Project

General

Profile

Activity

From 11/27/2009 to 12/26/2009

12/26/2009

11:59 PM Revision bb0802c0: use theme image, not hard coded one
Chris Buechler
11:54 PM Revision 0efdd147: fix typo and text alignment
Chris Buechler
11:22 PM Revision 56d41297: remove notice that unnecessarily appears on every clean install
Chris Buechler
10:41 PM Revision a0bb5a4d: Also match umodem for the UM175 unit.
Andrew Thompson
10:36 PM Revision ec51a222: Add graphing for 3G cellular modems.
Andrew Thompson
09:22 PM Bug #99 (New): Reflection is broken in 2.0
closer, still broken. Updated ticket with current status Chris Buechler
11:12 AM Bug #99: Reflection is broken in 2.0
I have done some commits which should fix this.
It even enhanced the rdr rules to specify ranges instead of creati...
Ermal Luçi
07:21 PM Bug #147 (Resolved): Voucher test page throws lock error
fixed Chris Buechler
06:20 PM Bug #237 (New): notices aren't displayed properly in Chrome
This issue is limited to Chrome only it appears. Not sure if it's our issue or Google's, I reported a broken site to ... Chris Buechler
02:39 PM Revision 2248a940: Do not mark non-required fields as required.
Ermal Luçi
12:50 AM Bug #247 (Closed): QoS (Traffic-shaper) problem when creating custom queues/rules
There are some issues with manual configuration of the shaper in 1.2.x and always have been. Since the shaper is a re... Chris Buechler

12/25/2009

10:02 PM Revision 78490e86: Fix the inetd definitions. Remove forgotten dead code.
Ermal Luçi
09:52 PM Revision 6745e860: Simplify a lot the code of rate extracting.
Ermal Luçi
12:07 PM Feature #248: Support for tun or tap mode in openvpn client
Also adds the direction of tls-auth for client/server mode Antonio No
12:05 PM Feature #248 (Resolved): Support for tun or tap mode in openvpn client
This is a patch that adds the option to choose tun or tap mode for openvpn clients.
Antonio No
04:25 AM Bug #247 (Closed): QoS (Traffic-shaper) problem when creating custom queues/rules
When creating custom rules or queues in the traffic shaper, it seems to be duplicating the "Down" parent queue in pla... Salvatore LaMendola
02:32 AM Revision 14900201: Moving on up, to the east side, to a deluxe apartment in the sky, aka 2.0-BETA1
Scott Ullrich
02:30 AM Revision b8d220ab: Nuke pkg_build_filter_rules();. It would have never covered reinstallation cases.
Scott Ullrich
01:37 AM Revision 58362f9d: Fix webgui protocol detection here, too.
Jim Pingle
01:28 AM Revision 43d9a2d3: Fix wizard webgui URL usage so it chooses https/http properly for refresh link and logo link
Jim Pingle
01:11 AM Revision ab94e136: Fix the quotes on this line.
Jim Pingle

12/24/2009

10:55 PM Revision 51f4c1c9: Add another ID so password confirmation fields also get this style applied (Fixes PPTP user edit screen, possibly others)
Jim Pingle
10:55 PM Revision eb72845c: Remove "-G all" as it was causing the useradd operation to fail, leading to other failures. (Users were not added to passwd, home directories were not being made, etc)
Jim Pingle
10:55 PM Revision 461df7c0: Remove extra / to avoid having a double slash in the directory name. Also add curly braces around $user_home.
Jim Pingle
10:17 PM Revision 0fa7902e: Fix identing
Scott Ullrich
10:13 PM Revision e56e5325: Simplify logic a bit
Scott Ullrich
10:10 PM Revision 2f31946f: Remove pptp_subnet from page as it isn't used or set, and breaks saving. Also remove redundant localip setting box (it was already on the page a few rows up) and remove the connection count output as that is set by a drop-down a few rows up as well.
Jim Pingle
10:08 PM Revision 85435536: Add safety belt check code written by Ermal originally
Scott Ullrich
05:57 PM Revision 4143a437: Nuke pkg_build_filter_rules(). It is not called anywhere in the code and adds complexity that I do not wish to see in the codebase
Scott Ullrich
05:50 PM Revision ffe76308: Make sure to properly use the configured monitor IP address for dynamic interfaces too.
Seth Mos
05:36 PM Revision 616e1956: Do not automatically save the monitor if it is not explicitly filled in. Leave the monitor field empty when it is
not filled in. Show a configured monitor address on the system_gateways.php page. Seth Mos
12:45 PM Revision 9ff9a1c7: Style fixes for the interfaces page, use switch instead of a large if,elseif procedure.
Fix the monitor IP route adding and removing to skip non IP addresses and dynamic entries
Add a Gateway item on the g...
Seth Mos
11:05 AM Revision d9d4c637: Reorder a few lines so we do not step on the interface variable. This was the cause of accidentaly adding gateway name entries in the
$config['interfaces'] xml Seth Mos
09:21 AM Bug #136: Issues with linked filter/NAT rules
There is no need for guid since its slow.
Take a look at the schedules code it uses something like this with uinque()
Ermal Luçi
02:55 AM Revision ec98a89d: Handle cases where no .inc files are present /usr/local/pkg/
Scott Ullrich
02:52 AM Revision 013ac632: Match coding style outlined in http://devwiki.pfsense.org/DeveloperRules
Scott Ullrich
02:48 AM Revision 8bd073ad: Output ls
Scott Ullrich
02:43 AM Revision 457a816a: Adding late pf hooks for packages. Name is 'pflate'
Scott Ullrich
02:40 AM Revision 6b12d9b5: Adding pf early hooks similar to nat and filter pkg hooks. Name is 'pfearly'
Scott Ullrich
02:35 AM Revision 19de945a: Add dynamic pkg hooks support. Submitted by Bill M on 11/17/08.
Scott Ullrich
02:19 AM Revision c9e09e0b: Add back plugins
Scott Ullrich
01:38 AM Revision 011b9493: Adding latest dom_TT. Fixes #202 Thanks to RobisCool
Scott Ullrich
12:10 AM Revision 3bb547c2: Updating to 1.8.3
Scott Ullrich

12/23/2009

11:38 PM Revision 72d51890: Add advacnced custom options box Ticket #234
Scott Ullrich
11:16 PM Revision 389beb16: Move decalration of tables always present in pfSense together with aliases to make an easier reading of the ruleset. Fix some whitespace while here.
Ermal Luçi
10:30 PM Revision 34fd6168: Do not generate countless rules for reflection, just use the pf range specification abilities. This reduces rulests a lot and should make even performance better on such cases overall.
Ermal Luçi
10:25 PM Revision 5c310990: Remove debugging alert
Scott Ullrich
10:24 PM Revision 15a13dab: Unbreak adding gateway #238
Scott Ullrich
09:30 PM Revision 204f33f6: Add FreeBSD handbook to Help menu
Scott Ullrich
09:19 PM Revision d9e258bb: If the port passed as argument is a range(having - in it) this function would still return true as a bad habit of intval. Fix this so it behaves correctly.
Ermal Luçi
09:09 PM Bug #236 (Closed): DHCP Server IP Range Validation
Chris Buechler
07:02 PM Bug #236: DHCP Server IP Range Validation
Must have been a bad snapshot. Recent (today's) snapshots function normally. Tyler Simpkin
08:47 PM Revision a3e027f6: Use /tmp/ssl.key Ticket #63
Scott Ullrich
08:40 PM Bug #202: Theme problems with IE 8
Fixed issues with the + on IE8
http://dom-tooltip.googlegroups.com/web/domtt-0.7.3.with.ie8.support.tar.gz
Robert
robert zelaya
08:40 PM Bug #202 (Resolved): Theme problems with IE 8
Applied in changeset commit:"011b9493627c28befbcc29d357f4a471b3582fe4". Scott Ullrich
06:36 PM Bug #202: Theme problems with IE 8
Using the theme "the wall", the main top menu is broken in IE8 compability mode. robert zelaya
08:29 PM Revision a63ab6b6: Fix variable name, this tagged all gateways as dynamic on upgrades.
Seth Mos
06:56 PM Bug #14: reply-to should not be added when bridging
It's not possible to definitively tell on the firewall, there are too many possible combinations and it ultimately de... Chris Buechler
05:31 PM Bug #14: reply-to should not be added when bridging
How would we tell when we need the reply-to or not. We need to define the logic that is involved. Scott Ullrich
06:51 PM Bug #108: Xauth is forced for IPsec mobile clients
Bringing back the PSK tab would probably be the best (and easiest) thing to do then. Anyone know if you can have both... Jim Pingle
06:40 PM Bug #108: Xauth is forced for IPsec mobile clients
Sounds like we need to bring back the PSK tab then. That would also minimize configuration upgrade behavior. Scott Ullrich
06:36 PM Bug #108: Xauth is forced for IPsec mobile clients
I'm not sure how to best handle this, users doesn't seem like a great place for it as that's commonly been used for s... Chris Buechler
06:26 PM Bug #108: Xauth is forced for IPsec mobile clients
In 1.2.3, for IPsec mobile clients, there was a tab to define a PSK/Identifier pair. This does not exist in 2.0.
I...
Jim Pingle
05:32 PM Bug #108: Xauth is forced for IPsec mobile clients
If someone can describe what needs to be fixed, I can give it a go but at the moment I do not understand the logistic... Scott Ullrich
06:31 PM Feature #246 (New): Allow dragging firewall rules over tab to reassign the interface
Chris Buechler
05:36 PM Feature #246 (Feedback): Allow dragging firewall rules over tab to reassign the interface
oops. wrong ticket. Scott Ullrich
01:41 PM Feature #246 (Needs Patch): Allow dragging firewall rules over tab to reassign the interface
It would be nice if you could drag a rule (or two+) over the interface tab and have it reassign. For example if you ... Scott Ullrich
06:30 PM Bug #234: OpenVPN - Client Specific Overrides regression from 1.2.3
same as in 1.2.x, the client specific configuration screen needs the advanced options box the same as the client and ... Chris Buechler
05:38 PM Bug #234: OpenVPN - Client Specific Overrides regression from 1.2.3
I misunderstand what needs to be done then. Can you please outline what is needed and I will take a look.. The adva... Scott Ullrich
05:58 PM Bug #136: Issues with linked filter/NAT rules
Information about our UUID library: http://www.shapeshifter.se/2008/09/29/uuid-generator-for-php/
filename is uuid...
Scott Ullrich
05:55 PM Bug #136 (New): Issues with linked filter/NAT rules
Spoke too soon. I deleted a rule and now its pointing to a new entry.
This is probably the wrong approach altoge...
Scott Ullrich
05:37 PM Bug #136 (Feedback): Issues with linked filter/NAT rules
I deleted the original entry and added a new one and its working. I think that was artifacts from the entry created ... Scott Ullrich
01:24 PM Bug #136: Issues with linked filter/NAT rules
Firewall rule added for HTTPS from 74.132.200.XXX Scott Ullrich
05:49 PM Bug #219: Reboot needed after Nic deletion (vlan parent).
Still happens. Tested with version Wed Dec 23 09:40:31 EST 2009 Perry Mason
05:14 AM Bug #219 (Feedback): Reboot needed after Nic deletion (vlan parent).
Ermal Luçi
05:33 PM Bug #131: "Static route filtering" doesn't add rules for routes on WAN
If you can describe the logic involved I can take a look. Scott Ullrich
05:30 PM Bug #238 (Feedback): Add new gateway on interfaces.php doesn't work on OPT interfaces
Fixed in r5c31099 Scott Ullrich
11:02 AM Revision e1f6e59e: Fix the script but leave a comment that the openvpn case needs fixing.
Ermal Luçi
11:00 AM Revision ff7dec00: add required include.
Ermal Luçi
10:58 AM Revision 7850de1c: Ticket #219. Fix this for vlans and vips. Though it is a very rare case. The other clones are handled half way but should work ok.
Ermal Luçi
10:28 AM Revision 7d017d92: Commit fix present in Ticket #244.
Ermal Luçi
03:34 AM Bug #244 (Feedback): Using IE, Downloading file fails when using SSL exec.php
Ermal Luçi
02:57 AM Bug #245 (Rejected): Upgrade 1.2.3 to 2.0 cause WebGui parse error
Please do not open bugs here before you have no answer on the forum.
This is just unfortunate snapshot.
Ermal Luçi
12:47 AM Bug #245 (Rejected): Upgrade 1.2.3 to 2.0 cause WebGui parse error
Im trying to upgrade 1.2.3 to 2.0 and since I do the upgrade I cannot access WebGui anymore.
Always getting this e...
Michel Samovojski

