Age | Commit message (Collapse) | Author | |
---|---|---|---|
2017-08-13 | don't issue a termination command to an already stopped vm | Jasper Lievisse Adriaanse | |
ok mlarkin@ | |||
2017-08-13 | bypass the filter code for incoming smtp sessions. | Eric Faurot | |
experimental support for filters has been removed from the config parser already, and we want to get rid of the remaining code. ok gilles@ | |||
2017-08-13 | The impossibility has been impossible since an impossible long | Florian Obser | |
time. And indeed it is impossible to arrive here with something other than a ND_OPT_PREFIX_INFORMATION. Remove #if 0'ed block. | |||
2017-08-12 | fix the else case (i.e. LSA_IS_SCOPE_AS) where header could remain | Sebastian Benoit | |
uninitialized. found by clang. ok claudio@ | |||
2017-08-12 | vmd: bump virtio queue size back to 128. The problem that resulted in | Mike Larkin | |
lowering the queue size to 64 was caused by something unrelated. | |||
2017-08-12 | Add manpage update for new grouping feature '{from,to} {i,e}bgp' | job | |
OK phessler@ | |||
2017-08-12 | allow filter rules to be written that affect ibgp or ebgp neighbors | Peter Hessler | |
discussed with henning@ OK claudio@, benno@, job@ | |||
2017-08-12 | Make not yet implemented pledges more visible in grep output. | Florian Obser | |
input benno, deraadt, tedu also standardize on #if 0 since it makes tedu's editor vomit. OK benno, pirofti on a previous version | |||
2017-08-12 | bring ospf6d's log.c in sync with ospfd and bgpd | Sebastian Benoit | |
ok florian@ claudio@ | |||
2017-08-12 | update to unbound 1.6.4, ok florian@ | Stuart Henderson | |
2017-08-12 | add a new option to set limits on max-sessions each IPCP. | Kazuya Goda | |
It can set limits on different max-sessions if there're using several protocols such as PPPoE and L2TP/IPsec. ok yasuoka@ | |||
2012-03-26 | Import Unbound 1.4.16 to work on in-tree (not yet linked to the build). | Stuart Henderson | |
These are the direct sources from NLnet Labs upstream, minus these: compat contrib libunbound/python pythonmod testcode testdata winrc ok deraadt@ jakob@ | |||
2017-08-12 | No need to constantly re-open a socket. Just open it up front and keep | Florian Obser | |
it around. OK jca | |||
2017-08-12 | Initial pledge for snmpd. snmpe remains unpledged. Regression tests pass. | rob | |
Ok benno@, jca@. | |||
2017-08-12 | stop pretending that qnames are always strings. treat everything as a | Ted Unangst | |
dname always. | |||
2017-08-11 | punctuation; | Jason McIntyre | |
2017-08-11 | zero out sockaddr_in before use; fixes use of stack garbage as port number | Christian Weisgerber | |
in "query from"; ok phessler@ job@ | |||
2017-08-11 | Convert httpd to tls_config_set_ecdhecurves(), allowing a list of curves | Joel Sing | |
to be specified, rather than a single curve. ok beck@ | |||
2017-08-11 | add a new option to set limits on user-max-sessions each AUTHENTICATION. | Kazuya Goda | |
It can set limits on different user-max-sessions if there're using several protocols such as PPPoE and L2TP/IPsec. ok yasuoka@ | |||
2017-08-11 | Use vmd's process rdomain via getrtable() instead of 0 by default. | Reyk Floeter | |
This allows to run "route -T 1 exec vmd" to get rdomain 1 tap(4) and bridge interfaces by default. ok mlarkin@ | |||
2017-08-11 | display MRU each sessions in npppctl session command | Kazuya Goda | |
ok yasuoka@ | |||
2017-08-11 | softreconfig in and out are on by default for ever and machines now have | Claudio Jeker | |
enough memory that it does not make sense to provide these knobs anymore. They just make the code more complex for no much gain. OK phessler@, benno@ | |||
2017-08-11 | missed in previous | Florian Obser | |
2017-08-11 | regen | Florian Obser | |
2017-08-11 | update to 4.1.17 | Florian Obser | |
OK sthen | |||
