Tom Eastep
0fa027802f
Don't allow accounting or manual changes to have the name of a builtin target
2011-02-14 10:50:04 -08:00
Tom Eastep
e67d8e6402
Document optimizer fix
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-14 10:30:18 -08:00
Tom Eastep
3b7232a5fa
Fix a bug in the optimizer
2011-02-14 10:00:28 -08:00
Tom Eastep
59e361e93e
Split the 'restriction' member into two members
2011-02-14 09:22:27 -08:00
Tom Eastep
e64070f9e1
Restore loop detection in sectioned accounting rules
2011-02-13 16:38:01 -08:00
Tom Eastep
dd81eedb42
Fix another accounting sectioning bug
2011-02-13 14:32:11 -08:00
Tom Eastep
46a99a7cd9
Correct Config.pm version again
2011-02-13 11:46:56 -08:00
Tom Eastep
567824b7e2
Correct Config.pm version
2011-02-13 11:45:46 -08:00
Tom Eastep
983f6a231e
Version to Beta 2
2011-02-13 11:43:37 -08:00
Tom Eastep
95f8100696
Cosmetic change
2011-02-13 11:34:53 -08:00
Tom Eastep
b1abb3f554
Don't do unref/loop detection when accounting file is sectioned
2011-02-13 11:13:43 -08:00
Tom Eastep
e9b2013f91
Document fix for IPv6 providers
2011-02-13 10:52:59 -08:00
Tom Eastep
a1eefea224
Fix FORWARD chain jumps with sectioning
2011-02-13 08:23:48 -08:00
Tom Eastep
1438332bbe
Remove hard-coded 0.0.0.0/0 from Providers.pm
2011-02-13 08:13:22 -08:00
Tom Eastep
5c0b592934
Section the accounting file
2011-02-12 12:47:15 -08:00
Tom Eastep
195903444d
Insist that SECTION headers have exactly two columns
2011-02-12 07:54:20 -08:00
Tom Eastep
677bd08d5d
Add more targets
2011-02-11 17:13:48 -08:00
Tom Eastep
4acdc5314a
Add 'NG' value for ACCOUNTING
2011-02-11 17:01:10 -08:00
Tom Eastep
9e921beb49
Fix a tri-value bug
2011-02-11 16:53:49 -08:00
Tom Eastep
af363888ab
Alphabetize the builtin target list
2011-02-10 16:55:04 -08:00
Tom Eastep
64614b7464
Add CLASSIFY to the builtin targets
2011-02-10 16:46:44 -08:00
Tom Eastep
2885081d86
Add more keywords to %builtin_targets
2011-02-10 13:11:58 -08:00
Tom Eastep
a3232516bb
Detect loops in accounting chain jumps
2011-02-09 15:43:19 -08:00
Tom Eastep
88244dc132
Don't allow MAC addresses in the accounting file
2011-02-07 17:12:43 -08:00
Tom Eastep
b4b59119ef
Don't allow non-accounting chain in the CHAIN accounting column
2011-02-07 16:32:38 -08:00
Tom Eastep
6e66736d28
Make IPv6 logic safer; cosmetic improvements in the generated script
2011-02-06 08:57:48 -08:00
Tom Eastep
2c2fdab0fe
Rename USE_LOCAL_MODULES to EXPORTMODULES
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-06 08:42:35 -08:00
Tom Eastep
44f7a4daf3
Update release docs for USE_LOCAL_MODULES -> EXPORTMODULES rename
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-06 08:41:29 -08:00
Tom Eastep
2b8579c090
Tweak USE_LOCAL_MODULES change
...
Make the "Other than /usr/share" test dependent on export
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-06 08:28:10 -08:00
Tom Eastep
946602bc1c
Modules file breakup for IPv6
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-06 08:15:50 -08:00
Tom Eastep
106f23634c
Make use of USE_LOCAL_MODULES independent of export
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-06 08:15:16 -08:00
Tom Eastep
ca23069f56
Tweak release notes
2011-02-05 18:10:34 -08:00
Tom Eastep
e74ae3b9e1
Document the first stage of modules breakup
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-05 17:58:17 -08:00
Tom Eastep
d99df29995
Fix some modules bugs
2011-02-05 17:43:00 -08:00
Tom Eastep
7a462d3ed5
Correct install file
2011-02-05 17:34:28 -08:00
Tom Eastep
6a078b9cda
Install modules.* files
2011-02-05 17:25:44 -08:00
Tom Eastep
88bce4100a
Initiate 4.4.18
2011-02-05 16:41:34 -08:00
Tom Eastep
92d5ed3824
Add note about file security to the release notes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-05 16:23:24 -08:00
Tom Eastep
cb0fbe8e51
Break up modules file
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-05 16:13:06 -08:00
Tom Eastep
06803b6e5f
Properly secure helper and modules files
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-02-05 16:12:43 -08:00
Tom Eastep
68ccac08cd
Add sch_tbf to modules and add several modles to the Shorewall6 modules file
2011-02-04 10:46:40 -08:00
Tom Eastep
c557ec3740
Bump version of Tc module
2011-02-04 07:46:35 -08:00
Tom Eastep
ea2c72d1b1
Prepare for 4.4.17
2011-02-04 06:44:02 -08:00
Tom Eastep
838c7ac57b
Change a comment
2011-02-03 17:22:04 -08:00
Tom Eastep
475b811171
Document accounting fixes
2011-02-03 09:57:59 -08:00
Tom Eastep
23eef3b215
Normalize IPv6 addresses in decompose_net
2011-02-03 09:57:47 -08:00
Tom Eastep
4ed4443abb
Do a fancier job of comparing networks
2011-02-03 09:44:46 -08:00
Tom Eastep
27684908c4
Catch mis-matched nets in per-IP accounting rules
2011-02-03 09:25:13 -08:00
Tom Eastep
d68d40ee1c
Correct an optimization bug involving empty/unreferenced chains
2011-02-03 09:12:50 -08:00
Tom Eastep
98ad7e15b0
Don't optimize the accounting chain
2011-02-03 08:45:54 -08:00
Tom Eastep
9d9c6c4a99
Document complex TC fixes
2011-02-03 08:37:19 -08:00
Tom Eastep
953c0b48de
Fix several issues with IPv6 tcfilters
2011-02-03 08:28:00 -08:00
Tom Eastep
27a2b32e9e
Update release notes
2011-02-02 10:46:47 -08:00
Tom Eastep
ff48a78eac
Rename 'ipaccount' to 'ipa'
2011-02-01 17:15:49 -08:00
Tom Eastep
2ef674dc40
Add 'show iptaccount' command
2011-02-01 16:47:20 -08:00
Tom Eastep
207db033b8
Disallow '.' in accounting and manual chain names
2011-02-01 12:58:05 -08:00
Tom Eastep
4e7f656a5b
Better ACCOUNT(...) parsing
2011-01-31 20:17:56 -08:00
Tom Eastep
f8e6c80ca0
Tighen up editing of ACCOUNT(...)
