Age | Commit message (Expand) | Author |
2001-07-04 | call ip_output() correctly, use ICMP_MINLEN, only m_copyback() where needed. ... | Daniel Hartmeier |
2001-07-03 | grr, you guys keep not obeying KNF | Theo de Raadt |
2001-07-03 | add DIOCNATLOOK ioctl and pf_natlook structure, this enables a userland | Bob Beck |
2001-07-02 | another memory leak | Niels Provos |
2001-07-02 | fix memory leak | Niels Provos |
2001-07-01 | -Wall | Dug Song |
2001-07-01 | tag packets generated by pf (return-rst, return-icmp) so they are not filtere... | Daniel Hartmeier |
2001-07-01 | Add port ranges to the rdr directive. Connections can be redirected | Kjell Wooding |
2001-07-01 | for ICMP error messages refering to TCP packets, only use the first 8 bytes o... | Daniel Hartmeier |
2001-06-29 | Prepend pf_ to limit potential namespace problems, shorten some lines. | Niklas Hallqvist |
2001-06-29 | list instead of tailq for frents, use pool hardlimits, correctly free | Niels Provos |
2001-06-28 | lower hiwat limits, enforce hi water mark | Niels Provos |
2001-06-28 | add tree traversal code (new pf_tree_node->parent), dump states TAILQ and tra... | Daniel Hartmeier |
2001-06-28 | wrap 5-tuple rule match with MATCH_TUPLE. from ben fleis <ben@monkey.org> | Dug Song |
2001-06-28 | forgot to init fr_timeout | Niels Provos |
2001-06-28 | first stab at packet normalization. includes full ip reassembly. | Niels Provos |
2001-06-28 | Disallow filter modification when the system is "highly secure". | Hugh Graham |
2001-06-27 | change pf_tree_key->addr[2] from u_int32_t to struct in_addr for Niels | Daniel Hartmeier |
2001-06-27 | in rdr rules, let port 0 be the port wildcard; ok dhartmei@ | jasoni |
2001-06-27 | change pf_tree_node->state to void *, so Niels can use a tree for fragment ha... | Daniel Hartmeier |
2001-06-27 | use proper icmp define | Niels Provos |
2001-06-27 | add -z flag for zeroing statistics. -s status no longer resets anything | Kjell Wooding |
2001-06-27 | add microtime, which seems to have gotten lost. | Kjell Wooding |
2001-06-27 | big KNF | Theo de Raadt |
2001-06-27 | remove unneccessary check in ioctl | Theo de Raadt |
2001-06-27 | typo | Dug Song |
2001-06-27 | for other protocols, keep correct track of match stats | Niels Provos |
2001-06-27 | handle non-TCP/UDP/ICMP protocols | Dug Song |
2001-06-27 | remove print_ip, its unused | Niels Provos |
2001-06-27 | clean up TAILQ usage | Niels Provos |
2001-06-27 | KNF | Niels Provos |
2001-06-27 | only set reason code match if there was a rule that we matched | Niels Provos |
2001-06-26 | update match counts | Niels Provos |
2001-06-26 | name comparison operators | Dug Song |
2001-06-26 | array of counters indexed by reason codes | Theo de Raadt |
2001-06-26 | rules have numbers now, use them. add two spl locks. | Daniel Hartmeier |
2001-06-26 | rule nr is in rule now | Niels Provos |
2001-06-26 | add rule nr for Niels | Daniel Hartmeier |
2001-06-26 | pass rule to logging for state matches | Niels Provos |
2001-06-26 | log-all causes state matches to log packets to pflog | Niels Provos |
2001-06-26 | add rule pointer and log option to states | Daniel Hartmeier |
2001-06-26 | get rid of another printf | Niels Provos |
2001-06-26 | use reasons in pull_hdr, default log if pull_hdr fails. okay deraadt@ | Niels Provos |
2001-06-26 | no longer pass around **m | Theo de Raadt |
2001-06-26 | deal with NULL rule being passed to logging | Niels Provos |
2001-06-26 | fix logging. the ip header is contained in the first mbuf. itojun and me. | Niels Provos |
2001-06-26 | forgot htons | Niels Provos |
2001-06-26 | add a subreason to the link header to allow us to determine why a packet was | Niels Provos |
2001-06-26 | allow 0.0.0.0/x in rules | Peter Stromberg |
2001-06-26 | more suitable error values when DIOCSTART/STOP fail; peters@telia.net | Daniel Hartmeier |