User Details
User Details
- User Since
- Sep 28 2014, 7:22 PM (539 w, 6 d)
Thu, Jan 30
Thu, Jan 30
if_ovpn: fix module load in NOINET6 kernels
kp committed rG491f5e37ae45: pf: add 'allow-related' to always allow SCTP multihome extra connections (authored by kp).
pf: add 'allow-related' to always allow SCTP multihome extra connections
kp committed rG4557b1693a11: pf: verify SCTP v_tag before updating connection state (authored by kp).
pf: verify SCTP v_tag before updating connection state
kp committed rGfc167e91313c: pf: verify that ABORT chunks are not mixed with DATA chunks (authored by kp).
pf: verify that ABORT chunks are not mixed with DATA chunks
pf: add extra SCTP multihoming probe points
Mon, Jan 27
Mon, Jan 27
netinet: enter epoch in garp_rexmit()
netinet: enter epoch in garp_rexmit()
Fri, Jan 24
Fri, Jan 24
pf: remove PFLOGIFS_MAX
pf: make reply-to work with nat64
kp committed rG06a6ec55fbd0: pf: ignore/preserve ECN bits on ToS matching and scrubbing (authored by kp).
pf: ignore/preserve ECN bits on ToS matching and scrubbing
pf: cope with route-to on af-to rules
pf: add a dedicated pf pool for route options
kp committed rG899e79760dcc: pfctl: allow an implicit address family for af-to rules (authored by kp).
pfctl: allow an implicit address family for af-to rules
carp: don't unintentionally revert to multicast mode
pf: check rather than assert pool type
pfctl: improve NAT pool handling
pfctl: follow rpool -> rdr rename
Thu, Jan 23
Thu, Jan 23
pf: fix IPv6 route lookup for nat64
Mon, Jan 20
Mon, Jan 20
pf: avoid use-after-free on reassembly
pf: avoid use-after-free on reassembly
netinet tests: basic garp test
netinet: enter epoch in garp_rexmit()
kp committed rG013784c967f9: netinet: virtualize net.link.ether.inet.garp_rexmit_count (authored by kp).
netinet: virtualize net.link.ether.inet.garp_rexmit_count
Sat, Jan 18
Sat, Jan 18
kp committed rG685cafd668f5: pf: allow ICMP messages related to an SCTP state to pass (authored by kp).
pf: allow ICMP messages related to an SCTP state to pass
Fri, Jan 17
Fri, Jan 17
kp committed rG7f846fc0e7ce: pf tests: reproduce use-after-free in fragment reassembly (authored by kp).
pf tests: reproduce use-after-free in fragment reassembly
dummymbuf: add 'enlarge'
pf: clean up mbuf passing for reassembly
kp committed rG4713d2fd5663: pf: verify SCTP v_tag before updating connection state (authored by kp).
pf: verify SCTP v_tag before updating connection state
kp committed rGe4f2733df8c9: pf: add 'allow-related' to always allow SCTP multihome extra connections (authored by kp).
pf: add 'allow-related' to always allow SCTP multihome extra connections
kp committed rG541ea3d7828e: pf: verify that ABORT chunks are not mixed with DATA chunks (authored by kp).
pf: verify that ABORT chunks are not mixed with DATA chunks
Thu, Jan 16
Thu, Jan 16
kp committed rG635c2b82f60e: pf tests: check cleared time when zeroing stats for table addresses (authored by leon_darkk.net.ru).
pf tests: check cleared time when zeroing stats for table addresses
kp committed rG3870483ec496: pf tests: check cleared time when zeroing stats for table addresses (authored by leon_darkk.net.ru).
pf tests: check cleared time when zeroing stats for table addresses
kp committed rG7c882c69a4f0: libpfctl: use snl_f_p_empty instead of declaring own empty array (authored by kp).
libpfctl: use snl_f_p_empty instead of declaring own empty array
Wed, Jan 15
Wed, Jan 15
pf: add extra SCTP multihoming probe points
kp requested review of D48460: libpfctl: use snl_f_p_empty instead of declaring own empty array.
Tue, Jan 14
Tue, Jan 14
pf: minor fixes for pf_walk_header6()
pf: reset index if it's outside the table
kp committed rG1941d370bf89: pf: pass struct pf_pdesc to pf_walk_option6() and pf_walk_header6() (authored by kp).
pf: pass struct pf_pdesc to pf_walk_option6() and pf_walk_header6()
kp committed rG3b79f6d2d394: pf: do not keep state when dropping overlapping IPv6 fragments (authored by kp).
pf: do not keep state when dropping overlapping IPv6 fragments
pf.conf.5: fix description for tcp.opening timeout
pfctl: convert an snprintf to strlcpy
kp committed rG6a3266f72e43: pf: drop IPv6 packets built from overlapping fragments in pf reassembly (authored by kp).
pf: drop IPv6 packets built from overlapping fragments in pf reassembly
pf.conf.5: make "self" a bit more visible
pf: remove pf_remove_fragment()
pf: simplify state key setup
pf improve the icmp direction check
pfctl: unbreak rule optimizer
pf: fixup af-to regression with match rules
pfctl: pfctl_set_hostid always returns 0
pf: convert DIOCRCLRTABLES to netlink
kp requested review of D48453: pf: add 'allow-related' to always allow SCTP multihome extra connections.