2011-01-31 10:14:10 -08:00
Tom Eastep
ae4d675d0d
Document chain name length restriction
2011-01-31 07:07:10 -08:00
Tom Eastep
fbdd4b5ede
Ensure that accounting and manual chains aren't too long
2011-01-31 06:56:38 -08:00
Tom Eastep
87d628e23d
Add OpenSuSE 11.3 to distros tested with per-IP accounting
2011-01-31 06:56:12 -08:00
Tom Eastep
ca73bd4846
Correct release notes statement about Lenny
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-30 16:20:59 -08:00
Tom Eastep
a026ffabe1
Add iptaccount -l example with output
2011-01-30 14:04:26 -08:00
Tom Eastep
5f76de3bda
Fix Config version
2011-01-30 12:35:31 -08:00
Tom Eastep
6fc8152464
Update version to RC 1
2011-01-30 11:30:45 -08:00
Tom Eastep
29966ea353
Reword a comment in the release notes
2011-01-30 11:27:56 -08:00
Tom Eastep
beab8fc481
Mention the iptaccount --help command
2011-01-30 10:47:25 -08:00
Tom Eastep
303afe8c7e
Some accounting fixes (code and docs)
2011-01-30 09:39:14 -08:00
Tom Eastep
b1f6895a1f
Correct a couple of versions
2011-01-30 08:41:33 -08:00
Tom Eastep
26cea4336e
Document per-IP accounting
2011-01-30 08:33:06 -08:00
Tom Eastep
70fc8bdfb6
Add support for per-IP accounting
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-30 07:20:05 -08:00
Tom Eastep
4cc8e5422d
Add ACCOUNT target detection
2011-01-30 07:14:08 -08:00
Tom Eastep
4a040135e5
Document module loading defect corrections
2011-01-29 12:50:44 -08:00
Tom Eastep
1c48a9dbd3
Fix a couple of defects in module loading
2011-01-29 12:42:22 -08:00
Tom Eastep
7555a0953d
Add conditional logic for optional run-time address variables
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-29 12:15:34 -08:00
Tom Eastep
47cdbd04db
Fix typo in release file
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-29 09:21:14 -08:00
Tom Eastep
ce5e218195
Document fix for IPv6 address scanning
2011-01-29 09:05:07 -08:00
Tom Eastep
1b87405d96
Fix silly bug in expand_rule()
2011-01-29 08:45:20 -08:00
Tom Eastep
a391916236
Correct typos in the release notes
2011-01-29 08:42:58 -08:00
Tom Eastep
ab39b977e0
Version to Beta 3
2011-01-28 16:52:22 -08:00
Tom Eastep
7421a679ba
Bump version of the Nat module
2011-01-28 16:46:36 -08:00
Tom Eastep
f3aedcf805
Allow runtime address variables in the ADDRESS column of the masq file
2011-01-28 16:32:53 -08:00
Tom Eastep
156b04c380
Implement Run-time Address Variables
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-26 09:08:48 -08:00
Tom Eastep
82913abeca
Specify 'mpu' when creating TBF
2011-01-23 09:23:17 -08:00
Tom Eastep
a2b440b093
Add USE_LOCAL_MODULES option
2011-01-22 08:13:17 -08:00
Tom Eastep
cf02781461
Document fix to modules file - take 2
2011-01-21 16:20:38 -08:00
Tom Eastep
a5f027a2a0
Document fix to modules file
2011-01-21 16:20:21 -08:00
Tom Eastep
9b7b39ca52
Add sch_prio to modules file
2011-01-21 16:10:59 -08:00
Tom Eastep
c0d5a32d11
Fix typo in alignment patch
2011-01-21 06:56:30 -08:00
Tom Eastep
3a5d664305
Fix 'check -r' output when OPTIMIZE=8 or OPTIMIZE=9
2011-01-21 06:52:58 -08:00
Tom Eastep
20cd9848f6
Align some assignments in the Config Module
2011-01-21 06:51:35 -08:00
Tom Eastep
24412c9498
Fix empty variable handling when /bin/sh is bash
2011-01-20 08:19:42 -08:00
Tom Eastep
878e5d66ae
Document fix for empty shell variables with bash
2011-01-20 08:19:05 -08:00
Tom Eastep
e21e8c0576
Move fix description to proper beta release
2011-01-20 07:18:27 -08:00
Tom Eastep
9d06125129
Bump Version to Beta 2
2011-01-19 15:38:51 -08:00
Tom Eastep
d5f3b31032
Handle lines containing only 'INCLUDE'
2011-01-18 14:58:56 -08:00
Tom Eastep
cdd897e620
More tweaks to the release notes
2011-01-17 09:03:34 -08:00
Tom Eastep
8cd903fad0
Reword sentence in the release notes
2011-01-17 08:07:21 -08:00
Tom Eastep
b7733941fa
Update release documents with updaterc.d fix
2011-01-17 07:57:18 -08:00
Tom Eastep
e9b3cd5b57
Run updaterc.d out of uninstall on Debian-based systems
2011-01-16 13:09:02 -08:00
Tom Eastep
cbb27662b9
Correct inconsistent terminology in Release Notes
2011-01-16 10:22:15 -08:00
Tom Eastep
eaa08ab76f
Fix typo that broke ULOG
2011-01-16 09:45:49 -08:00
Tom Eastep
e8bedcae93
Update release notes
2011-01-16 09:45:37 -08:00
Tom Eastep
3074d3009f
Tom being anal
2011-01-15 20:59:59 -08:00
Tom Eastep
4ea02a5e72
Eliminate silly duplication
2011-01-15 19:20:24 -08:00
Tom Eastep
370cd04408
Remove unneeded line of code in export_params()
2011-01-15 15:56:37 -08:00
Tom Eastep
265ca85d02
Allow INCLUDE in extension scripts
2011-01-15 15:43:45 -08:00
Tom Eastep
5c4da0b581
Use open_file()/close_file() in copy1
2011-01-15 14:33:16 -08:00
Tom Eastep
978e8e3849
Only issue 'done.' progress message on success
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-14 11:46:38 -08:00
Tom Eastep
12eaf81dcc
Add some comments
2011-01-13 19:59:17 -08:00
Tom Eastep
8da9f4183a
Tweaks to 4.4.17
2011-01-10 19:35:45 -08:00
Tom Eastep
2be63c9406
Delete unneeded exports
2011-01-10 19:30:38 -08:00
Tom Eastep
10ae1c7dde
Don't export read_a_line1()
2011-01-10 19:14:10 -08:00
Tom Eastep
a04e854f21
Simplify exception processing in process_rules1()
2011-01-10 17:02:12 -08:00
Tom Eastep
fd6afa7742
Minor fixes to comments
2011-01-09 15:56:01 -08:00
Tom Eastep
3392312cef
Automate the maintenance of the hash of compiler-defined entries in %params
2011-01-09 13:12:36 -08:00
Tom Eastep
0dc4cd7937
Don't quote param values unnecessarily; add a comment to the emitted params
2011-01-09 12:14:48 -08:00
Tom Eastep
3bb67423c3
Tweak release notes
2011-01-09 11:31:38 -08:00
Tom Eastep
08f09d7de0
Deprecate EXPORTPARAMS
2011-01-09 10:12:36 -08:00
Tom Eastep
14c4bd99aa
Don't lookup standard target if target is an action, macro, or chain
2011-01-09 10:10:27 -08:00
Tom Eastep
97bba29c07
Add lookup hash for standard targets
2011-01-08 15:29:10 -08:00
Tom Eastep
8dc60e788f
Avoid early return in process_action()
2011-01-08 14:05:27 -08:00
Tom Eastep
6143c7ddbd
Improve readability of logging logic in expand_rule()
2011-01-08 09:07:32 -08:00
Tom Eastep
bdbc9ab29d
Initiate 4.4.17
2011-01-08 08:00:56 -08:00
Tom Eastep
ad57272c7f
Fix tag handling in Limit()
2011-01-05 17:21:50 -08:00
Tom Eastep
974aeb9e39
Reword a comment
2011-01-03 18:48:09 -08:00
Tom Eastep
e3c16b8233
Different way to catch empty parameter lists
2011-01-03 17:56:07 -08:00
Tom Eastep
014d0eb607
Don't recognize an empty param list
2011-01-03 17:06:54 -08:00
Tom Eastep
b7a9a48508
Handle COUNT:<level> correctly
2011-01-03 14:29:10 -08:00
Tom Eastep
8400a2ab31
Handle ':' in a param
2011-01-03 12:18:04 -08:00
Tom Eastep
33b54e4ebe
Version to 4.4.16
2011-01-03 09:00:39 -08:00
Tom Eastep
fe86964fd6
Move and reword an error message
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-02 08:42:09 -08:00
Tom Eastep
f6228ca31b
Two error messages:
...
