oweals/firewall3.git
2013-08-14 Jo-Philipp... Revert "Make sure that NOTRACK is linked into firewall3...
2013-08-14 Jo-Philipp... Make sure that NOTRACK is linked into firewall3 if...
2013-07-16 Jo-Philipp... Treat redirects as port redirections if the specified...
2013-06-29 Jo-Philipp... Properly dereference struct ether_addr
2013-06-29 Jo-Philipp... Do not rely on ether_ntoa() when formatting mac addresses.
2013-06-18 Jo-Philipp... Don't mistreat unknown protocol names as "any protocol"
2013-06-18 Jo-Philipp... Fix processing of CIDRs with mask 0
2013-06-13 Jo-Philipp... Fix processing of negated options
2013-06-13 Jo-Philipp... Properly handle reject target in rules with specific...
2013-06-06 Jo-Philipp... Keep all basic chains on reload and only flush them...
2013-06-06 Jo-Philipp... Fix endian issue in compare_addr(), solves auto detecti...
2013-06-06 Jo-Philipp... For ingress rules, only jump into zone_name_src_ACTION...
2013-06-06 Jo-Philipp... Implement limit and limit_burst options for rules.
2013-06-05 Jo-Philipp... Use zone_name_src_ACTION chain for input rules with...
2013-06-05 Jo-Philipp... Extend ipset option syntax to support specifying direct...
2013-06-04 Jo-Philipp... Fix wrong signature of fw3_xt_print_matches()
2013-06-04 Jo-Philipp... Add abstract fw3_xt_print_matches() and fw3_xt_print_ta...
2013-06-04 Jo-Philipp... Fix wrong chain emitted for zone forward policy, the...
2013-06-03 Jo-Philipp... Decouple handle destroying from committing, add fw3_ipt...
2013-06-03 Jo-Philipp... Do not let libxtables implicitely load extensions,...
2013-05-27 Jo-Philipp... Make IPv6 support optional
2013-05-27 Jo-Philipp... Add abstract fw3_xt_reset() implementation
2013-05-27 Jo-Philipp... Dynamically create rules for available libext*.a librar...
2013-05-27 Jo-Philipp... Fix compatibility with older libiptc/libip6tc
2013-05-26 Jo-Philipp... Only emit different ip family warnings if the ip wasn...
2013-05-26 Jo-Philipp... Mark fw3_address objects that got resolved by fw3_parse...
2013-05-26 Jo-Philipp... Change wording of inferred destination warning for...
2013-05-26 Jo-Philipp... Replace fw3_free_zone() with the generic implementation
2013-05-26 Jo-Philipp... Avoid segfault when freeing rules whose target could...
2013-05-26 Jo-Philipp... Infer destination zone of DNAT redirects from dest_ip...
2013-05-26 Jo-Philipp... Add fw3_resolve_zone_addresses() helper to obtain a...
2013-05-26 Jo-Philipp... Remove fw3_ubus_address_free() and use fw3_free_list...
2013-05-26 Jo-Philipp... Add fw3_free_list() helper
2013-05-25 Jo-Philipp... Fix output rules with "option dest *"
2013-05-25 Jo-Philipp... Allow devices for src_ip, src_dip and dest_ip options
2013-05-24 Jo-Philipp... Pass -Wl,--whole-archive and -Wl,--no-whole-archive...
2013-05-23 Jo-Philipp... Don't leak memory when encountering unknown match or...
2013-05-23 Jo-Philipp... Use weak function pointers to call extension init funct...
2013-05-22 Jo-Philipp... Limit zone names to 14 bytes
2013-05-22 Jo-Philipp... Add required ipset declarations for kernels < 3.7
2013-05-22 Jo-Philipp... Further fixes for zone reloads
2013-05-22 Jo-Philipp... Only perform selective reload if firewall was already...
2013-05-21 Jo-Philipp... Fix another crash bug if ipsets are supported but none...
2013-05-21 Jo-Philipp... Fix rules for custom filter chains
2013-05-21 Jo-Philipp... Do not print to pipe or close command if nothing was...
2013-05-17 Jo-Philipp... Add missing libip6t_REJECT initialization
2013-05-17 Jo-Philipp... Only initialize extensions we actually use
2013-05-17 Jo-Philipp... Wait for ipsets to appear before continuing
2013-05-17 Jo-Philipp... Restore iptables-save include functionality
2013-05-17 Jo-Philipp... Also add comments for unnamed rules
2013-05-17 Jo-Philipp... Only process selected family for print
2013-05-17 Jo-Philipp... Include iptables command and table name in iptables...