12/22/2009

11:18 PM Revision ba0be463: This is not called only for wan.
Ermal Luçi
11:16 PM Revision 5e3ed9bc: Fix logging statements to not consider this only as called from dhcp.
Ermal Luçi
10:04 PM Revision ac2dee1d: Add some comments to explain available debugging levels. Requested-by: Seth.
Ermal Luçi
10:02 PM Revision d09c4aae: Default to first level of debugging. This seems to be at least required for propper debugging when there are issues not related with filterdns.
Ermal Luçi
10:01 PM Revision 596bc941: Bind to correct fields for the PPPoE/PPTP credentials.
Ermal Luçi
09:29 PM Revision 3cfa11c2: Unbreak remote-ip box. Mpd is now starting for ppptp server
Scott Ullrich
08:48 PM Revision aab4ca82: Automatically generate a certificate Resolves #63
Scott Ullrich
07:54 PM Bug #136: Issues with linked filter/NAT rules
I also can't reproduce that problem, and don't appear to have access to Scott's firewall at the moment. Scott, if you... Chris Buechler
07:51 PM Bug #136: Issues with linked filter/NAT rules
Ok Chris, that sounds logical.
Just a note for Scott: I am also unable to reproduce the problem you reported about...
Pierre POMES
07:29 PM Bug #136: Issues with linked filter/NAT rules
I'd prefer prohibiting deletion of a linked firewall rule. If the NAT rule is deleted, the associated firewall rule i... Chris Buechler
04:06 PM Bug #136: Issues with linked filter/NAT rules
Yes, need to unassociate the rule upon deletion. Scott Ullrich
07:33 PM Bug #242 (Closed): Backport IPV6 support from m0n0wall
this is a duplicate of #177 Chris Buechler
02:51 PM Bug #242 (Closed): Backport IPV6 support from m0n0wall
After 2.0 releases it will be desirable to backport IPV6 from m0n0wall. Scott Ullrich
07:22 PM Bug #238 (New): Add new gateway on interfaces.php doesn't work on OPT interfaces
Confirmed it does work on WAN, it doesn't work on any OPT interfaces. Does as described in the description. Chris Buechler
05:30 PM Bug #238 (Feedback): Add new gateway on interfaces.php doesn't work on OPT interfaces
Just tested a fresh install and could not reproduce this. Steps taken, install, interfaces wan, set to static, ente... Scott Ullrich
07:12 PM Bug #244 (Resolved): Using IE, Downloading file fails when using SSL exec.php
Using IE, Downloading file fails when using SSL. Pfsense file exec.php.
Fix
Add these headers.
header("Pra...
robert zelaya
07:06 PM Bug #217: Can't change pfSense default gateway
Sorry if it's a bit of topic but I tried to edit 2 dynamic gateways. It was not indicate witch one was the default an... Perry Mason
04:22 PM Bug #217: Can't change pfSense default gateway
I just rewrote a few parts of the gateway code on the backend and frontend. It should properly set the route now upon... Seth Mos
07:02 PM Bug #234 (New): OpenVPN - Client Specific Overrides regression from 1.2.3
There is no custom options/advanced configuration for client specific overrides, this will have to be addressed. Chris Buechler
04:15 PM Bug #234 (Closed): OpenVPN - Client Specific Overrides regression from 1.2.3
That is now called "Advanced configuration" and is present. Scott Ullrich
06:41 PM Revision 0d1a1f8b: We are on 2.0-ALPHA. Resolves #241
Scott Ullrich
05:10 PM Bug #243 (Resolved): filterdns does not resolve hostnames with a network mask
Seth Mos
04:57 PM Bug #243: filterdns does not resolve hostnames with a network mask
Added the extra parameter "3" for debugging to the filterdns startup in filter.inc.
Now it logs this:
# clog /var...
Seth Mos
04:50 PM Bug #243 (Resolved): filterdns does not resolve hostnames with a network mask
On a network alias where a hostname is used with a subnetmask this will not correctly work for filterdns.
The alia...
Seth Mos
04:34 PM Feature #150: Option to change syslog facility
Chris Buechler wrote:
> (moved from cvstrac # 1740)
> Is it possible to add the option of changing which syslog fac...
Dan Swartzendruber
04:32 PM Bug #202: Theme problems with IE 8
How would we change the dashboard to run in non compatibility mode? Scott Ullrich
04:29 PM Bug #139 (Feedback): PPTP Server subnet and clients needs combined
Scott Ullrich
04:19 PM Bug #237 (Feedback): notices aren't displayed properly in Chrome
Scott Ullrich
04:19 PM Bug #237: notices aren't displayed properly in Chrome
Seems to be working OK for me? See screenshot. Scott Ullrich
04:17 PM Bug #236 (Feedback): DHCP Server IP Range Validation
Scott Ullrich
04:17 PM Bug #236: DHCP Server IP Range Validation
I am having trouble reproducing this. Could you please elaborate on how to reproduce (include the range you where tr... Scott Ullrich
04:13 PM Bug #231: carp_input: packet received on non-carp interface log flooding
Commited a fix for this in r5b2341a Scott Ullrich
04:13 PM Bug #231 (Feedback): carp_input: packet received on non-carp interface log flooding
Scott Ullrich
04:12 PM Bug #219: Reboot needed after Nic deletion (vlan parent).
I suspect this is hardware related. Scott Ullrich
04:11 PM Bug #233 (Closed): Config upgrade should change theme
There is no "default" theme. With that said it is impossible to detect this since there is no default.
For exampl...
Scott Ullrich
04:05 PM Bug #232 (Closed): lagg not in vlan_long_frame
lagg already appears here. Scott Ullrich
03:50 PM Todo #63 (Resolved): Change web interface default to HTTPS
Applied in changeset commit:"aab4ca82f485d1ca2f628c5674cd648b87104352". Scott Ullrich
02:28 PM Revision e9044239: Correct variable typos.
Ermal Luçi
02:26 PM Revision 641bf139: Try to send the update through the interface that has the ip so some services do not complain.
Ermal Luçi
02:25 PM Revision eb346556: Try to be more consistent on boolean value checking.
Ermal Luçi
02:12 PM Revision 8f1b45aa: Fix variable name type. Fix CURLOPT_INTERFACE opt setting.
Ermal Luçi
02:05 PM Revision 88f65b7e: Add forgotten curly.
Ermal Luçi
01:53 PM Revision 82b95fa9: Simplify code.
Ermal Luçi
01:45 PM Bug #241 (Resolved): Release tag is incorrect
Applied in changeset commit:"0d1a1f8bbd3a34c53e3f443f3d79c3540f1ad547". Scott Ullrich
01:17 PM Bug #241: Release tag is incorrect
Dan Swartzendruber wrote:
> 2.0 recently moved from ALPHA ALPHA to ALPHA. The change is reflected in the snapshot n...
Dan Swartzendruber
01:07 PM Bug #241 (Resolved): Release tag is incorrect
2.0 recently moved from ALPHA ALPHA to ALPHA. The change is reflected in the snapshot names (e.g. now 2.0-ALPHA inst... Dan Swartzendruber
01:43 PM Revision a584475a: * Fix alias handling around the repo.
* Add new function filter_expand_alias to allow expanding single alias.
* Fix reflection rules generation(missing the...
Ermal Luçi
10:45 AM Revision e5dcdd65: Fix occurence twice of the nc command, once with full path and once without the full path.
Reported-by: http://forum.pfsense.org/index.php/topic,19957.0.html
Pointyhat-to: ?
Ermal Luçi
09:13 AM Bug #229 (Rejected): fitler rules doesn't create redirect (rdr)
You seem to not have proper pf(4) knowledge to validate this as bug report. Ermal Luçi
09:05 AM Bug #240 (Feedback): No Dyndns-Update
Patch commited with 75f2da4e3282a1a12bf1e4f726a37fd1ccd49065. Ermal Luçi

12/21/2009

11:33 PM Revision ca59a45f: show proper commas
Chris Buechler
05:39 PM Revision 3ac30070: Do not break rc.newwanip by putting more information than requested in the file.
Ermal Luçi
05:31 PM Revision 771df54e: More fine grained update of dyndns and dnsupdate.
Ermal Luçi
05:25 PM Revision 2ec2a374: Make dnsupdate runnable per interface. Update the calls on interface_configure to per interface. Remove unused dyndns_reset function.
Ermal Luçi
02:42 PM Revision 2290a686: Make sure to use the correct dummy IP address for the monitor for dynamic interfaces
Seth Mos
02:37 PM Revision 9a21b547: Fix status page to correctly itterate the gateways array
Seth Mos
02:27 PM Revision 2328dcc5: Partial rewrite of gateway code, now partially facilitates dynamic interfaces
- Upgrade code takes different naming into account
- Add gateway entries for dynamic interfaces
- Rewrite status arra...
Seth Mos
10:37 AM Bug #238: Add new gateway on interfaces.php doesn't work on OPT interfaces
What I think might be happening is that the input validation throws a error and thus doesn't save.
Not sure entirely...
Seth Mos
12:23 AM Bug #238 (Resolved): Add new gateway on interfaces.php doesn't work on OPT interfaces
It looks like it works, i.e. after adding a gateway it's shown in the gateways drop down, but the gateway isn't actua... Chris Buechler
10:27 AM Revision b4deddce: Fix type handling to save what was choosen end not to guess it. Save the cidr when specified with hostnames seems people used this feature in 1.2.x branch.
Ermal Luçi
08:54 AM Bug #240: No Dyndns-Update
I've noticed this too but hadn't reported it yet. In my case, the DynDNS configuration page also doesn't show any cac... Steve McGrath
07:36 AM Bug #240 (Resolved): No Dyndns-Update
No dyndns-Update is working.
Even after new connect to ISP dyndns-Update it thinks IP hasn't changed: (shoewn in rev...
igor igor
08:53 AM Revision d30bbdd7: Make sure we test for the right gateway name in the upgrade code.
Seth Mos
08:29 AM Revision 7321c93c: fix for disabled theme selection
Chris Buechler
07:32 AM Revision cf360495: increase the default cert lifetime
Chris Buechler
07:05 AM Revision 0cdaaa8e: Generate a certificate at first boot rather than using a default public cert/key pair. Ticket #63
Chris Buechler
06:49 AM Revision 0d7ff226: fix typo
Chris Buechler
05:53 AM Revision 3b1a9531: run filter_configure_sync after PPP comes up
Chris Buechler
05:50 AM Revision 3169ec8e: add PPP support to dynamic gateways
Chris Buechler
05:43 AM Revision 106804a2: shift this around a little, put the dynamic gateways beneath the static ones, not beneath the gateway groups. Also show the dynamic gateways correctly ($ifent not $if)
Chris Buechler
05:28 AM Revision 90dc86b5: allow unlimited gateways to have a blank monitor IP (i.e. monitor IP == gateway IP)
Chris Buechler
05:04 AM Revision 29adf437: clean up text
Chris Buechler
05:00 AM Revision 29e6e88b: use correct gateway IP for PPP
Chris Buechler
04:58 AM Revision 58a52416: fix text
Chris Buechler
04:19 AM Feature #239 (Resolved): Hostname support in aliases
Resolve all ips of a hostname present in the alias. Ermal Luçi
04:13 AM Revision 08c00cdf: remove wrong no nat
Chris Buechler
04:01 AM Revision 60f417b4: fix whitespace
Chris Buechler
03:58 AM Revision 92373f5b: this just duplicates the PPP interface, as it's handled above
Chris Buechler
03:51 AM Revision 81f256c0: clean this up a bit, add comments
Chris Buechler
03:17 AM Bug #235 (Feedback): Manual 1.2.3 -> 2.0 Upgrade
I just upgraded my 1.2.3 install to 2.0 and it works without issue?
I have also been upgrading my install using the ...
Seth Mos
12:14 AM Revision 65420310: escape // so it fills in properly
Chris Buechler

12/20/2009

11:05 PM Revision f333e853: lower a little more so VMware w/128 MB is ok
Chris Buechler
10:11 PM Revision 9f274393: Use the globals for minimum RAM warning, drop limit a little to accommodate 128 MB RAM systems
Chris Buechler
10:09 PM Revision 7c8dcff2: add Verizon
Chris Buechler
06:40 PM Bug #237 (Resolved): notices aren't displayed properly in Chrome
Notices show up scrolling across, but the content of the notices is never shown. Chris Buechler

12/19/2009

03:37 PM Bug #236 (Closed): DHCP Server IP Range Validation
When LAN subnet is changed from default, it seems impossible to select a valid IP address range for the DHCP server.
...
Tyler Simpkin
11:06 AM Bug #235 (Closed): Manual 1.2.3 -> 2.0 Upgrade
When upgrading from 1.2.3 -> 2.0 using the "Manual Update" tab, router fails to reboot when finished.
Upon pressin...
Tyler Simpkin
10:53 AM Bug #234 (Closed): OpenVPN - Client Specific Overrides regression from 1.2.3
pfSense 2.0 is missing the 'Custom Options' field for 'Client Specific Overrides' found in pfSense 1.2.3, which among... Tyler Simpkin
08:45 AM Revision e7c623c4: match the interface check with the later "pass out" rule's check, so as to not generate invalid ruleset
Chris Buechler
05:19 AM Revision 43bc3e3f: Pass the right argument to killbypid. Pointy-hat: myself.
Ermal Luçi
03:41 AM Revision eb29fd9b: fix text
Chris Buechler
03:20 AM Revision e91baab8: fix reject rules to the same as in 1_2. return is valid on all rules
Chris Buechler
03:04 AM Revision a29dc11b: fixup text
Chris Buechler
02:32 AM Revision b6c3aebc: show correct site in "Unable to communicate" error, clarify error message.
Chris Buechler

12/18/2009

10:23 PM Revision 816a5aff: Attempt to work around both static configs and dynamic configs on load balancer upgrades. Needs testing on
live installs 1.2 => 2.0. Seth Mos
09:48 PM Revision eb0facb8: Use _descr() instead for getting the log interface, so it uses the user-supplied name rather than wan/opt1/opt2/etc.
Jim Pingle
09:01 PM Revision 134f6b6e: Add a FIXME note to the upgrade part.
Seth Mos
08:37 PM Revision acae946b: Make sure that the upgraded load balancer configuration reflects the new gateway names
Seth Mos
08:13 PM Revision 035a5e01: Remove the existing default route before when can add a new one, check when it differs from the existing one
Seth Mos
05:37 PM Bug #233 (Resolved): Config upgrade should change theme
If the default theme is selected in a 1.2.x config, it should be changed during the config upgrade to the new default... Chris Buechler
03:32 PM Revision 42c462c3: Make sure that we mark the wan interface as the default gateway on upgrades
Seth Mos
03:20 PM Revision ab55eb1d: Fine tune the wording
Seth Mos
03:01 PM Revision fc85edaf: Replace the previous itteration with this version 2 attempt.
The interface gateways array previously contained no interface name that could be used.
Succesfully upgraded 1 config...
Seth Mos
02:38 PM Revision 137ea11c: Correct CSS class name for the normal view of the gateway description
Seth Mos
02:36 PM Revision 3240836a: Replace gateways configuration upgrade code with 1st attempt to fix.
Revert the lbpool descriptopn variable name. It was correct before. Seth Mos
12:51 PM Bug #232 (Closed): lagg not in vlan_long_frame
In /etc/inc/globals.inc, "lagg" is missing in "vlan_long_frame". Please add. Aarno Aukia
12:22 PM Revision d68e299b: clarify comment, throw a log message when get into this code path, which should not happen
Seth Mos
12:20 PM Revision 295ff120: Disable the delete icon for system gateways
Set the background for the description to grey if this is a automatically added gateway. Normal ones stay red. Seth Mos
12:16 PM Revision e9df5769: Do no throw a duplicate IP address warning when creating a new entry from a existing gateway which was previously a
automatically added gateway entry.
- clarify comment message
Seth Mos
12:04 PM Revision 85b14810: Clarify the description for Dynamic gateways that it is automatically added
Seth Mos
12:02 PM Revision eb4637d8: Make sure that when upgrading the load balancer pools to the gateway format we set the description as well. Typo in the
variable name Seth Mos
12:01 PM Revision 6ee1b7eb: Make sure that when upgrading a balance pool that we always user tier 1, it previously used tier 0 which equals "Do not use".
Seth Mos
03:36 AM Revision cb565d6d: make re-brand friendly
Chris Buechler
02:40 AM Revision b39ca83c: Move conf_mount_ro() to the stop section. Fix formatting while here
Scott Ullrich
02:33 AM Revision 6eddeb95: Fix formatting while here.
Scott Ullrich
02:27 AM Revision 0535db81: Move conf_mount_ro() to the stop section.
Scott Ullrich