- Disallow server port in ACTION rule.
- Add server IP address in message re: REDIRECT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2011-01-02 08:20:28 -08:00
Tom Eastep
9777f4989f
Update release notes
2011-01-02 07:12:25 -08:00
Tom Eastep
b3598f3766
Validate action names
2011-01-02 07:09:42 -08:00
Tom Eastep
faa541ee1f
Update release notes
2011-01-01 18:58:08 -08:00
Tom Eastep
cb372cf2cd
Change a couple of comments
2011-01-01 16:13:38 -08:00
Tom Eastep
d64edf3470
Clone a small function
2011-01-01 11:19:53 -08:00
Tom Eastep
8f0d0ac5a7
Use external representation in recursive call message
2011-01-01 09:18:10 -08:00
Tom Eastep
d71c11791f
Report normalized action names in recursive call message
2011-01-01 09:06:11 -08:00
Tom Eastep
4da682365d
Restore ability to detect recursive action invocations
2011-01-01 08:58:00 -08:00
Tom Eastep
ed3b336a81
Correct prototype
2011-01-01 06:55:10 -08:00
Tom Eastep
fc2d76aa7a
Move a function; don't export %policy_actions
2010-12-31 16:58:06 -08:00
Tom Eastep
e1b4e345fb
Add Eclipse files to project
2010-12-31 15:19:56 -08:00
Tom Eastep
8e6fdceeb5
Back out useless change
2010-12-31 14:30:31 -08:00
Tom Eastep
b36ad0d065
Change several more compiler progress messages
2010-12-31 14:19:31 -08:00
Tom Eastep
f8e04b4110
Change a couple of compiler progress messages
2010-12-31 14:12:57 -08:00
Tom Eastep
e0d2eb997d
Restore the name 'process_rule1'
2010-12-31 12:41:01 -08:00
Tom Eastep
1bdaf862d3
Populate %targets out of new_action()
2010-12-31 10:36:07 -08:00
Tom Eastep
6c14c76ab5
Another comment
2010-12-31 08:37:56 -08:00
Tom Eastep
aa6754cb40
Add a comment
2010-12-31 07:51:15 -08:00
Tom Eastep
d4d1bb7b41
Bump version of the Zones module
2010-12-30 13:14:07 -08:00
Tom Eastep
33ff6db6bc
Whitespace changes
2010-12-30 12:25:22 -08:00
Tom Eastep
3f9cd713c3
Correct known problems
2010-12-30 12:01:46 -08:00
Tom Eastep
aaf2834917
Update known problems
2010-12-30 11:47:25 -08:00
Tom Eastep
c1cae8a1aa
Update release notes
2010-12-30 11:45:40 -08:00
Tom Eastep
cd7f94dbdb
Merge branch 'master' into 4.4.16
2010-12-30 10:37:15 -08:00
Tom Eastep
746c2a5163
Correct comment about the action member of the chain structure
2010-12-30 10:36:03 -08:00
Tom Eastep
cb751bd225
Remove extraneous change log entries
2010-12-30 10:02:39 -08:00
Tom Eastep
91227b6d13
Don't log jumps to NAT actions
2010-12-30 09:56:44 -08:00
Tom Eastep
d8541e4a58
Update problems corrected
2010-12-30 08:05:04 -08:00
Tom Eastep
527ea7de3f
A couple of more version changes
2010-12-30 07:34:09 -08:00
Tom Eastep
e3d1032ab3
Set version to Beta 8
2010-12-30 07:32:30 -08:00
Tom Eastep
ad32ce6986
Update release file
2010-12-30 07:04:38 -08:00
Tom Eastep
3c4cddeeeb
Eliminate process_action3()
2010-12-30 06:56:21 -08:00
Tom Eastep
d767d9fea3
Better Editing of BLACKLIST_DISPOSITION
2010-12-29 18:43:14 -08:00
Tom Eastep
1c55143524
Allow parameterized Limit to use log tags
2010-12-29 12:20:18 -08:00
Tom Eastep
230d284980
Correct a couple of comments
2010-12-29 11:36:59 -08:00
Tom Eastep
b7d936dd8e
Merge levels in process_action2()
2010-12-29 08:23:44 -08:00
Tom Eastep
a4bf11c7d5
Some cosmetic cleanup
2010-12-28 17:18:43 -08:00
Tom Eastep
d90d56161c
Improve readability
2010-12-28 16:42:28 -08:00
Tom Eastep
7d41e4b38c
Restore level merge behavior with nested actions
2010-12-28 16:04:55 -08:00
Tom Eastep
17ed14a895
Update comments in the Rules module
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-28 16:02:10 -08:00
Tom Eastep
2805d16246
Update change log
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-28 16:01:30 -08:00
Tom Eastep
c135a7e594
Update change log
2010-12-28 14:06:02 -08:00
Tom Eastep
17a3ca62d5
Eliminate the Actions module
2010-12-28 13:51:45 -08:00
Tom Eastep
3d4aaad0eb
Remove a couple of superfluous tests
2010-12-28 12:53:16 -08:00
Tom Eastep
4a8f724f9b
Handle duplicate chain name for action chain
2010-12-28 12:18:42 -08:00
Tom Eastep
6f7a1c7fd0
Update release docs
2010-12-28 07:49:55 -08:00
Tom Eastep
50a3b76e40
Rename a variable; reformat an error message
2010-12-28 07:49:35 -08:00
Tom Eastep
cc30fc4dbb
Eliminate max nest level on actions
2010-12-27 17:16:34 -08:00
Tom Eastep
0c3ed598ca
Improve diagnostic
2010-12-27 17:02:06 -08:00
Tom Eastep
297df02047
Catch loops in action invocation graph
2010-12-27 16:41:53 -08:00
Tom Eastep
6a1487d628
Correct existing optimization issue
2010-12-27 12:31:34 -08:00
Tom Eastep
215c05d12b
Add some comments -- fix logging with NAT actions
2010-12-27 09:05:44 -08:00
Tom Eastep
d5ac12a8ff
Bump version to RC 1
2010-12-27 07:49:52 -08:00
Tom Eastep
311797e0bf
Create nat chain during pre-processing of nat action
2010-12-27 07:47:16 -08:00
Tom Eastep
79cbfd0126
Allow '--' to specify '-' as an action parameter
2010-12-26 17:03:05 -08:00
Tom Eastep
4111432a52
Implement optional action parameters
2010-12-26 16:13:53 -08:00
Tom Eastep
d8bcbffb88
Dead code removal
2010-12-26 12:08:10 -08:00
Tom Eastep
d1d9518c42
Move process_action2()
2010-12-26 11:44:15 -08:00
Tom Eastep
088480e5d9
Fix a couple of bugs
2010-12-26 11:34:58 -08:00
Tom Eastep
8f9d5a967b
Simplify variable substitution
2010-12-26 11:07:00 -08:00
Tom Eastep
d4d285af39
Revert version to Beta 7
2010-12-26 09:01:15 -08:00
