Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Unifies libip[6]t_limit.c into libxt_limit.c. | Yasuyuki KOZAKAI | 2007-07-24 | 5 | -249/+51 |
| | |||||
* | Unifies libip[6]t_mac.c into libxt_mac.c | Yasuyuki KOZAKAI | 2007-07-24 | 4 | -154/+40 |
| | |||||
* | Unifies libip[6]t_physdev.c into libxt_physdev.c | Yasuyuki KOZAKAI | 2007-07-24 | 6 | -295/+97 |
| | |||||
* | Add IPv6 support to pkttype match | Yasuyuki KOZAKAI | 2007-07-24 | 4 | -22/+38 |
| | |||||
* | Add IPv6 support to quota match | Yasuyuki KOZAKAI | 2007-07-24 | 2 | -6/+22 |
| | |||||
* | Unifies libip[6]t_sctp.c into libxt_sctp.c | Yasuyuki KOZAKAI | 2007-07-24 | 5 | -588/+50 |
| | |||||
* | Unifies libip[6]t_standard.c into libxt_standard.c | Yasuyuki KOZAKAI | 2007-07-24 | 3 | -74/+27 |
| | |||||
* | Unifies libip[6]t_tcp.c into libxt_tcp.c. | Yasuyuki KOZAKAI | 2007-07-24 | 3 | -447/+49 |
| | |||||
* | Add IPv6 support to tcpmss match | Yasuyuki KOZAKAI | 2007-07-24 | 4 | -23/+40 |
| | |||||
* | Unifies libip[6]t_udp.c into libxt_udp.c | Yasuyuki KOZAKAI | 2007-07-24 | 4 | -249/+76 |
| | |||||
* | Unifies libip[6]_mark.c into libxt_mark.c | Yasuyuki KOZAKAI | 2007-07-24 | 4 | -135/+19 |
| | |||||
* | Use unified API in libipt_mark.c | Yasuyuki KOZAKAI | 2007-07-24 | 3 | -18/+19 |
| | |||||
* | Add IPv6 support to string match | Yasuyuki KOZAKAI | 2007-07-24 | 1 | -0/+16 |
| | |||||
* | Moves libipt_string.c to libxt_string.c | Yasuyuki KOZAKAI | 2007-07-24 | 3 | -2/+3 |
| | |||||
* | Use unified API in string match | Yasuyuki KOZAKAI | 2007-07-24 | 1 | -20/+21 |
| | |||||
* | Unifies libip[6]t_multiport.c into libipxt_multiport.c | Yasuyuki KOZAKAI | 2007-07-24 | 5 | -524/+86 |
| | |||||
* | Moves libipt_multiport.c to libxt_multiport.c | Yasuyuki KOZAKAI | 2007-07-24 | 2 | -2/+2 |
| | |||||
* | Splits ipt_multport into family dependent parts and others | Yasuyuki KOZAKAI | 2007-07-24 | 1 | -34/+68 |
| | |||||
* | Use unified API in multiport match | Yasuyuki KOZAKAI | 2007-07-24 | 2 | -46/+80 |
| | |||||
* | Add IPv6 support to NOTRACK | Yasuyuki KOZAKAI | 2007-07-24 | 1 | -0/+16 |
| | |||||
* | Renames libipt_NOTRACK.c to libxt_NOTRACK.c | Yasuyuki KOZAKAI | 2007-07-24 | 2 | -1/+2 |
| | |||||
* | Use unified API in NOTRACK target. | Yasuyuki KOZAKAI | 2007-07-24 | 1 | -16/+15 |
| | |||||
* | Moves all declarations in iptables_common.h to xtables.h. | Yasuyuki KOZAKAI | 2007-07-24 | 6 | -41/+32 |
| | |||||
* | Installs libxt_*.so to DEST_IPT_LIBIDR and link libip[6]t_*.so to it. | Yasuyuki KOZAKAI | 2007-07-24 | 1 | -0/+26 |
| | |||||
* | Introduces DEST_IPT_LIBDIR to simplify $(DESTDIR)$(LIBDIR)/iptables | Yasuyuki KOZAKAI | 2007-07-24 | 2 | -8/+10 |
| | |||||
* | Fixes warning on compilation, part 2 | Yasuyuki KOZAKAI | 2007-07-24 | 6 | -29/+46 |
| | | | | | | | | | | This changes the type of arguments as follows in multiport, DNAT, SNAT, MASQUERADE, and REDIRECT - ip[6]t_ip[6] * -> void * - ip[6]t_entry * -> void * and adds lines to cast these pointer with intended type. | ||||
