summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2002-07-30Update BSD licenses to include 'with or without modification'.Federico G. Schwindt
From binutils -current.
2002-07-30sometimes no-return syscalls (execve) emit errno < 0. ignore them.Jun-ichiro itojun Hagino
2002-07-30sync with http://www.openssl.org/news/patch_20020730_0_9_7.txtMarkus Friedl
(adds fix for unused kerberos and engine code, and some more assertions, as well as a 64bit integer string fix for conf_mod.c)
2002-07-30minor KNF. pid_t is unsigned.Jun-ichiro itojun Hagino
2002-07-30negative regression test for flags handlingHenning Brauer
2002-07-30positive regression test for flag handlingHenning Brauer
2002-07-30grmpf.Henning Brauer
in some cases, on non-tcp rules flags weren't resetted. cosmetical only problem. but, well, checking for r->flags and r->flagset if we could have assigned them zero just one round ago is just stupid, and it's not needed to check them at all. ok pb@, dhartmei@
2002-07-30Merge filter and nat BNF for simplification:Philipp Buehler
- top of reduction is now 'line', better to add more keywords later on - reorder, group - remove double productions ok dhartmei@, henning@
2002-07-30BNF catchup to reality:Philipp Buehler
- set loginterface none - add "self" to hosts ok henning@
2002-07-30typo/pasto in route-to/dup-to syntaxPhilipp Buehler
ok henning@
2002-07-30apply patches from OpenSSL Security Advisory [30 July 2002],Markus Friedl
http://marc.theaimsgroup.com/?l=openssl-dev&m=102802395104110&w=2
2002-07-30strip_chroot here as well.Henning Brauer
pointed out by sengel at melshake dot com
2002-07-30allow to specify flags on all rules that include tcp.Henning Brauer
these are valid: pass in from any to any flags S pass in proto { tcp, udp, icmp } from any to any flags S pass in proto tcp from any to any flags S these are invalid: pass in proto { udp, icmp } from any to any flags S pass in proto udp from any to any flags S ok "I've lost my slacker status for at least a week" frantzen@ ok pb@, dhartmei@, deraadt@
2002-07-30.Sh GRAMMAR moves to bottom, it's a reference and not readablePhilipp Buehler
for the casual user in first place ok henning@
2002-07-30sync function decl and prototype (static-ness)Jun-ichiro itojun Hagino
2002-07-3065335->65535 typoPhilipp Buehler
henning ok@
2002-07-30backout, this will go in in little piecesPhilipp Buehler
as advised by theo and henning
2002-07-30two more strip_chrootHenning Brauer
found by Steph <sengel@melshake.com>, who also tested this. I'm very happy with the way you help here. Thanks a lot.
2002-07-30avoid using same variable name for global and auto variable.Jun-ichiro itojun Hagino
2002-07-30oops, i've been looking at older tree.hJun-ichiro itojun Hagino
2002-07-30SPLAY_INSERT is a void functionJun-ichiro itojun Hagino
2002-07-30sync prototype for yyerror().Jun-ichiro itojun Hagino
2002-07-30include filter.h, dont' duplicate prototypeJun-ichiro itojun Hagino
2002-07-30ansi wump, plus a more accurate commentPaul Janzen
2002-07-30extern decls should be outside of function.Jun-ichiro itojun Hagino
2002-07-30Kill buffer overflow.Paul Janzen
2002-07-30whitespace at EOLJun-ichiro itojun Hagino
2002-07-30solve a problem with realpath when the last component of the path isNiels Provos
a directory without S_IXUSR; tested by me and dugsong.
2002-07-30Add SIZE_MAX define. This is the same as SIZE_T_MAX but more portable.Todd C. Miller
The only OSes I've seen that use SIZE_T_MAX are 4.4BSD-derived whereas SYSV things seem to use SIZE_MAX. It is also consistent with SSIZE_MAX (which we already have). deraadt@ OK
2002-07-30more strlcpy; itojun okTheo de Raadt
2002-07-30Release sessions to avoid memory leak. From NetBSD. ok deraadt@Thomas Nordin
2002-07-30be even more careful with strlcpy()Theo de Raadt
2002-07-30Clarify time handling at securelevel 2. Idea from mpech@ ok millert@Thomas Nordin
2002-07-30return failure if integer overflow happens. sigh; too people had toTheo de Raadt
help get this right.
2002-07-29switch to ether_input_mbuf(); mickey@ tested and ok.Federico G. Schwindt
2002-07-29turn off more methods by default -- enable them if you need them; millert okTheo de Raadt
2002-07-29Try to gracefully handle out of memory conditions.Artur Grabowski
Not that it will help much, but what the hell. noticed by: tedu <grendel@zeitbombe.org>
2002-07-29careful mallocTheo de Raadt
2002-07-29minor formattingArtur Grabowski
2002-07-29o complete restructuringPhilipp Buehler
o BNF has been fixed and should represent -current as close as possible o theo: commit this, and then let us get started fixing it.
2002-07-29dma support for serverwors osb4 and csb5, from netbsd; csapuntz@, deraadt@ okMichael Shalayeff
2002-07-29Replace an instance of chmod() with fchmod()Todd C. Miller
2002-07-29this should be a DPRINTFNathan Binkert
2002-07-29Recognize additional host bridges, pretty printing only, no function diff.Dale Rahn
2002-07-29Replace atexit handler. mprotect() the pages so an attempt to modify theDaniel Hartmeier
function pointers from the outside will segfault. Idea, hints and feedback from deraadt. ok deraadt.
2002-07-29Try to modify __atexit directly and see if our function gets called.Daniel Hartmeier
2002-07-29regenTodd C. Miller
2002-07-29PCI_PRODUCT_USR2_WL11000P not PCI_PRODUCT_USR2_USR11000PTodd C. Miller
2002-07-29It is WL11000P, not USR11000P. Woohoo, we save a byte!Todd C. Miller
2002-07-29regenMichael Shalayeff