2017-08-10 | naddy@ reported confusion on why "query from" seemed to be ignored in | job | |
some cases. OK naddy@ henning@ | |||
2017-08-10 | don't have cu try to open '/dev', instead check if there's a valid tty | Jasper Lievisse Adriaanse | |
associated with the vm upfront as discussed with and ok mlarkin@ pd@ | |||
2017-08-10 | No need to handle multiple routing messages here. | Jeremie Courreges-Anglas | |
route(4) sockets only ever ship a single routing message per read(2) call, so simplify this. Mostly mechanical diff for now, some further cleanups will follow. ok rob@ florian@ | |||
2017-08-10 | vmd: partially back out a change committed yesterday regarding guest | Mike Larkin | |
changing IRQs. After discussing with kettenis, that wasn't the right way to do things, and this diff fixes that. ok kettenis | |||
2017-08-10 | whitespace | Mike Larkin | |
2017-08-10 | Pledge snmpctl. Ok jca@, tb@ | rob | |
2017-08-10 | Fix a comment and line length. Noted by Dennis fondras. | Sebastian Benoit | |
ok benno@ | |||
2017-08-10 | replace memcpy() with assignements where the type is the same. | Sebastian Benoit | |
noticed by deraadt@, ok claudio@ | |||
2017-08-10 | handle extended communities in bgpctl. | Sebastian Benoit | |
From Dennis Fondras, thanks! ok phessler@ | |||
2017-08-09 | vmd: allow guest PCI interrupt line reassignment. | Mike Larkin | |
I also added a couple config space register names to pcireg.h to try and reduce the use of magic numbers in vmd/pci.c ok pd@ | |||
2017-08-09 | Use X509_pubkey_digest() like libtls to hash the keys for the TLS privsep | Claudio Jeker | |
code. This fixes interception mode (since there we rewrite the CERT which would alter the hash of the cert but the keys still remain the same). OK bluhm@ and jsing@ | |||
2017-08-09 | Call tls_config_skip_private_key_check() to disable the key checking in | Claudio Jeker | |
the inspect case (same is done in the regular server mode). OK bluhm@ and jsing@ | |||
2017-08-09 | the recent adjustment of -i means usage() fits nicely on | Jason McIntyre | |
two lines now, instead of three; | |||
2017-08-09 | Remove knob and always do neighbor unreachable detection. | Florian Obser | |
2017-08-09 | accept_rtadv doesn't do anything since some time. | Florian Obser | |
OK mpi | |||
2017-08-09 | add mail.mda MDA in charge of running a third-party MDA, not linked yet | Gilles Chehade | |
2017-08-09 | at the exception of mail.local, smtpd never executes an MDA as root. | Gilles Chehade | |
the check is performed daemon-side before even forking the child process, but let's also check euid in the mda we ship in case someone executes them by hand and needs to see an explicit error message. | |||
2017-08-08 | Kernel sendsyslog(2), libc syslog(3), and syslogd(8) restrict and | Alexander Bluhm | |
truncate the length of a syslog message to 8192 bytes. Use one global define LOG_MAXLINE for all of them. OK deraadt@ millert@ | |||
2017-08-08 | Use configtest as one word like other network daemon man pages. | rob | |
Ok benno@, jmc@ | |||
2017-08-08 | Consistent use of log.c, and removal of err.h include. Makes ifstated | rob | |
configtest output the same as other networking daemons. Ok jca@ | |||
2017-08-08 | Do not forget to reschedule the timer when we receive a new prefix. | Jeremie Courreges-Anglas | |
This way the new prefix can be advertized asap. ok florian@ | |||
2017-08-06 | Improve error checking during processing of routing messages. Handling of | rob | |
RTM_DESYNC encouraged by deraadt. ok jca@ benno@ | |||
2017-08-06 | packet.c and parse.y no longer require err.h. ok jca@ florian@ | rob | |
2017-08-06 | Remove comma from last element since that is the terminator. | Claudio Jeker | |
2017-08-06 | add a zeroed out element at the end of the iana_ext_comms array, so | Sebastian Benoit | |
that the iteration over it actually stops. ok and feedback from florian@ phessler@ and claudio@ |