| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
|
|
| |
rdr-to, nat-to, af-to rules. The kernel uses the information from
the packet description and fills it into the fields in the pflog
header. While doing this, it is trival to figure out whether the
packet has been rewritten.
OK sashan@
|
| |
|
|
|
|
|
|
|
|
|
|
| |
There's not reason to build without IPv6 support, `-U INET6' builds were
broken anyway.
Fix an empty redefine for IPPROTO_IPV6 in print-ip.c while here.
No object change on amd64 and sparc64 with clang, gcc compiles differently
but behaviour stays the same.
OK denis deraadt
|
| |
|
|
|
|
| |
#ifdef _KERNEL, so it does not work automatically. This prevents
some bogus uid and pid print when dumping from pflog interface.
from Matthias Pitzl; OK deraadt@
|
| | |
|
| |
|
|
| |
removal from mbuf.h. ok mpi@
|
| |
|
|
| |
ok deraadt@
|
| |
|
|
|
| |
delete <sys/param.h> if now possible
ok guenther
|
| |
|
|
|
|
|
|
|
| |
possible. Annotate <sys/param.h> lines with their current reasons. Switch
to PATH_MAX, NGROUPS_MAX, HOST_NAME_MAX+1, LOGIN_NAME_MAX, etc. Change
MIN() and MAX() to local definitions of MINIMUM() and MAXIMUM() where
sensible to avoid pulling in the pollution. These are the files confirmed
through binary verification.
ok guenther, millert, doug (helped with the verification protocol)
|
| | |
|
| |
|
|
| |
OK mcbride@
|
| |
|
|
|
| |
to 8-byte boundary on 64-bit architectures. Instead explicitly round up
to a 4-byte boundary. Reported and tested by sthen@
|
| |
|
|
| |
addresses/ports too. ok ryan dlg
|
| |
|
|
| |
ok ryan theo & herr reyksminister
|
| |
|
|
|
|
|
| |
unmaintainable). these days, people use source. these id's do not provide
any benefit, and do hurt the small install media
(the 33,000 line diff is essentially mechanical)
ok with the idea millert, ok dms
|
| | |
|
| | |
|
| | |
|
| |
|
|
|
|
|
|
|
| |
inserted the rule which causes the logging. secondly, the uid/pid of the
process in case the logged packet is delivered to/from a local socket.
a lookup of the local socket can be forced for logged packets with a new
option, 'log (user)'. make tcpdump print the additional information when
-e and -v is used. note: this changes the pflog header struct, rebuild all
dependancies. ok bob@, henning@.
|
| |
|
|
|
| |
when irrelevant. print 'def' for default rule. omit numerical reason if
description is printed. ok henning@, deraadt@
|
| | |
|
| |
|
|
|
|
| |
old datalink type is still recognized.
ok henning@ dhartmei@ frantzen@
|
| |
|
|
| |
debugging session with and ok'd by dhartmei@
|
| |
|
|
|
|
| |
dropped, others may as well in the future).
ok dhartmei@ henning@
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
|