summaryrefslogtreecommitdiff
path: root/sbin
AgeCommit message (Collapse)Author
2006-04-08Plug simple memory leak. ``Don't forget to free tcpopts when youRay Lai
are done.'' From NetBSD from Coverity CID 2057. OK henning@ and jaredy@
2006-04-08Remove a little bit of dead code; minburst is set to 2 earlier, andRay Lai
cannot be 0. From NetBSD from Coverity CID 577. OK henning@
2006-04-08Memory leak on fork error plus change time variable to preventRay Lai
shadowing time(3) function. From NetBSD from Coverity CID 1688. OK jaredy@ and moritz@
2006-04-07fsck needs to unset FS_FLAGS_UPDATED if it changes the super blockPedro Martelletto
2006-04-06allow lists inside lists for address specs, has been in my tree forHenning Brauer
quite some time... theo likes
2006-04-06if "/etc/rc shutdown" exits 2, attempt powerdown. it does so ifHenning Brauer
rc.shutdown sets powerdown to YES. From: Michele 'mydecay' Marchetto <mydecay@openbeer.it> but didn't apply, so I redid & added comment to clarify ok mickey theo
2006-04-02malloc(x * y) -> calloc(x, y) from adobriyan AT gmail.com, with tweaksDamien Miller
suggested by kjell@; ok otto@ pat@ millert@ jaredy@
2006-04-02use SEEK_* for lseek()Theo de Raadt
2006-04-01Do not attempt to print parameters which turned out to be dead; fixes PR#5066.Miod Vallat
2006-03-31tweaks;Jason McIntyre
2006-03-31Be careful when accessing the external destination address, as it is not setHans-Joerg Hoexer
for bypass and deny flows. Also display acquire/dontacquire flows. ok henning@
2006-03-31wenn dumping rules always show type, srcid and dstid (if set).Hans-Joerg Hoexer
ok reyk@
2006-03-31allow do delete dynamic rulesHans-Joerg Hoexer
ok reyk@
2006-03-31allow specification of encapsulated protocol for ike; ok hshoexerMarkus Friedl
2006-03-31allow specification of encapsulated protocol for flows; ok hshoexerMarkus Friedl
2006-03-31uppercase `ip';Jason McIntyre
2006-03-31Super block changes for FFS2, thanks to all who tested.Pedro Martelletto
Silent okay after almost 3 weeks, hackers@.
2006-03-30when resolving interface names to ip adresses, set netmask to all bits 1Hans-Joerg Hoexer
2006-03-30Print the "Encap" heading only when the sadb is not empty.Hans-Joerg Hoexer
Fix identation (was off by one space). both requested and ok markus@
2006-03-30allow specification of outer local ips in flows (SADB_EXT_ADDRESS_SRC); ok ↵Markus Friedl
hshoexer, reyk
2006-03-30document -encap. ok claudio@Hans-Joerg Hoexer
2006-03-30If an address family is specified do not print IPSec "routes". AdditionallyClaudio Jeker
add a -encap option to show only the IPSec part. OK hshoexer@, henning@
2006-03-30Minor cleanup and start using rmx_refcnt to show the refcount instead of 0.Claudio Jeker
OK henning@
2006-03-30Really ignore sendpipe, recvpipe, rtt, rttvar, etc. in route(8) instead ofClaudio Jeker
passing these values to the kernel where they get ignored anyway. OK henning@
2006-03-30Document 'F' as an answer to fsck, okay deraadt@ jolan@Pedro Martelletto
2006-03-30when asking y or n, accept "F" which forces yes from the on. i haveTheo de Raadt
wished for this for 10+ year, but always forgotten to make the change after cleaning up a nasty file system; ok pedro millert
2006-03-29Use sysctl to get information about encap routes (aka ipsec). NowHans-Joerg Hoexer
you see something actually useful... requested by and ok henning@
2006-03-26fix output of ``ccdconfig -gv'': one typo, and one missing \tAlexander von Gernler
mickey@ ok
2006-03-23Print the lladdr on carp interfaces.Ryan Thomas McBride
ok henning@
2006-03-23Fix pretty-print of carp link addresses by making them print like IFT_ETHER.Ryan Thomas McBride
Diff from jon@abccomm.com
2006-03-23sloppy style to cast the sockaddrs backwards, and then potentially wrong ↵Theo de Raadt
size; ok cloder
2006-03-22earlier asprintf diff caused malloc in signal handler. clarify theTheo de Raadt
code a bit more so that this mistake will not be done again
2006-03-22add support for macros in ipsec.conf(5). some bits have already beenReyk Floeter
there. requested by david@ ok hshoexer@, msf@
2006-03-22No need to specify the DOI, make examples more consistent.Hans-Joerg Hoexer
Suggested by david@
2006-03-21Correctly check for the end of the cmds table. There is no need to check forClaudio Jeker
c_func2. Until now ifconfig accepted something like ifconfig tun0 1.2.3.4 1.2.3.5 foobar without error. Additionally change the error message to a more comprehensible message. OK markus@, henning@
2006-03-21instead of sizeof(array) / sizeof(element) computation, use the existingDaniel Hartmeier
end-of-array NULL marker, shuts up source analysis tool, from deraadt@
2006-03-20NetBSD Coverity CID 2298: Fix memory leak.David Hill
NetBSD Coverity CID 2299: Fix memory leak. NetBSD Coverity CID 2301: Fix memory leak. ok ray@
2006-03-20Don't increment a pointer *before* testing it for NULLDavid Hill
ok deraadt@
2006-03-20NetBSD Coverity CID 2302: Free fat if fatal error to avoid leak.David Hill
ok otto@ deraadt@
2006-03-20NetBSD Coverity CID 774: Don't increment a pointer *before* testing it for NULL!David Hill
ok otto@
2006-03-20NetBSD Coverity CID 2074: Fix memory leak.David Hill
ok deraadt@
2006-03-20NetBSD Coverity CID 1745: Fix memory leak.David Hill
yes otto@
2006-03-20NetBSD Coverity CID 2305: Fix memory leak.David Hill
ok deraadt@
2006-03-20When being verbose while deleting ike rules (-dv), print deletions instead ofHans-Joerg Hoexer
additions. Suggested by david@
2006-03-20When adding a connection, do not explicitly start that connectionHans-Joerg Hoexer
using "t" and "c" fifo commands. This is prone to a race when adding several tunnels between the same peers. Just let isakmpd start that connection on its own (using the connection checker).
2006-03-20make sure the command fifo is ready before isakmpd returns. ThisHans-Joerg Hoexer
resolves a startup race when interacting with ipsecctl. Suggested by and discussed with moritz@ ok moritz@
2006-03-19Fix mem leaks in error path. From NetBSD's coverity analysis. ok pat@Otto Moerbeek
deraadt@
2006-03-17Off-by-one; from NetBSD's coverity analysis; ok millert@Otto Moerbeek
2006-03-16typo.Alexandre Anriot
ok otto@
2006-03-14implement a Unicast Reverse Path Forwarding (uRPF) check for pf(4)Damien Miller
which optionally verifies that a packet is received on the interface that holds the route back to the packet's source address. This makes it an automatic ingress filter, but only when routing is fully symmetric. bugfix feedback claudio@; ok claudio@ and dhartmei@