| Commit message (Collapse) | Author | Age | Files | Lines |
|
|
|
| |
discussion on security@freebsd.org.
|
|
|
|
|
|
| |
it according to ancient and obsolete rules.
This removes one more user of <sys/diskslice.h>
|
| |
|
|
|
|
|
|
| |
doesn't have a process group, which can occur if you're working with
a custom init that doesn't set up a full tty context. Rather than
refusing to reboot, ignore ESRCH from the kill attempt in reboot(8).
|
|
|
|
| |
RFC3514 poses an unacceptale risk to compliant systems.
|
| |
|
|
|
|
|
|
|
| |
combinations of mdconfig(8) command-line arguments.
Make mdconfig(8) accept "-a -f file -o options"
equally with "-a -f file" (assuming "-t vnode".)
|
|
|
|
|
|
| |
in a saved disklabel file.
MFC after: 1 week
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
(See: ftp://ftp.rfc-editor.org/in-notes/rfc3514.txt)
This fulfills the host requirements for userland support by
way of the setsockopt() IP_EVIL_INTENT message.
There are three sysctl tunables provided to govern system behavior.
net.inet.ip.rfc3514:
Enables support for rfc3514. As this is an
Informational RFC and support is not yet widespread
this option is disabled by default.
net.inet.ip.hear_no_evil
If set the host will discard all received evil packets.
net.inet.ip.speak_no_evil
If set the host will discard all transmitted evil packets.
The IP statistics counter 'ips_evil' (available via 'netstat') provides
information on the number of 'evil' packets recieved.
For reference, the '-E' option to 'ping' has been provided to demonstrate
and test the implementation.
|
|
|
|
| |
people should be OK.
|
|
|
|
|
|
|
| |
512 for sectorsize.
63 for sectors.
255 for heads.
This will mostly show up on MD(4) devices.
|
| |
|
| |
|
|
|
|
|
|
| |
- Provide function prototypes.
Submitted by: trhodes
|
|
|
|
| |
Submitted by: trhodes
|
| |
|
| |
|
|
|
|
| |
- Retire Traps array; this was obsoleted in 1.2
|
| |
|
|
|
|
|
| |
PR: docs/50049
Submitted by: Colin Percival <cperciva@sfu.ca>
|
|
|
|
|
| |
- Reformat log output.
- Consolidate PDU printing code into print_pdu().
|
| |
|
| |
|
|
|
|
|
|
|
| |
- Deal with MADGE_OBJECT1 requests.
- Move code inside of switch cases to separate functions.
Submitted by: Richard Hodges <rh@matriplex.com>
|
|
|
|
| |
Submitted by: Richard Hodges <rh@matriplex.com>
|
|
|
|
|
|
|
| |
- Add an Objid definition for MADGE_OBJECT1
- Add an array to map ilmi_states to ASCII descriptions.
Submitted by: Richard Hodges <rh@matriplex.com>
|
|
|
|
| |
Submitted by: Richard Hodges <rh@matriplex.com>
|
|
|
|
|
| |
PR: 50294
Submitted by: Sergey A. Osokin <osa@FreeBSD.org.ru>
|
|
|
|
| |
Submitted by: KONDOU Kazuhiro <kazuhiro@alib.jp>
|
| |
|
|
|
|
|
| |
without a full make release cycle fails as the correct include path
isn't setup.
|
|
|
|
|
|
|
| |
address families.
This is useful for preventing NFS mounts from using IPv6 on hosts
that have both A and AAAA records for the same name.
|
|
|
|
| |
- WARNS=2
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
- Correct some problems with packet construction.
+--------+------------+----------+-------------+---------+
| | | | | |
| IP Hdr | MINICMPLEN | phdr_len | TIMEVAL_LEN | payload |
| | | | | |
+--------+------------+----------+-------------+---------+
| | | |
|<- IP ->|<------- ICMP -------->|<------ datalen ------>|
My previous changes tried to mess around with 'datalen' instead of
modifying 'phdr_len'.
I'm including this nice ASCII diagram (from Maxim) to further clarify things
in CVS history.
Submitted by: Maxim Konovalov <maxim@macomnet.ru>
|
|
|
|
|
|
|
|
| |
when WARNS was increased recently, but __printf0like() has been
temporarily disabled for 8 months.
Fixed related style bugs (disordered declaraction and silly type for
maxpayload -- assume 16-bit ints like the rest of ping.c).
|
|
|
|
|
|
|
|
|
|
| |
- Use it in atacontrol(8) when listing ATA devices instead of
stopping at the first ENXIO received.
This makes atacontrol list work on my sparc64 where the two ATA
channels I have are numbered 2 and 3.
Reviewed by: sos
|
|
|
|
|
|
|
|
|
|
| |
This is aimed at creating floppies during cross-releases.
For different endianness machines, a tool like bswapfs(8)
is necessary to make the generated floppies readable on
the target machine. While here, fixed unaligned access
on Alphas.
Tested on: i386, alpha
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Notable changes:
- Removed the "disktype" argument from the -B only synopsis
form. This form doesn't touch the disk label, and doesn't
use this argument.
- Fixed the first example in the EXAMPLES section. Support
for compatibility slices has been recently dropped from
the GEOM kernels, and a bit later GEOM became standard.
- Removed the buggy notion from rev. 1.37 that disklabel(8)
may be used to define mount points; it cannot. Improve
some DOS partition / FreeBSD slice wording. Among these,
``dangerously-dedicated slice'' was just a nonsense. ;-)
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
comes in on is the same interface that we would route out of to get to
the packet's source address. Essentially automates an anti-spoofing
check using the information in the routing table.
Experimental. The usage and rule format for the feature may still be
subject to change.
|
| |
|
|
|
|
| |
Submitted by: bde
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
width of fields for packets and bytes counters.
PR: bin/47196
Reviewed by: -audit
Not objected by: luigi, des
o Use %llu instead of deprecated %qu convert specification for ipfw
packets and bytes counters.
Noted by: des
MFC after: 1 month
|
|
|
|
| |
Prodded by: bde
|
|
|
|
| |
instead of NS.
|
| |
|
|
|
|
| |
disappear soon. Exporting the softc in the first place is a mistake.
|
|
|
|
|
| |
Reviewed by: -audit (no objections ~1mo)
Approved by: nectar
|