12/17/2009

11:40 PM Revision 786e70b7: fix call to undefined function
Chris Buechler
11:29 PM Bug #231 (Resolved): carp_input: packet received on non-carp interface log flooding
Where a non-CARP system is on the same broadcast domain as a CARP system, the system logs get flooded once a second w... Chris Buechler
11:28 PM Revision 3b29612f: add ability to hide help menu
Chris Buechler
11:15 PM Revision 755aecb7: use product_name
Chris Buechler
09:45 PM Revision 8b289232: add ability to hide theme selection
Chris Buechler
05:37 PM Revision d950db87: Fix call to fwrite.
Ermal Luçi
04:29 PM Feature #230: DHCPD should have ability to specify tftp-server option
Chris Buechler wrote:
> Already exists in 2.0 and 1.2.x is feature frozen (and likely won't see another release anyw...
Dan Swartzendruber
04:12 PM Feature #230 (Closed): DHCPD should have ability to specify tftp-server option
Already exists in 2.0 and 1.2.x is feature frozen (and likely won't see another release anyway). We appreciate contri... Chris Buechler
03:38 PM Feature #230: DHCPD should have ability to specify tftp-server option
Dan Swartzendruber wrote:
> This exists in 2.0, but it would be nice to have it prior to that. Please see attached ...
Dan Swartzendruber
03:37 PM Feature #230: DHCPD should have ability to specify tftp-server option
Dan Swartzendruber wrote:
> This exists in 2.0, but it would be nice to have it prior to that. Please see attached ...
Dan Swartzendruber
03:32 PM Feature #230 (Closed): DHCPD should have ability to specify tftp-server option
This exists in 2.0, but it would be nice to have it prior to that. Please see attached patch. I have verified this ... Dan Swartzendruber
04:08 PM Revision bdf81ce3: Start using the new utility for monitoring dns hostnames used in aliases.
Ermal Luçi
11:01 AM Revision e5ac67ed: Correctly reconfigure vips when the underlying/parent interface gets reconfigured.
Ermal Luçi
10:49 AM Revision 435f11c8: Fix deletion of ipaliases. Use get_real_interface instead of the long name of function.
Ermal Luçi
08:52 AM Bug #229 (Rejected): fitler rules doesn't create redirect (rdr)
Could this be disabled in the kernel or somewhere?
Tried pfsense's transparent squid proxy; manually create a rdr ...
Ker Ruben Ramos
04:12 AM Bug #217 (Feedback): Can't change pfSense default gateway
Ermal Luçi
04:08 AM Bug #225 (Feedback): Deleting a CARP VIP doesn't remove it
Ermal Luçi
03:55 AM Bug #225: Deleting a CARP VIP doesn't remove it
Commit 435f11c8b1ce6a3b800bc45a386832903d6805a3
Should fix this. It was checking the friendly interface with does_...
Ermal Luçi

12/16/2009

11:45 PM Feature #228: Multi-WAN support with same gateway on multiple WANs
If you can only route-to IP address, then why bother putting IF in there.
Ex: ...
Ker Ruben Ramos
11:12 PM Feature #228: Multi-WAN support with same gateway on multiple WANs
You can only route-to IP addresses, and IP addresses can only exist on one MAC address, which the system can only see... Chris Buechler
11:09 PM Feature #228: Multi-WAN support with same gateway on multiple WANs
Any reference of the "known" pf's limitation on route-to regarding 'same gateway'? Ker Ruben Ramos
10:50 PM Feature #228 (New): Multi-WAN support with same gateway on multiple WANs
Currently multi-WAN cannot function where multiple WANs have the same gateway IP because of the way PF's route-to fun... Chris Buechler
10:54 PM Bug #227 (Closed): Missing route groups on load balance
You can do the route-to { (pppoe0 1.1.1.1), (pppoe1 1.1.1.1), (pppoe3 2.2.2.2) }
but it's not going to do what you e...
Chris Buechler
10:49 PM Bug #227: Missing route groups on load balance
Or is there somewhere already that can specify which IP apinger will check? Ker Ruben Ramos
10:45 PM Bug #227: Missing route groups on load balance
Additional info:
I think the reason why it only gives 2 interfaces on that situation.
* apinger configuration t...
Ker Ruben Ramos
07:15 PM Bug #227: Missing route groups on load balance
I'd like to verify more on this cause I remember it worked before adding the 3rd(other ISP) pppoe. Both NICs were dis... Ker Ruben Ramos
05:35 PM Bug #227: Missing route groups on load balance
That limitation still stands from 1.2
Load balancing to multiple connections with the same gateway just won't work...
Seth Mos
04:58 PM Bug #227 (Closed): Missing route groups on load balance
I've got three pppoe accounts, 2 from same ISP and the other.
The two pppoe account, when connected, they have the...
Ker Ruben Ramos
08:14 PM Bug #225: Deleting a CARP VIP doesn't remove it
Also verified for a CARP vip. Pierre POMES
01:55 PM Bug #225: Deleting a CARP VIP doesn't remove it
That must be the ifconfig <ibterface> delete cmd line I removed.
It was related to ifconfig trying to set the inte...
Seth Mos
07:20 PM Revision aef6d76f: Revert b15ae348, add mute flag set to true
Seth Mos
05:38 PM Todo #204: All write_config() statements should include a reason of some sort
I've previously talked with Bill about this at the hackathon and was offering a bounty at the time.
This also includ...
Seth Mos
05:37 PM Bug #221 (Resolved): Warnings thrown out when visiting System->Advanced->Networking
Can not replicate it here either. If it still fails for you on a more recent Snapshot then the one you have re-open i... Seth Mos
02:20 PM Revision 8556ce57: use /var/etc/hosts instead of /etc/hosts which should be a symlink
Scott Ullrich
02:14 PM Revision 663d1937: Do not pass option -l to dnsmasq any longer. Only launch the registration helper daemon if the option is enabled
Scott Ullrich
08:33 AM Bug #226 (Rejected): Unable to run pfSense from USB device
This sounds like a FreeBSD regression. Please ask for help on the forum or mailing list. Scott Ullrich
05:32 AM Bug #226 (Rejected): Unable to run pfSense from USB device
My mainboard Asus P5GC-VM has problem run from Kingston 4GB DataTraveler 100. It loops just after boot with umass0: B... Vladimir Navrat
05:05 AM Revision 1f28c1e0: Merge branch 'RELENG_1_2' of http://gitweb.pfsense.org/pfsense/mainline into RELENG_1_2
Chris Buechler

12/15/2009

11:29 PM Bug #62: Check vlan 1.2 -> 2.0 upgrade code and interface naming.
I did a test upgrade on a fully VLAN test box (LAN and WAN) using an image which included the new VLAN upgrade code a... Jim Pingle
05:29 PM Bug #136: Issues with linked filter/NAT rules
Maybe another issue: if you delete a firewall rule linked to a NAT rule, the NAT rule remains associated to this (del... Pierre POMES
11:18 AM Bug #136: Issues with linked filter/NAT rules
Yes, latest code. Just sync'd again to make sure.
You can see the rule on my primary firewall. It's @thompsa's r...
Scott Ullrich
11:10 AM Bug #136: Issues with linked filter/NAT rules
You on the latest code? I fixed the ID being off by one yesterday, it's working for me now. Chris Buechler
10:30 AM Bug #136 (New): Issues with linked filter/NAT rules
Unfortunately there is a new problem with the link on the firewall nat edit screen.
In my case the id of the rule ...
Scott Ullrich
04:42 PM Revision 1eb9325d: Revert "include needed libraries"
This reverts commit 4e955eb1d6af6e6e00765a2d2c1afec93cc54ee3. Scott Ullrich
04:41 PM Revision 869538d5: Resolve Warning: Invalid argument supplied for foreach() in /usr/local/sbin/pfSsh.php(334) : eval()'d code on line 257
Scott Ullrich
04:36 PM Revision 784a0768: Include needed libraries
Scott Ullrich
12:33 PM Revision a37ef4ff: Resolves #220. Fixed because of missed changes as in Ticket #170.
Ermal Luçi
10:47 AM Revision 32f0eb87: Reverting this because:
1- It is broken. It breaks the recursivity of the function itself.
2- It harms the boot time of pfSense too much.
3- ...
Ermal Luçi
10:40 AM Bug #225: Deleting a CARP VIP doesn't remove it
Verified, they aren't removed anymore. I tested that and it worked roughly a month ago. Chris Buechler
08:50 AM Bug #225 (Resolved): Deleting a CARP VIP doesn't remove it
Deleting a CARP VIP should remove it.
The VIP after apply/save doesn't get removed.
Ker Ruben Ramos
09:31 AM Bug #202: Theme problems with IE 8
So the menuissue only affects compatibilitymode in IE8? Compatibilitymode mimics IE6 and IE6 was broken by design. It... Holger Bauer
08:46 AM pfSense Packages Bug #224 (Resolved): Squid enable transparent proxy did not create redirect rule
Squid enable transparent proxy did not create redirect rule.
Ker Ruben Ramos
08:45 AM pfSense Packages Bug #223 (Resolved): Squid package not showing after install
The squid package after installing doesn't show in "installed packages".
The package did execute/installed. But th...
Ker Ruben Ramos
05:40 AM Bug #220 (Resolved): Multi_Lan shaper wizard stalls at first screen.
Applied in changeset commit:"a37ef4fffbc532b3b0565ddc0dc74c8c5f0d206b". Ermal Luçi
03:58 AM Revision 7fa79fff: This function appears to not be needed on 2.0 (It is needed on 1.2.3 where I originally coded this part). Use convert_real_interface_to_friendly_interface_name() instead, since it seems to have special case handling for PPPoE and such now. Tested and working on a static IP setup, still needs tested by a PPPoE user on 2.0. (Logs should show "WAN" in the interface column, not "pppoe0".)
Jim Pingle
03:32 AM Revision 2c97c5d9: Add include for config.inc. Without it, the log parser was failing when called from the CLI (e.g. filterparser.php)
Jim Pingle

12/14/2009

08:41 PM Bug #222 (Closed): pfSense PPTP configurator shows some fields twice
this is a result of an incorrect fix to #139, and #139 notes this issue among others that now exist, so this is a dup... Chris Buechler
08:08 PM Bug #222 (Closed): pfSense PPTP configurator shows some fields twice
On the VPN->PPTP page, the Server Address and Remote Address Range fields are shown twice. Screenshot attached. Steve McGrath
08:18 PM Revision 201fbd66: Make sure that hostnames inside a alias that does not resolve will not result in a unloadable ruleset.
Seth Mos
06:26 PM Revision 4e955eb1: include needed libraries
Scott Ullrich
06:25 PM Revision d1892212: Ticket #217. Comment out code that is half finished.
Ermal Luçi
05:56 PM pfSense Packages Bug #200: 100% CPU on PHP with Snort
robert zelaya wrote:
> I have reproced this error by loading a large amout of ips into the snort2c table.
>
> Exa...
robert zelaya
05:14 PM pfSense Packages Bug #200: 100% CPU on PHP with Snort
I have reproced this error by loading a large amout of ips into the snort2c table.
Example loading 200,000 ips to ...
robert zelaya
05:52 PM Bug #62 (Feedback): Check vlan 1.2 -> 2.0 upgrade code and interface naming.
Mark for feedback as a reminder for me to test Chris Buechler
07:30 AM Bug #62 (Resolved): Check vlan 1.2 -> 2.0 upgrade code and interface naming.
I just checked in the code that properly upgrades the vlan configuration in 054 to 055.
It now creates a config.xm...
Seth Mos
03:45 PM Revision 0c2fd958: Revert previous change, this was already handled and I verified it works after fixing
guess_interface_from_ip() Seth Mos
03:35 PM Revision 80a2c1e6: Correct Typo in function name, this broke guess_interface_from_ip()
Seth Mos
03:21 PM Revision 0a32bc9b: Make sure that if we are passed a IP address but do not have the interface yet, which can happen when
rules are upgraded from 1.2, then find the interface and carry on.
This fixes upgrades where rules might direct traff...
Seth Mos
03:15 PM Revision 9ff8c299: Forward port the guess_interface_from_ip() from 1.2-RELEASE TO 2.0
This one works far better then the old one that was still in 2.0.
Problem being, if it was not in the ARP cache it wa...
Seth Mos
03:12 PM Bug #221: Warnings thrown out when visiting System->Advanced->Networking
There must be something wrong with that upgrade file then.
run this from a shell:
pkg_add -r git ; pfSsh.php pl...
Scott Ullrich
02:56 PM Bug #221: Warnings thrown out when visiting System->Advanced->Networking
Just upgraded to the latest build this morning before checking and posting the bug :| I can't see any errors on the u... John Mitchell
02:55 PM Bug #221 (Feedback): Warnings thrown out when visiting System->Advanced->Networking
I saw that too at some point about a week or two ago, but pretty sure it's been fixed, upgrading made it go away and ... Chris Buechler
02:54 PM Bug #221: Warnings thrown out when visiting System->Advanced->Networking
I fixed this weeks ago. Please make sure you are on the latest code.
Scott Ullrich
02:42 PM Bug #221 (Resolved): Warnings thrown out when visiting System->Advanced->Networking
When visitng the networking tab on the advanced settings page, the gui throws out some warnings, doesn't look like it... John Mitchell
01:02 PM Revision bb6a3dfe: Make sure to surpress stderr
Seth Mos
12:32 PM Revision da74e673: Fix the VLAN upgrade code so that it correctly renames the vlan entries and updates the interfaces
config section to the new name. Tested with 2 VLANS. Seth Mos
12:01 PM Revision 54f8bad0: Make sure we do not place the temporary files in / but in /tmp
Seth Mos
11:34 AM Revision c6933c6d: $g[pptp_subnet] is gone on 2.0. Ticket #139
Ermal Luçi
10:00 AM Bug #220 (Resolved): Multi_Lan shaper wizard stalls at first screen.
This could be considered a duplicate of bug #170 however this applies to multi_lan shaper and not multi all. It is al... John Mitchell
07:36 AM Bug #219 (Closed): Reboot needed after Nic deletion (vlan parent).
If all nic's are VLAN nic's and the parent nic is added and then deleted right away (before a save) pfSense will hang. Perry Mason
04:43 AM Bug #139: PPTP Server subnet and clients needs combined
It was using the old $g['pptp_subnet'] directive. Ermal Luçi
03:40 AM Todo #122 (Resolved): Update the miniupnpd pfPort after the 1.2.3 release
pfPort is upgraded to miniupnpd version 1.4 which is up-to-date with upstream.
Changelog is here
http://miniupnp....
Seth Mos
03:05 AM Revision 5b631e88: Home directory of uid 0 should be /root. Ticket #218
Pierre POMES
12:13 AM Revision 35662d4d: Merge branch 'RELENG_1_2' of http://gitweb.pfsense.org/pfsense/mainline into RELENG_1_2
Chris Buechler

