2006-07-04 19:15:33 +02:00
|
|
|
Changes in 3.2.0 Final
|
|
|
|
|
|
|
|
1) Avoid extraneous double quotes in log rules generated at run-time.
|
|
|
|
|
|
|
|
Changes in 3.2.0 RC 6
|
2006-06-19 17:00:29 +02:00
|
|
|
|
2006-06-25 16:10:36 +02:00
|
|
|
1) Correct generation of the balanced default route.
|
2006-06-26 21:32:47 +02:00
|
|
|
|
|
|
|
2) Allow 'detect' in the ADDRESS column of the masq file.
|
2006-06-28 17:22:01 +02:00
|
|
|
|
|
|
|
3) Correct some permission problems.
|
2006-07-04 19:15:33 +02:00
|
|
|
|
2006-06-25 16:10:36 +02:00
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
Changes in 3.2.0 RC 5
|
|
|
|
|
2006-06-19 17:00:29 +02:00
|
|
|
1) Fix DOA 'LITEDIR' problem in /sbin/shorewall.
|
|
|
|
|
2006-06-20 01:57:01 +02:00
|
|
|
2) Stop the compiler from running iptables.
|
|
|
|
|
2006-06-20 01:59:40 +02:00
|
|
|
3) Avoid problem with ash.
|
|
|
|
|
2006-06-20 16:20:21 +02:00
|
|
|
4) Make the 'try' command use the correct SHOREWALL_SHELL.
|
|
|
|
|
2006-06-22 00:21:10 +02:00
|
|
|
5) Don't defer Action/chain extension script processing until
|
|
|
|
run-time.
|
|
|
|
|
|
|
|
6) Run extension script for policy chains.
|
2006-06-21 22:44:48 +02:00
|
|
|
|
2006-06-19 17:00:29 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-06-14 17:00:21 +02:00
|
|
|
Changes in 3.2.0 RC 4
|
|
|
|
|
2006-06-14 17:18:52 +02:00
|
|
|
1) Fix permissions on Limit file.
|
2006-06-14 17:00:21 +02:00
|
|
|
|
2006-06-14 18:32:13 +02:00
|
|
|
2) Make progress messages product-specific.
|
|
|
|
|
2006-06-14 20:12:06 +02:00
|
|
|
3) Add 'reload' command.
|
|
|
|
|
2006-06-14 17:00:21 +02:00
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
Changes in 3.2.0 RC 3
|
|
|
|
|
|
|
|
1) Remove hard directory references from compiled programs.
|
|
|
|
|
|
|
|
2) Fix /nat <-> /proxyarp typo.
|
|
|
|
|
|
|
|
3) Avoid use of symbolic link for /sbin/shorewall
|
|
|
|
|
|
|
|
-------------------------------------------------------------------------------
|
2006-06-08 00:18:49 +02:00
|
|
|
Changes in 3.2.0 RC 2
|
|
|
|
|
|
|
|
1) Update versions.
|
|
|
|
|
2006-06-08 23:49:34 +02:00
|
|
|
2) Rationalize the use of IPTABLES and LOGFORMAT.
|
|
|
|
|
2006-06-09 20:20:49 +02:00
|
|
|
3) Allow Shorewall/Shorewall-lite coexistance under RPM
|
|
|
|
|
2006-06-08 00:18:49 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-05-30 18:37:50 +02:00
|
|
|
Changes in 3.2.0 RC 1
|
|
|
|
|
|
|
|
1) Update versions.
|
|
|
|
|
|
|
|
-------------------------------------------------------------------------------
|
2006-05-15 23:08:02 +02:00
|
|
|
Changes in 3.2.0 Beta 8
|
|
|
|
|
|
|
|
1) Issue more helpful BRIDGING=No error messages.
|
|
|
|
|
2006-05-18 20:05:16 +02:00
|
|
|
2) Implement "all-" in rules file.
|
|
|
|
|
2006-05-20 17:25:11 +02:00
|
|
|
3) Add xmodules file.
|
|
|
|
|
2006-05-22 19:03:11 +02:00
|
|
|
4) Detect devices in tcdevices entries.
|
|
|
|
|
2006-05-26 21:39:22 +02:00
|
|
|
5) Fix for white-space in log prefix.
