Age | Commit message (Collapse) | Author | |
---|---|---|---|
2002-07-05 | unbreak. | Henning Brauer | |
2002-07-05 | another small bug I found while installing a -current pf firewall. | Henning Brauer | |
we don't support pass/block in on ! <interface> (at least, not yet) let the parser complain instead of ignoring the '!' ok pb@, dhartmei@ | |||
2002-07-05 | allow unsetting the statusinterface via | Henning Brauer | |
set loginterface none ok dhartmei@ | |||
2002-07-05 | volatile sig_atomic_t, suggested by Theo. | Hakan Olsson | |
2002-07-05 | gcc 3.1 nits. Pointed out by David Krause. | Hakan Olsson | |
2002-07-04 | Do not assume we have an active exchange during payload validation. | Hakan Olsson | |
2002-07-04 | style | Hakan Olsson | |
2002-07-03 | ansi | Theo de Raadt | |
2002-07-03 | convert to ansi. suddenly realise that means yet another function is a | Theo de Raadt | |
signal handler in some cases, and make it cope with the termination race. | |||
2002-07-01 | cut and pasto (fetch maxage correctly); Benny Holmgren <bigfoot@astrakan.hig.se> | Jason Wright | |
2002-07-01 | do not Xr startkey | Theo de Raadt | |
2002-07-01 | streamline parse buffer handling (no need to copy value that is not | Marc Espie | |
going to go away). add explicit pushback buffer, to be able to push IPv6 failed parses back. handle pushback + parse buffer interactions by using negative indices. okay dhartmei@, deraadt@ | |||
2002-07-01 | KNF | Theo de Raadt | |
2002-06-29 | ansi | Theo de Raadt | |
2002-06-29 | IPPROTO_ICMP will not change in our life; itojun ok | Theo de Raadt | |
2002-06-28 | Don't check for address family conflicts in nat/rdr before expansion, | Daniel Hartmeier | |
rules will expand to all valid combinations, and there's an error when none is found. Makes "nat on tun0 from 10.0.0.0/8 to any -> (tun0)" work (again). | |||
2002-06-27 | fix synopsis, closes pr2775 | Henning Brauer | |
ok pb@ | |||
2002-06-27 | repair formatting - the new "enabled since" format is longer than the old | Henning Brauer | |
one and thus the field lengths need to be adjusted. ok dhartmei@, pb@ | |||
2002-06-26 | Missing .Xr's from Margarida Sequeira <niness@devilness.org>. | Federico G. Schwindt | |
Remove unmount(2) per millert suggestion; millert@ ok. | |||
2002-06-26 | include <bsd.own.mk> before using NOMAN; ok millert@ | Wilbern Cobb | |
2002-06-25 | Minor fixes, including duplicate and missing words; Brian Poole | Todd C. Miller | |
2002-06-25 | move pfctl options -t, -m, -O and -l to pf.conf. These are set using the | Henning Brauer | |
"set" keyword. example rulefile: set optimization aggressive set timeout { tcp.closing 6, tcp.opening 6 } set limit { states 1000, frags 1000 } set loginterface wi0 pass out all keep state label "$nr:$srcaddr:$srcport:$dstaddr:$dstport" block in all fries@ is working on an updated pf.conf(5) discussed at c2k2 and on icb ok dhartmei@, kjell@ | |||
2002-06-24 | Use interface when specified in scrub rule. No support for ! or {} yet. | Daniel Hartmeier | |
2002-06-23 | uid_t and gid_t are unsigned | Theo de Raadt | |
2002-06-22 | document -T option, PR#2766. ok deraadt@ | Jakob Schlyter | |
2002-06-20 | wi_ssid_len is in little-endian as well, so convert it. fixes ssid | Federico G. Schwindt | |
printing on sparc64; millert@ ok. | |||
2002-06-20 | Copy address family from inet/inet6 keyword, if specified. | Daniel Hartmeier | |
2002-06-20 | enable wicontrol on sparc64 as well; deraadt ok. | Federico G. Schwindt | |
2002-06-19 | Since we can no longer count on isprint() to tell us whether or not | Todd C. Miller | |
a character is 7-bit ASCII, check the high bit by hand when deciding whether to print a WEP key as ASCII or hex. | |||
2002-06-19 | "Enabled for Ss" -> "Enabled for D days HH:MM:SS", ok frantzen@ | Daniel Hartmeier | |
2002-06-18 | propogate a '!' when a host resolves to multiple IP addresses | Mike Frantzen | |
ok dhartmei@ | |||
2002-06-18 | don't allow individual keep state rules to specify timeouts for 'interval' and | Mike Frantzen | |
'frag' -- they aren't applied anyway ok dhartmei@ and henning@ | |||
2002-06-17 | only make -g available to root, by disabling setgid kmem; bunch of people ok | Theo de Raadt | |
2002-06-17 | A bit better. Remove debug cruft. | Hakan Olsson | |
2002-06-16 | Rules must in order -> Rules must be in order | Aaron Campbell | |
2002-06-15 | ecn_* policy attributes --- ok ho@ | Angelos D. Keromytis | |
2002-06-15 | Reset rulestate in parse_rules(), so consecutive calls (like from authpf) | Daniel Hartmeier | |
will not fail. Reported by Chris Kuethe. | |||
2002-06-15 | Move ATA SMART defines to atactl. | Grigoriy Orlov | |
No kernel parts use this constants. From Alexander Yurchenko <grange@rt.mipt.ru> | |||
2002-06-15 | Document transparent IPsec. | Angelos D. Keromytis | |
2002-06-14 | spelling; from Brian Poole <raj@cerias.purdue.edu> | Todd T. Fries | |
2002-06-14 | make the output of pfctl -k look nice again | Henning Brauer | |
noticed by pb@ ok dhartmei@ | |||
2002-06-14 | Recognize the ECN_TUNNEL attribute. | Hakan Olsson | |
2002-06-14 | manpage for eui64 | Jun-ichiro itojun Hagino | |
2002-06-14 | add "eui64" option. from ww@styx.org. sync usage with reality. | Jun-ichiro itojun Hagino | |
2002-06-14 | metric and mtu are u_long, not int. | Jun-ichiro itojun Hagino | |
2002-06-13 | Fix the numbering of scrub rules. pointed out and oked by frantzen@ | Kjell Wooding | |
2002-06-12 | this stuff really belongs to stderr, not stdout | Henning Brauer | |
pointed out by ho@ ok dhartmei@, kjell@ | |||
2002-06-12 | Rewrite for pf, plus some other small stuff | Hakan Olsson | |
2002-06-12 | Fix uninitialized access. Spotted by danh@ This is a good reason to | Kjell Wooding | |
develop with "ln -s 'J' /etc/malloc.conf" enabled. ok henning@ | |||
2002-06-12 | Five higher MODP groups, but commented out for now (until IANA assigns | Hakan Olsson | |
them proper numbers). |