Tom Eastep
|
ee74696747
|
IPv6 work to only export when necessary
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-03 08:59:58 -08:00 |
|
Tom Eastep
|
234e4fa754
|
Update module versions
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-03 08:51:55 -08:00 |
|
Tom Eastep
|
7457f643ee
|
Don't export globals when the script is 4.4.8 or later
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-03 08:51:40 -08:00 |
|
Tom Eastep
|
cce4bf277a
|
Reduce export usage; Allow PURGE and RESTOREFILE to be specified on the run-line
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-02 14:49:31 -08:00 |
|
Tom Eastep
|
2656a9b0c7
|
Eliminate use of PRODUCT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-02 12:34:36 -08:00 |
|
Tom Eastep
|
68f5215f07
|
Remove Reliance on HOSTNAME in generated programs
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-02 11:45:35 -08:00 |
|
Tom Eastep
|
3ea6f6792f
|
Eliminate VERSION reserved variable name
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-02 08:02:10 -08:00 |
|
Tom Eastep
|
5fc6d58e19
|
Eliminate STOPPING variable
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-02 07:37:30 -08:00 |
|
Tom Eastep
|
d4936f4bad
|
Tweak to an RE used in optimization
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-02 06:58:09 -08:00 |
|
Tom Eastep
|
f11bfd3890
|
Eliminate redundate setting of PRODUCT
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-01 08:32:59 -08:00 |
|
Tom Eastep
|
cfa09dce22
|
Avoid multiple policy matches with OPTIMIZE=7 and not KLUDGEFREE
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-01 08:32:37 -08:00 |
|
Tom Eastep
|
3ba797cb14
|
Correct several bugs in the VERBOSITY overhaul
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-03-01 06:57:04 -08:00 |
|
Tom Eastep
|
53c73bc8e9
|
Eliminate VERBOSE
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 17:58:01 -08:00 |
|
Tom Eastep
|
14f83759ae
|
Propagate VERBOSITY even though we don't use it yet
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 17:39:35 -08:00 |
|
Tom Eastep
|
546a48543d
|
Propagate LOG_VERBOSITY
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 17:30:11 -08:00 |
|
Tom Eastep
|
39883aa690
|
Eliminate LOG_VERBOSE
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 16:58:30 -08:00 |
|
Tom Eastep
|
fb55d63eaf
|
Allow verbosity to be separate from -V
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 16:42:50 -08:00 |
|
Tom Eastep
|
333ac21c2f
|
Prepare the footers for 4.6.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 15:25:25 -08:00 |
|
Tom Eastep
|
83ed0a401b
|
I'll eventually get it the way I like it
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 13:45:33 -08:00 |
|
Tom Eastep
|
585711caa8
|
Even simpler RE for detecting builtins
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 13:29:26 -08:00 |
|
Tom Eastep
|
693d0e5d4c
|
Make new test in add_jump() a bit safer.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-28 12:44:29 -08:00 |
|
Tom Eastep
|
d2992c21f4
|
Update version to Beta 2
|
2010-02-28 09:04:37 -08:00 |
|
Tom Eastep
|
061d850c16
|
Rename RESTOREPATH to g_restorepath
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-26 08:35:50 -08:00 |
|
Tom Eastep
|
7fe7ebc891
|
Fix Handling of NFQUEUE(queue-num) in policies
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-25 08:44:28 -08:00 |
|
Tom Eastep
|
70a246501e
|
Update version of Tc.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-23 07:08:48 -08:00 |
|
Tom Eastep
|
3fc10cd94b
|
Prepend 'SW_' to constructed shell variable names.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-22 10:27:59 -08:00 |
|
Tom Eastep
|
2a965d42b9
|
Add a comment
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-21 07:57:34 -08:00 |
|
Tom Eastep
|
6307653a01
|
Pick up one fix from 4.4.7.4 regarding CONTINUE rules.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-20 09:42:58 -08:00 |
|
Tom Eastep
|
