summaryrefslogtreecommitdiff
path: root/sbin/pfctl
AgeCommit message (Collapse)Author
2003-01-05don't whine about missing altq support in the kernel in the -q caseHenning Brauer
ok dhartmei@
2003-01-05err after calloc failure, not errxHenning Brauer
2003-01-05Move ifname from pf_addr to pf_addr_wrap, prepare pf_addr_wrap for tableDaniel Hartmeier
name. ok henning@, mcbride@, cedric@
2003-01-05err()/errx() do not return, errx() -> err() after calloc(), it sets errno.Daniel Hartmeier
From Andrey Matveev.
2003-01-04minor styleHenning Brauer
2003-01-04move noroute from flag in pf_rule_addr into type in pf_addr_wrap.Daniel Hartmeier
ok henning@, mcbride@
2003-01-04I do not know where this policy of "one .h file for every .c file" comesTheo de Raadt
from, but whoever thought of it is stupid.
2003-01-03Make good use of the 'else' keyword.Cedric Berger
2003-01-03knfTheo de Raadt
2003-01-03no need to closeTheo de Raadt
2003-01-03KNFTheo de Raadt
2003-01-03zero sockaddr before useTheo de Raadt
2003-01-03I am ready to strange the person who put a new strcpy() into ourTheo de Raadt
source tree.
2003-01-03(a && (b & c))Theo de Raadt
2003-01-03simplify ioctl accessTheo de Raadt
2003-01-03Remove _ before static functions & variables.Cedric Berger
2003-01-03Remove _ before static functions & variables.Cedric Berger
2003-01-03whitespace KNF (no, i don't touch the option inits)Daniel Hartmeier
2003-01-03kill stupid macroTheo de Raadt
2003-01-03KNFTheo de Raadt
2003-01-03Initialize hints addrinfo in a safe way.Cedric Berger
2003-01-03KNFTheo de Raadt
2003-01-03knfTheo de Raadt
2003-01-03Bring in userland code for accessing PF radix tables.Cedric Berger
ok dhartmei@ mcbride@
2003-01-02Require a direction to be specified for rules which do routing.Ryan Thomas McBride
ok dhartmei@ henning@
2003-01-01KNFHenning Brauer
2003-01-01Remove skip step for action (scrub vs. non-scrub), as scrub rules areDaniel Hartmeier
stored in a separate list now. Regress tests still pass after sed "s/ a=end / /g", other skip steps are not affected.
2003-01-01Extend two error messages, change one err() -> errx() where there's noDaniel Hartmeier
errno to translate. From Andrey Matveev.
2002-12-31Match kernel changes splitting scrub rules into their own ruleset type.Ryan Thomas McBride
ok henning@ dhartmei@
2002-12-31err() doesn't return. from Andrey Matveev.Daniel Hartmeier
2002-12-30Change ipv6-icmp-type to icpm6-type. pf.conf files will need to be adjustedRyan Thomas McBride
to reflect this. ok dhartmei@ henning@
2002-12-29Make pfctl -a name -sr/-sn show all rules of all rulesets within theDaniel Hartmeier
anchor. From discussion with Michael Lucas. ok henning@
2002-12-27Since pf_norm.c looks at rule.log to see if it should log packets beingRyan Thomas McBride
dropped due to scrub violations, this adds the ability to set this in pf.conf. ok henning@
2002-12-25Honour -R/-N and don't attempt to load other rules in those cases.Daniel Hartmeier
Found by Michael Lucas.
2002-12-24print_cbq_opts should print "control" if CBQCLF_CTLCLASS is set.Ryan Thomas McBride
ok henning@
2002-12-23remove dead codeHenning Brauer
2002-12-22Handle pool addresses in binat rules, ok mcbride@Daniel Hartmeier
2002-12-22Instead of inserting and removing rules at the top/bottom of the mainDaniel Hartmeier
ruleset, make authpf manage its rules inside anchors.
2002-12-21always initialize rpool.key; diff from Frank Denis; KNF by meHenning Brauer
2002-12-21KNFHenning Brauer
2002-12-20remove a redundant assignment.Daniel Hartmeier
2002-12-19fix 'no rdr'.Daniel Hartmeier
2002-12-18Store translation rule pointer in state entries, so pfctl -vsn can printDaniel Hartmeier
evaluation, packet, byte and state entry counters similar to -vsr. Helps verify whether/how often translation rules are evaluated/matched. ok frantzen@, henning@
2002-12-18more KNFHenning Brauer
2002-12-18Pass skip step values through ioctl interface, pfctl -vvsr shows them,Daniel Hartmeier
main purpose is making them regress-testable.
2002-12-18rule.nr USHRT_MAX -> -1, to detect states whose creating rules areDaniel Hartmeier
already gone.
2002-12-18ryan, look at this.Henning Brauer
2002-12-18Maintain separate pfioc_rule structures for each type of rule,Ryan Thomas McBride
to prevent tickets from getting overwritten. bug reported by dhartmei@ ok dhartmei@
2002-12-18proto list expansion is not supported in binat-anchor yet, print an errorDaniel Hartmeier
when attempted.
2002-12-18Support (single) destination port in rdr-anchor rules. Print an errorDaniel Hartmeier
where parameters are not supported (in rdr-anchor and binat-anchor) yet. If those are needed, we'll have to expand them properly.