Tom Eastep
31bd00e42e
Document parameterized actions
2010-12-26 08:59:31 -08:00
Tom Eastep
4fdec73808
Fix target of <action(params)>
2010-12-26 07:58:20 -08:00
Tom Eastep
758a50fa84
Extantiate params during module processing
2010-12-25 14:48:14 -08:00
Tom Eastep
bdc3ca16a4
Finish revision of action processing
2010-12-25 14:28:57 -08:00
Tom Eastep
8218cb3444
Pass normalized action name to process_rule_common()
2010-12-25 10:15:08 -08:00
Tom Eastep
39f4f03b60
Segregate process_action1() from process_actions1()
2010-12-25 08:21:32 -08:00
Tom Eastep
1285b73d52
Simplify detection of action self-invocation
2010-12-25 08:10:23 -08:00
Tom Eastep
6240d41754
Add new progress message
2010-12-25 07:41:18 -08:00
Tom Eastep
ce8f33b623
Add a comment
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-23 15:38:47 -08:00
Tom Eastep
5e642a1406
Update a comment
2010-12-23 15:34:07 -08:00
Tom Eastep
b100991cfa
Add a couple of comments; move a declaration; simplify a statement
2010-12-23 14:17:22 -08:00
Tom Eastep
8ad7300165
Fix NONAT and NATONLY rules in an action
2010-12-23 07:49:20 -08:00
Tom Eastep
37a383ea4d
Used normalized names in requires list
2010-12-22 16:57:59 -08:00
Tom Eastep
a51eac91b0
Add documentation for parameterized actions
2010-12-22 15:09:54 -08:00
Tom Eastep
c6e35be8bc
Update version to RC 1
2010-12-22 14:37:10 -08:00
Tom Eastep
350f20fc7e
Add a comment
2010-12-22 14:35:19 -08:00
Tom Eastep
e8de4ce563
Add an <action> member to the chain table
2010-12-22 10:59:02 -08:00
Tom Eastep
e52feb7da7
Fix another bug
2010-12-21 17:50:35 -08:00
Tom Eastep
f3abf56cac
Restore proper NAT in action handling
2010-12-21 15:20:19 -08:00
Tom Eastep
b8d5e09b58
Put a couple of routines back in the Rules module
2010-12-21 14:57:46 -08:00
Tom Eastep
7052738cd0
Remove param manipulation routines for now
2010-12-21 13:38:10 -08:00
Tom Eastep
ffbcd1b1fe
Catch an action that invokes itself
2010-12-21 13:20:44 -08:00
Tom Eastep
ac42fddbce
Finish (unpublished) parameterized actions
2010-12-21 12:29:52 -08:00
Tom Eastep
6263689c3e
Allow Limit to accept parameters
2010-12-21 11:38:54 -08:00
Tom Eastep
7989f5094e
Implement a better solution to down shared gateways
2010-12-21 11:15:41 -08:00
Tom Eastep
9a78a0242f
Revise wildcard fix description in the release notes.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-21 10:01:45 -08:00
Tom Eastep
25e93b4df3
Change dummy MAC address.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-21 09:22:58 -08:00
Tom Eastep
242a9f5a98
Remove trailing whitespace
2010-12-20 15:16:20 -08:00
Tom Eastep
ef9caf3588
Update module versions
2010-12-20 15:10:23 -08:00
Tom Eastep
7b8522f756
Supply dummy MAC for unreachable gateway
2010-12-20 15:07:53 -08:00
Tom Eastep
c63bb70585
Bump version to Beta 6
2010-12-20 13:17:35 -08:00
Tom Eastep
708e7672a3
More wildcard optimization
2010-12-20 13:00:48 -08:00
Tom Eastep
7061997324
Optimize wildcard resolution.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-20 12:22:26 -08:00
Tom Eastep
ebbf381e27
Rename %logactionchains -> %usedactions
2010-12-20 10:32:04 -08:00
Tom Eastep
8c8e4d1654
Unconditionally cache interface lookup results
2010-12-20 10:31:14 -08:00
Tom Eastep
7a1a303265
Unconditionally cache the result of wildcard lookups
2010-12-20 10:07:19 -08:00
Tom Eastep
433b3fbd87
Add some insurance against wildcard interfaces
2010-12-20 08:45:10 -08:00
Tom Eastep
5c890938ed
Document fixes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-20 08:01:55 -08:00
Tom Eastep
b56b81ef74
Elmininate export of %usedactions
2010-12-19 18:18:37 -08:00
Tom Eastep
262b4044f8
Fix more physical name issues
2010-12-19 16:38:24 -08:00
Tom Eastep
44f001388a
Only call normalized_action_name() when needed
2010-12-19 13:32:08 -08:00
Tom Eastep
7be3ed33d5
Fix undef access out of notrack file
2010-12-19 13:30:02 -08:00
Tom Eastep
c302e82233
Disallow wildcard interfaces in additional contexts
2010-12-19 10:46:35 -08:00
Tom Eastep
54c57e3bc7
Disallow wildcard interfaces in additional contexts
2010-12-19 10:43:03 -08:00
Tom Eastep
55452c6e59
Disallow wildcards in the proxyarp file
2010-12-19 08:55:03 -08:00
Tom Eastep
8526dafc5d
Don't allow interface that is identical to the root of a wildcard
2010-12-19 08:10:41 -08:00
Tom Eastep
45faba0b7c
Enable parameters for actions
2010-12-18 16:29:29 -08:00
Tom Eastep
4b22bbd90d
Add logic for parameterized actions
2010-12-18 16:16:29 -08:00
Tom Eastep
4573b5ba8e
Generate normalized name in process_rule_common()
2010-12-18 13:32:53 -08:00
Tom Eastep
21166e07f3
Add action normalization routines
2010-12-18 12:31:37 -08:00
Tom Eastep
c659f05491
Make generate_matrix locals more obvious
2010-12-17 20:16:09 -08:00
Tom Eastep
b9a086c7f2
Fix fly-speck in prog.header
2010-12-16 09:55:31 -08:00
Tom Eastep
9d0bff62fa
Finish code re-org
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-15 12:57:55 -08:00
Tom Eastep
92894a7482
Step 1 of module re-org
2010-12-15 11:57:51 -08:00
Tom Eastep
9db42bf3da
Update wording in the release notes
2010-12-14 11:28:46 -08:00
Tom Eastep
880a94e42f
Update documentation regarding Hack removal
2010-12-14 11:19:17 -08:00
Tom Eastep
999ef7105b
Eliminate process_macro1() and process_action1()
...