|
|
|
|
|
2006-05-27 15:29:42 +02:00
|
|
|
6) Fix rule parsing of single excluded MAC address.
|
|
|
|
|
2006-05-20 18:01:22 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-05-06 18:15:33 +02:00
|
|
|
Changes in 3.2.0 Beta 7
|
|
|
|
|
|
|
|
1) Fix mark/mask validation.
|
|
|
|
|
|
|
|
2) Restore traffic control to 'refresh'.
|
|
|
|
|
2006-05-10 18:21:31 +02:00
|
|
|
3) Detect MTU for entries in /etc/shorewall/tcdevices.
|
2006-05-10 16:34:50 +02:00
|
|
|
|
2006-05-13 16:46:50 +02:00
|
|
|
4) Avoid fatal error after missing forwardUPnP rule warning.
|
|
|
|
|
2006-05-20 18:01:22 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-04-27 18:45:08 +02:00
|
|
|
Changes in 3.2.0 Beta 6
|
|
|
|
|
|
|
|
1) Fix tc "notfound" errors when 'restart' is run out of ip-up.local.
|
|
|
|
|
2006-04-28 04:48:18 +02:00
|
|
|
2) Allow 'detectnets' to work.
|
|
|
|
|
2006-05-02 19:34:37 +02:00
|
|
|
3) Add TOS column to tcrules.
|
|
|
|
|
2006-05-02 22:27:50 +02:00
|
|
|
4) Fix 'proxyarp' interface attribute handling.
|
|
|
|
|
|
|
|
5) Fix default route generation in providers handling.
|
|
|
|
|
2006-05-05 22:40:28 +02:00
|
|
|
6) Change interraction of 'track' and PREROUTING marking.
|
|
|
|
|
2006-05-20 18:01:22 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-04-10 23:16:02 +02:00
|
|
|
Changes in 3.2.0 Beta 5
|
|
|
|
|
|
|
|
1) Fix compilation problem on LEAF Bering.
|
|
|
|
|
2006-04-11 00:52:10 +02:00
|
|
|
2) Remove traffic shaping code from the 'firewall' script to avoid
|
|
|
|
unmaintainable code duplication.
|
|
|
|
|
2006-04-12 22:29:13 +02:00
|
|
|
3) Fix DETECT_DNAT_IPADDRS=No bug.
|
|
|
|
|
2006-04-13 17:00:42 +02:00
|
|
|
4) Handle absense of mangle FORWARD chain.
|
|
|
|
|
2006-04-16 00:35:50 +02:00
|
|
|
5) Rename the rtrules file to route_rules.
|
|
|
|
|
2006-04-16 00:40:03 +02:00
|
|
|
6) Fix deletion of SNAT ip addresses.
|
|
|
|
|
2006-04-17 21:59:51 +02:00
|
|
|
7) Accomodate ancient kernel's with no FORWARD or POSTROUTING in mangle.
|
|
|
|
|
2006-04-26 00:46:36 +02:00
|
|
|
8) Clear SUBSYSLOCK on Debian/Ubuntu installs.
|
|
|
|
|
2006-05-20 18:01:22 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-03-28 20:14:40 +02:00
|
|
|
Changes in 3.2.0 Beta 4
|
|
|
|
|
|
|
|
1) Fix 'routeback' with bridge ports.
|
|
|
|
|
2006-04-02 17:17:41 +02:00
|
|
|
2) Add support for explicit routing rules.
|
|
|
|
|
2006-04-04 21:45:42 +02:00
|
|
|
3) Fix mktempdir problem.
|
|
|
|
|
2006-04-05 04:08:33 +02:00
|
|
|
4) Implement HIGH_ROUTE_MARKS
|
|
|
|
|
2006-03-24 00:26:41 +01:00
|
|
|
Changes in 3.2.0 Beta 3
|
|
|
|
|
|
|
|
1) Correct handling of verbosity in the 'try' command.
|
|
|
|
|
2006-03-24 01:05:09 +01:00
|
|
|
2) Add IMPLICIT_CONTINUE option to shorewall.conf.