12/13/2009

11:57 PM Revision 36f5df24: remove authorized_keys check, many users won't have SSH access anyway, this check is much too restrictive
Chris Buechler
10:21 PM Revision f9150249: clarify input_error
Chris Buechler
10:19 PM Bug #218 (Resolved): admin's SSH key written to wrong location
fixed, thanks! Chris Buechler
10:06 PM Bug #218 (Feedback): admin's SSH key written to wrong location
Pierre POMES
09:38 PM Bug #218: admin's SSH key written to wrong location
Oh, I see what the problem is, admin's home directory is /root but the key gets written to /home/admin/ so it doesn't... Chris Buechler
09:34 PM Bug #218: admin's SSH key written to wrong location
Strange ! I'am also running a snapshot from today (the first one of the day: http://snapshots.pfsense.org/FreeBSD_REL... Pierre POMES
09:30 PM Bug #218: admin's SSH key written to wrong location
Same on a different box, running a Dec. 6 snapshot. Chris Buechler
09:27 PM Bug #218: admin's SSH key written to wrong location
This is the first I've tried it on 2.0 (in a long while at least, maybe ever). I don't have a .ssh directory at all. ... Chris Buechler
09:23 PM Bug #218: admin's SSH key written to wrong location
I tried to add a SSH key to the default admin user, the authorized_key files is created successfully:
# pwd
/home...
Pierre POMES
06:59 PM Bug #218 (Resolved): admin's SSH key written to wrong location
After adding authorized keys in the user manager and saving, these keys are not written out to the authorized_keys fi... Chris Buechler
09:34 PM Revision 55ec57b9: link to correct associated firewall rule
Chris Buechler
09:28 PM Revision 66772edc: fix text
Chris Buechler
08:38 PM Revision a14bc953: More special meaning words.
Ermal Luçi
08:17 PM Revision 4f80a11e: Ooops remove bogus text.
Ermal Luçi
05:22 PM Bug #145 (Resolved): DHCP server available range is wrong
fixed Chris Buechler
04:53 PM Todo #63: Change web interface default to HTTPS
So generate a key outside of the new cert framework. Got it.
Scott Ullrich
04:52 PM Todo #63: Change web interface default to HTTPS
Don't have to prompt for anything, can generate a self-signed cert on the fly without any prompting. Just run:
op...
Chris Buechler
04:24 PM Todo #63: Change web interface default to HTTPS
I disagree with this. I do not think it is a good thing to need to prompt the user for 7+ items (cert authority item... Scott Ullrich
04:20 PM Todo #63 (New): Change web interface default to HTTPS
This works, but it needs to generate the cert at first boot as stated. Using a hard coded default cert is a major sec... Chris Buechler
04:41 PM Bug #139 (New): PPTP Server subnet and clients needs combined
This wasn't synced up with m0n0wall properly, PPTP is broken now (vpn_pptp.php at least, not sure about back end). Chris Buechler
04:36 PM Bug #136 (Resolved): Issues with linked filter/NAT rules
this is all good now (after a minor fix I just committed) Chris Buechler
04:22 PM Bug #211 (Resolved): IPsec GUI bugs
fixed Chris Buechler
12:28 AM Bug #211 (Feedback): IPsec GUI bugs
Pierre POMES
04:14 PM Bug #55 (Resolved): 2.0 / FreeBSD 8 needs wireless changes to work.
This seems to be ok, if there are any issues we'll open new tickets with specifics. Chris Buechler
02:35 PM Bug #217 (Resolved): Can't change pfSense default gateway
Using the snapshot released 12/13/09, I cannot change the pfSense default gateway. The automatically created WAN inte... Steve McGrath
02:14 PM Revision a56b2fa0: Add missing PF 'max' tracking option , and clarify message for 'max-src-nodes'
Pierre POMES
05:26 AM Revision fa03b3c1: Remove some sort of extra space/break in ipsec screen. Ticket #211
Pierre POMES
05:21 AM Revision b1d215c5: fix text
Chris Buechler
05:14 AM Revision 341a01da: clean up text
Chris Buechler
05:03 AM Revision 9c6ea412: fixup text
Chris Buechler
04:48 AM Revision 50cc6048: clarify input_errors
Chris Buechler
04:46 AM Revision b29b1a33: fix input validation of gateways. Ticket #173
Chris Buechler
04:34 AM Revision 7b995bec: clarify input validation message
Chris Buechler
12:25 AM Bug #124 (Resolved): Polling problems with 8
fixed Chris Buechler
12:23 AM Bug #201 (Resolved): Adding domain override doesn't restart dnsmasq
fixed Chris Buechler
12:11 AM Bug #158 (Resolved): Setup wizard breaks single interface configurations
fixed Chris Buechler
12:08 AM Bug #103 (Resolved): OpenVPN client custom options missing
fixed Chris Buechler
12:06 AM Bug #125 (Resolved): Erroneous "interface not present" alert
fixed Chris Buechler
12:04 AM Bug #142 (Resolved): Alias autocompletion broken
fixed Chris Buechler
12:03 AM Bug #173 (Resolved): Missing input validation for gateways
the particular issues mentioned in the ticket are fixed after my last commit fixing the input validation
not sure ...
Chris Buechler

12/12/2009

11:53 PM Bug #143 (Resolved): Apostrophe in alias description breaks mouse-over display
fixed Chris Buechler
11:52 PM Bug #190 (Resolved): Configuration backup very slow
fixed Chris Buechler
11:25 PM Bug #196 (Resolved): remote syslog does not work after reboot
Fixed in 1.2.3, verified it also works in 2.0. Chris Buechler
11:22 PM Bug #162 (Resolved): Expanding traffic graphs and saving doesn't save
Chris Buechler
11:16 PM Bug #162: Expanding traffic graphs and saving doesn't save
It is the fix. The original author does not have time to fix it further. And no, I am not spending any more time o... Scott Ullrich
07:20 PM Bug #162: Expanding traffic graphs and saving doesn't save
They're now unable to be collapsed at all, graphs for all interfaces are always expanded. Is that the intended "fix"?... Chris Buechler
08:57 PM Revision 473d0ff0: Add patch from lietu (Janne Enberg). Ticket #136
1) Multiple NAT rules can be assigned the same filter rule
-> Fixed, added assigned-nat-rule-id to filter rules to ke...
Pierre POMES
04:07 PM Bug #136 (Feedback): Issues with linked filter/NAT rules
Ok, merge done manually (since the merge is not functionnal) Pierre POMES
02:51 PM Revision 1b665090: Only get ip address from internet if it is a private address on the interface. This should optimize the speed of dyndns a lot.
Ermal Luçi

12/11/2009

11:46 PM Revision c1aa682e: really fix input validation
Chris Buechler
11:26 PM Revision e8ce1bd1: fix input validation
Chris Buechler
11:15 PM Revision e4e3f16e: This breaks the firewall log. Unknown intent, Ermal if you want to improve it, please make sure it works.
Revert "Remove completely bogus code with propper one."
This reverts commit be620dfd9283ee644c57b3c558c7dd603d0f4897.
Chris Buechler
11:44 AM Revision 55bd0d73: Try to update only one interface if we are asked so.
Ermal Luçi
11:42 AM Revision 0be93267: Touch up some comments and error messages. Teach dydns_configure to update only one interface.
Ermal Luçi
11:30 AM Revision be620dfd: Remove completely bogus code with propper one.
Ermal Luçi
10:14 AM Revision 7514c2e2: Remove "$Id$ to unbreak page.
Ermal Luçi
09:47 AM Revision 7dfa60fa: Check if item is set before foraching.
Ermal Luçi
01:48 AM Revision 507af8dd: Use get_interface_ip instead of a manual shell_exec(ifconfig). Ticket #69
Pierre POMES

12/10/2009

11:13 PM Revision e4c3d767: Transmit freebsd machine (uname -m) so that we can be begin offering multi platform packages
Scott Ullrich
10:34 PM Revision 67b0902f: Add IP alias and 'any' support to OpenVPN. Feedback #69
Pierre POMES
09:56 PM Bug #136: Issues with linked filter/NAT rules
there is a merge request that fixes this.
http://rcs.pfsense.org/projects/pfsense/repos/mainline/merge_requests/45
...
Chris Buechler
09:54 PM Bug #136 (Assigned): Issues with linked filter/NAT rules
Pierre POMES
08:50 PM Bug #69 (Feedback): OpenVPN 'local' directive
/etc/inc/openvpn.inc now used get_interface_ip() when generating config file. Pierre POMES
07:54 PM Bug #69 (Assigned): OpenVPN 'local' directive
Advice from Ermal:
Please use get_interface_ip() for friendly interfaces
and find_interface_ip() for real interfa...
Pierre POMES
07:48 PM Bug #69 (Feedback): OpenVPN 'local' directive
Added revision https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/67b0902fe1979b904b2f56a61d59309d971138... Pierre POMES
08:50 PM Revision 9cadc543: Escape CARP password. Resolves #213
Scott Ullrich
08:34 PM Revision 942fdd55: Escape CARP password. Resolves #213.
Jim Pingle
06:37 PM Bug #216: Upgrade from 1.2.3-RC3 to 1.2.3-RELEASE Fails with error mounting on nanobsd alix system
Apologies, only thought it was a bug as other people are experiancing it :- http://forum.pfsense.org/index.php?topic=... John Mitchell
06:34 PM Bug #216 (Rejected): Upgrade from 1.2.3-RC3 to 1.2.3-RELEASE Fails with error mounting on nanobsd alix system
We've tested numerous updates, this isn't a legit bug report. Please post to the forum or mailing list, if a specific... Chris Buechler
06:32 PM Bug #216: Upgrade from 1.2.3-RC3 to 1.2.3-RELEASE Fails with error mounting on nanobsd alix system
When was the date of the 1.2.3-RC3 installation? You most likely have an image before we resized them and if this i... Scott Ullrich
06:30 PM Bug #216 (Rejected): Upgrade from 1.2.3-RC3 to 1.2.3-RELEASE Fails with error mounting on nanobsd alix system
When trying an upgrade from 1.2.3-RC3 to RELEASE, pFSense bails out half way through with the error messages
Misc...
John Mitchell
03:35 PM Bug #213 (Resolved): Invalid/Improperly escaped CARP password breaks CARP Interface creation.
Applied in changeset commit:"942fdd555964d4854e38f8508ffe6acc190b94f4". Anonymous
03:05 PM Bug #213: Invalid/Improperly escaped CARP password breaks CARP Interface creation.
Ok, the password above was not the offending password. The password that had issues contained a double quote (")
T...
Jim Pingle
09:19 AM Bug #215: allow IPv6 traffic not complete
We know exactly where everything comes from, we don't add those. Those rules are generated by PF's antispoof. You'll ... Chris Buechler
08:44 AM Bug #215: allow IPv6 traffic not complete
Chris Buechler wrote:
> It's not coming from anywhere in our code:
I made the setup quick and dirty with the 1.2...
Beat Siegenthaler
08:31 AM Bug #215: allow IPv6 traffic not complete
It's not coming from anywhere in our code:
:~/gitroot/pfsense-RELENG_1_2$ grep -r inet6 *
etc/inc/filter.inc: ...
Chris Buechler
05:03 AM Bug #215: allow IPv6 traffic not complete
Chris Buechler wrote:
> hrm, my explanation earlier wasn't posted.
>
> the "Allow IPv6" box works exactly as it...
Beat Siegenthaler

12/09/2009

08:59 PM Revision a331bc2a: Note that the file will be labeled nanobsd upgrade
Scott Ullrich
05:27 PM Bug #215: allow IPv6 traffic not complete
hrm, my explanation earlier wasn't posted.
This isn't a legit bug report, inet6 only appears in our source code i...
Chris Buechler
04:30 PM Bug #215: allow IPv6 traffic not complete
Hey! Please not this way! I know that You not like and support IPv6. But at least I deserve that You read and comment... Beat Siegenthaler
04:03 PM Bug #215 (Closed): allow IPv6 traffic not complete
pfSense does not have IPV6 support. Scott Ullrich
12:18 PM Bug #215 (Closed): allow IPv6 traffic not complete
If "allow IPv6 traffic" is unset, I see:
[1.2.3-RELEASE] ...
Beat Siegenthaler
05:21 PM Revision 60be9d51: Merge branch 'RELENG_1_2' of http://gitweb.pfsense.org/pfsense/mainline into RELENG_1_2
Chris Buechler
03:56 PM Feature #214: Simultaneuous Serial/Video Console
I just tried this out. I only needed the /boot/loader.conf changes in the original text of the ticket, not the boot.c... Jim Pingle
11:55 AM Feature #214: Simultaneuous Serial/Video Console
/boot.config may also need to contain -D in order for this to work. Jim Pingle
12:45 PM Revision 712b72d7: Add listtopic and note that only ip addresses may be imported.
Ermal Luçi
12:37 PM Revision 984c64a4: Add the same checks to the aliases import functionality as the ones that are done during creation/editing of aliases. Ticket #146
Ermal Luçi