They are replaced with process_macro() and process_rule_common() respectively.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-14 08:55:30 -08:00
Tom Eastep
94faafd662
Reorg export list
2010-12-13 21:05:21 -08:00
Tom Eastep
9e684a80c1
Move more code from Rules.pm to Actions.pm
2010-12-13 17:54:53 -08:00
Tom Eastep
5b0d8922e7
Consolidate definitions of rule exception command handling
2010-12-13 17:29:22 -08:00
Tom Eastep
0ec68c7407
Prune the Actions.pm export list
2010-12-13 16:55:00 -08:00
Tom Eastep
09bb5bb9b3
Use $macro_commands when splitting action file records
2010-12-13 16:46:40 -08:00
Tom Eastep
aba63d5c9b
More action/macro documentation
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-13 09:06:29 -08:00
Tom Eastep
9ba8823011
Document Action Changes in the release documents
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-13 08:45:58 -08:00
Tom Eastep
c18154cedc
NAT in Actions
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-13 08:26:24 -08:00
Tom Eastep
ff402dcf09
Add a comment to the params for process_rule_common()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-12 13:02:27 -08:00
Tom Eastep
2e7dd0de97
Use process_rule_common() to process entries in action files.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-12 12:55:32 -08:00
Tom Eastep
444a38ae2e
Add a chain reference argument to process_rule_common()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-12 12:22:12 -08:00
Tom Eastep
dfa47cc300
Implement format-2 Actions
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-12 12:09:48 -08:00
Tom Eastep
1bbe95ead8
Allow wide macros in actions
2010-12-12 10:14:47 -08:00
Tom Eastep
acbbdc1690
Bump version in the Proxyarp module
2010-12-12 08:56:12 -08:00
Tom Eastep
13c4d21762
Replace a couple of lists of scalars with arrays; document move of process_rules1()
2010-12-12 07:29:46 -08:00
Tom Eastep
138e49276d
Rename process_rule1() to process_rule_common()
2010-12-11 17:19:43 -08:00
Tom Eastep
7b86c699b6
Move process_rule1() from Rules.pm to Actions.pm
2010-12-11 17:16:50 -08:00
Tom Eastep
48b00d719e
Complete Proxy NDP implementation
2010-12-11 10:04:07 -08:00
Tom Eastep
147e4da223
Ensure that interfaces listed in the tcinterfaces file are known
2010-12-11 07:39:16 -08:00
Tom Eastep
0344cdb294
Correct handling of proxyndp
2010-12-11 07:10:50 -08:00
Tom Eastep
1f4b218cde
Ensure that interfaces listed in the proxyarp (proxyndp) file are known
2010-12-11 07:10:23 -08:00
Tom Eastep
caa4a54e38
Implement IPv6 proxyndp
2010-12-10 19:06:44 -08:00
Tom Eastep
2ae809888c
Document fix for logical naming
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-10 12:19:43 -08:00
Tom Eastep
0a4e098c69
Fix broken logical naming in Proxy ARP
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-10 07:52:54 -08:00
Tom Eastep
fc6dbb3d56
Bump version to Beta 4
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-10 06:53:36 -08:00
Tom Eastep
6d65100457
Add PPP support in RedHat and SuSE
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-05 09:11:08 -08:00
Tom Eastep
b9ee064284
Update version to Beta 4
2010-12-04 11:40:34 -08:00
Tom Eastep
19f40ab721
Bump version to Beta 3
2010-12-03 13:43:46 -08:00
Tom Eastep
2e35ad0a1b
Fix params parsing on older distros
2010-12-03 13:40:11 -08:00
Tom Eastep
5458d9367f
Bump version and document bug catcher
2010-12-03 09:17:26 -08:00
Tom Eastep
8ce1755f8e
Add bug-catcher to get_params()
2010-12-03 08:05:11 -08:00
Tom Eastep
04537b8f2d
Add some comments
2010-12-02 16:10:35 -08:00
Tom Eastep
79c87b2c72
Document fixes.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-02 12:26:58 -08:00
Tom Eastep
4cd77bf9aa
Correct handling of params file opens.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-12-02 10:14:45 -08:00
Tom Eastep
ec75c8aa86
Redirect params output to stderr
2010-12-01 15:04:33 -08:00
Tom Eastep
f68bfde86f
Continue to fine-tune params processing
2010-12-01 13:57:16 -08:00
Tom Eastep
d33491d6c6
Continue to enhance params procesing
2010-12-01 13:18:10 -08:00
Tom Eastep
49cdc5d9eb
Make new get_params work with bash
2010-12-01 10:41:49 -08:00
Tom Eastep
22580c5be0
More parameter processing improvements
2010-12-01 10:11:02 -08:00
Tom Eastep
901a986b18
Update release notes regarding suppressed warning
2010-12-01 09:21:46 -08:00
Tom Eastep
b224eb80d5
Omit warning message
2010-12-01 09:21:23 -08:00
Tom Eastep
cdb75bfd96
Better solution to multi-line exported symbols issue
2010-12-01 09:14:09 -08:00
Tom Eastep
5761bfd7d1
Document change to params processing
2010-12-01 08:16:41 -08:00
Tom Eastep
0455673bcb
Remove fly speck from release notes
2010-12-01 07:27:31 -08:00
Tom Eastep
cae5ddc7e0
Initiate 4.4.16
2010-11-30 17:30:11 -08:00
Tom Eastep
6ef0f0f9d3
Document addition of startup_error()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-11-29 16:02:35 -08:00
Tom Eastep
6dc65e2811
Update Rules.pm version
2010-11-28 19:21:31 -08:00
Tom Eastep
81cc39049c
Cosmetic change
2010-11-28 09:22:03 -08:00
Tom Eastep
f45af8ff0a
Localize $current_params
2010-11-28 09:14:52 -08:00
Tom Eastep
ecb71f7791
Eliminate @param_stack
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-11-28 08:06:58 -08:00
Tom Eastep
195c0cdaca
Document fix of root cause
2010-11-28 07:48:03 -08:00
Tom Eastep
4db68697b2
Fix root cause of macro.JAP failure
2010-11-28 07:42:12 -08:00
Tom Eastep
d5b5e7fa75
Document correction to macro.JAP
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-11-28 07:07:58 -08:00
Tom Eastep
3a8634934a
Correct macro.JAP
2010-11-28 07:05:18 -08:00
Tom Eastep
b771ce2925
Clarify 'switch' in the Fool's firewall article
2010-11-27 10:28:44 -08:00
Tom Eastep
1ae9a3185a
Disallow standard providers in the routes file
2010-11-26 16:41:30 -08:00
Tom Eastep
053da3a2c0
Fix undefined value on HEADER_MATCH
2010-11-26 16:41:07 -08:00
Tom Eastep
d5fc0150d0
Set version to 4.4.15
2010-11-26 09:49:40 -08:00
Tom Eastep
81622fe63b
Add new Macros
2010-11-26 08:32:54 -08:00
Tom Eastep
00cedeeda3
Update macro template for HEADERS column
2010-11-24 11:23:37 -08:00
Tom Eastep
2702d7f208
Implement header matching
2010-11-24 10:46:06 -08:00
Tom Eastep
70453f2648
Avoid regression in fixing syn flood chain names
2010-11-22 14:34:58 -08:00
Tom Eastep
f2f2ef713d