edaf541850
|
Don't apply rate limiting twice in ACCEPT+ rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-19 14:01:45 -08:00 |
|
Tom Eastep
|
ceff8adc78
|
Restore duplicate interface detection in tcinterfaces.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-18 16:11:30 -08:00 |
|
Tom Eastep
|
3a2173ddb4
|
Some code cleanup in Tc.pm.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-18 15:56:59 -08:00 |
|
Tom Eastep
|
ea8be87720
|
Use Hex representation of device numbers > 9 in simple TC.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-18 12:53:01 -08:00 |
|
Tom Eastep
|
00b0490cd7
|
Create a unique hashtable for each instance of a per-IP rate limit
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-17 15:39:21 -08:00 |
|
Tom Eastep
|
625963a4f0
|
Final (hopefully) fix for SFQ handle assignment
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-17 09:02:18 -08:00 |
|
Tom Eastep
|
41bb0782a3
|
Another tweak to SFQ handle assignment.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-17 08:06:27 -08:00 |
|
Tom Eastep
|
5649dbf9a8
|
Improve assignment of class ID for SFQ classses
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-17 07:41:30 -08:00 |
|
Tom Eastep
|
eaafeb8c2b
|
Add --hashlimit-htable-expire if the units are minutes or larger
|
2010-02-17 06:43:52 -08:00 |
|
Tom Eastep
|
375160d733
|
Avoid duplicate SFQ class numbers
|
2010-02-17 06:43:16 -08:00 |
|
Tom Eastep
|
167b29c2c5
|
Bump module version in Compiler.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-15 14:24:52 -08:00 |
|
Tom Eastep
|
8aaf4aab3a
|
Don't create log chain for 'RETURN' rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-15 14:24:00 -08:00 |
|
Tom Eastep
|
4546394531
|
Cosmetic changes to Compiler.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-15 14:07:35 -08:00 |
|
Tom Eastep
|
12d3420a5d
|
Detect FLOW_FILTER when LOAD_HELPERS_ONLY=No
|
2010-02-14 10:34:19 -08:00 |
|
Tom Eastep
|
5e9ecf1491
|
Update version of Config module
|
2010-02-13 11:00:34 -08:00 |
|
Tom Eastep
|
50d246c8be
|
A little cleanup of compiler.pl
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-13 10:03:32 -08:00 |
|
Tom Eastep
|
1258149e0e
|
Don't apply rate limiting twice in NAT rules
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-13 07:21:27 -08:00 |
|
Tom Eastep
|
ea5a6c79bc
|
Bump CAPVERSION
|
2010-02-11 16:22:47 -08:00 |
|
Tom Eastep
|
5a96771e07
|
Start 4.4.8 Beta 1
|
2010-02-11 15:46:57 -08:00 |
|
Tom Eastep
|
b35f20b403
|
Avoid CAPVERSION bump to implement FLOW_FILTER detection
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-11 07:29:41 -08:00 |
|
Tom Eastep
|
b8c195f570
|
Accurately detect 'flow' availability
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-10 14:50:26 -08:00 |
|
Tom Eastep
|
433fc385bc
|
'bridge' implies 'routeback'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-09 14:04:36 -08:00 |
|
Tom Eastep
|
46e2afcf16
|
Ignore TYPE if old distro
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-08 07:13:20 -08:00 |
|
Tom Eastep
|
b45a70f98a
|
Make 'nosmurfs' work correctly on IPv6 with Address Type Match
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-08 07:12:58 -08:00 |
|
Tom Eastep
|
18d03a61f5
|
Make 'nosmurfs' work with Address Type Match on IPv6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-07 08:43:31 -08:00 |
|
Tom Eastep
|
11a2ec9f7c
|
Update version to 4.4.7
|
2010-02-05 16:40:48 -08:00 |
|
Tom Eastep
|
e64af57cae
|
Give smurf logging chain a fixed name.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-03 16:04:59 -08:00 |
|
Tom Eastep
|
f4e175f149
|
Fix IPv6 'nosmurfs'. Make 'nosmurfs' logging more efficient.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-03 15:03:15 -08:00 |
|
Tom Eastep
|
52880a8822
|
Clean up generate_matrix() fix.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-03 06:57:51 -08:00 |
|
Tom Eastep
|
9d288241da
|
Fix issues in generate_matrix().