12/08/2009

10:22 PM Revision c13b87a0: Openvpn tunnel network should not be a required parameter as it was not reuired in 1.2.3- Resolves #212
Scott Ullrich
07:40 PM Bug #213: Invalid/Improperly escaped CARP password breaks CARP Interface creation.
I finally had a chance to attempt replication of this issue and so far I am unable to do so. I tried on 1.2.2-RELEASE... Jim Pingle
04:05 PM Bug #213: Invalid/Improperly escaped CARP password breaks CARP Interface creation.
escapeshellarg() Scott Ullrich
04:00 PM Bug #213: Invalid/Improperly escaped CARP password breaks CARP Interface creation.
Most likely it will just take addslashes() on the password and quoting with '' instead of "" on the shell exec to fix. Jim Pingle
03:40 PM Bug #213: Invalid/Improperly escaped CARP password breaks CARP Interface creation.
Seth suggests using base64_encode on that field, which means any value is safe to store.
Possible issue being, how...
Seth Mos
01:24 PM Bug #213: Invalid/Improperly escaped CARP password breaks CARP Interface creation.
Judging by a quick look at the code, this appears to be an issue on 2.0 as well but I haven't tried it in a test envi... Jim Pingle
01:16 PM Bug #213 (Resolved): Invalid/Improperly escaped CARP password breaks CARP Interface creation.
Relayed from Gary on IRC, a support customer had a complex CARP VHID password which contained some special characters... Jim Pingle
05:47 PM Revision 7c3f1ed2: Use is_port here.
Ermal Luçi
05:41 PM Revision 52d618c2: Add one more check for port aliases now that /etc/services can be used in port names.
Ermal Luçi
05:25 PM Bug #212 (Resolved): OpenVPN client Tunnel Network
Applied in changeset commit:"c13b87a076e49202cc35248a9327e63452b403c6". Scott Ullrich
12:10 PM Bug #212 (Resolved): OpenVPN client Tunnel Network
'Tunnel Network' probably should not be a required parameter.
In previous versions, this was assigned automatically ...
Tyler Simpkin
04:31 PM Feature #214 (Closed): Simultaneuous Serial/Video Console
FreeBSD is capable of using both serial and video consoles at the same time. It seems like a good idea to enable this... Jim Pingle
03:54 PM Revision aad51dbf: Add the no nat for tftp-proxy entry. Ticket #140
Ermal Luçi
03:53 PM Revision 6b31f539: Allow specifying services/ports in firewall rules or nat rules by their /etc/services name.
Ermal Luçi
03:45 PM Revision 1cf931f6: Correctly unset rules when switching disabling AON.
Ermal Luçi
03:44 PM Revision fb3590e5: Revert "Correctly unset rules when switching disabling AON."
This reverts commit 989e5d62da2f7f6dad2bb55d20d2558cfb3fa34a. Ermal Luçi
03:44 PM Revision 989e5d62: Correctly unset rules when switching disabling AON.
Ermal Luçi
03:40 PM Revision 1ddb870b: Ticket #140 Fix Outbound edit page to really show errors. Propperly generate rules when switching from/to AON.
Ermal Luçi
11:16 AM Revision 070a82a9: add teredo-protocol to port definitions
Martin
09:01 AM Bug #140 (Resolved): Switching to AON should generate proper full NAT rules
Patches commited. Ermal Luçi
04:21 AM Revision bd4ea800: Squeeze help menu in
Scott Ullrich
04:01 AM Revision 92cf9fcd: Show Loading new configuration to make bootup text unfiorm
Scott Ullrich
03:45 AM Revision 895445e5: Remove ph2 add button. It is shown when needed
Scott Ullrich
03:42 AM Revision 83221d3b: Pass ph1ent
Scott Ullrich
03:38 AM Revision afcda0d0: Make g a global and pass ph1ent
Scott Ullrich
03:23 AM Revision fbc8af8f: Replace dollarsigndollarsign with dollarsign
Scott Ullrich
03:03 AM Revision 38b5beaf: s/loadbalancer/load_balancer/
Scott Ullrich
02:56 AM Revision 25753b5b: Add back chopped off and. Output updating configuration after rrd upgrade to make upgrade text look uniform.
Scott Ullrich
02:50 AM Revision cb945ced: oops, revert this. there is code already. focus on making it work for this config instead
Scott Ullrich
02:23 AM Revision 7a7f3af1: Reboot after uploading config
Scott Ullrich
02:21 AM Revision a6327ffc: Only kill processes if they are running
Scott Ullrich
02:11 AM Revision 886922e7: Ensure item is array.
Scott Ullrich
02:09 AM Revision b5e8ddee: Upgrade outgoing load balancing to gateway groups. Ticket #78
Scott Ullrich
02:03 AM Bug #173: Missing input validation for gateways
The parse error is now gone, but upon further inspection I can create empty array entries by attempting to delete a g... Seth Mos
12:01 AM Revision 166c82ed: fix old_ip detection, clean up white space
Chris Buechler

12/07/2009

11:50 PM Revision 4494cf6a: fix typos
Chris Buechler
10:39 PM Bug #211: IPsec GUI bugs
Committed rafcda0d which should unbreak the image. Scott Ullrich
06:43 PM Bug #211 (Resolved): IPsec GUI bugs
see screenshot attached.
1) some sort of extra space/break
2) floating add P2 box
Chris Buechler
10:05 PM Bug #78 (Feedback): Outgoing load balancer needs configuration upgrade
Turns out the code was there! needed to change loadbalancer to load_balancer and now it works! Scott Ullrich
06:20 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
Targeting 3.0 for an enhanced daemon. This seems to work really well. Scott Ullrich
03:53 PM Revision fcf6a458: Do not rely on PHP5 features which are not widely used in pfSense.
Ermal Luçi
02:49 PM Revision 7c587b9f: Try to prevent empty interfaces.
Ermal Luçi
12:33 PM Revision 5208e648: Include needed files. Ticket #209.
Ermal Luçi
12:31 PM Bug #210 (Rejected): Captive Portal RADIUS authentication - "Authentication error - Username and/or password invalid."
this is not a legit bug report, RADIUS authentication works fine, this is some sort of configuration issue. Please as... Chris Buechler
12:20 PM Bug #210 (Rejected): Captive Portal RADIUS authentication - "Authentication error - Username and/or password invalid."
Using the pfSense Captive Portal. I am getting the "Authentication error - Username and/or password invalid." messag... netserv netserv
10:51 AM Revision 81231803: Fix missing ).
Ermal Luçi
10:50 AM Revision fa551089: Rename unknown.pat to any.pat pattern since that is what it really means. This pattern matches any traffic.
Ermal Luçi
09:23 AM Bug #62 (Feedback): Check vlan 1.2 -> 2.0 upgrade code and interface naming.
Patched. Ermal Luçi
08:43 AM Revision 65615d89: Make sure that do not set the interface to a empty value, this affects the ipsec counters.
Seth Mos
07:50 AM Revision f5476f2a: Fix typo in Importing SSL certificate message.
Seth Mos
07:33 AM Revision 86c3a4de: Remove extra ) which broke the page
Seth Mos
07:01 AM Bug #209 (Resolved): undefined function saving RRD settings
Confirmed Fixed. Seth Mos
05:48 AM Bug #209 (Feedback): undefined function saving RRD settings
Ermal Luçi
03:10 AM Bug #209 (Resolved): undefined function saving RRD settings
Fatal error: Call to undefined function read_altq_config() in /etc/inc/rrd.inc on line 215 Seth Mos
03:03 AM Revision 9dc9718d: don't enable idle_poll, causes 100% CPU on FreeBSD 7.2
Chris Buechler
02:38 AM Revision eed290e7: disable idle_poll, causes 100% CPU on 7.2
Chris Buechler
01:24 AM Revision 1bf0cb21: Use tabs to push comment out
Scott Ullrich
12:40 AM Revision 8713bf55: Do not include grep
Scott Ullrich
12:34 AM Revision fe144dc1: Restart parser after changes
Scott Ullrich
12:31 AM Revision b55a27fd: Add # dynamic entry created by rc.parse-isc-dhcpd
Scott Ullrich
12:26 AM Revision 7ea754a8: Adding script to parse dhcpd log file and populate /etc/hosts so that we can move to a newer dnsmasq. in addition, the current dnsmasq isc parsing is broken so there is not a choice to move either way. Ticket #79
Scott Ullrich

12/06/2009

09:23 PM Revision 55f681dd: Move port to correct part of URL
Scott Ullrich
08:49 PM Revision 52b41d5c: Use interface given in gateways array. No need to find this. Reminded-by: Ermal
Scott Ullrich
08:41 PM Revision f99cd0a7: Bring syslog up after all interfaces are up and running
Scott Ullrich
08:40 PM Revision 7d736708: Fix RELENG_1_2 gitsync
Scott Ullrich
08:17 PM Revision bcc84d48: Move syslogd start to after LAN interface bringup. Tested-by: jim-p, myself. Resolves #196
Scott Ullrich
07:57 PM Todo #208 (Closed): Need PPTP helper
Need a PPTP helper that can accommodate PPTP caller-id.
Scott Ullrich
07:34 PM Revision 64e9ae07: Use correct argument for pfctl -b Ticket #8
Scott Ullrich
07:29 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
All code commited. This appears to work but I am concerned that the shell script forks so it doubles the ram usage t... Scott Ullrich
06:42 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
Wrote this shell script: http://cvs.pfsense.org/~sullrich/rc.parse-isc-dhcpd
Please review.
Scott Ullrich
05:11 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
system_hosts_generate() generates the /etc/hosts entries for dnsmasq. so it does look like we will need the code to ... Scott Ullrich
07:26 PM Revision 908c4eea: upgrade sysctls to value default. Ticket #71
Scott Ullrich
07:20 PM Revision ee216fee: Increase bogons font size Resolves #205
Scott Ullrich
05:58 PM Bug #207 (Resolved): Bridging an Interface do not deactivate DHCP Server on this Interface
If you setup a DHCP server on an aktive interface and after this you bridge that device with another one, the dhcp se... Jochen Becker
05:30 PM Bug #62 (New): Check vlan 1.2 -> 2.0 upgrade code and interface naming.
Scott Ullrich
05:29 PM Bug #62: Check vlan 1.2 -> 2.0 upgrade code and interface naming.
Perry did a upgrade from a 1.2 install and it complained about missing interfaces.
Seems the upgrade code made it ...
Seth Mos
05:29 PM Bug #206 (Closed): Verify vlan upgrade code
Duplicate of #62 Seth Mos
05:01 PM Bug #206 (Closed): Verify vlan upgrade code
Scott Ullrich
03:51 PM Feature #8: Clear states after failover
Yep, you are right. gateway['interface'] had the goods so I adjusted the code. Please test! Scott Ullrich
03:45 PM Feature #8: Clear states after failover
I do not have a environment now but that code seems to grown in home.
The return_gateways_array() return even the in...
Ermal Luçi
02:35 PM Feature #8 (Feedback): Clear states after failover
OK, I figured it out. Please test. Scott Ullrich
02:27 PM Feature #8 (New): Clear states after failover
Scott Ullrich
02:00 PM Feature #8: Clear states after failover
Huh!? What if an interface use more than that one gateway? It's going to whipe all the states for that interface? ... Scott Ullrich
08:44 AM Feature #8: Clear states after failover
Just be aware that the ip specified on pfctl -b is the ip of the interface not of the gateway.
Bascially it is mea...
Ermal Luçi
03:20 PM Bug #196 (Feedback): remote syslog does not work after reboot
Scott Ullrich
02:26 PM Todo #71 (Feedback): Improve sysctl handling
Scott Ullrich
02:22 PM Bug #205 (Resolved): Show Bogons. Text size
Scott Ullrich
12:08 PM Bug #205 (Resolved): Show Bogons. Text size
Bigger font size needed for bogons table Perry Mason
11:56 AM Bug #173: Missing input validation for gateways
unexpected ',' on line 97 Perry Mason
05:55 AM Revision 45849d22: Show default values
Scott Ullrich
05:48 AM Revision d0b461f5: Add lookup table for sysctl tunable (sysctl.inc). Make config.xml values default to value 'default' Ticket #71
Scott Ullrich
05:27 AM Revision e02099c6: Remove leading space
Scott Ullrich
05:23 AM Revision 151eb2a9: Add listtopic and extra save button.
Scott Ullrich
03:48 AM Revision 102ab75d: Clear states for an interface if it is down Ticket #8
Scott Ullrich
02:50 AM Revision 8ecbdab6: Set back to post.
Scott Ullrich
02:47 AM Revision b8cc74ed: Allow GET calling of diag_ping and diag_traceroute so other areas of the GUI can easily link to them. Add links from DNS page for ping and traceroute.
Scott Ullrich
02:36 AM Revision 91a73b8a: _REQUEST has data, too. Don't just check _POST only.
Scott Ullrich
01:48 AM Revision b97c5ed6: Use a br instead of a tr.
Scott Ullrich
01:37 AM Revision 0786c308: Use host
Scott Ullrich
01:32 AM Revision b02b3399: Remove req from class
Scott Ullrich
01:27 AM Revision 87fa30ba: Set table size to 170
Scott Ullrich
01:25 AM Revision 37d98ce7: Do not show resolution tr unless browser is posting
Scott Ullrich
01:21 AM Revision 77f87165: Replace '' with No response
Scott Ullrich
01:14 AM Revision 86ab47ff: Query each DNS server and report the resolution time.
Scott Ullrich
12:46 AM Revision c51684d7: Open links in new tab/window
Scott Ullrich
12:44 AM Revision 4c7e2f4e: Add listtopic header
Scott Ullrich
12:38 AM Revision 9080cb52: Make td cell class vncell. Add whitespace between save button and table
Scott Ullrich
12:26 AM Revision fd87c928: Increase colspan to 90
Scott Ullrich
12:14 AM Todo #204 (Resolved): All write_config() statements should include a reason of some sort
Need to sweep the tree and modify write_config() to include a reason for the change. Scott Ullrich

