Permalink
Commits on Jun 13, 2000
  1. make it compilable.

    sakane committed Jun 13, 2000
  2. forgot to add important file...

    itojun committed Jun 13, 2000
  3. * - side effects of rtrequest[1](RTM_DELETE)

     *	BSDI[34]: delete all cloned routes underneath the route.
     *	FreeBSD[234]: delete all protocol-cloned routes underneath the route.
     *		      note that cloned routes from an interface direct route
     *		      still remain.
     *	NetBSD, OpenBSD: no side effects.
    jinmei committed Jun 13, 2000
  4. do not install scriptdump, since we don't have perl interpreter in ba…

    …se system.
    itojun committed Jun 13, 2000
  5. * netbsd/sbin/setkey: move setkey from usr.sbin/setkey to sbin/setkey.

      we need it for encrypted NFS (sync better with netbsd-current).
    itojun committed Jun 13, 2000
  6. move setkey to sbin.

    itojun committed Jun 13, 2000
  7. setkey will move to sbin, since we need to setup keys for NFS traffic

    before /usr gets mounted (no effect for kame - sync with netbsd-current).
    itojun committed Jun 13, 2000
  8. * kame/racoon/safefile.c: be more picky about secret file permission.

      now pre-shared key file (psk.txt) is required to be owned by the
      uid running racoon (= root), and must not be accessible by others
      (like 0400).
    itojun committed Jun 13, 2000
  9. document psk.txt permission restriction.

    itojun committed Jun 13, 2000
  10. nroff correction. ALWAYS break line after terminating period to get the

    spacing between sentences right.
    itojun committed Jun 13, 2000
  11. add safefile.c

    itojun committed Jun 13, 2000
  12. do not permit opening psk.txt with insufficient permission.

    we may want to add safefile() calls to other locations as well.
    (like certificates)
    itojun committed Jun 13, 2000
  13. avoid duplicated define for INET6

    itojun committed Jun 13, 2000
  14. add comment for privileged port check.

    itojun committed Jun 13, 2000
  15. in_pcbbind() uses suser() for privilege control, for all operating sy…

    …stems.
    
    not sure why we don't use SS_PRIV here.
    
    corrects breakage of freebsd2 inetd (can't bind(2) to privileged IPv6 port).
    itojun committed Jun 13, 2000
  16. sys/netkey/key.c fix for SADB_X_SA2.

    itojun committed Jun 13, 2000
  17. pim6dd also seems OK.

    jinmei committed Jun 13, 2000
  18. style nit

    itojun committed Jun 13, 2000
  19. 2000-06-13 JINMEI, Tatuya <jinmei@isl.rdc.toshiba.co.jp>

    	* kame/sys/netinet6/nd6_rtr.c (in6_ifadd): made sure to gain a
    	reference counter to in6_ifaddr for the autoconfigured address
    	in bsdi and freebsd2 cases.
    	This fix would be important to those OSes, since the older code
    	woulde cause duplicated free when the lifetime for the address
    	expired.
    jinmei committed Jun 13, 2000
  20. more correction for ifa_refcnt.

    itojun committed Jun 13, 2000
  21. (in6_ifadd) gain ifa_refcnt regardless of OSes

    (I believe this is correct, but please check it > itojun?)
    jinmei committed Jun 13, 2000
  22. correct netbsd-current ipsec date stamp

    itojun committed Jun 13, 2000
  23. 2000-06-13 JINMEI, Tatuya <jinmei@isl.rdc.toshiba.co.jp>

    	* kame/kame/dhcp6/common.c (getifaddr): corrected arguments to
    	in6_addrscopebyif().
    	In response to a report from Hajimu UMEMOTO<ume@bisd.hitachi.co.jp>
    jinmei committed Jun 13, 2000
  24. corrected arguments to in6_addrscopebyif().

    from ume@bisd.hitachi.co.jp
    jinmei committed Jun 13, 2000
Commits on Jun 12, 2000
  1. * kame/kame/racoon:

    send error message against sadb_acquire message to the kernel
    when IPsec-SA negotiation fail.
    sakane committed Jun 12, 2000
  2. fix the counter to check existent of phase 1 sa.

    sakane committed Jun 12, 2000
  3. add a row for IPv6 NFS

    itojun committed Jun 12, 2000
  4. send error message against sadb_acquire message to the kernel

    when IPsec-SA negotiation fail.
    sakane committed Jun 12, 2000