summaryrefslogtreecommitdiff
path: root/sbin/pfctl/parse.y
AgeCommit message (Expand)Author
2002-07-15cosmetics/consolidations to manpage in yyerror()sPhilipp Buehler
2002-07-15o complain about keep state on block rulesHenning Brauer
2002-07-13add list expansion for interface and proto in nat rules and for proto in rdrHenning Brauer
2002-07-09check sin6_scope_id field, just in case we change the routing socket APIJun-ichiro itojun Hagino
2002-07-09getifaddrs(3) grabs link-local addrs in kernel internal form, convert themJun-ichiro itojun Hagino
2002-07-09rework the interface-to-IP routines.Henning Brauer
2002-07-08Don't allow 'flags' option in non-TCP rules, found by mpech@Daniel Hartmeier
2002-07-05unbreak.Henning Brauer
2002-07-05another small bug I found while installing a -current pf firewall.Henning Brauer
2002-07-01streamline parse buffer handling (no need to copy value that is notMarc Espie
2002-07-01KNFTheo de Raadt
2002-06-28Don't check for address family conflicts in nat/rdr before expansion,Daniel Hartmeier
2002-06-25move pfctl options -t, -m, -O and -l to pf.conf. These are set using theHenning Brauer
2002-06-24Use interface when specified in scrub rule. No support for ! or {} yet.Daniel Hartmeier
2002-06-23uid_t and gid_t are unsignedTheo de Raadt
2002-06-20Copy address family from inet/inet6 keyword, if specified.Daniel Hartmeier
2002-06-18propogate a '!' when a host resolves to multiple IP addressesMike Frantzen
2002-06-18don't allow individual keep state rules to specify timeouts for 'interval' andMike Frantzen
2002-06-16Rules must in order -> Rules must be in orderAaron Campbell
2002-06-15Reset rulestate in parse_rules(), so consecutive calls (like from authpf)Daniel Hartmeier
2002-06-13Fix the numbering of scrub rules. pointed out and oked by frantzen@Kjell Wooding
2002-06-12Fix uninitialized access. Spotted by danh@ This is a good reason toKjell Wooding
2002-06-11split the grammar of scrub(fragcache) into scrub ... 'fragment reassemble',Mike Frantzen
2002-06-11SCRUB(fragcache) to do gap tracking and overlap pruning of IPv4 fragmentsMike Frantzen
2002-06-11Make NAT proxy port range configurable per rule, for instance privilegedDaniel Hartmeier
2002-06-10Merge the NAT and rules files into a single rulefile. Rules must beKjell Wooding
2002-06-10Allow ports to be specified in nat rules, useful later on for individualDaniel Hartmeier
2002-06-10Move enum out of struct (gcc 3.1 wasn't happy), from David KrauseDaniel Hartmeier
2002-06-10split scrub rule processing into its own yacc target,Kjell Wooding
2002-06-09Make pf_nat.saddr/daddr a pf_rule_addr instead of pf_addr_wrap, so itDaniel Hartmeier
2002-06-09spaced out developers...Theo de Raadt
2002-06-09Add list parsing in RDR rules: e.g.Kjell Wooding
2002-06-08nuke unused parameter af to expand_label_portHenning Brauer
2002-06-08Change remaining read-only lookup tables to const, suggestion drahn@Daniel Hartmeier
2002-06-08comment on IPv6 link-local twistsJun-ichiro itojun Hagino
2002-06-08add list expansion to src/dest in NAT rules. i.e.Kjell Wooding
2002-06-08remove macro concatenation via += per Theo's adviceHenning Brauer
2002-06-08allow macro concatenation likeHenning Brauer
2002-06-08Make state timeouts configurable per rule, likeDaniel Hartmeier
2002-06-08expand $nr -> rule number in rule labelsHenning Brauer
2002-06-08expand $proto in rule labelsHenning Brauer
2002-06-07Handle realloc() failure gracefully. Terminates with err() anyway in thisDaniel Hartmeier
2002-06-07henning, read this to see what i mean by KNFTheo de Raadt
2002-06-07add the possibility to configure a TTL while return-rstPhilipp Buehler
2002-06-07Add "(max <number>)" option for "keep/modulate state" to limit the numberDaniel Hartmeier
2002-06-07allow using $srcaddr, $srcport, $dstaddr and $dstport in rule labels,Henning Brauer
2002-06-07make IPv6 scope identification work for dst (from any to fe80::1%lo0)Jun-ichiro itojun Hagino
2002-06-07support scoped IPv6 address in from/to portion.Jun-ichiro itojun Hagino
2002-06-01ECN flag support for pf. Committed in consultation with Daniel.Hugh Graham
2002-05-24Support mixed (IPv4/v6) address lists, expand to all possible and validDaniel Hartmeier