12/05/2009

10:49 PM Feature #8 (Feedback): Clear states after failover
I have committed code for this. Please test! Scott Ullrich
10:42 PM Feature #8: Clear states after failover
Well, after a filter_configure() run we can simply loop through gateways checking for any that are down. if they are... Scott Ullrich
10:13 PM Feature #8: Clear states after failover
That's good Ermal, that fixes a different problem with the same cause where upon PPPoE reconnect (primarily in countr... Chris Buechler
11:35 AM Feature #8: Clear states after failover
I already told:
"I have done this for pppoe/pptp/l2tp interfaces through pfctl -b in 2.0."
Look at the link down ...
Ermal Luçi
08:59 PM Revision cb8c3cfc: Hide debugging item
Scott Ullrich
08:59 PM Revision 51a2e892: Cleanup after sync
Scott Ullrich
07:29 PM Revision 0d7b21de: Latest PPP changes from 'BG'. Reformat this royal mess of formatting while I am here.
Scott Ullrich
07:10 PM Revision fec980e2: Nuke (). Noticed-by: JimP
Scott Ullrich
07:09 PM Revision ee7f9f3d: Note correct extension. Noticed-by: JimP
Scott Ullrich
07:06 PM Revision 7da73c3d: Show correct update source URL
Scott Ullrich
01:50 PM Bug #140 (Feedback): Switching to AON should generate proper full NAT rules
Seth Mos
05:34 AM Revision ada9cdc8: Adding code-red theme from 'cheesyboofs' on forum
Scott Ullrich
03:40 AM Revision 8fdc621d: Add page global variable
Scott Ullrich
02:06 AM Revision e22aff02: Run git clean
Scott Ullrich
02:06 AM Revision 0b904d98: No need for duplicate command
Scott Ullrich

12/04/2009

09:17 PM Revision b4a9785a: Fix typo in prev. commit
Jim Pingle
09:13 PM Revision fdcd8ac7: Set firmware_update_text properly for the platform
Jim Pingle
08:34 PM Revision 07356178: Prompt for the correct image extension when updating firmware. (.img.gz for nano and .tgz for others)
Jim Pingle
02:31 PM Revision 753157ac: Adding code-red theme from cheesyboofs via forum. http://forum.pfsense.org/index.php/topic,14282.0.html
Scott Ullrich
02:18 PM Revision c1dc0652: Make all autocompletes in there case insensitive.
Ermal Luçi
02:01 PM Revision 9b45f821: Ticket #146 Fix typos ansd copy/pasto errors.
Ermal Luçi
01:49 PM Revision 3d8237f4: Adding patch from "G B":
First, I update the get_real_interface function so that it returns just the serial port for the ppp device (instead o... Scott Ullrich
12:13 PM Feature #8: Clear states after failover
I don't think it is being used, it needs to be tested to ensure it works, then added to run appropriately when a WAN ... Chris Buechler
08:43 AM Feature #8: Clear states after failover
I looked through the tree last night and I did not see pfctl -b in use anywhere. Can someone point me to where its ... Scott Ullrich
01:53 AM Revision 07623d8e: Reset to HEAD on non master
Scott Ullrich
01:46 AM Revision 672d9ab6: Use git reset --hard HEAD
Scott Ullrich
01:38 AM Revision ebc93ea1: Lower buffer to 1000. This reduces page load from 1.2 to 0.9
Scott Ullrich
01:31 AM Revision 5c15e649: Recommit #161 changes. It appears a different commit has broken firewall rules edit and firewall nat edit.
Scott Ullrich
01:17 AM Revision c9dddd59: Revert "Redirect to / when logging in to avoid posting to forms accidently and clearing the form and causing all kinds of chaos. Ticket #161"
This reverts commit 6af7c40b296e0f95ec308d41aea55b3306c5e1ee. Scott Ullrich
01:14 AM Revision 6af7c40b: Redirect to / when logging in to avoid posting to forms accidently and clearing the form and causing all kinds of chaos. Ticket #161
Scott Ullrich
12:29 AM Revision 93291959: Start syslogd after interfaces are configured. Ticket #196
Scott Ullrich
12:16 AM Revision 00a30067: Uncomment code and move to checkout tree after intiial fetch
Scott Ullrich
12:12 AM Revision e2dc4289: Do not download entire tree every time, use cached version
Scott Ullrich

12/03/2009

11:34 PM Revision 8cef78c0: Really preload
Scott Ullrich
11:26 PM Revision 87d6cd83: Die with an error if not 127.0.0.1
Scott Ullrich
11:25 PM Revision bdbef260: Include config.inc, too
Scott Ullrich
11:25 PM Revision 62fd530a: Use preload.php
Scott Ullrich
11:12 PM Revision b0a4e5ee: Sleep for a second in beween
Scott Ullrich
11:09 PM Revision cc093472: Prefetch index.php after starting webConfigurator and send it to /dev/null allowing the priming of the apc cache
Scott Ullrich
10:58 PM Revision e8e12c54: Increase buffer to 500000
Scott Ullrich
10:38 PM Revision ea7f7a84: Minor formatting change
Scott Ullrich
10:38 PM Revision effb9797: Set default protocol to HTTPS. Somehow this commit did not make it last time
Scott Ullrich
10:27 PM Revision f602d493: Turn off debugging
Scott Ullrich
10:21 PM Revision 5f156797: dnsmasq defaults to 150 concurrent lookups. For some environments (large) this is not enough. Increase to 5000
Scott Ullrich
10:16 PM Revision e265d9f5: Oops, unbreak td
Scott Ullrich
10:09 PM Revision 61c0250d: Fixup Source OS box
Scott Ullrich
10:05 PM Revision adb633a0: Minor formatting + hide Source OS behind Advanced box
Scott Ullrich
10:02 PM Revision f1602cc4: Style / formatting changes
Scott Ullrich
09:54 PM Revision 75c34cbb: Show advanced option instead of Show state for every entry
Scott Ullrich
09:50 PM Revision 4c263f57: Hide layer7 and in/out behind advanced button
Scott Ullrich
09:44 PM Revision ad7446d1: Add system and VPN areas to user item privs
Scott Ullrich
09:35 PM Revision 9c9b8845: Nuke comment. its giving me a migrane with the header include problem for some reason and is being cached
Scott Ullrich
09:26 PM Revision f5bdff7f: Add priv.defs.inc to authgui.inc
Scott Ullrich
09:10 PM Revision 9f1a3565: Load pkg privs from /usr/local/pkg/priv if it exists
Scott Ullrich
09:08 PM Revision 6b6e8d08: Rework includes a bit
Scott Ullrich
08:59 PM Revision dd415d52: Roll custom run_plugins routine
Scott Ullrich
08:37 PM Revision ae2951d3: Make item a global
Scott Ullrich
08:33 PM Bug #161 (Feedback): HTTPS certificates invalid - duplicate serial
Back to feedback. https://rcs.pfsense.org/projects/pfsense/repos/mainline/commits/1e578a7f10843f470d2bf5274bbef695a1... Scott Ullrich
08:17 PM Bug #161 (New): HTTPS certificates invalid - duplicate serial
Scott Ullrich
08:14 PM Bug #161 (Feedback): HTTPS certificates invalid - duplicate serial
Scott Ullrich
07:49 PM Bug #161: HTTPS certificates invalid - duplicate serial
How to reproduce:
Set the webgui logout timer to 1 minute.
Navigate to System -> Advanced
Wait 2 minutes.
...
Scott Ullrich
08:27 PM Revision b7dbef8e: Do not output plugin name during boot:
Scott Ullrich
08:27 PM Revision d21d556c: remove closing php bracket
Scott Ullrich
08:20 PM Revision f423cff2: Require util.inc for run_plugins
Scott Ullrich
08:17 PM Revision 0239d8ee: Make xmlrpc sync, schedule, gateway, in/out, ackqueue and layer7 all advanced type buttons simplifying the firewall rule edit form for 99% of the cases
Scott Ullrich
08:02 PM Revision 2816a089: Rename isAllowedPageUser() to isAllowed(). Add and move user priv items to /etc/inc/user.priv.inc. New privs can be added to this /etc/inc/priv/ directory and they will be automatically processed (packages, etc).
Scott Ullrich
05:40 PM Revision 72dbef4d: Start rolling towards 1.2.3-REL
Scott Ullrich
02:58 PM Revision 0d60f50a: Simplify and fix available memory calculation to fix shell script errors on boot.
Fix spelling error in comment Seth Mos
01:54 PM Revision 1e578a7f: Resolves #146 Add propper validation on alias usage. Allow port type aliases only on port side and other aliases in ip specifications and similar. Introduce a new function is_portoralias to ressemble the is_ipaddroralias to check for the cases.
Ermal Luçi
12:30 PM Revision 596a3aba: Prevent bootup code from dying on empty load_balancer arrays
Seth Mos
12:14 PM Revision 0b5b4f32: Extra protection to prevent empty load_balancer arrays on configuration upgrades
Seth Mos
10:42 AM Revision b96cad97: Fix missing include for config upgrade 1.2 -> 2.0
Fix missing include for /etc/rc.reload_all Seth Mos
09:38 AM Bug #146 (Feedback): Missing validation for alias usage
needs testing Chris Buechler
07:05 AM Bug #146 (Resolved): Missing validation for alias usage
Applied in changeset commit:"1e578a7f10843f470d2bf5274bbef695a14bb9d0". Ermal Luçi
07:34 AM Bug #203 (Resolved): Static routes not added on upgrade from 1.2 -> 2.0
Seth Mos
07:33 AM Bug #203: Static routes not added on upgrade from 1.2 -> 2.0
False report, this was caused by a empty load balancer array which then breaks vslb.inc.
In vslb.inc it will compl...
Seth Mos
05:44 AM Bug #203 (Resolved): Static routes not added on upgrade from 1.2 -> 2.0
When upgrading a 1.2 install with static routes, these are not present after the upgrade. Seth Mos
05:05 AM Revision 0456d952: Include priv.inc
Scott Ullrich
04:59 AM Revision dff909d8: Revert isAllowedUser commit and duplicate function to isAllowedPageUser()
Scott Ullrich
04:51 AM Revision 97733a27: Ensure process is running before killing
Scott Ullrich
04:42 AM Revision 375f7bbe: Make sure process is running before killing
Scott Ullrich
04:25 AM Revision 99f98b80: Check to see if processes are running before killing
Scott Ullrich
04:21 AM Revision cd12593b: Check to see if syslogd is running before killing
Scott Ullrich
04:15 AM Revision 1e5c49aa: Check to see if powerd is running before killing
Scott Ullrich
03:49 AM Revision 1703e5c5: Revert "Turn off xauth by default. Ticket #108"
This reverts commit 7998c3f280370991beca62c6a99ae6dd6051228a. Scott Ullrich
03:47 AM Revision 53b30505: Set 2nd parameter for isAllowedPage. Will be required for #34, 33, 32
Scott Ullrich
03:41 AM Revision 953ab2d4: fix error
Scott Ullrich
03:41 AM Revision 7281bb73: Reload tunnel policies Ticket #137
Scott Ullrich
03:31 AM Revision 3d06e8f0: Add carp support for OpenVPN. Ticket #69
Pierre POMES
03:25 AM Revision 7998c3f2: Turn off xauth by default. Ticket #108
Scott Ullrich
03:18 AM Revision 6d28f4d0: Show all widgets. Remove - button as there is no save mechanism at all for this widget.
Scott Ullrich
03:07 AM Revision 3fa86ecd: Formatting cleanups. Increase buffer size
Scott Ullrich
02:52 AM Revision 0b013ef0: Allow a username. Default to _SESSION['Username']
Scott Ullrich
02:15 AM Revision ecae7e91: Unbreak auto ugprade. Resolves #181
Scott Ullrich
02:06 AM Revision e788b01d: Add a few more commands for the lazy
Scott Ullrich
02:03 AM Revision f6907eb4: Add tab completion
Scott Ullrich
01:31 AM Revision 98dfa9e0: update certs
Scott Ullrich
01:17 AM Revision f2b4ff2b: Restore lost code. Noticed-by: Ermal
Scott Ullrich
12:59 AM Revision 2c75b451: Disallow virtual IP addresses withing the range Ticket #50
Scott Ullrich
12:42 AM Revision a2c8cd51: Set name in array
Scott Ullrich
12:33 AM Todo #34: PPTP users integration with user manager
IIRC mpd passwords are stored in plain text. This might be a challenge if not impossible. Scott Ullrich
12:17 AM Revision 21f88b49: Restore the external port range to. Resolves #192
Scott Ullrich
12:09 AM Revision 5d2742d5: Correctly set vtable class
Scott Ullrich
12:04 AM Revision c9eca74f: Show correct availavble usable range and disallow using network or broadcast address. Ticket #145
Scott Ullrich