Sun, Jan 12
Sun, Jan 12
umtx: handle allocation failire in umtx_pi_alloc()
umtx: handle allocation failire in umtx_pi_alloc()
Sun, Jan 5
Sun, Jan 5
umtx: handle allocation failire in umtx_pi_alloc()
Sat, Jan 4
Sat, Jan 4
kp committed rG7d5e02b01577: pf: allow ICMP messages related to an SCTP state to pass (authored by kp).
pf: allow ICMP messages related to an SCTP state to pass
Fri, Jan 3
Fri, Jan 3
kp accepted D48306: pf: netlink KPI use cleanup.
That looks good. Nice little tidy-up.
Jan 2 2025
Jan 2 2025
kp committed rG0749d8134300: pf tests: check cleared time when zeroing stats for table addresses (authored by leon_darkk.net.ru).
pf tests: check cleared time when zeroing stats for table addresses
Dec 30 2024
Dec 30 2024
pf: fix double free in pf_state_key_attach()
if_ovpn: improve reconnect handling
pf: fix double free in pf_state_key_attach()
pf: initialise addresses in pf_get_transaddr_af()
kp committed rG54ead732cf08: pf: deduplicate IPPROTO_ICMPV6 and IPPROTO_ICMP handling (authored by kp).
pf: deduplicate IPPROTO_ICMPV6 and IPPROTO_ICMP handling
pf: sprinkle const over function arguments
pf: remove impossible condition
Dec 29 2024
Dec 29 2024
kp added a comment to D48242: pf (tests): Set cleared time when zeroing stats for table addresses.
I assume you're not entirely serious about the 'Sponsored by:' line?
I'm happy to credit any organisation for your work, but um .. it raises questions?
Dec 27 2024
Dec 27 2024
kp committed rG6c7cef47bdd0: pf: Set cleared time when zeroing stats for table addresses (authored by vegeta_tuxpowered.net).
pf: Set cleared time when zeroing stats for table addresses
kp committed rG1d673cc1fd82: pf: Set cleared time when zeroing stats for table addresses (authored by vegeta_tuxpowered.net).
pf: Set cleared time when zeroing stats for table addresses
Dec 24 2024
Dec 24 2024
kp committed rG13ea23ee6eeb: pf: fix potential NULL dereference in SCTP multihome handling (authored by kp).
pf: fix potential NULL dereference in SCTP multihome handling
kp committed rG30b9d8a73721: pfctl: add -T `reset` to touch pfras_tzero only for non-zero entries (authored by Leonid Evdokimov <leon+freebsd@darkk.net.ru>).
pfctl: add -T `reset` to touch pfras_tzero only for non-zero entries
kp committed rGfd8dadbe222a: pf: fix potential NULL dereference in SCTP multihome handling (authored by kp).
pf: fix potential NULL dereference in SCTP multihome handling
kp committed rG3fa5d13c5be0: pfctl: add -T `reset` to touch pfras_tzero only for non-zero entries (authored by Leonid Evdokimov <leon+freebsd@darkk.net.ru>).
pfctl: add -T `reset` to touch pfras_tzero only for non-zero entries
Dec 21 2024
Dec 21 2024
kp requested review of D48170: pf: allow ICMP messages related to an SCTP state to pass.
Dec 20 2024
Dec 20 2024
net/libpfctl: update main version
Dec 18 2024
Dec 18 2024
if_ovpn: improve reconnect handling
Dec 17 2024
Dec 17 2024
pf: fix double free in pf_state_key_attach()
pf: SCTP abort messages fully close the connection
pf tests: test dummynet on nat64 rules
pf: teach nat64 to handle 0 UDP checksums
kp committed rG706b42cc4bd9: pf: give the correct address family to dummynet after nat64 (authored by kp).
pf: give the correct address family to dummynet after nat64
pf: fix dummynet + route-to for IPv6
kp committed rG7f3d159b9ff2: pf tests: test using an address range inside a table for nat64 (authored by kp).
pf tests: test using an address range inside a table for nat64
pf tests: test address range as nat64 from address
pfctl: do not allow af-to tables without round-robin
kp committed rG125e395278cf: pf tests: test not having an IPv4 address to nat64 to (authored by kp).
pf tests: test not having an IPv4 address to nat64 to
pf tests: validate ToS translation with nat64
pf: preserve TOS with nat64
pf tests: check packet reassembly with nat64
pf: handle fragmentation for nat64
pf: update pd->tot_len after reassembly