needed 2024-10-09 23:20:46 +02:00
xt_comment.c
xt_connbytes.c net: Add SPDX ids to some source files 2026-03-09 18:32:45 -07:00
xt_connlabel.c
xt_connlimit.c net: Add SPDX ids to some source files 2026-03-09 18:32:45 -07:00
xt_connmark.c netfilter: xtables: avoid NFPROTO_UNSPEC where needed 2024-10-09 23:20:46 +02:00
xt_CONNSECMARK.c netfilter: xtables: avoid NFPROTO_UNSPEC where needed 2024-10-09 23:20:46 +02:00
xt_conntrack.c
xt_cpu.c netfilter: xt_cpu: prefer raw_smp_processor_id 2026-05-22 12:28:46 +02:00
xt_CT.c netfilter: nf_conntrack_helper: add refcounting from datapath 2026-06-05 16:16:44 +02:00
xt_dccp.c netfilter: add deprecation warning for dccp support 2026-04-08 07:51:27 +02:00
xt_devgroup.c netfilter: x_tables: add .check_hooks to matches and targets 2026-04-30 08:03:22 +02:00
xt_dscp.c
xt_DSCP.c
xt_ecn.c netfilter: xtables: fix L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
xt_esp.c
xt_hashlimit.c netfilter: xtables: fix L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
xt_helper.c
xt_hl.c netfilter: xt_HL: add pr_fmt and checkentry validation 2026-04-10 12:16:26 +02:00
xt_HL.c
xt_HMARK.c
xt_IDLETIMER.c netfilter: xt_IDLETIMER: Switch to alarm_start_timer() 2026-05-01 21:36:14 +02:00
xt_ipcomp.c
xt_iprange.c
xt_ipvs.c
xt_l2tp.c
xt_LED.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_length.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf 2023-02-22 21:25:23 -08:00
xt_limit.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_LOG.c
xt_mac.c netfilter: xtables: restrict several matches to inet family 2026-04-20 23:27:52 +02:00
xt_mark.c netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds 2025-05-22 17:16:02 +02:00
xt_MASQUERADE.c
xt_multiport.c netfilter: xt_multiport: validate range encoding in checkentry 2026-04-08 13:33:38 +02:00
xt_nat.c
xt_NETMAP.c
xt_nfacct.c netfilter: xt_nfacct: don't assume acct name is null-terminated 2025-07-25 18:40:43 +02:00
xt_NFLOG.c netfilter: xtables: fix typo causing some targets not to load on IPv6 2024-10-21 11:31:26 +02:00
xt_NFQUEUE.c netfilter: xt_NFQUEUE: prefer raw_smp_processor_id 2026-06-01 13:43:52 +02:00
xt_osf.c netfilter: xtables: fix L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
xt_owner.c netfilter: xtables: restrict several matches to inet family 2026-04-20 23:27:52 +02:00
xt_physdev.c netfilter: x_tables: add .check_hooks to matches and targets 2026-04-30 08:03:22 +02:00
xt_pkttype.c
xt_policy.c netfilter: x_tables: add .check_hooks to matches and targets 2026-04-30 08:03:22 +02:00
xt_quota.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_rateest.c netfilter: x_tables: ensure names are nul-terminated 2026-04-01 11:55:29 +02:00
xt_RATEEST.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_realm.c netfilter: xtables: restrict several matches to inet family 2026-04-20 23:27:52 +02:00
xt_recent.c Convert 'alloc_flex' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_REDIRECT.c netfilter: nft_redir: use struct nf_nat_range2 throughout and deduplicate eval call-backs 2023-03-22 21:48:59 +01:00
xt_repldata.h netfilter: xtables: Use strscpy() instead of strscpy_pad() 2025-03-23 10:53:47 +01:00
xt_sctp.c netfilter: xt_sctp: validate the flag_info count 2023-08-30 17:34:01 +02:00
xt_SECMARK.c netfilter: xtables: avoid NFPROTO_UNSPEC where needed 2024-10-09 23:20:46 +02:00
xt_set.c netfilter: x_tables: add .check_hooks to matches and targets 2026-04-30 08:03:22 +02:00
xt_socket.c netfilter: xt_socket: enable defrag after all other checks 2026-04-10 12:16:26 +02:00
xt_state.c
xt_statistic.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_string.c
xt_tcpmss.c netfilter: xtables: fix L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
xt_TCPMSS.c netfilter: x_tables: add .check_hooks to matches and targets 2026-04-30 08:03:22 +02:00
xt_TCPOPTSTRIP.c netfilter: xtables: support arpt_mark and ipv6 optstrip for iptables-nft only builds 2025-05-22 17:16:02 +02:00
xt_tcpudp.c netfilter: x_tables: guard option walkers against 1-byte tail reads 2026-03-10 14:10:42 +01:00
xt_TEE.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
xt_time.c Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net 2026-03-19 14:16:00 -07:00
xt_TPROXY.c netfilter: xtables: fix L4 header parsing for non-first fragments 2026-04-30 17:59:01 +02:00
xt_TRACE.c netfilter: xtables: fix typo causing some targets not to load on IPv6 2024-10-21 11:31:26 +02:00
xt_u32.c netfilter: xt_u32: validate user space input 2023-08-30 17:34:01 +02:00