12/02/2009

11:19 PM Revision 26e3ca70: Do not allow broadcast or the network address in the range
Scott Ullrich
10:46 PM Bug #108 (New): Xauth is forced for IPsec mobile clients
That change is unrelated and should be reverted. The problem will appear in upgraded configurations, and at this time... Chris Buechler
10:25 PM Bug #108 (Feedback): Xauth is forced for IPsec mobile clients
Scott Ullrich
10:37 PM Revision fad728ab: Move { and } to same line.
Scott Ullrich
10:37 PM Bug #137 (Feedback): Change of IPsec remote gateway doesn't trigger SPD reload
Scott Ullrich
10:32 PM Revision 045c9cc9: Combine PPTP Server subnet and clients. Code imported from m0n0wall. Ticket #139
Scott Ullrich
10:18 PM Bug #162 (Feedback): Expanding traffic graphs and saving doesn't save
Scott Ullrich
10:13 PM Revision e2e8ab0a: Add ===>
Scott Ullrich
10:11 PM Revision eac1acd9: Do not output done twice Ticket #63
Scott Ullrich
10:08 PM Revision c687a927: Call file_exists for each file. Ticket #63
Scott Ullrich
10:07 PM Revision f8a36d95: Setup a_cert and a_ca for write_config() Ticket #63
Scott Ullrich
10:03 PM Revision c3b70489: use same variable
Scott Ullrich
10:01 PM Revision 367e08b0: Shorten output string. Setup crt
Scott Ullrich
09:51 PM Revision 02b383fe: Assign unique ref and commit certificate. Ticket #63
Scott Ullrich
09:46 PM Revision f1755af4: Adding default SSL certs to import. Ticket 63
Scott Ullrich
09:45 PM Revision 326d2b8a: Make the default HTTPS. Ticket #63
Scott Ullrich
09:20 PM Bug #181 (Resolved): Auto Update doesn't work
Applied in changeset commit:"ecae7e91a34e6095f40f200c5ebbe46c1abae28b". Scott Ullrich
09:20 PM Bug #181 (Feedback): Auto Update doesn't work
Scott Ullrich
09:20 PM Bug #202 (New): Theme problems with IE 8
Scott Ullrich
09:19 PM Bug #202 (Feedback): Theme problems with IE 8
Scott Ullrich
09:11 PM Bug #190 (Feedback): Configuration backup very slow
This is no longer an issue now that lighttpd is doing gzip. Backed up a 3.1 MB file in about 1 second. Scott Ullrich
08:55 PM Revision 48285469: Add Jim's VLAN fix for Ticket #199
Scott Ullrich
08:49 PM Revision 570ef08c: Use lighty compression instead of php gzip Resolves #198
Scott Ullrich
08:37 PM Revision 7ef2b260: Unbreak console lockout on bootup and in gitsync (pfSsh.php) Resolves #195
Scott Ullrich
08:00 PM Bug #50 (Feedback): DHCP Server input validation lacking
Think I got all of the cases covered. Please test. Scott Ullrich
07:30 PM Bug #161: HTTPS certificates invalid - duplicate serial
Having trouble replicating this one again. It happened to me once when system -> advanced lost all of its settings b... Scott Ullrich
07:20 PM Bug #192 (Resolved): Port Forward external port range shown wrong
Applied in changeset commit:"21f88b49b799400a96f586b8fc9efb6c969ace93". Scott Ullrich
07:04 PM Bug #145 (Feedback): DHCP server available range is wrong
Scott Ullrich
05:23 PM Bug #145: DHCP server available range is wrong
Anyone know if this occurs in m0n0wall? Scott Ullrich
05:32 PM Bug #139 (Feedback): PPTP Server subnet and clients needs combined
Scott Ullrich
05:14 PM Todo #63 (Feedback): Change web interface default to HTTPS
Committed. Seems to work. Please test. Scott Ullrich
03:55 PM Bug #199 (Feedback): Deleting an unused VLAN ID removes IP addresses from all active VLAN interfaces
Scott Ullrich
03:50 PM Bug #198 (Resolved): Web interface garbage
Applied in changeset commit:"570ef08c8767d8ad1f0dd4960d61aa2f4d38ec06". Scott Ullrich
02:41 PM Bug #198 (New): Web interface garbage
While I would love to mark this is resolved unfortunately I just worked around the issue.
We still need to determi...
Scott Ullrich
02:28 PM Bug #198 (Resolved): Web interface garbage
Seth Mos
03:46 PM Bug #196: remote syslog does not work after reboot
This still happens even with a snapshot from Dec 1st, so it doesn't appear the patch changes made a difference. Jim Pingle
03:43 PM Bug #201 (Feedback): Adding domain override doesn't restart dnsmasq
Scott Ullrich
03:40 PM Bug #195 (Resolved): Can not log out of console menu
Applied in changeset commit:"7ef2b26090d642aec398f18e8b5c61093ffa6341". Scott Ullrich
03:24 PM Bug #195: Can not log out of console menu
Just ran a diff between /etc/gettytab before and after a gitsync.
It indeed removes the :ht:np:sp#115200: with :ht...
Seth Mos
03:07 PM Bug #195: Can not log out of console menu
When I click the enable password protect the console menu checkbox it does not immediately take effect.
After a re...
Seth Mos
01:57 PM Revision 6e5eadf8: Put back a wrongly removed line.
Ermal Luçi

12/01/2009

11:16 PM Bug #152: Deleting a VIP leaves <vip/> in config.xml
Hum, I tried a 2009/12/01 snapshot (pfSense-Full-Update-2.0-ALPHA-ALPHA-20091201-1245.tgz), here are my results:
- I ...
Pierre POMES
06:49 PM Revision ac85424e: Reload dnsmasq after domain changes. Ticket #201
Scott Ullrich
06:49 PM Revision a149e9e0: Reload dnsmasq after domain changes. Ticket #201
Scott Ullrich
03:23 PM Bug #202: Theme problems with IE 8
Using IE8 on Win7 in normal mode, I see the menu but the RSS widget causes rendering issues. The "+" does nothing on ... Jim Pingle
02:54 PM Bug #202 (Resolved): Theme problems with IE 8
There are at least a couple problems with the default theme in 2.0 with IE 8, possibly limited to Windows 7 only, unk... Chris Buechler
12:54 PM Bug #199: Deleting an unused VLAN ID removes IP addresses from all active VLAN interfaces
Try as I might, I can't replicate the reboot that happened yesterday. I have created and deleted a couple dozen vlans... Jim Pingle
12:19 PM Bug #201 (Resolved): Adding domain override doesn't restart dnsmasq
After adding a domain override, you have to click Save to restart dnsmasq for it to take effect. Adding a domain over... Chris Buechler
10:46 AM Bug #14: reply-to should not be added when bridging
Well if you are doing NAT in bridge mode and the 'other' gateway of the host is not on the same subnet as the gateway... Ermal Luçi
04:20 AM Bug #198: Web interface garbage
It's deflate/gzip issue.
the latest snapshot 01/12 is without gzip, so its ok.
thank you
Thierry Pimont

11/30/2009

10:47 PM Bug #152: Deleting a VIP leaves <vip/> in config.xml
The target was changed because this was caused by the new XML parser code that's been reverted, so this is no longer ... Chris Buechler
10:42 PM Bug #152: Deleting a VIP leaves <vip/> in config.xml
Target has been changed to 3.0, however, on the NAT screen, the list of available addresses contains empty elements (... Pierre POMES
10:19 PM Revision 8df5eae4: Fix get_configured_carp_interface_list: use the right interface name using vhid
Pierre POMES
08:36 PM Revision f1c276a1: Try to enable even filtering of vlans in hardware. New with FreeBSD 8.
Ermal Luçi
07:14 PM Bug #138 (Feedback): Missing input validation for aliases
sounds good, looks ok at a glance. Needs testing Chris Buechler
06:49 PM Bug #138: Missing input validation for aliases
For the record still some strings will pass as valid hostname though the only way to prevent that is the usage of get... Ermal Luçi
06:30 PM Bug #138 (Resolved): Missing input validation for aliases
Applied in changeset commit:"f71e0ac64d69f423ae202afa93cb13b745ccff99". Ermal Luçi
06:57 PM Revision 9444761e: Turn off compression for time being. Ticket #198
Scott Ullrich
04:45 PM pfSense Packages Bug #200 (Resolved): 100% CPU on PHP with Snort
The problem seems to be with snort and the option(s):
- Convert Snort alerts urls to clickable links
- Associate ...
Chris Buechler
04:07 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
PS: I don't think anything else writes to /etc/hosts except dnsmasq. Scott Ullrich
04:04 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
Sounds good to me. Scott Ullrich
04:03 PM Bug #79: DNSMasq removed ISC-DHCP Log parsing. Need to write a replacement
It seems that dnsmasq keeps all of these internally.
If we rewrite this with a daemon or cron script of some kind,...
Jim Pingle
03:37 PM Bug #199: Deleting an unused VLAN ID removes IP addresses from all active VLAN interfaces
I may have spoken too soon on that. I deleted a few in a row rapidly and the system rebooted itself. I couldn't get t... Jim Pingle
03:29 PM Bug #199: Deleting an unused VLAN ID removes IP addresses from all active VLAN interfaces
The attached patch may be the equivalent of swatting a fly with a cannon, but it seems to do the trick. With this pat... Jim Pingle
11:20 AM Bug #199 (Closed): Deleting an unused VLAN ID removes IP addresses from all active VLAN interfaces
On 1.2.3 (Current snapshots, and from at least last month) when you delete a VLAN ID that is not assigned to an inter... Jim Pingle
03:18 PM Bug #196: remote syslog does not work after reboot
I can reproduce this in a VM and on a real test box. Adding to the weirdness, from my VM I actually do get log messag... Jim Pingle
11:43 AM Bug #196: remote syslog does not work after reboot
Definitely something odd here. I booted the VM, and once it was up, from the console, i shutdown the WAN enet (since... Dan Swartzendruber
01:09 AM Bug #196 (New): remote syslog does not work after reboot
Confirmed issue, after upgrading to a snapshot from today. This is something that's changed in the past month, except... Chris Buechler
01:50 PM Bug #68 (Resolved): Dyndns for second WAN( opt1) does not work
Applied in changeset commit:"7ae7a9720fc06c6c24de29b50197b1d0b19de4ef". Ermal Luçi
01:11 PM Bug #198: Web interface garbage
I also had the same problem for an full upgrade to pfSense-Full-Update-2.0-ALPHA-ALPHA-20091130-0110.tgz.
This see...
Pierre POMES
10:59 AM Bug #198 (Resolved): Web interface garbage
Hello i try a fresh install from livecd to solve some bugs iso pfSense-2.0-ALPHA-ALPHA-20091129-0034.iso.gz,pfSense-2... Thierry Pimont
10:49 AM Feature #197: [PATCH] dns service: alias option for DNS forwarder
Actually I meant that this is my second attempt to solve #129 znerol znerol
10:41 AM Feature #197: [PATCH] dns service: alias option for DNS forwarder
Add backport to RELENG_1_2_2_RELEASE. znerol znerol
10:40 AM Feature #197: [PATCH] dns service: alias option for DNS forwarder
Actually this is my second attempt to solve #197 znerol znerol
10:39 AM Feature #197 (Closed): [PATCH] dns service: alias option for DNS forwarder
Provide a checkbox in the "Edit DNS Forwarder entry" form to indicate if an entry should be treated as an alias to an... znerol znerol
06:43 AM Revision b6867d81: Ticket #146. Fix the autocompletion of ports aliases only for the ports and host/network aliases for the src/dst. Checking if a valid alias is entered end if it is a correct one for this box seems like to much overhead and work for this. (For firewall_nat_edit.php)
Ermal Luçi
06:40 AM Revision 72cb5baf: Ticket #146. Fix the autocompletion of ports aliases only for the ports and host/network aliases for the src/dst. Checking if a valid alias is entered end if it is a correct one for this box seems like to much overhead and work for this.
Ermal Luçi
06:07 AM Revision f71e0ac6: Resolves #138 Add propper input validation to aliases. Do not allow to nested different types of aliases. Do not allow on ports to enter something that is not in the range 0-65535.
Ermal Luçi
06:07 AM Revision 21d41faa: Remove uneccessary variable.
Ermal Luçi
01:54 AM Revision 7ae7a972: Resolves #68 When checking for the secondary wan ip address curl is forced to go through the it for all traffic. This might mean that DNS fails. Resolve the checkip.dyndns.org ip outside of curl so it can be guaranteed that the traffic of curl will be just http and nothing else. This allows pfSense installation without internet access to work still since if gethostbyname fails now it just extracts the ip from the local interface. To be checked out is what behaviour this should give for CARPgit diff! (Write now surely it does the wrong thing!)
Ermal Luçi
01:35 AM Revision 9d96a475: Cleanup code to make it easier to read and faster.
Ermal Luçi
01:33 AM Revision 854415fa: Move files to pfSense.obsoletedfiles
Scott Ullrich
12:30 AM Revision b93a3dd5: Do not allow duplicate netcat reflection entries. Resolves #193
Scott Ullrich
12:00 AM Revision f7973caf: Use any for block until a diff solution can be created
Scott Ullrich