* | Fixes warning on compilation of ip6tables matches/targets | Yasuyuki KOZAKAI | 2007-07-24 | 36 | -107/+107 |
| | | | | | | This changes the type of arguments as follows - ip6t_ip6 * -> void * - ip6t_entry * -> void * | ||||
* | Fixes warning on compilation of iptables matches/targets | Yasuyuki KOZAKAI | 2007-07-24 | 60 | -177/+177 |
| | | | | | | | | | This changes the type of arguments as follows - ipt_ip * -> void * - ipt_entry * -> void * This patch doesn't change multiport, DNAT, SNAT, MASQUERADE, REDIRECT because these need more changes (casting void * variable with intended type) | ||||
* | Replaces ip6t_entry_* with xt_entry_* in matches/targets | Yasuyuki KOZAKAI | 2007-07-24 | 34 | -128/+127 |
| | |||||
* | Replaces ipt_entry_* with xt_entry_* in matches/targets | Yasuyuki KOZAKAI | 2007-07-24 | 64 | -237/+237 |
| | |||||
* | Moves IPPROTO_* and IP[6]T_LIB_DIR definitions to xtables.h | Yasuyuki KOZAKAI | 2007-07-24 | 3 | -22/+16 |
| | |||||
* | Moves some duplicated functions in ip[6]tables.c to xtables.c | Yasuyuki KOZAKAI | 2007-07-24 | 7 | -230/+120 |
| | | | | | string_to_number_ll, string_to_number_l, string_to_number, service_to_port, parse_port, parse_interface, are moved. | ||||
* | Introduces xtables match/target registration | Yasuyuki KOZAKAI | 2007-07-24 | 11 | -875/+728 |
| | | | | | | | | | | | | | | | | | | | | | | | - moves lib_dir to xtables.c - introduces struct pfinfo which has protocol family dependent infomations. - unifies load_ip[6]tables_ko() and moves them as load_xtables_ko() - introduces xt_{match,match_rule,target,tryload} and replaces ip[6]t_* with them - unifies following functions and move them to xtables.c - find_{match,find_target} - compatible_revision, compatible_{match,target}_revision - introduces xtables_register_{match,target} and make register_{match,target}[6] call them. xtables_register_* register ONLY matches/targets matched protocol family Some concepts: - source compatibility for libip[6]t_xxx.c with warning on compilation not binary compatibility. - binary compatibility between 2.4/2.6 kernel and iptables/ip6tables, of cause. - xtables is enough to support only one address family at runtime. Then xtables keeps infomations of only the focused address famiy in struct afinfo. | ||||
* | Moves ip[6]tables_insmod() to xtables.c as xtables_insmod() | Yasuyuki KOZAKAI | 2007-07-24 | 8 | -167/+94 |
| | |||||
* | Moves common fw_malloc() and fw_calloc() to xtables.c | Yasuyuki KOZAKAI | 2007-07-24 | 4 | -48/+35 |
| | |||||
* | Adds xtables.[ch] and change Makefile to compile it | Yasuyuki KOZAKAI | 2007-07-24 | 3 | -7/+30 |
| | |||||
