summaryrefslogtreecommitdiff
path: root/sbin/pfctl
AgeCommit message (Expand)Author
2015-01-21Include <netinet/in.h> before <net/pfvar.h>. In a future change whenTheo de Raadt
2015-01-20Rewrite to void using union sockaddr_unionTheo de Raadt
2015-01-19DEFAULT_PRIORITY and DEFAULT_QLIMIT no longer usedTheo de Raadt
2015-01-16Replace <sys/param.h> with <limits.h> and other less dirty headers whereTheo de Raadt
2014-12-19Support source-hash and random with tables and dynifs; not just pools.Reyk Floeter
2014-12-10If pfctl cannot set a limit in the kernel, print the name of theAlexander Bluhm
2014-11-20Don't allow embedded nul characters in strings.Jonathan Gray
2014-11-13keep queues around when anchors are being loadedMartin Pelikan
2014-10-27Fixup incorrect expansion of the networking mask for dynamic interfaceMike Belopuhov
2014-10-25Remove unnecessary netinet/in_systm.h include.Lawrence Teo
2014-09-13Replace all queue *_END macro calls except CIRCLEQ_END with NULL.Doug Hogan
2014-08-23when you specify queues in a rule, make sure they have been defined.Martin Pelikan
2014-08-21deny "once" flags for match rules; ok henningMike Belopuhov
2014-07-02condition above makes this part of the check useless;Mike Belopuhov
2014-06-30Merge two loops in collapse_redirspec into oneMike Belopuhov
2014-06-25Make stricter decisions when handling translation specifications.Mike Belopuhov
2014-05-17When parsing a numerical value for the TOS bits, make sure that itAlexander Bluhm
2014-05-07consolidate some code by using reallocarray in all cases.Ted Unangst
2014-04-19remove altq bits here, tooHenning Brauer
2014-04-11fix a use after free in an error pathJonathan Gray
2014-02-28Bring back the code removed in rev1.317 used to print anchors withMike Belopuhov
2014-02-17Remove a stray debug printf that crept in via one of the newqueueLawrence Teo
2014-01-22relax the cfg file secrecy check slightly to allow group readabilityHenning Brauer
2014-01-21if_item can be "any" now.Henning Brauer
2014-01-20support "!received-on <interface>", ok dlg bennoHenning Brauer
2014-01-19Fix minor ident issue. OK benno@, pelikan@Claudio Jeker
2013-11-25use u_char for buffers in yylex, for ctype callsSebastian Benoit
2013-11-22Whole bunch of (unsigned char) casts carefully added for ctype calls.Theo de Raadt
2013-11-01keep net/hfsc.h away from userspace, except in pfctlpelikan
2013-10-28use %d instead of %i in a few fprintf for clarityTheo de Raadt
2013-10-17cannot have queue definitions inside anchors.Henning Brauer
2013-10-12config bits for the bandwidth shaping part of the new queueing subsystemHenning Brauer
2013-10-09Make sure that pfctl_state_store() frees the inbuf pointer and closesLawrence Teo
2013-08-12Remove duplicate and incorrect recursive anchor printing codeMike Belopuhov
2013-08-02Remove an incorrect call to pfctl_print_rule_counters when trying toMike Belopuhov
2013-08-01Provide local implementations of if_nametoindex(3) and if_indextoname(3)Mike Belopuhov
2013-07-21zap one redundant line, replacing it with a note that althoughJason McIntyre
2013-07-21tidy up DESCRIPTION somewhat, and format nicer;Jason McIntyre
2013-07-21re-zap the previous paragraph, but this time in its place documentJason McIntyre
2013-07-20reverting previous until i can work out what henning is telling me...Jason McIntyre
2013-07-19remove redundant paragraph; from Pieter VerberneJason McIntyre
2013-07-05Collect and display 'match' counters for pf tables.Bret Lambert
2013-06-01remove set-tos backwards compat, moved into the set {} block a year agoHenning Brauer
2013-04-21avoid truncating a time_t division into daysTheo de Raadt
2013-03-21fetch NMBCLUSTERS at runtime from the sysctl kern.maxclustersTheo de Raadt
2013-03-20MCLBYTES does not belong in here.Theo de Raadt
2013-03-13Describe the counters that "pfctl -s info" displays. Tweaks jmc@, ok deraadt@Stuart Henderson
2013-03-02When a PF rule contains 'set tos' *followed by* a scrub option, the tosStuart Henderson
2013-01-16for consistency with prio etc, the queue assignment really belongsHenning Brauer
2012-12-04remove some unnecessary sys/param.h inclusionsTheo de Raadt