summaryrefslogtreecommitdiff
path: root/share/man
AgeCommit message (Collapse)Author
2009-04-06rewrite the description for the recently added "match" action.Igor Sobrado
ok henning@
2009-04-06no more normalization statements, remove it from require-order description.Stuart Henderson
ok henning
2009-04-06documentation changes related with the monster pf diff from basel;Igor Sobrado
we are mostly documenting that fragment reassembly has nothing to do with scrubbing anymore; there is room for a lot of improvements yet. "commit it and we work on it in-tree. it is certainly well, better than what there is now" henning@
2009-04-06Adapt PF rule to new scrub syntax.Antoine Jacoutot
input from and ok henning@
2009-04-061) scrub rules are completely gone.Henning Brauer
2) packet reassembly: only one method remains, full reassembly. crop and drop-ovl are gone. . set reassemble yes|no [no-df] if no-df is given fragments (and only fragments!) with the df bit set have it cleared before entering the fragment cache, and thus the reassembled packet doesn't have df set either. it does NOT touch non-fragmented packets. 3) regular rules can have scrub options. . pass scrub(no-df, min-ttl 64, max-mss 1400, set-tos lowdelay) . match scrub(reassemble tcp, random-id) of course all options are optional. the individual options still do what they used to do on scrub rules, but everything is stateful now. 4) match rules "match" is a new action, just like pass and block are, and can be used like they do. opposed to pass or block, they do NOT change the pass/block state of a packet. i. e. . pass . match passes the packet, and . block . match blocks it. Every time (!) a match rule matches, i. e. not only when it is the last matching rule, the following actions are set: -queue assignment. can be overwritten later, the last rule that set a queue wins. note how this is different from the last matching rule wins, if the last matching rule has no queue assignments and the second last matching rule was a match rule with queue assignments, these assignments are taken. -rtable assignments. works the same as queue assignments. -set-tos, min-ttl, max-mss, no-df, random-id, reassemble tcp, all work like the above -logging. every matching rule causes the packet to be logged. this means a single packet can get logged more than once (think multiple log interfaces with different receivers, like pflogd and spamlogd) . almost entirely hacked at n2k9 in basel, could not be committed close to release. this really should have been multiple diffs, but splitting them now is not feasible any more. input from mcbride and dlg, and frantzen about the fragment handling. speedup around 7% for the common case, the more the more scrub rules were in use. manpage not up to date, being worked on.
2009-04-06- tweak for recent gnome.port.mk changesAntoine Jacoutot
ok jasper@
2009-04-05In the previous commit, i confused "any" and "all".Ingo Schwarze
Fix prodded and checked by jmc@, thanks.
2009-04-05/usr/X11R6/lib/xserver is more or less replaced by /usr/X11R6/lib/xorg.Matthieu Herrb
Pointed by jmc@.
2009-04-05regen;Jason McIntyre
2009-04-04Do not run make in /var/yp at the end of ypinit -m.Ingo Schwarze
That way, you can edit the new domain Makefile before using it, in particular to change variables like DIR and UNSECURE. from ajacoutot@ with message tweaks and documentation updates by myself "I like this" otto@
2009-04-02Anchor names with characters after the terminating null byte are invalid.Stuart Henderson
ok jmc@
2009-04-02tweak previous;Jason McIntyre
2009-04-01Give some hints about debugging live kernels with gdb(1).Mark Kettenis
2009-04-01Add raid 6 and 60Marco Peereboom
2009-03-31document the changes to the route filter API. basically:David Gwynne
-ROUTE_SETFILTER(rtfilter, RTM_IFINFO); -ROUTE_SETFILTER(rtfilter, RTM_IFANNOUNCE); +rtfilter = ROUTE_FILTER(RTM_IFINFO) | + ROUTE_FILTER(RTM_IFANNOUNCE); poked by claudio@
2009-03-30sort the hardware list; from bradJason McIntyre
2009-03-30document new versions supportedTheo de Raadt
2009-03-28Add a bunch more run devices.Jonathan Gray
2009-03-28Add "Chen-Source CM12402 Eagle IR Cam" to the supported device list.Marcus Glocker