|
|
|
|
|
2006-03-25 17:58:08 +01:00
|
|
|
3) Fix SAME/ADD_SNAT_ALIASES interaction.
|
|
|
|
|
2006-05-20 18:01:22 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-03-12 01:00:22 +01:00
|
|
|
Changes in 3.2.0 Beta 2
|
|
|
|
|
|
|
|
1) Make "shorewall start -f" work correctly.
|
|
|
|
|
2006-03-12 23:18:00 +01:00
|
|
|
2) Remove SUBSYSLOCK code from default and debian footers.
|
|
|
|
|
2006-03-13 01:50:29 +01:00
|
|
|
3) Add 'refreshed' extension script.
|
|
|
|
|
2006-03-23 17:37:45 +01:00
|
|
|
4) Implement 'logdrop' and 'logreject'
|
|
|
|
|
2006-05-20 18:01:22 +02:00
|
|
|
-------------------------------------------------------------------------------
|
2006-03-12 01:00:22 +01:00
|
|
|
Changes in 3.1.x. and 3.2.x
|
2005-12-14 17:18:38 +01:00
|
|
|
|
2006-01-07 18:33:10 +01:00
|
|
|
1) Removal of dynamic zones.
|
2005-12-14 17:18:38 +01:00
|
|
|
|
2006-01-07 18:33:10 +01:00
|
|
|
2) Implement 'generate' command.
|
2006-01-09 18:11:30 +01:00
|
|
|
|
|
|
|
3) Implement 'super-quiet' mode using multiple -q options (e.g., -qq).
|
2006-01-12 00:30:33 +01:00
|
|
|
|
|
|
|
4) Add back dynamic zones.
|
2006-01-13 00:26:37 +01:00
|
|
|
|
|
|
|
5) Allow remote compiles.
|
2006-01-13 18:08:23 +01:00
|
|
|
|
|
|
|
6) Change output of 'generate' to always be the file name entered (do not
|
|
|
|
prepend /var/lib/shorewall/)
|
2006-01-13 21:33:16 +01:00
|
|
|
|
|
|
|
7) Remove some restrictions on remote compiles.
|
2006-01-14 19:35:50 +01:00
|
|
|
|
|
|
|
8) Add error checking to generated script.
|
2006-01-15 23:54:12 +01:00
|
|
|
|
|
|
|
9) Merge Fabio Longerai's 'length' patch.
|
2006-01-18 00:27:54 +01:00
|
|
|
|
|
|
|
10) Add the "-p" option to the compile command.
|
2006-01-22 03:35:15 +01:00
|
|
|
|
|
|
|
11) Fix 'check' bug in setup_masq
|
2006-01-22 17:29:33 +01:00
|
|
|
|
|
|
|
12) Break compiler/firewall into two files
|
2006-01-23 02:41:24 +01:00
|
|
|
|
|
|
|
13) Make Shoreall quiet for a change.
|
2006-01-27 20:59:27 +01:00
|
|
|
|
|
|
|
14) Make "Compile-and-go" the only mode of operation.
|
|
|
|
|
|
|
|
15) Remove -p
|
|
|
|
|
|
|
|
16) Apply Tuomo's patches for IPSEC and Noecho.
|
|
|
|
|
2006-01-29 19:02:42 +01:00
|
|
|
17) Fix bridging
|
|
|
|
|
|
|
|
18) Fix QUEUE when used in the ESTABLISHED section.
|
|
|
|
|
2006-01-31 21:02:17 +01:00
|
|
|
19) Apply Ed Suominen's patch to tcrules.
|
2006-02-08 23:33:13 +01:00
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
3.1.5
|
2006-01-31 21:02:17 +01:00
|
|
|
|
2006-02-02 00:43:12 +01:00
|
|
|
20) Speed up compilation by rewriting 'fix_bang()'.
|
|
|
|
|
2006-02-02 18:35:28 +01:00
|
|
|
21) Correct GATEWAY handling in the providers file.
|
|
|
|
|
2006-02-03 22:26:58 +01:00
|
|
|
22) Remove sub-zone exclusion from DNAT/REDIRECT.
|
|
|
|
|
|
|
|
23) Add compiled-program/library versioning scheme.
