Jan Engelhardt
3f96deb0f0
iface: remove define for internal array size
...
The macro was only used inside kernel code and not relevant to
user-space anyway.
2009-04-26 22:07:53 +02:00
Jan Engelhardt
6d8ce3acae
iface: dissolve module name/revision macros
...
The module name will unlikely be changing anytime soon. And if the
revision increases, we cannot just bump the number (well, in
Xtables-addons we can, but it would not be the case for the core
kernel). So let's not get into bad habits.
2009-04-26 22:07:43 +02:00
Jan Engelhardt
f6c317710f
iface: remove version/revision from helptext
...
XTABLES_VERSION does not contain anything meaningful to display.
Printing the revision is not of value too, I think.
2009-04-26 22:01:30 +02:00
Jan Engelhardt
6799806300
iface: use NFPROTO_*
2009-04-26 21:59:41 +02:00
Jan Engelhardt
0d36136f54
iface: some command decoupling
2009-04-26 21:56:53 +02:00
Jan Engelhardt
e1fc5f2086
iface: remove redundant parentheses
2009-04-26 21:56:25 +02:00
Jan Engelhardt
1aae519356
iface: remove DEBUGP
2009-04-05 10:59:12 +02:00
Jan Engelhardt
af5823b407
iface: remove redundant functions
2009-04-05 10:50:45 +02:00
Jan Engelhardt
9b198fe6e7
iface: import version 20081029
2009-04-05 10:37:05 +02:00
Jan Engelhardt
ba6aa51f91
SYSRQ: do proper L4 header access in IPv6 code
2009-03-27 21:06:26 +01:00
Jan Engelhardt
beb7546e20
SYSRQ: ignore non-UDP packets
2009-03-27 20:27:03 +01:00
Jan Engelhardt
67579079e0
layer: block use of DEBUGP
...
As per "Writing Netfilter Modules" e-book 20090326 section 4.8, one
should use pr_debug instead.
2009-03-27 00:00:44 +01:00
Jan Engelhardt
3a632a9bc5
dhcpmac: rename from dhcpaddr
2009-03-26 21:55:10 +01:00
Jan Engelhardt
45b2e64d82
desc: add informational Kconfig descriptions
2009-03-26 21:32:44 +01:00
Jan Engelhardt
538d74b5d8
Update my email address
2009-03-25 22:10:42 +01:00
Jan Engelhardt
e3988b50b5
Add the "STEAL" target from the "demos" branch
2009-03-25 19:54:25 +01:00
Jan Engelhardt
f4b8440fba
libxt_geoip: geoip: remove XT_ALIGN from .userspacesize when used with offsetof
...
XT_ALIGN rounds up to the nearest multiple of 64 bits, but that is wrong
for .userspacesize if it is less than .matchsize/.targetsize.
2009-03-24 08:27:41 +01:00
Changli Gao
d3ee3a0c3c
libxt_fuzzy: need to account for kernel-level modified variables in .userspacesize
...
When reviewing the code, I found there maybe a bug in libxt_fuzzy.c.
If a user wants to delete this match, he will get an error reported,
and the command fails. As the fields after maximum_rate in
xt_fuzzy_mtinfo will be altered in kernel space, we should assign the
userspacesize with the value offsetof(struct xt_fuzzy_mtinfo,
packets_total) instead.
2009-03-24 08:26:24 +01:00
Jan Engelhardt
a0c791dc88
Upgrade to iptables 1.4.3 API
2009-03-19 11:05:26 +01:00
Jan Engelhardt
8bd5fc14ba
libxt_ipv4options: add manpage
2009-03-19 10:34:27 +01:00
Jan Engelhardt
a51b16097b
Add a reworked IPv4 options match - xt_ipv4options
...
This revision 1 of ipv4options makes it possible to match the
presence or absence of any of the 32 possible IP options, either all
or any of the options the user specified.
2009-03-08 23:38:12 +01:00
Jan Engelhardt
e11a07b230
build: fix compile issues with <= 2.6.19
...
Resolve compile breakage from commits
36f80be2f7
and
7b9ca945d4
.
2009-03-07 02:58:36 +01:00
Jan Engelhardt
d263cfbd50
ipset: fast forward to 2.5.0
2009-03-07 01:33:31 +01:00
Jan Engelhardt
36f80be2f7
xt_TEE: enable routing by iif, nfmark and flowlabel
...
Patrick McHardy suggests in
http://marc.info/?l=netfilter-devel&m=123564267330117&w=2 that
routing should handle the clone more like its original.
2009-03-07 01:27:08 +01:00
Jan Engelhardt
7b9ca945d4
xt_LOGMARK: print incoming interface index
2009-03-07 01:15:48 +01:00
Jan Engelhardt
ffeb1da7d7
build: silence warning about ignored variable
...