2013-05-17 Jo-Philipp... Add debug prints for policy setting, don't commit rules...
2013-05-17 Jo-Philipp... Rename struct fw3_rule_spec to struct fw3_chain_spec...
2013-05-17 Jo-Philipp... Remove now unused fw3_pr_rulespec()
2013-05-17 Jo-Philipp... Remove now unused fw3_format_*() functions
2013-05-17 Jo-Philipp... Drop iptables-restore and create rules through libiptc...
2013-05-13 Jo-Philipp... Use libiptc to clear current ruleset
2013-05-08 Jo-Philipp... Force fsync() after writing statefile
2013-05-08 Jo-Philipp... Make reload atomic
2013-05-06 Jo-Philipp... Family "any" is not applicable to ipsets, default to...
2013-05-02 Jo-Philipp... Simplify ipset external checks and optionally initializ...
2013-05-02 Jo-Philipp... Check whether ipset exists before referencing it in...
2013-05-02 Jo-Philipp... Record device-network relation in state file, fix zone...
2013-04-30 Jo-Philipp... Record default policies in state file
2013-04-30 Jo-Philipp... Store ipset storage method and matches in state file...
2013-04-30 Jo-Philipp... Send quit comment in fw3_destroy_ipsets() and initializ...
2013-04-30 Jo-Philipp... Don't track family of ipsets
2013-04-30 Jo-Philipp... Fix parsing of ipset datatypes
2013-04-30 Jo-Philipp... Track ipsets in state file
2013-04-30 Jo-Philipp... Write statefile flags in hexadecimal format
2013-04-30 Jo-Philipp... Allow hex notation in int type options
2013-04-30 Jo-Philipp... Add common fw3_address_to_string() helper function
2013-04-30 Jo-Philipp... Remove referenced to unused FW3_FLAG_DELETED flag
2013-04-30 Jo-Philipp... Remove unused "running" argument form fw3_lookup_ipset()
2013-04-30 Jo-Philipp... Remove unused "running" argument form fw3_lookup_zone()
2013-04-30 Jo-Philipp... Split runtime and config states, store runtime state...
2013-04-09 Jo-Philipp... Add support for fwmark matches and targets
2013-03-22 Jo-Philipp... Increase compatibility to old firewall by initializing...
2013-03-22 Jo-Philipp... Fix parsing of '*' device and 'all' protocol value
2013-03-21 Jo-Philipp... Fix DNAT port remapping rules by not emitting 0.0.0...
2013-03-19 Jo-Philipp... Properly handle deleted zones and ipsets on restarts
2013-03-19 Jo-Philipp... Accept network names in per-zone subnet option
2013-03-19 Jo-Philipp... Also read addresses from "ipv6-prefix-assignment" ifsta...
2013-03-19 Jo-Philipp... Rework option parsing to support emitting multiple...
2013-03-19 Jo-Philipp... Implement support for "network" datatype and use it...
2013-03-18 Jo-Philipp... Do not accept option src_mac for SNAT rules
2013-03-14 Jo-Philipp... Consolidate and unify argument order for functions
2013-03-14 Jo-Philipp... Only perform locking for start, stop, restart, reload...
2013-03-14 Jo-Philipp... Implement reload option for includes to decide whether...
2013-03-13 Jo-Philipp... Make nat reflection src address configurable by introdu...
2013-03-13 Jo-Philipp... Emit hotplug calls when flushing / creating zone chains
2013-03-13 Jo-Philipp... Unify fw3_default and fw3_target enums
2013-03-12 Jo-Philipp... Track used networks and devices in state file
2013-03-12 Jo-Philipp... Unify print_chains() implementations in utils.c fw3_pr_...
2013-03-11 Jo-Philipp... Include limits.h to fix compilation against eglibc
2013-03-11 Jo-Philipp... Rework zone flush logic
2013-03-11 Jo-Philipp... Change fw3_no_family() macro to take bit field value...
2013-03-10 Jo-Philipp... Cosmetic output changes
2013-03-10 Jo-Philipp... Only run includes and set sysctls if either v4 or v6...
next