Reported by Kenji Aoyama
2009-03-27Match on EW-7717Un, EW-7718UnJonathan Gray
2009-03-27Match on Edimax EW-7318Ug, EW-7318USg, EW-7618UgJonathan Gray
2009-03-27some more devices which should workJonathan Gray
2009-03-27Add support for the BCM5825 and the next-generation BCM5860, 5861,Reyk Floeter
5862 Broadcom CryptoNetX IPSec/SSL Security Processors. The 5825 is a faster version of the already supported 5823, and the even faster 586x series is a bit different and needed some more changes. The RNG engine on the 586x is not supported yet but I hope to fix it soon... ubsec0 at pci4 dev 0 function 0 "Broadcom 5862" rev 0x01: 3DES MD5 SHA1 AES PK, apic 10 int 10 (irq 11) tested by phessler@ and me ok deraadt@
2009-03-27zap trailing whitespace; from grunkJason McIntyre
2009-03-27Match on ASUS USB-N11Jonathan Gray
2009-03-27D-Link DWA-140 is one of the D-Link ids already in the driver.Jonathan Gray
2009-03-27getgrouplist: If YP is #defined and enabled in /etc/group(5) and /etc/netid(5)Ingo Schwarze
contains a matching entry, use that and refrain from accessing YP. getpwnam/getpwuid: If YP is #defined and /etc/master.passwd(5) contains a matching entry before the first YP entry, use that and stay away from YP. Taken together, this allows a solution to the following problem pointed out by deraadt@: When YP was configured but temporarily unavailable, even root login would block, hindering you when trying to do repairs. To avoid this, you can now provide a static entry for root in /etc/netid. Using suggestions from miod@ otto@ blambert@ jmc@. "commit" deraadt@, "cool" ajacoutot@, "looks fine" jmc@.
2009-03-27Sitecom WL-603 should work according to linux driverJonathan Gray
2009-03-27Linksys WUSB200 should work according to linux driverJonathan Gray
2009-03-27Add a bunch of GW3887/v2 based upgt devices found in linux driver.Jonathan Gray
ok mglocker@
2009-03-26attach CACE AirPcap Nx.Damien Bergamini
2009-03-25Remove LK_SLEEPFAILOwain Ainsworth
2009-03-25Add support for the watchdog timer.Michael Knudsen
``just have the balls and commit it'' deraadt
2009-03-25sdmmc(4) is not an SD host controller.Michael Knudsen
Input from deraadt, grange, and kettenis.
2009-03-25RegenMiod Vallat
2009-03-25add new umsm(4) device. Emobile D21LC (longcheer's OEM product)Yojiro Uo
ok jsg@, fgsch@
2009-03-25punctuation must be space separated here;Jason McIntyre
2009-03-25add support for AES-CBC with the BCM5823 (or newer, but we don't support newerReyk Floeter
variants yet). ok deraadt@ dlg@
2009-03-25clarify wording of examples for subpackages, pointed out by Lajos BoróczkiStuart Henderson
2009-03-25Lying is bad, so stop lying about functionality that was removed agesOwain Ainsworth
ago. ok blambert (who had a similar diff a few days ago)
2009-03-24link to newish firmware package (3.1).Damien Bergamini
i have absolutely no idea what this new firmware is supposed to fix. actually, even the Intel people have no idea according to this thread: http://marc.info/?l=linux-wireless&m=123791786426974&w=2
2009-03-24AR9101 is MIMO 1x2, not 1x1.Damien Bergamini
2009-03-24fix a few typographical errors.Igor Sobrado
ok jmc@
2009-03-24Document that due to bioctl limitations ips associate all unused andAlexander Yurchenko
spare drive with the first volume but the drives can be used for rebuilding any degraded volume. ok jmc@
2009-03-23Xr otus(4)Theo de Raadt
2009-03-23otus(4), a driver for Atheros AR9001U USB IEEE 802.11 devices.Damien Bergamini
more work is required but basic operations work. requires a non-free firmware to operate. partly based on source code released under the ISC by Atheros Communications for Linux, although I had to rewrite almost everything (actually I only used some .h files from the Atheros driver.) there also exists a rewrite of the Atheros driver for Linux (ar9170) but the guy decided to make the code less free by wrapping the GPL around the ISC. committed over a NETGEAR WNDA3100. ok deraadt@
2009-03-23some smtpd bits; ok jacekm gillesJason McIntyre
2009-03-22Mention that msk(4) support 88E807x chips now.Mark Kettenis
2009-03-22tweaks;Jason McIntyre
2009-03-19comment out some macros until they are needed;Jason McIntyre