summaryrefslogtreecommitdiff
path: root/sbin/pfctl
AgeCommit message (Expand)Author
2016-08-26Add <time.h> for time(); sort <*.h> includesPhilip Guenther
2016-08-03A couple of "a->blah == a->blah" -> "a->blah == b->blah".Kenneth R Westerback
2016-07-18no more cbq_opts - CBQ is gone, ok mpi phessler bennoHenning Brauer
2016-07-18g/c unused (global!) var: oqueues isn't used any more. ALTQ leftover; notHenning Brauer
2016-06-22Add curly braces that were missed in rev 1.651. Add parenthesis to make theMark Kettenis
2016-06-21do not allow whitespace in macro names, i.e. "this is" = "a variable".Sebastian Benoit
2016-06-21the manpage documents that af-to does not work on pass out rules, butSebastian Benoit
2016-06-16allow include in inline anchorsHenning Brauer
2016-01-14detect multiple root queues on a single interface and give a nice errorHenning Brauer
2016-01-05remove long deprecated "set debug "none|urgent|misc|loud" levels inSebastian Benoit
2015-12-10Remove NULL-checks before free(). ok tb@mmcc
2015-10-02Make 'pfctl -s all' show queues. pfctl(8) says it does, and 5.4Kenneth R Westerback
2015-09-03interface should only be specified for root queues; found by jsgMike Belopuhov
2015-09-01- route-to, dup-to, reply-to should not override the block actionAlexandr Nedvedicky
2015-06-15document pfctl -ss -R <rule>, ok mikeb@Stuart Henderson
2015-06-12Allow rule ID filter to be specified for show states outputMike Belopuhov
2015-06-03Do not assume that asprintf() clears the pointer on failure, whichTodd C. Miller
2015-04-21Improve divert-to specification parsing w.r.t. rule address family.Mike Belopuhov
2015-02-26%% not % in error message; ok millert@ henning@Stuart Henderson
2015-02-14Rather than using 0xff as a placeholder for "don't check prio", use 0xff toStuart Henderson
2015-02-10since we inherit prio (as in, the queuing priority) from outside sources,Henning Brauer
2015-02-07parse debug levels with strtonum, so that debug 1banana doesn't parse.Ted Unangst
2015-01-21Include <netinet/in.h> before <net/pfvar.h>. In a future change whenTheo de Raadt
2015-01-20Rewrite to void using union sockaddr_unionTheo de Raadt
2015-01-19DEFAULT_PRIORITY and DEFAULT_QLIMIT no longer usedTheo de Raadt
2015-01-16Replace <sys/param.h> with <limits.h> and other less dirty headers whereTheo de Raadt
2014-12-19Support source-hash and random with tables and dynifs; not just pools.Reyk Floeter
2014-12-10If pfctl cannot set a limit in the kernel, print the name of theAlexander Bluhm
2014-11-20Don't allow embedded nul characters in strings.Jonathan Gray
2014-11-13keep queues around when anchors are being loadedMartin Pelikan
2014-10-27Fixup incorrect expansion of the networking mask for dynamic interfaceMike Belopuhov
2014-10-25Remove unnecessary netinet/in_systm.h include.Lawrence Teo
2014-09-13Replace all queue *_END macro calls except CIRCLEQ_END with NULL.Doug Hogan
2014-08-23when you specify queues in a rule, make sure they have been defined.Martin Pelikan
2014-08-21deny "once" flags for match rules; ok henningMike Belopuhov
2014-07-02condition above makes this part of the check useless;Mike Belopuhov
2014-06-30Merge two loops in collapse_redirspec into oneMike Belopuhov
2014-06-25Make stricter decisions when handling translation specifications.Mike Belopuhov
2014-05-17When parsing a numerical value for the TOS bits, make sure that itAlexander Bluhm
2014-05-07consolidate some code by using reallocarray in all cases.Ted Unangst
2014-04-19remove altq bits here, tooHenning Brauer
2014-04-11fix a use after free in an error pathJonathan Gray
2014-02-28Bring back the code removed in rev1.317 used to print anchors withMike Belopuhov
2014-02-17Remove a stray debug printf that crept in via one of the newqueueLawrence Teo
2014-01-22relax the cfg file secrecy check slightly to allow group readabilityHenning Brauer
2014-01-21if_item can be "any" now.Henning Brauer
2014-01-20support "!received-on <interface>", ok dlg bennoHenning Brauer
2014-01-19Fix minor ident issue. OK benno@, pelikan@Claudio Jeker
2013-11-25use u_char for buffers in yylex, for ctype callsSebastian Benoit
2013-11-22Whole bunch of (unsigned char) casts carefully added for ctype calls.Theo de Raadt