The warning was:
config.status: WARNING: 'extensions/ipset/GNUmakefile.in'
seems to ignore the --datarootdir setting
2009-03-07 00:59:05 +01:00
Florian Westphal
d2d8712980
xt_TEE: resolve unknown symbol error with CONFIG_IPV6=n
...
WARNING: xt_TEE.ko needs unknown symbol ip6_route_output
Signed-off-by: Florian Westphal <fwestphal@astaro.com >
2009-03-07 00:48:16 +01:00
Jan Engelhardt
621cef39f5
revert "TEE: do not use TOS for routing"
...
Revert commit f77a8e2eda
.
Patrick McHardy suggests in
http://marc.info/?l=netfilter-devel&m=123564267330117&w=2 that
routing should handle the clone more like its original.
2009-03-05 02:03:06 +01:00
Jan Engelhardt
08e6f23655
xt_lscan: rename from xt_portscan
2009-03-05 01:43:29 +01:00
Jan Engelhardt
8c322a0119
ipset: replace RW_LOCK_UNLOCKED
...
ipset uses RW_LOCK_UNLOCKED directly, but this is not quite right,
and causes compilation errors with 2.6.29-rt.
2009-03-05 01:25:17 +01:00
Jan Engelhardt
ce03d0ee8e
build: make kbuild call obey V
2009-02-21 16:54:49 +01:00
Jan Engelhardt
47a34e0ccf
ipset: upgrade to ipset 2.4.9
2009-02-11 16:51:40 +01:00
Jan Engelhardt
36dab67658
Update .gitignore
2009-02-11 15:57:10 +01:00
Jan Engelhardt
7bb2957e47
compat: compile fixes for 2.6.29
...
2.6.29 removes at least NIP6, and NIPQUAD is scheduled to follow.
2009-02-11 15:56:33 +01:00
Jan Engelhardt
68af6989b1
ipset: bump version to 2.4.7
...
Moving from ipset 2.4.5 to 2.4.7. Upstream changed, but
the Xtables-addons copy did not (issues were not present):
>2.4.7
> - Typo which broke compilation with kernels < 2.6.28
> fixed (reported by Richard Lucassen, Danny Rawlins)
>
>2.4.6
> - Compatibility fix for kernels >= 2.6.28
2009-01-30 06:33:21 +01:00
Jan Engelhardt
446c67018a
TEE: remove calls to check_inverse
2009-01-30 06:19:22 +01:00
Jan Engelhardt
0fe8e180c4
ipp2p: version bump
...
For cosmetics, or so. The recent bugfix warrants this I'd say.
2009-01-30 06:02:10 +01:00
Jan Engelhardt
7cdfc0ac3d
Add xt_length2
...
xt_length2 provides exact layer-4,-5 and -7 length matching
besides the preexisting layer-3 length match.
2009-01-30 06:01:12 +01:00
Jan Engelhardt
61d8425cb6
Merge branch 'TEE6'
2009-01-10 14:03:04 +01:00
Jan Engelhardt
d49b6244c1
Merge branch 'TEE'
2009-01-10 14:03:03 +01:00
Jan Engelhardt
10c2b97786
Merge branch 'ipp2p'
2009-01-10 13:59:43 +01:00
Jan Engelhardt
9ed364ed36
TEE: collapse tee_tg_send{4,6}
2009-01-10 13:58:19 +01:00
Jan Engelhardt
b95e5f6417
TEE: IPv6 support for iptables module
2009-01-10 10:19:21 +01:00
Jan Engelhardt
4afebf88eb
Merge branch 'TEE' into TEE6
2009-01-10 10:01:31 +01:00
Jan Engelhardt
d523158e92
TEE: iptables -nL and -L produced conversely output
2009-01-10 10:01:27 +01:00
Jan Engelhardt
1fd1787a1c
TEE: limit iptables module to NFPROTO_IPV4
...
The code here is only usable with IPv4.
2009-01-10 09:57:44 +01:00
Jan Engelhardt
fbbca68790
ipp2p: partial revert of 3c8131b9
...
Revert part of 3c8131b976
.
The transport header offset is not (yet) set by the time Netfilter
is invoked so using tcp_hdr/udp_hdr has undefined behavior.
2009-01-10 08:25:42 +01:00
Jan Engelhardt
4cdfd49637
ipp2p: add boundary check in search_all_kazaa
...
To avoid underflow on "end - 18", we must check for plen >= 18.
2009-01-10 06:11:13 +01:00
Jan Engelhardt
31c01cf107
portscan: update manpage about --grscan caveats
2009-01-10 05:23:43 +01:00
Jan Engelhardt
879e964f60
ipp2p: remove log flooding
...
Syslog was flooded by lots of messages due to if (plen >= 5) firing
on any packet, when it should have been plen < 5. Incidentally, this
turned up that plen also takes on huge nonsense values, assuming
underflow - yet to be investigated.
2009-01-10 04:47:14 +01:00