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-02 19:42:54 -08:00 |
|
Tom Eastep
|
1d8a7ad09f
|
Clear DEBUG and PURGE shell variables
Delete a blank line
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-02 13:55:29 -08:00 |
|
Tom Eastep
|
753eb97667
|
Update version to 4.4.7 RC2
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-02 10:30:53 -08:00 |
|
Tom Eastep
|
dd60f04a9f
|
Work around lack of MARK Target support
|
2010-02-01 16:22:57 -08:00 |
|
Tom Eastep
|
d354560863
|
Finish last change.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-01 14:25:51 -08:00 |
|
Tom Eastep
|
f0d101605b
|
Don't try to combine nat chains that include '-s'.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-02-01 14:24:07 -08:00 |
|
Tom Eastep
|
1981372c94
|
Make search for "-j ACCEPT" a little tighter
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-31 08:27:30 -08:00 |
|
Tom Eastep
|
3d39a47582
|
Set $have_ipsec after completing parse of the hosts file.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-30 07:26:35 -08:00 |
|
Tom Eastep
|
659f774451
|
Sort %detect_capability for easier verification.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-29 13:09:53 -08:00 |
|
Tom Eastep
|
9d2decd26d
|
Modify determine_capabilities to use detect_capability()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-29 10:38:22 -08:00 |
|
Tom Eastep
|
b8ec2be516
|
Clean up handling of %detect_capability
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-28 16:39:45 -08:00 |
|
Tom Eastep
|
ecc7861115
|
Validate LOAD_HELPERS_ONLY before detecting capabilities.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-28 08:05:24 -08:00 |
|
Tom Eastep
|
ebd847ef70
|
Don't display capabilties if they have not been determined
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-28 08:04:54 -08:00 |
|
Tom Eastep
|
05f2bb4b3a
|
Correction to last patch.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-27 17:52:27 -08:00 |
|
Tom Eastep
|
9d25318d80
|
Fix detection of HASHLIMIT_MATCH on old kernels.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-27 12:53:31 -08:00 |
|
Tom Eastep
|
54456de888
|
Update module versions
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-27 09:01:00 -08:00 |
|
Tom Eastep
|
c05c1a6f50
|
Update version to 4.4.7 RC1
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-27 06:58:44 -08:00 |
|
Tom Eastep
|
1556002b54
|
A couple of tweaks to the LOAD_HELPERS_ONLY optimization change.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-25 15:59:31 -08:00 |
|
Tom Eastep
|
fb007bc1c7
|
Bump version to Beta 4
|
2010-01-25 12:25:01 -08:00 |
|
Tom Eastep
|
9408a114c6
|
Don't load unused modules when LOAD_HELPERS_ONLY=Yes
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-25 10:50:49 -08:00 |
|
Tom Eastep
|
d933aa602b
|
Eliminate 'ORIGINAL_POLICY_MATCH'
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-25 08:13:22 -08:00 |
|
Tom Eastep
|
90b68a05de
|
Don't export %capabilities
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-25 07:56:16 -08:00 |
|
Tom Eastep
|
bfdc6719c1
|
Fix DropBcasts()
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-24 12:16:15 -08:00 |
|
Tom Eastep
|
e14d48c2cf
|
Bump version to 4.4.7-Beta3
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-22 16:46:29 -08:00 |
|
Tom Eastep
|
0d63182ab4
|
Fix ambiguous syntax in Config.pm
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-22 16:44:45 -08:00 |
|
Tom Eastep
|
199a50e1c7
|
Update version to 4.4.7 Beta 2
Add problems corrected to the release notes.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-22 10:35:27 -08:00 |
|
Tom Eastep
|
8f85c75264
|
Implement LOAD_HELPERS_ONLY for IPv6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-21 15:49:44 -08:00 |
|
Tom Eastep
|
efc43b1b24
|
Add implementation of LOAD_HELPERS_ONLY
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-21 15:49:35 -08:00 |
|
Tom Eastep
|
a248acb4d4
|
Add LOAD_HELPERS_ONLY Option
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-21 15:49:23 -08:00 |
|
Tom Eastep
|
e119037dea
|
Make 'is_isable()' work with 'lo'
|
2010-01-17 15:38:20 -08:00 |
|
Tom Eastep
|
f072c10b18
|
Set version to 4.4.7 Beta1
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-17 09:10:48 -08:00 |
|
Tom Eastep
|
f4102417ff
|
Shorewall::Config changes for TPROXY from 4.5
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-17 08:15:14 -08:00 |
|
Tom Eastep
|
07cdb8ca82
|
Backport TPROXY from 4.5
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-17 08:12:44 -08:00 |
|
Tom Eastep
|
47007c5dbd
|
Allow protocol to be expressed in octal or hex
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-16 14:20:47 -08:00 |
|
Tom Eastep
|
aad8ea837a
|
Allow port numbers to be specified in Hex
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-16 14:00:47 -08:00 |
|
Tom Eastep
|
5ec7759d81
|
Don't pass an undefined value to fatal_error when numeric conversion fails.
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-16 12:35:18 -08:00 |
|
Tom Eastep
|
4bf0b8e1dd
|
Add new configuration options and optimization changes from 4.5
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-16 09:53:53 -08:00 |
|
Tom Eastep
|
d5cc302ad9
|
Start 4.4.7
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-16 08:11:13 -08:00 |
|
Tom Eastep
|
ebf1e55609
|
Version to 4.4.6
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-13 15:38:19 -08:00 |
|
Tom Eastep
|
880cd269c7
|
More mark geometry misses
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-13 12:16:40 -08:00 |
|
Tom Eastep
|
72de96760f
|
One more 0xFF -> $globals{TC_MASK} fix
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-13 12:11:00 -08:00 |
|
Tom Eastep
|
10c5630786
|
A few more instances of TC_MASK
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-13 10:50:14 -08:00 |
|
Tom Eastep
|
555133fa3c
|
Bump version to 4.4.6-Beta2
Signed-off-by: Tom Eastep <teastep@shorewall.net>
|
2010-01-13 10:14:31 -08:00 |
|