Age | Commit message (Collapse) | Author | |
---|---|---|---|
2002-05-22 | strcpy, sprintf death; mpech ok | Theo de Raadt | |
2002-05-22 | remove crud | Theo de Raadt | |
2002-05-20 | raise RTF_HOST for IPv6 /128 destination. from ume | Jun-ichiro itojun Hagino | |
2002-05-19 | KNF | Theo de Raadt | |
2002-05-19 | KNF | Theo de Raadt | |
2002-05-19 | KNF | Theo de Raadt | |
2002-05-19 | nicer usage | Theo de Raadt | |
2002-05-18 | Handle long (unsigned 32-bit) IDs in print_uid/gid(). From Oleg Safiullin. | Daniel Hartmeier | |
2002-05-15 | typo in comment. | Artur Grabowski | |
From Sam Smith S at mSmith.net | |||
2002-05-15 | Kill commented out stubs for swapoff. | Artur Grabowski | |
2002-05-15 | kill the reference to swapoff. | Artur Grabowski | |
2002-05-12 | These small setuid programs allocate a resvport, and then immediately revoke | Theo de Raadt | |
privs. Link them static, so that even less code is run before main does that job. | |||
2002-05-12 | Explain that user/group 'unknown' can only be used with operators = and != | Daniel Hartmeier | |
and refuse other constructs in the parser. Also note that 'user >= 0' does not match forwarded packets with unknown user ID. | |||
2002-05-12 | Add gid based filtering, reduce to one (effective) uid, rename parser | Daniel Hartmeier | |
keywords to 'user' and 'group'. | |||
2002-05-11 | Add missing libraries to bsd.prog.mk (mostly kerberosV) | Marc Espie | |
Use them in DPADD throughout the tree. Fix a few mispells (LIBMATH -> LIBM...) Wipe obsolete lib (LIBRESOLV) Sort added missing libraries, move obsolete stuff apart. Synch documentation in bsd.README ok deraadt@ | |||
2002-05-10 | Use DLT_LOOP instead of DLT_NULL for pcap, to keep track of changes in | Hakan Olsson | |
tcpdump(8). This repairs the '-L' (cleartext packet capture) option. | |||
2002-05-10 | DLT_NULL -> DLT_LOOP | Hakan Olsson | |
2002-05-10 | Handle host name resolution returning multiple addresses in the rule | Daniel Hartmeier | |
parser (expand to every address). ok frantzen@ | |||
2002-05-09 | Add a max-mss option to the scrub rule which will enforce a maximum mss | jasoni | |
by lowering it to the given value. - ok dhartmei@, provos@ | |||
2002-05-09 | Introduce user based filtering. Rules can specify ruid and euid (real and | Daniel Hartmeier | |
effective user ID) much like ports. The user of a packet is either the user that opens an outgoing connection, the one that listens on a socket, or 'unknown' if the firewall is not a connection endpoint (for forwarded connections). Socket uid lookup code from jwk@bug.it. | |||
2002-05-08 | add a newline after pcap error string (as pcap_geterr() doesn't). | jasoni | |
- ok dhartmei@ (a long time ago) | |||
2002-05-06 | Correct info in "-a maxcontig" section. | Todd C. Miller | |
2002-05-06 | Use the default calculation of maxcontig, based on fs_bsize and MAXPHYS, so | Todd C. Miller | |
that the cluster summary information is correct for bsize=4k and MAXPHYS=64k. From NetBSD (mycroft) | |||
2002-05-05 | Instead of returning a useless kernel space pointer for the rule that | Daniel Hartmeier | |
created the state from DIOCGETSTATE(S), return the integer rule number, Print rule number (if existant) from pfctl -vss. Suggested by Jeff Nathan. | |||
2002-04-30 | print usage right | Theo de Raadt | |
2002-04-30 | use scsictl, not scsictl(8); closes pr/2577. | Federico G. Schwindt | |
2002-04-29 | wierd -> weird | Peter Valchev | |
2002-04-26 | Fix typo--2347 should be 2047; from FreeBSD (moses) | Todd C. Miller | |
2002-04-26 | use struct in_aliasreq instead of ifaliasreq when setting new inet | Federico G. Schwindt | |
address. solves a sigbus error seen on sparc64 with new binutils. from itojun@ | |||
2002-04-26 | Mention that just because you can store a 104 bit WEP key on the card | Todd C. Miller | |
doesn't mean the card can actually do 104 bit WEP. | |||
2002-04-25 | sysctl wants size_t. | Marc Espie | |
2002-04-25 | no need for __alignment__, it was paste error. from fgs/deraadt | Jun-ichiro itojun Hagino | |
2002-04-24 | Add dynamic (in-kernel) interface name -> address translation. Instead of | Daniel Hartmeier | |
using just the interface name instead of an address and reloading the rule set whenever the interface changes its address, the interface name can be put in parentheses, and the kernel will keep track of changes and update rules. There is no additional cost for evaluating rules (per packet), the cost occurs when an interface changes address (and the rules are traversed and updated where necessary). | |||
2002-04-23 | fix grammar in tcpdump example | Mike Frantzen | |
2002-04-23 | In mount.h, rename field export -> export_info, to avoid collision with C++. | Marc Espie | |
Synch files that use that field. (This argument is an internal interface specific to OpenBSD, so it won't cause compatibility problems.) (No bump, not an ABI change). ok art, millert... | |||
2002-04-23 | Allow explicit filtering of fragments when they are not reassembled. | Daniel Hartmeier | |
Document fragment handling in the man page. Short version: if you're scrubbing everything (as is recommended, in general), nothing changes. If you want to deal with fragments manually, read the man page. ok frantzen. | |||
2002-04-23 | More up to date. | Hakan Olsson | |
2002-04-22 | Handle configuration lines that end in whitespace or ^M. | Hakan Olsson | |
Also avoid a potential memory leak. | |||
2002-04-21 | Speak English please. | Todd C. Miller | |
2002-04-20 | Build pdisk for mac68k as well. | Miod Vallat | |
2002-04-20 | machine/limits.h is not userland. Use limits.h | Marc Espie | |
ok millert@ | |||
2002-04-19 | Do not depend upon <ansidecl.h> to compile. | Miod Vallat | |
Conforming to espie's evil plans, and ok espie@ tdeval@ | |||
2002-04-19 | Do not commit kbd for arches where it provides no real support. | Miod Vallat | |
While there, remove dead parts. | |||
2002-04-18 | There is no point in embedding an out-of-date copy of <sys/disklabel.h>, | Miod Vallat | |
especially since this manual page refers to said file. ok deraadt@ millert@ | |||
2002-04-18 | use strlcpy | Theo de Raadt | |
2002-04-17 | Reset lineno for each file, so pfctl -R ... -N ... reports the right | Daniel Hartmeier | |
line number for non-first files. Reported by aaron@ | |||
2002-04-15 | Use in_addr_t instead of unsigned long, which breaks on alpha (64-bit). | Daniel Hartmeier | |
Closes PR 2547. Reported by Dries Schellekens. Found by frantzen@. | |||
2002-04-12 | kbd setting code for the installer. kbd needs to be compiled without KVM | Theo de Raadt | |
support. smat@acm.org, miod, and krw. | |||
2002-04-11 | o Document the difference between "open system" and "shared key" auth | Todd C. Miller | |
o IBSS is now port type 4 o Add an explanation of the various port types | |||
2002-04-11 | Accept "ibss" for port type 4 | Todd C. Miller | |