|
2006-02-04 18:14:46 +01:00
|
|
|
|
2006-02-08 23:33:13 +01:00
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
3.1.6
|
|
|
|
|
2006-02-04 18:14:46 +01:00
|
|
|
24) Apply Steven Springl's help patch.
|
|
|
|
|
|
|
|
25) Fix 'allow/drop/reject' while Shorewall not running.
|
2006-02-04 21:57:38 +01:00
|
|
|
|
|
|
|
26) Implement bi-directional macros.
|
2006-02-08 23:33:13 +01:00
|
|
|
|
|
|
|
27) Fix TC bridge port handling.
|
2006-02-10 19:45:05 +01:00
|
|
|
|
2006-02-10 20:33:31 +01:00
|
|
|
28) Fix/document "check -e"
|
|
|
|
|
|
|
|
29) Automatically use capabilities file when non-root.
|
2006-02-11 16:03:48 +01:00
|
|
|
|
|
|
|
30) Correct typo in help file ("help drop").
|
2006-02-12 21:45:57 +01:00
|
|
|
|
|
|
|
31) Added 'tcpsyn'
|
2006-02-13 18:57:42 +01:00
|
|
|
|
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
3.1.7
|
|
|
|
|
|
|
|
32) Change 'tcpsyn' to 'tcp:syn'
|
2006-02-14 00:32:18 +01:00
|
|
|
|
|
|
|
33) Remove superfluous rules in MAC validation.
|
2006-02-14 17:36:29 +01:00
|
|
|
|
|
|
|
34) Correct Makefile.
|
2006-02-15 16:20:17 +01:00
|
|
|
|
|
|
|
35) Add -t option
|
2006-02-15 16:43:32 +01:00
|
|
|
|
|
|
|
36) Restore log messages.
|
2006-02-18 16:22:03 +01:00
|
|
|
|
|
|
|
37) Fix "shorewall capabilities" with VERBOSITY < 2.
|
2006-02-20 23:28:47 +01:00
|
|
|
|
|
|
|
-------------------------------------------------------------------------------
|
2006-02-26 02:47:50 +01:00
|
|
|
3.1.8
|
2006-02-20 23:28:47 +01:00
|
|
|
|
|
|
|
38) Remove compile-time running of extension scripts.
|
2006-02-21 17:46:21 +01:00
|
|
|
|
|
|
|
39) Correctly handle interfaces named 'inet'.
|
2006-02-23 16:50:53 +01:00
|
|
|
|
|
|
|
40) SUBSYSLOCK functionality restored.
|
2006-02-26 02:47:50 +01:00
|
|
|
|
|
|
|
-------------------------------------------------------------------------------
|
|
|
|
3.1.9
|
|
|
|
|
|
|
|
41) Fix Provider route generation when a specific gateway is specified.
|
2006-02-26 18:10:16 +01:00
|
|
|
|
|
|
|
42) Be sure that restore file name is preserved regardless of 'set --' in
|
|
|
|
define_firewall().)
|
2006-03-01 17:46:19 +01:00
|
|
|
|
|
|
|
43) Add Simon's redhat prog files.
|
2006-03-01 18:53:45 +01:00
|
|
|
|
|
|
|
44) Add 'delete_nat' to compiled program.
|
2006-03-03 00:31:27 +01:00
|
|
|
|
|
|
|
45) Move 'shorecap' to /usr/share/shorewall
|
|
|
|
|
2006-03-03 00:58:56 +01:00
|
|
|
46) Add debian prog files.
|
|
|
|
|
|
|
|
47) Correct syntax error in validate_policy()
|
2006-03-09 17:40:21 +01:00
|
|
|
-------------------------------------------------------------------------------
|
2006-03-09 22:10:32 +01:00
|
|
|
3.2.0 Beta 1.
|
2006-03-09 17:40:21 +01:00
|
|
|
|
|
|
|
48) Streamlined some code in setup_tc1()
|
|
|
|
|
|
|
|
49) Process /etc/shorewall/params at run-time.
|
|
|
|
|
|
|
|
50) Add new modules to /etc/shorewall/modules.
|
2006-03-09 23:55:28 +01:00
|
|
|
|
|
|
|
51) Make default behavior of "compile" distribution-neutral.
|