Update version of a couple of Perl Modules
2010-11-22 13:23:15 -08:00
Tom Eastep
93d165d3ec
Document Munin Macro
2010-11-22 13:04:21 -08:00
Tom Eastep
6f6b417232
Add Munin Macro
2010-11-22 13:01:38 -08:00
Tom Eastep
9427510e8f
Update version to RC 1
2010-11-22 13:01:12 -08:00
Tom Eastep
93f9e8914c
Add another SNAT virtual alias example
2010-11-22 11:59:59 -08:00
Tom Eastep
2e4da207de
Update version to Beta 3
2010-11-21 09:52:34 -08:00
Tom Eastep
befdbb4a04
Move version_command() to where it belongs
2010-11-21 07:41:29 -08:00
Tom Eastep
d08f8d6ac3
Update release documents
2010-11-19 17:53:58 -08:00
Tom Eastep
3ca3d64efe
Generate correct name for synflood chains
2010-11-18 20:32:20 -08:00
Tom Eastep
407b92829f
Another Perl 5.12 issue
2010-11-18 20:12:13 -08:00
Tom Eastep
63e5f6aff9
Correct handling of family switch in tcfilters processing
2010-11-18 06:56:07 -08:00
Tom Eastep
63fd81f9ec
Simplify getparams
2010-11-17 17:26:41 -08:00
Tom Eastep
5e1c8f8d2a
Add DEVICE column to routes file
2010-11-17 08:35:20 -08:00
Tom Eastep
421b1e745d
Update release documents with /etc/shorewall/routes information
2010-11-16 21:02:50 -08:00
Tom Eastep
71eb783fcd
Implement explicit provider routing
2010-11-16 20:38:54 -08:00
Tom Eastep
81e6e0889c
Initiate Beta 2
2010-11-15 15:09:22 -08:00
Tom Eastep
3c5cadb02c
Add another variable to the preceding optimization
2010-11-15 08:42:58 -08:00
Tom Eastep
64e49229f8
Simply variable initialization
2010-11-15 08:14:31 -08:00
Tom Eastep
7507f67d9a
Now that I've RTFM, simplify the rule for skipping over the IPv6 header
2010-11-15 07:40:50 -08:00
Tom Eastep
94e827862e
Fix typo in release notes
2010-11-15 07:40:18 -08:00
Tom Eastep
31bcb8727e
Update release documents
2010-11-14 15:54:58 -08:00
Tom Eastep
5d0e719d03
Prevent suprious 'fi' in filter output
2010-11-14 10:51:42 -08:00
Tom Eastep
0e5dc41d31
Fix 'Shared' traffic shaping
2010-11-14 09:31:00 -08:00
Tom Eastep
997a697a65
Fix required/optional interface with physical eq '+'
2010-11-14 08:43:20 -08:00
Tom Eastep
9568a6ef59
Add getparams to the .spec file - Take 2
2010-11-14 08:10:05 -08:00
Tom Eastep
59f6b10a55
Add getparams to the .spec file
2010-11-14 08:03:14 -08:00
Tom Eastep
2d8785d574
Add 'TC_ENABLED=Shared' support
2010-11-14 07:52:51 -08:00
Tom Eastep
5bae689fe1
Generate distinct progress messages for IPv4 and IPv6 filters
2010-11-14 07:38:01 -08:00
Tom Eastep
ff571cb83b
Give IPv6 filters a distinct priority
2010-11-14 06:55:09 -08:00
Tom Eastep
1d93a18b8d
IPV6 now working -- BOTH still broken
2010-11-13 18:08:19 -08:00
Tom Eastep
3f6cce10d2
Protect against accidental output from params file
2010-11-13 16:16:58 -08:00
Tom Eastep
19122512d0
Fix new params file processing for INCLUDE
2010-11-13 10:59:09 -08:00
Tom Eastep
b20ed2d4de
Simply another RE
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-11-11 14:03:00 -08:00
Tom Eastep
775bee278a
Fix for unexpected /usr/share/shorewall/init
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-11-11 13:03:00 -08:00
Tom Eastep
ff61d4dba4
Correct documentation of NULL_ROUTE_RFC1918 fix
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-11-10 14:18:33 -08:00
Tom Eastep
0602b619bd
Fix NULL_ROUTE_RFC1918=Yes
2010-11-09 15:20:23 -08:00
Tom Eastep
8a9aaff4e8
Change shell variable resolution order
2010-11-07 13:28:03 -08:00
Tom Eastep
1e6b7c8130
Simplify an RE
2010-11-06 20:25:46 -07:00
Tom Eastep
092f032b8e
Realign precedence of environment inheritance
2010-11-06 19:02:14 -07:00
Tom Eastep
25397e8284
Document params file processing change
2010-11-06 18:33:41 -07:00
Tom Eastep
69c3600107
Modernize processing of params file
2010-11-06 17:12:05 -07:00
Tom Eastep
7c4bc900d6
Belated update to Perl module versions
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-30 10:45:14 -07:00
Tom Eastep
dcf2d633b1
Don't save ipsets if there are no dynamic zones or ipset rules
2010-10-30 10:35:52 -07:00
Tom Eastep
d4f857f877
Update version to 4.4.15-Beta1
2010-10-30 07:12:03 -07:00
Tom Eastep
4daf4c372e
Initialize release documents for 4.4.15
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-29 08:28:58 -07:00
Tom Eastep
1db13849ab
Clear VERBOSE and VERBOSITY at CLI startup
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-28 15:17:37 -07:00
Tom Eastep
5cf0cd2c33
Document VERBOSITY fix.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-28 11:41:38 -07:00
Tom Eastep
8758d3a834
Insure that VERBOSITY=0 when interrogating compiled script version
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-28 11:25:56 -07:00
Tom Eastep
20bb781874
Document fix for 10+ TC interfaces
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-28 10:33:17 -07:00
Tom Eastep
bc406b39bc
Fix > 10 TC interfaces
2010-10-28 10:27:55 -07:00
Tom Eastep
6c90046ab5
Document fix for split_list()
2010-10-26 06:55:01 -07:00
Tom Eastep
f2ab068044
Fix split_list()
2010-10-26 06:49:55 -07:00
Tom Eastep
1060b201dd
Update version to 4.4.14
2010-10-23 21:40:22 -07:00
Tom Eastep
ded852e0ee
Fix compilation warning
2010-10-19 08:42:35 -07:00
Tom Eastep
3ec6185f72
Run update-rc.d on Debian
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-13 08:42:35 -07:00
Tom Eastep
28e473d9a1
Document change to FORWARD_CLEAR_MARK default
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-10 07:49:17 -07:00
Tom Eastep
11f2c7772a
Clear FORWARD_CLEAR_MARK setting in the remaining config files
2010-10-09 11:28:13 -07:00
Tom Eastep
17860cacd8
Move dump_command() to a more logical place in the file
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-07 14:36:05 -07:00
Tom Eastep
033d43b014
Implement undocumented dumpfilter extension file
2010-10-07 14:35:51 -07:00
Tom Eastep
f0ef27b3e5
Update version to RC1
2010-10-06 16:16:37 -07:00
Tom Eastep
b9602d9a6a
Correct typo in the release notes
2010-10-06 11:24:45 -07:00
Tom Eastep
3d90c63528
Improve validation and reporting in the net list processing.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-05 16:20:07 -07:00
Tom Eastep
a10ced2da2
Make exclusion of set lists more consistent
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-05 12:22:27 -07:00
Tom Eastep
7767d30c7c
Improve error message
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-05 11:25:18 -07:00
Tom Eastep
587dacdae0
Allow set lists with "!"
