* BSDI: delete all cloned routes underneath the route. * FreeBSD: delete all protocol-cloned routes underneath the route. * note that cloned routes from an interface direct route * still remain. * NetBSD, OpenBSD: no side effects.
we need it for encrypted NFS (sync better with netbsd-current).
before /usr gets mounted (no effect for kame - sync with netbsd-current).
now pre-shared key file (psk.txt) is required to be owned by the uid running racoon (= root), and must not be accessible by others (like 0400).
spacing between sentences right.
we may want to add safefile() calls to other locations as well. (like certificates)
…stems. not sure why we don't use SS_PRIV here. corrects breakage of freebsd2 inetd (can't bind(2) to privileged IPv6 port).
* kame/sys/netinet6/nd6_rtr.c (in6_ifadd): made sure to gain a reference counter to in6_ifaddr for the autoconfigured address in bsdi and freebsd2 cases. This fix would be important to those OSes, since the older code woulde cause duplicated free when the lifetime for the address expired.
* kame/kame/dhcp6/common.c (getifaddr): corrected arguments to in6_addrscopebyif(). In response to a report from Hajimu UMEMOTO<email@example.com>
when IPsec-SA negotiation fail.