* | iptables-xml | Sam Liddicott | 2007-07-17 | 3 | -3/+117 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Attached are: 1. A man page for iptables-xml 2. A fix for iptables.xslt allowing for an arbitrary depth of arguments or modifiers. Although iptables-xml cannot generate more than two levels deep, xml generated by other systems may prefer to generate <action> <restore-mark> <mask>0xff00</mask> </restore-mark> </action> than <action> <restore-mark/> <mask>0xff00</mask> </action> (which is what iptables-xml generates) even though the same iptables is re-generated on conversion. 3. A fix for iptables-xml.c so that combining of consecutive targets of rules with the same match into one XML rule, will not combine over a terminating action; i.e. there is no point in converting -A table -p tcp -j DROP -A table -p tcp -j MARK --set-mark 25 -A table -p tcp -j RETURN into one XML rule with multiple actions as they are probably not logically combined in the mind of the author. Signed-off by: Sam Liddicott <azez@ufomechanic.net> | ||||
* | Ignore generated files | Patrick McHardyYasuyuki KOZAKAI | 2007-07-16 | 0 | -0/+0 |
| | |||||
* | Adds missing explanations about FIN in mask part of '--syn' in libip[6]_tcp.c | Patrick McHardyYasuyuki KOZAKAI | 2007-07-16 | 3 | -3/+3 |
| | | | | and libip6t_tcp.man. | ||||
* | Adds missing FIN to mask part generated by '--syn' of libip6t_tcp | Yasuyuki KOZAKAI | 2007-07-16 | 2 | -2/+2 |
| | |||||
* | Change default KERNEL_DIR location and add KBUILD_OUTPUT (Sven Wegener ↵ | Sven Wegener | 2007-07-15 | 1 | -2/+8 |
| | | | | <sven.wegener@stealer.net>) | ||||
* | Fixes compile error of connlimit where NO_SHARED_LIBS=1 is specified | Yasuyuki KOZAKAI | 2007-07-13 | 2 | -2/+2 |
| | |||||
* | PATCH: Add connlimit to iptables. | Jan Engelhardt | 2007-07-09 | 6 | -2/+352 |
| | | | | Signed-off-by: Jan Engelhardt <jengelh@gmx.de> | ||||
* | libipt_statistic: add a few missing validity checks | Nicolas Bouliane | 2007-07-03 | 1 | -0/+9 |
| | | | | Signed-off-by: Nicolas Bouliane | ||||
* | Removes KERNEL_64_USERSPACE_32 | Yasuyuki KOZAKAI | 2007-06-30 | 6 | -124/+0 |
| | | | | | | | The recent kernel has compat layer for iptables. It doesn't have compat layer for libipq and ip6tables, but ip6tables with KERNEL_64_USERSPACE_32 is still broken. We should fix kernel instead of fixing them if and when we want use their 32bit binary with 64bit kernel. | ||||
* | Removes some KERNEL_64_USERSPACE_32 because linux 2.6 has compat layer | Yasuyuki KOZAKAI | 2007-06-28 | 16 | -167/+3 |
| | |||||
* | Fix "iptables getsockopt failed strangely" when querying revisions for ↵ | Patrick McHardy | 2007-06-26 | 2 | -2/+2 |
| | | | | | | non-existant matches and targets Reported by Joseph Jezak <josejx@gentoo.org>. | ||||
* | Add Jozsef's TRACE target. | Patrick McHardy | 2007-06-25 | 5 | -2/+148 |
| | | | | | Changed to be built unconditionally by myself since it doesn't need any headerfiles anyways. | ||||
* | bump versionv1.3.8 | Pablo Neira Ayuso | 2007-06-25 | 1 | -2/+2 |
| | |||||
* | Fixes build error of conntrack match because of missing ip_conntrack_tuple.h | Yasuyuki KOZAKAI | 2007-06-24 | 1 | -1/+0 |
| | | | | | in linux 2.6.22. It is not needed because nf_conntrack headers can be used instead. |