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-05 08:38:30 -07:00
Tom Eastep
8fd221ef30
Refine source/dest network parsing in expand_rule()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-04 18:57:11 -07:00
Tom Eastep
e74f48410f
Correct handling of exclusion with ipset lists
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-04 14:29:50 -07:00
Tom Eastep
38851fe446
Delete obsolete options from shorewall.conf
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-04 07:44:28 -07:00
Tom Eastep
cee05d9763
Refine -lite handling of scfilter.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-03 12:52:30 -07:00
Tom Eastep
b3d0447ef2
Reword scfilter -lite explaination
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-03 11:00:51 -07:00
Tom Eastep
432534a650
Eliminate need to restart -lite to extract scfilter
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-03 10:56:55 -07:00
Tom Eastep
994ea3cce6
Document -lite log reading fix.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-03 08:35:17 -07:00
Tom Eastep
f9af35ffbe
Document -lite fixes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-02 07:22:37 -07:00
Tom Eastep
b27fd07e9f
Don't indent the embedded scfilter file.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-01 13:20:36 -07:00
Tom Eastep
ac71868cc1
Package the scfilter along with the generated script for -lite
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-01 10:59:15 -07:00
Tom Eastep
6e9fc12517
Update version to Beta 4
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-01 09:31:11 -07:00
Tom Eastep
468af44876
Add support for 'scfilter' script
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-01 09:15:58 -07:00
Tom Eastep
2fa7e11976
Add 'scfilter' extension script
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-10-01 07:38:14 -07:00
Tom Eastep
3898edfddb
Make 'show connections' work on ancient distros
2010-09-30 17:18:58 -07:00
Tom Eastep
077aa18a2d
Update release notes
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-30 15:03:02 -07:00
Tom Eastep
e795a9995b
Update release documents
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-30 14:17:51 -07:00
Tom Eastep
1218ccf0cb
More optimization performance improvements
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-30 14:15:19 -07:00
Tom Eastep
252a9f2205
More speedup of optimization level 8
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-29 13:30:10 -07:00
Tom Eastep
46f1074422
Reduce the cost of optimization substantially.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-29 11:54:39 -07:00
Tom Eastep
8017f603a0
Add progress message for each optimization pass.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-28 12:20:35 -07:00
Tom Eastep
6171d938f7
Correction to last change -- move two declarations to an outer block.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-28 12:20:06 -07:00
Tom Eastep
48c3200a5a
Issue error message when required file is missing or has zero size.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-28 11:22:47 -07:00
Tom Eastep
68f537ac5b
Bypass processing logic when an optional config file is absent.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-28 10:48:44 -07:00
Tom Eastep
47fbc83419
Don't add trailing whitespace to DNAT/REDIRECT target
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-28 09:27:42 -07:00
Tom Eastep
91aabfc078
Revise fix for extraneous progress messages
2010-09-27 16:18:11 -07:00
Tom Eastep
0109b8113a
Prevent random progress messages during compilation.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-27 15:56:22 -07:00
Tom Eastep
75d50d126c
Make zones with 'mss' complex.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-27 13:57:56 -07:00
Tom Eastep
f7eb3c3d8c
Periodic elimination of trailing white space
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-27 11:16:18 -07:00
Tom Eastep
f33912d5f7
Correct/update release notes.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-27 09:11:17 -07:00
Tom Eastep
ac646930a3
Tighter validation of ipset names in the hosts file.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-26 08:36:27 -07:00
Tom Eastep
066c772fcd
Correct minor issue with previous error message improvement change
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-26 08:28:25 -07:00
Tom Eastep
0becb39202
Bump version to Beta 3
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-26 08:15:32 -07:00
Tom Eastep
2828b65326
Improve error message generated when a token beginning with '+' reaches validate_net()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-26 07:56:55 -07:00
Tom Eastep
74f1cb2443
Mention maclist file in shorewall-ipsets(5)
2010-09-25 16:07:56 -07:00
Tom Eastep
f07ec1e9d3
Clean up untidiness where Shorewall6 tries to start on a system with an old kernel
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-25 08:46:14 -07:00
Tom Eastep
e018ee6adc
Don't create <zone>_frwd when unnecessary
...
- Set the zone {complex} flag based on ipsec options rather than the presense of any options.
- Generate forwarding blacklist rules in lieu of creating<zone>_frwd
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-24 15:25:57 -07:00
Tom Eastep
b5fdb089bc
Fix syntax error in blacklist fix
2010-09-24 13:42:05 -07:00
Tom Eastep
0768235278
Correct blacklisting in simple configurations
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-24 13:41:54 -07:00
Tom Eastep
03161ed57d
Bump version to 4.4.14 Beta 2
2010-09-23 19:33:37 -07:00
Tom Eastep
0f4d8eb929
Use 'conntrack' for 'show connections'
2010-09-23 19:08:40 -07:00
Tom Eastep
6702fbbd40
Make timestamps in log uniform
2010-09-23 07:40:27 -07:00
Tom Eastep
2c7b1b5d7b
Add more comments
2010-09-22 15:26:01 -07:00
Tom Eastep
9d5642aedd
Update Version to 4.4.14-Beta1
2010-09-21 11:34:26 -07:00
Tom Eastep
dbd7914ee6
More fiddling with move_rules()
...
- Assert that the chain being moved has no blacklist jumps
- delete duplicate rules in case the destination chain has such a jump
2010-09-20 18:00:39 -07:00
Tom Eastep
271154ed60
Rename DESTIFAC_DISALLOW -> DESTIFACE_DISALLOW
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-20 09:45:48 -07:00
Tom Eastep
bde0a297f9
Misc cleanup for 4.4.13
...
1. Replace statement with equivalent function call in promote_blacklist_rules()
2. Bump version of Tunnels.pm
3. Fix typo in comment in Zones.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-20 09:45:38 -07:00
Tom Eastep
7baa1839cf
Tighen up parsing of bracketed lists -- Take 2
2010-09-20 07:24:22 -07:00
Tom Eastep
f64993fe40
Tighen up parsing of bracketed lists
2010-09-20 07:05:23 -07:00
Tom Eastep
0ed33a0552
Document fix for '*' in interface names
2010-09-19 15:55:09 -07:00
Tom Eastep
9335ef5745
Don't allow '*' in interface names
2010-09-19 15:10:21 -07:00
Tom Eastep
25ca73ca54
Support alternative syntax for ipet lists
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-19 13:22:12 -07:00
Tom Eastep
0c6882c3a8
Merge branch '4.4.13'
2010-09-19 12:55:08 -07:00
Tom Eastep
c7fc4ce1f5
Correct order of release note entries
2010-09-19 12:54:54 -07:00
Tom Eastep
9111540a7f
Support ipset lists
2010-09-19 12:36:20 -07:00
Tom Eastep
35a686eaa1
Add delete_reference() function.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-19 08:28:29 -07:00
Tom Eastep
9ba82bec1f
Add warning about redundant 'blacklist' option
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-19 08:28:05 -07:00
Tom Eastep
e06ca34298
Add redundancy warning re 'blacklst'
2010-09-19 08:03:01 -07:00
Tom Eastep
b3d6ae78ba
Add redundancy warning re 'blacklst'
2010-09-19 07:57:36 -07:00
Tom Eastep
940ccf2c34
Document for tcfilter port ranges
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 15:11:41 -07:00
Tom Eastep
c0382b8cb9
Adjust reference count in move rules.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 15:11:17 -07:00
Tom Eastep
ce9b5ee944
Make blacklist rule promotion much more effecient.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 13:35:24 -07:00
Tom Eastep
74abd4ad54
In copy_rules(), handle the unlikely case where both chains have blacklist jumps.
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 12:26:07 -07:00
Tom Eastep
f7db24f756
Merge branch '4.4.13'
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 09:29:50 -07:00
Tom Eastep
f25b9e1967
Allow :<port> in tcfilters
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 09:26:29 -07:00
Tom Eastep
0e9c704069
Don't scan the filter table for jumps to 'blacklst' if the 'blacklst' chain does not exist
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 08:42:21 -07:00
Tom Eastep
c3299d5f89
Enable blacklist rule promotion
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 08:38:22 -07:00
Tom Eastep
6f0893cd7a
Correct Chains::promote_blacklist_rules()
...
