summaryrefslogtreecommitdiff
path: root/usr.sbin
AgeCommit message (Collapse)Author
2004-02-07send filter rules to the RDE on reloads, help & ok claudioHenning Brauer
2004-02-07when connected routes show up at runtime we have to set ifindex in struct kifHenning Brauer
2004-02-07houps, fetchtable() had the default route special cased... bad.Henning Brauer
sin_len == 0 here too.
2004-02-07the sockaddr holding the netmask and advertised by rtm_addrs mightHenning Brauer
mave sa_len == 0 to indicate a mask of /0
2004-02-07sin_family in the sockaddr_n representing the netmask we sniffed on theHenning Brauer
routing socket is meaningless. so we're better off not checking it.
2004-02-06use a struct bgpd_addr for the address token instead of a in_addr, claudio okHenning Brauer
2004-02-06initial cut at the filtering language.Henning Brauer
structs etc to describe a rule, filter rule list management parser groks filter defs now. claudio ok, discussion & help also jakob theo
2004-02-06`numbits' arg to openssl dsaparam does not have to be the last argumentJason McIntyre
specified;
2004-02-05allocate curpeer little earlier.Henning Brauer
there's a rather obscure error path where teh later allocation causes trouble, claudio ok
2004-02-05Don't print two confusing error messages, print a single clear one.Otto Moerbeek
ok deraadt@ hshoexer@ avsm@
2004-02-05error message tuningHenning Brauer
more power!
2004-02-05introduce group IDs. will be needed for filtering (or rather, ease thingsHenning Brauer
there) just assign them from the neighbor ID pool - fortunately, that is rather simple, we just have to make sure that all members of the group and (later) all filter rules pointing to the group agree on the ID, but it does not need to stay the same across config reloads. ok claudio@
2004-02-05plug memory leak; PR3668 Emil Mikulic <emikulic@dmr.ath.cx>Henning Brauer
2004-02-05some small cleanup;Jason McIntyre
ok mcbride@
2004-02-05Add ifstated(8) manpage.Ryan Thomas McBride
2004-02-05Clean up command line options:Ryan Thomas McBride
- Make -v work as intended. - Add -n to test config without doing anything.
2004-02-05Emphasise 'stderr'.Ryan Thomas McBride
ok henning@
2004-02-04Update to ifstated; replace parser, introduce the concept of states,Ryan Thomas McBride
external tests, and boolean logic. Allows ifstated to handle partial failures on firewalls that are CARPd to each other. ok deraadt@
2004-02-04s/transmitts/transmits/Jason McIntyre
from Gavin Atkinson (FreeBSD PR 62346);
2004-02-04Better error message when bpf device open fails.Otto Moerbeek
ok dhartmei@ brad@
2004-02-04Move BGP path attribute handling functions in a own file. henning@ conceptual okClaudio Jeker
2004-02-04Move the update generation into a separate file. The update generation hasClaudio Jeker
nothing to do with the decision process. henning@ "conceptual ok ;-)"
2004-02-04Some more non-alignment problems resolved.Otto Moerbeek
ok deraadt@
2004-02-03replace the previous hack for the internal peer id allocator (which just usedHenning Brauer
the peer's ip address as u_int32_t) by a real id allocator that tries to keep locality high. claudio ok
2004-02-03defer free()ing the previous peer list until after parsing the config fileHenning Brauer
so in the parser we can access it. will be needed soon.
2004-02-03somehow cvs revived this long dead directory, but fgs@ noticedHenning Brauer
2004-02-02close socket on error in control_initHenning Brauer
From: Patrick Latifi <pat@eyeo.org>
2004-02-022 missing returns in error pathesHenning Brauer
From: Patrick Latifi <pat@eyeo.org>
2004-02-02* use macro expansion instead of hardcoding 'buf'.Henning Brauer
From: Patrick Latifi <pat@eyeo.org>, claudio ok
2004-02-02spacesTheo de Raadt
2004-02-02Fix bug in the decision process. The decision process is unable to directlyClaudio Jeker
detect changes of the active prefix. This bug is only triggered when a nexthop changes state. While doing that clarify prefix_move a bit. OK henning@
2004-02-02Somehow I missed this peace in one of my last commits. OK henning@Claudio Jeker
2004-02-02Use correct struct in sizeof for calloc. OK henning@Claudio Jeker
2004-02-02Seal a memory leak and fix a format string, conf->as is unsigned.Claudio Jeker
OK henning@
2004-02-02Do away with non-aligned memory accesses.Otto Moerbeek
ok deraadt@ hshoexer@
2004-02-01pasto, from glukHenning Brauer
2004-02-01Update: document the network statement and update the announce descriptionClaudio Jeker
OK henning@
2004-02-01Set sane default announce types according to the peer type. For IBGP useClaudio Jeker
announce all and for EBGP use announce self. OK henning@
2004-02-01put v6 cruft into session_up() while beeing there... claudio okHenning Brauer
2004-02-01sort openssl rand options;Jason McIntyre
2004-02-01add paper.txt target;Jason McIntyre
2004-02-01add paper.txt target;Jason McIntyre
2004-01-31rename tcp sockopt TCP_SIGNATURE_ENABLE to TCP_MD5SIGHenning Brauer
requested by theo ok markus@ hshoexer@
2004-01-31pkg_create -L support, which I forgot to commit.Marc Espie
-B pkg-destdir, synonymous to -S, and PKG_DESTDIR support.
2004-01-31general cleanup and better SIGCHLD handling from millert@Otto Moerbeek
ok canacar@
2004-01-30in the parse_config() -> merge_config() chain, you shall not nullHenning Brauer
conf->opts that holds some of the command line opts. repairs -n.
2004-01-30missing free() in an error path that should be unreachableHenning Brauer
From: Patrick Latifi <pat@eyeo.org>
2004-01-30please sparc64, with & ok claudioHenning Brauer
2004-01-30-enable md5sig on the listening socketHenning Brauer
-on connections we just accepted, check wether md5sig is configured for that peer, and check wether the connection is md5sig'd too. if not, refuse tested against cisco 7200.
2004-01-29enable tcp md5sig om the connecting socket when md5sig is configured for thatHenning Brauer
peer. I just successfully established an md5sig'd session against a cisco 7200 with that.