Age | Commit message (Collapse) | Author | |
---|---|---|---|
1998-11-25 | typo in comment | Niklas Hallqvist | |
1998-11-25 | Better error code for too large packets | Niklas Hallqvist | |
1998-11-25 | more min vs. ulmin/lmin fixes | Todd C. Miller | |
1998-11-25 | Must use lmin() not min() when comparing longs. Fixes alpha | Todd C. Miller | |
1998-11-25 | typo in diagnostic | Niklas Hallqvist | |
1998-11-25 | Add checks of packets getting to big after transforms. | Niklas Hallqvist | |
Also make sure some more error conditions get told to the caller. | |||
1998-11-25 | Tell caller of error condition | Niklas Hallqvist | |
1998-11-24 | Use our exact size types instead of char/long | Niklas Hallqvist | |
1998-11-18 | 64-bit clean up | Niels Provos | |
1998-11-18 | do not require userland programs to define cpp variables, that is stupid | Theo de Raadt | |
1998-11-18 | indent right | Theo de Raadt | |
1998-11-17 | NewReno, SACK and FACK support for TCP, adapted from code for BSDI | Niels Provos | |
by Hari Balakrishnan (hari@lcs.mit.edu), Tom Henderson (tomh@cs.berkeley.edu) and Venkat Padmanabhan (padmanab@cs.berkeley.edu) as part of the Daedalus research group at the University of California, (http://daedalus.cs.berkeley.edu). [I was able to do this on time spent at the Center for Information Technology Integration (citi.umich.edu)] | |||
1998-11-16 | Please GCC | Niklas Hallqvist | |
1998-11-16 | Break long lines. Use correct format for expiry times | Niklas Hallqvist | |
Present "first use" expirations correctly. | |||
1998-11-16 | SPIs are kept in network byte order | Theo de Raadt | |
1998-11-13 | Recompute ip header length after packet has been reassembled, and also | Niels Provos | |
use the actual header length for m_pullup, pointed out by jdb@es2.net and guido@freebsd.org. | |||
1998-10-28 | - fix three bugs pointed out in Stevens, i.a. updating timestamps correctly | Niels Provos | |
- fix a 4.4bsd-lite2 bug, when tcp options are present the maximum segment size is not updated correctly, so that fast recovery forces out a segment which is split in two segments by tcp_output(), the fix is adpated from FreeBSD, the effective mss is recorded after option negotiation in 3way handshake. [I was able to fix this on time spent at Center for Information Technology Integration (citi.umich.edu)] | |||
1998-10-13 | Remove NULL deref condition | Niklas Hallqvist | |
1998-10-11 | bad ioctls return EINVAL; garath@code.ridgefield.org | Theo de Raadt | |
1998-09-15 | Updated to v3.2.9 of Darren's codebase. His code reimplements variable | pattonme | |
locking, replaces u_long's with u_32_t to properly handle 64bit archs. Wrapped OpenBSD specific preprocessor logic. | |||
1998-09-09 | Make RMD160Update a little less overzealous when fed small crumbs. | janjaap | |
1998-08-02 | cleanup ipsec error handling | Niels Provos | |
1998-08-01 | more careful error handling, some simplification and beautification. | Niels Provos | |
1998-07-30 | fixing a stupid bug I introduced when trying to improve the encryption | Niels Provos | |
performance by avoiding unnecessary copies. There was a problem when two subsequent mbufs were != 0 mod blocksize and the next < blocksize, so we lost the rest of the last mbuf as IV. | |||
1998-07-30 | Forgot this one with the previous batch of commits; use ip4_input() | Angelos D. Keromytis | |
instead of ipip_input() whenever possible, it seems more stable. | |||
1998-07-29 | Proper handling of IP in IP and checksumming. | Angelos D. Keromytis | |
1998-07-29 | Don't do checksumming unless we're doing IP-in-IP. | Angelos D. Keromytis | |
1998-07-03 | wrong endian conversion caused vif stats to be wrong; jonny@jonny.eng.br | Theo de Raadt | |
1998-06-30 | remove unnecessary assignment | Niels Provos | |
1998-06-27 | delete extra KFREE(); d@openbsd.org | Theo de Raadt | |
1998-06-27 | indent | Theo de Raadt | |
1998-06-27 | indent | Theo de Raadt | |
1998-06-27 | Disallow TCP connect() to multicast addresses; cmetz@inner.net | Angelos D. Keromytis | |
1998-06-26 | indent | Theo de Raadt | |
1998-06-11 | indent | Theo de Raadt | |
1998-06-11 | fix a mbuf chain corruption which happened when m_pullup was called on an | Niels Provos | |
mbuf in the middle of the chain and had to MGET a new one. | |||
1998-06-10 | make the packets which were successfully processed by IPSec available to | Niels Provos | |
bpf via the enc0 interface, using linktype DLT_ENC. | |||
1998-06-10 | wasteland quality control cleanup | Theo de Raadt | |
1998-06-10 | New TCPCTL_IDENT sysctl for identd without kmem insanity. | Bob Beck | |
1998-06-03 | request only auth in notify when vpn ipsec route is found with a different | Niels Provos | |
security protocol than IPPROTO_ESP. | |||
1998-06-03 | cleanup debug printfs | Niels Provos | |
1998-06-02 | nbytes - ofs should never be less than 0 (Oops on me) | janjaap | |
1998-05-27 | for icmpbmcastecho, block all of them | Theo de Raadt | |
1998-05-24 | allow SAs with non-specified source address | Niels Provos | |
1998-05-24 | allow the use of blowfish and cast encryption with implicit iv | Niels Provos | |
1998-05-24 | avoid source address spoofing for mutual hostile hosts which have SAs to | Niels Provos | |
us, reported by Craig Metz <cmetz@inner.net>. | |||
1998-05-24 | add support for Virtual Private Networks (VPN). | Niels Provos | |
1998-05-22 | Set the outter IP header's ttl, not the inner. | Angelos D. Keromytis | |
1998-05-19 | Wall for non-IPSEC case | Theo de Raadt | |
1998-05-18 | first step to the setsockopt/getsockopt interface as described in | Niels Provos | |
draft-mcdonald-simple-ipsec-api, kernel notifies (EMT_REQUESTSA) signal userland key management applications when security services are requested. this is only for outgoing connections at the moment, incoming packets are not yet checked against the selected socket policy. |