- Interate through chains that jump to 'blacklst' until no rule is promoted
This is required to promote jumps past exclusion chains
- Correct reference counting; the first cut was horribly wrong
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 08:38:14 -07:00
Tom Eastep
c040344bc1
Promote 'in' blacklist rules to the head of the interface chain
...
- Added Chains::promote_blacklist_rules()
- Called the function from Rules::generate_matrix()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 08:38:02 -07:00
Tom Eastep
2fa16f6d08
Enable blacklist rule promotion
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 08:36:59 -07:00
Tom Eastep
578fc6c521
Correct Chains::promote_blacklist_rules()
...
- Interate through chains that jump to 'blacklst' until no rule is promoted
This is required to promote jumps past exclusion chains
- Correct reference counting; the first cut was horribly wrong
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 08:36:35 -07:00
Tom Eastep
fd6ff1849a
Promote 'in' blacklist rules to the head of the interface chain
...
- Added Chains::promote_blacklist_rules()
- Called the function from Rules::generate_matrix()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-18 07:37:42 -07:00
Tom Eastep
801c1cb6b3
Update release docs
2010-09-17 17:44:05 -07:00
Tom Eastep
fd568ece47
Clear raw table on 'clear'
2010-09-17 17:43:57 -07:00
Tom Eastep
1588c700c5
Fix blacklisting vs vservers
2010-09-17 17:43:40 -07:00
Tom Eastep
6106dd3ada
Zero out {frozen} in a deleted chain entry
2010-09-17 17:43:04 -07:00
Tom Eastep
9946fbd3b5
Update release docs
2010-09-17 17:37:07 -07:00
Tom Eastep
580c561a51
Clear raw table on 'clear'
2010-09-17 17:12:34 -07:00
Tom Eastep
a42576aef8
Fix blacklisting vs vservers
2010-09-17 16:38:34 -07:00
Tom Eastep
79bb47582a
Zero out {frozen} in a deleted chain entry
2010-09-17 16:00:36 -07:00
Tom Eastep
596d207dfc
Simplify a test
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-17 15:43:56 -07:00
Tom Eastep
8cdbe5f88d
Fix an optimization bug with the new blacklisting code
2010-09-17 15:43:47 -07:00
Tom Eastep
402b3b929e
Restore trace output in move_rules()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-17 15:43:03 -07:00
Tom Eastep
c5bb3ecfac
Simplify a test
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-17 15:42:05 -07:00
Tom Eastep
c9e876fcf5
Fix an optimization bug with the new blacklisting code
2010-09-17 15:10:02 -07:00
Tom Eastep
85430e459c
Restore trace output in move_rules()
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-17 14:35:25 -07:00
Tom Eastep
ad660d7fe5
Simplify move_rules()
2010-09-17 13:53:10 -07:00
Tom Eastep
3d0f8e962e
Simplify move_rules()
2010-09-17 13:49:32 -07:00
Tom Eastep
7a6943fa54
Disallow mss and blacklist on firewall and vserver zones
2010-09-17 12:54:58 -07:00
Tom Eastep
b76ee408a5
Emit clearer error messages
2010-09-17 12:54:54 -07:00
Tom Eastep
2e3635ff50
Be sure that {frozen} is defined
2010-09-17 12:54:44 -07:00
Tom Eastep
28aa7b8267
Re-add OPTIONS column to blacklist templates
2010-09-17 12:54:38 -07:00
Tom Eastep
ab78aac3a4
Disallow mss and blacklist on firewall and vserver zones
2010-09-17 12:46:38 -07:00
Tom Eastep
330afe1701
Emit clearer error messages
2010-09-17 12:35:34 -07:00
Tom Eastep
239b4a2356
Be sure that {frozen} is defined
2010-09-17 12:08:48 -07:00
Tom Eastep
65de1e4e6e
Re-add OPTIONS column to blacklist templates
2010-09-17 11:56:47 -07:00
Tom Eastep
7175f8a63e
Revert versions on Rules and Zones modules
2010-09-17 11:08:45 -07:00
Tom Eastep
d898c87617
Eliminate a parameter to add_jump()
2010-09-17 11:08:12 -07:00
Tom Eastep
07930fc535
Revert versions on Rules and Zones modules
2010-09-17 11:06:32 -07:00
Tom Eastep
5357f4c347
Eliminate a parameter to add_jump()
2010-09-17 11:05:35 -07:00
Tom Eastep
af24baaecd
Update version to RC1 (one more time)
2010-09-17 09:14:56 -07:00
Tom Eastep
e61230a3db
Update version to Beta 6
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-17 08:23:24 -07:00
Tom Eastep
8e2c8e5a8f
Document use of state match for NOTRACK
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-17 08:21:16 -07:00
Tom Eastep
882970a598
Use state match for UNTRACKED
2010-09-17 07:58:21 -07:00
Tom Eastep
2ce3c8aa88
Ensure that blacklist rules are before the other interface-oriented rules
2010-09-16 18:19:16 -07:00
Tom Eastep
27c445381e
Treat 'blacklist' uniformly in hosts and zones
2010-09-16 15:48:12 -07:00
Tom Eastep
67b9ae0d2c
Update release documents
2010-09-16 15:47:05 -07:00
Tom Eastep
1c870b532a
Preserve dynamic blacklist during stop/clear/restore
2010-09-16 12:17:04 -07:00
Tom Eastep
a8c9fc1859
Implement new Blacklisting Scheme
2010-09-16 09:40:28 -07:00
Tom Eastep
3c1cff0794
First steps toward zone-based blacklisting
2010-09-16 06:55:48 -07:00
Tom Eastep
1d650b41cd
Remove blacklisting by destination IP address support
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-15 15:24:58 -07:00
Tom Eastep
3ad3f0d9e0
Allow floating point numbers in tcinterfaces fields other than <rate>
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-15 14:07:21 -07:00
Tom Eastep
ba89ec39b5
Add :<burst> to /etc/shorewall/tcdevices
2010-09-15 11:56:14 -07:00
Tom Eastep
69a2fa1907
Replace to/from with dst/src
2010-09-15 11:25:46 -07:00
Tom Eastep
f925b335ef
Ignore the 'blacklist' host option
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-15 08:10:57 -07:00
Tom Eastep
373fc87165
More blacklisting wrapup
...
- Deprecate 'blacklist' in the hosts file
- Base blacklisting on interfaces alone
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-15 07:38:20 -07:00
Tom Eastep
4d0e8d129b
Add dup blacklist message
2010-09-14 18:04:27 -07:00
Tom Eastep
10a9ae496a
More manpage updates for 4.4.13
2010-09-14 16:47:45 -07:00
Tom Eastep
94cdc73ec2
Restore setpolicy() to prog.header*
...
Signed-off-by: Tom Eastep <teastep@shorewall.net>
2010-09-14 13:50:22 -07:00
Tom Eastep
c4a40d8c7b
Set version to RC1 (again)
2010-09-14 13:09:50 -07:00
Tom Eastep
c6960f1ac2
Edit release notes
2010-09-14 07:36:29 -07:00
Tom Eastep
1f2691b052
Another fix for blacklisting; correct composition of $hosts1
2010-09-14 06:47:29 -07:00
Tom Eastep
0f913fca2f
Don't create blackout unnecessarily
2010-09-13 18:15:50 -07:00