11/29/2009

11:52 PM Bug #196: remote syslog does not work after reboot
Hmmm, on the other hand, don't think it package related - my virtualbox repro, is a barebones "quick install" with no... Dan Swartzendruber
11:50 PM Bug #196: remote syslog does not work after reboot
yes, i have a number of packages loaded (squid, havp, etc...) i have been looking at the source on cvsweb and i thin... Dan Swartzendruber
11:42 PM Bug #196: remote syslog does not work after reboot
Sounds like syslog fails binding to the local address, as if something else were already bound to 514. What's the exa... Chris Buechler
11:40 PM Bug #196: remote syslog does not work after reboot
That is odd then. As far as binding, yes and no. I reread the log message, and the complaint is about sendto(), not... Dan Swartzendruber
11:27 PM Bug #196 (Feedback): remote syslog does not work after reboot
This isn't universally true, I have multiple boxes that use remote syslog on 1.2.3 and work fine after rebooting. A c... Chris Buechler
11:01 PM Bug #196 (Resolved): remote syslog does not work after reboot
If you enable remote syslogging it works fine until you reboot pfsense, at which point no messages are ever sent to t... Dan Swartzendruber
11:46 PM Revision e910d203: Lock out SSH going to LANIPS. Use correct SSH port if custom port is defined.
Scott Ullrich
11:39 PM Revision c1fdf37f: Process old entries, too
Scott Ullrich
11:37 PM Revision 26d22470: Update ttys serial lines. Resolves #165
To prevent collisions with the sio(4) driver, the uart(4) driver
uses different names for its device nodes. T...
Scott Ullrich
11:33 PM Revision 07b1797b: Define full path to binaries
Scott Ullrich
11:23 PM Revision c0c7eb48: Remove Header
Scott Ullrich
11:22 PM Revision 344c68b2: Post against reboot.php and reboot instead of reinventing the wheel. Ticket #191
Scott Ullrich
11:22 PM Revision 343bb325: Do not show reboot notices twice. Resolves #191
Scott Ullrich
11:20 PM Revision 0069f9fc: Fix ' in alias description. Confirmed working fix for ticket #143
Jim Pingle
11:11 PM Todo #63: Change web interface default to HTTPS
This is important for 2.0. Not one modern security appliance ships defaulted to HTTP. It's fine to allow people to sw... Chris Buechler
10:57 PM Revision 4909d142: Delete DHCP Server interfaces and do not leave XXXX based interfaces. Resolves #16
Scott Ullrich
10:56 PM Bug #195: Can not log out of console menu
Doesn't work at the console for me either. Via SSH it does. Chris Buechler
07:23 PM Bug #195 (Feedback): Can not log out of console menu
Strange, I just tested this on a 2.0 / 8.0 box and it works? Scott Ullrich
04:55 PM Bug #195 (Resolved): Can not log out of console menu
When the console lockout is enabled on 2.0 you can not log out after logging in. Thus leaving the terminal open. Seth Mos
09:54 PM Revision b3a07b12: Notate what code does and remove XXX
Scott Ullrich
09:50 PM Revision cc558460: Do not show motd
Scott Ullrich
09:46 PM Revision 43a8195e: Nuke motd
Scott Ullrich
09:17 PM Bug #109: Drop down menu for pages with long tabs only works in Firefox
In addition to Firefox, it also works on Opera, at least 10.xx
It doesn't work on IE 8, in normal or compatibility...
Jim Pingle
08:27 PM Revision f8cc63e7: Revert commit and change back to dnsIf Ticket #68
Scott Ullrich
07:35 PM Bug #193 (Resolved): NAT reflection duplicate entries
Applied in changeset commit:"b93a3dd5087ee7c719ce4a6c2b190350fcc81c8b". Scott Ullrich
03:35 PM Bug #193 (Resolved): NAT reflection duplicate entries
(confirmed in 2.0 and moved from cvstrac)
Hi, the problem is with automatic NAT reflection.
Everytime you add a...
Chris Buechler
07:12 PM Feature #8: Clear states after failover
pfctl -b <IP of interface>
does this reportedly (haven't tested thoroughly, it's in our code and appears to work).
Chris Buechler
07:04 PM Feature #8: Clear states after failover
This is important, services that maintain a connection never come back after failover without this. VoIP is a good ex... Chris Buechler
06:45 PM Bug #165 (Resolved): Serial console on 8.x doesn't work properly
Applied in changeset commit:"26d224707f3e0c9e0bfc3b81604d61358f9a8cf5". Scott Ullrich
06:25 PM Bug #191 (Resolved): Config restore problems
Applied in changeset commit:"343bb325f6d3e6b9d477495b367885b317e40d0a". Scott Ullrich
06:21 PM Bug #143: Apostrophe in alias description breaks mouse-over display
That commit fixed schedule descriptions, but not Alias descriptions. I just committed a fix for Alias descriptions wh... Jim Pingle
06:07 PM Bug #66 (Feedback): Nanobsd does not work on WRAP
Scott Ullrich
05:58 PM Bug #16 (Resolved): Deleting multiple OPT interfaces results in an invalid configuration
Scott Ullrich
05:58 PM Bug #164 (Resolved): Custom installer does not allow kernel selection
Scott Ullrich
04:59 PM Bug #21 (Feedback): Rulesets containing hostnames do not load at boot time
With a snapshot from 18-11-2009 it still does not load the rules at boot. Worse yet, failure of the DNS server causes... Seth Mos
04:50 PM Revision 04967d99: Fix reboot function on 2.0.
Jim Pingle
04:31 PM Feature #132 (Resolved): update OLSRd to 0.5.6-r6
Updated in ra2847f7 Scott Ullrich
04:30 PM Bug #194 (Closed): Rules specifying a deleted interface skipped
(updated to reflect status in 2.0, and moved from cvstrac)
When an interface is deleted, any rules referencing tha...
Chris Buechler
04:23 PM Bug #166 (Closed): Input validation on Gateway editor needs work
Confirmed, this works fine now.
Thanks!
Jim Pingle
03:56 PM Bug #106 (Feedback): 1.2.3-RC2 - NanoBSD - Dynamic DNS Updates (DynDNS.org)
Scott Ullrich
03:42 PM Bug #88 (Resolved): TXCSUM forced on at boot which breaks wireless bridging
It appears the driver bug that necessitated this change in RELENG_1_2 is no longer an issue in FreeBSD 8.0, so no nee... Chris Buechler
03:31 PM Bug #192 (Resolved): Port Forward external port range shown wrong
When editing a port forward using a named port, for instance SSH, the external port range shows:
from SSH
to (othe...
Chris Buechler
02:55 PM Bug #68 (New): Dyndns for second WAN( opt1) does not work
Chris Buechler
12:18 PM Bug #68: Dyndns for second WAN( opt1) does not work
I looked at the change revision and added the changes but it still did not work.
There was actually an error in th...
GS FON
04:41 AM Revision 407f6220: clarify what is valid for input errors on hostname
Chris Buechler
03:09 AM Bug #140: Switching to AON should generate proper full NAT rules
I'll look at this, I made the existing nat code in 1.2 iirc.
I just tested this with multi wan on 2.0 from a 18-11-2...
Seth Mos
02:26 AM Revision d539e0e8: Make the graph IDs z-index: 1, which seems to fix it overwriting the menu. Tested on FF and Opera. While here, remove redundant graph ID declaration. Fixes #35 on 2.0.
Jim Pingle
02:19 AM Revision 7db2e2e8: No need for priv.inc
Scott Ullrich
02:15 AM Revision 5092a6fb: include priv.inc
Scott Ullrich
01:48 AM Revision f1a73dbf: Add select all button
Scott Ullrich
01:32 AM Revision 2afddcb1: Disabled is not a required field
Scott Ullrich
01:13 AM Revision 649b4d59: Update default privs
Scott Ullrich
01:08 AM Revision ead24d63: Include priv.defs.inc
Scott Ullrich
12:55 AM Revision 7deffa40: Add listtopic. Remove tab
Scott Ullrich

11/28/2009

11:44 PM Bug #187 (Resolved): m0n0wall config conversion trigger invalid
fixed Chris Buechler
05:48 PM Bug #187 (Feedback): m0n0wall config conversion trigger invalid
It now looks for <m0n0wall> as of r1d68379 Scott Ullrich
05:46 PM Bug #187 (New): m0n0wall config conversion trigger invalid
It's triggered now with "m0n0wall", not "<m0n0wall>". The latter would be fine.
Chris Buechler
01:39 PM Bug #187 (Feedback): m0n0wall config conversion trigger invalid
The change is only triggered if <m0n0wall> is found. It then proceeds to convert all m0n0wall -> pfSense which is p... Scott Ullrich
12:44 AM Bug #187 (Resolved): m0n0wall config conversion trigger invalid
If the string "m0n0wall" is found anywhere in the configuration, including things like a rule description, it gets co... Chris Buechler
11:43 PM Revision 24caf104: Automatically select the last known vhid + 1 when creating new entries
Scott Ullrich
11:38 PM Revision 03fdfdd6: Verify carp VHIDS no matter what and compare to current id if needed Resolves #189
Scott Ullrich
11:19 PM Revision 07a3b40b: Correctly deterimine the IP address for optional interfaces. Ticket #68
Scott Ullrich
10:47 PM Revision 1d683793: Search for <m0n0wall> not m0n0wall
Scott Ullrich
10:29 PM Revision c7323d81: Add openvpn client custom option. Ticket #103
Scott Ullrich
10:22 PM Revision e6dd418d: Slow down updates for rate util
Scott Ullrich
10:09 PM Revision 6347e08c: Remove ipsec_in_use sysctl
Scott Ullrich
10:06 PM Revision 0674f163: Unbreak configuration sync. Resolves #182
Scott Ullrich
10:00 PM Revision 1386e392: Set a+rx
Scott Ullrich
09:51 PM Revision 140a111d: Require filter.inc and shaper.inc
Scott Ullrich
09:48 PM Feature #84: Nightly Filter Summary E-Mail
Change the target on this to 3.0. It might be a package for 2.0 but I doubt it would be complete and refined enough t... Jim Pingle
09:47 PM Revision cace2dbb: Dedicate 6 characters
Scott Ullrich
09:47 PM Revision 9c38bcea: Do not dedicate 16 characters to interface name
Scott Ullrich
09:45 PM pfSense Packages Bug #35 (Resolved): traffic graph in dashboard may hide the toolbar in pfsense-ng theme
Applied in changeset commit:"a6f480947baaf4c2bc11ded3b132981f71271c39". Anonymous
09:45 PM pfSense Packages Bug #35 (Feedback): traffic graph in dashboard may hide the toolbar in pfsense-ng theme
I committed fixes for this in 2.0 (it had not been fixed there as I thought) and also for the dashboard package.
I...
Jim Pingle
09:32 PM Revision d74b5b8b: Fix formatting.
Scott Ullrich
09:30 PM Bug #191 (Resolved): Config restore problems
When restoring a config, noted two issues:
1) It displays two notifications (screenshot attached).
2) After clic...
Chris Buechler
08:57 PM Revision d11c1f93: Add radius mac formatting GUI bits. The backend bits where already present. Resolves #178
Scott Ullrich
08:16 PM Bug #190 (Resolved): Configuration backup very slow
After clicking "Download configuration", it takes more than 30 seconds for the configuration to download. Chrome sits... Chris Buechler
07:56 PM Revision 30c4ae8a: Seperate diffserv box into a <select> dropdown. Hide item behind advanced button. Move down one section near other advanced items. Resolves #60
Scott Ullrich
07:40 PM Revision c898b8aa: Diffserv code point is not a reqired field
Scott Ullrich
07:16 PM Revision f69f34f1: sysctl kern.polling.enable=0 has been phased out. Simply run ifconfig interface polling or ifconfig interface -polling. Ticket #124
Scott Ullrich
07:13 PM Revision 5c1f3ed2: Remove GMT time zone items which are actually reversed and confusing. Resolves #176 - http://www.freebsd.org/cgi/query-pr.cgi?pr=24385
Scott Ullrich
06:51 PM Revision c7ed2141: Build a new array of items that have .pat in them. Resolves #171
Scott Ullrich
06:40 PM Bug #189 (Resolved): CARP VHID missing input validation
Applied in changeset commit:"03fdfdd652b86da67eb44235f67a75e90fc9dfea". Scott Ullrich
05:21 PM Bug #189 (Resolved): CARP VHID missing input validation
When switching an existing VIP to a CARP VIP, the VHID is not validated. It's possible to create duplicate VHIDs when... Chris Buechler
06:21 PM Bug #68 (Feedback): Dyndns for second WAN( opt1) does not work
Please try commit r07a3b40 or a new snapshot and report back.
Scott Ullrich
06:18 PM Bug #186 (Closed): pptp can not unset radius issueips
You have an outdated version if you have two of those check boxes, I fixed that a while ago. I also fixed a problem a... Chris Buechler
05:35 AM Bug #186: pptp can not unset radius issueips
I found the problem there...
the checkbox Radiusissued Ips is shown twice on this page
once below the pptp dns...
Matthias Matthias
05:31 PM Bug #103 (Feedback): OpenVPN client custom options missing
Scott Ullrich
05:10 PM Bug #182 (Resolved): Carp sync broken in 2.0
Applied in changeset commit:"0674f163850c338a4e1f6f12c3d484c9a8d5b955". Scott Ullrich
05:04 PM Bug #188 (Rejected): NIC getting error in/out after upgrade 1.2.3 RC1 to 1.2.3 RC3
This is a FreeBSD issue we can't do anything about. See:
http://doc.pfsense.org/index.php/Policy_on_FreeBSD_issues
Chris Buechler
04:58 PM Bug #188 (Rejected): NIC getting error in/out after upgrade 1.2.3 RC1 to 1.2.3 RC3
working build was built on Wed Apr 22
not working build 1.2.3-RC3 built on Mon Nov 23
my nic in dmesg is:
bge0...
Michel Samovojski
04:21 PM Feature #17 (Closed): LED support on ALIX, WRAP, etc.
I have already addressed the alert issue, and the interface assignment issue is apparently either fixed or no longer ... Jim Pingle
04:00 PM Todo #178 (Resolved): Import MAC address formatting option from m0n0
Applied in changeset commit:"d11c1f931a20d2d9ed692b396787cab55a5ff68b". Scott Ullrich
03:53 PM Bug #144 (Needs Patch): Syslog messages violate RFC 3164
Nearly everything appears to violate RFC 3164. Stock BSDs, m0n0wall, Cisco IOS (by default). The most common syslog s... Chris Buechler
03:00 PM Bug #60 (Resolved): Firewall rules edit -> DiffServ Code Point
Applied in changeset commit:"30c4ae8a6bf91f7656f07d80f2e8cafb83d1113a". Scott Ullrich
02:16 PM Bug #124 (Feedback): Polling problems with 8
Scott Ullrich
02:15 PM Bug #176 (Resolved): GMT offset zones reversed
Applied in changeset commit:"5c1f3ed27083c9ce218c7c638488dec44110d7ff". Scott Ullrich
02:06 PM Bug #78: Outgoing load balancer needs configuration upgrade
What appears to be left: upgrading configuration from 1.2 -> relayd
Bill mentioned one more area that might just ...
Scott Ullrich
01:55 PM Bug #171 (Resolved): "LICENSE" shows up in L7 protocol list
Applied in changeset commit:"c7ed2141c2d277b0974a825bf60a9958ac7a0ffe". Scott Ullrich
10:52 AM Revision ceae2616: Use propper name for interface groups.
Ermal Luçi
10:47 AM Revision 4400ad66: Rework qinq a bit. Make it use a vlan(4) as the firt Q and a ng_vlan(4) for the second Q in QinQ.
Ermal Luçi
08:05 AM Revision a726c0e8: Missed name change.
Ermal Luçi
07:28 AM Revision 7c9d8d71: Please pretty please use the interfaces function rather than than growing yet again the horrendous custom made things. Thank you. Ticket #141
Ermal Luçi
06:57 AM Bug #141: Reserved names cannot be used for aliases or interfaces
It would be better to just add a single char to the beginning of alias names.
So people can have some freedom on nam...
Ermal Luçi
12:15 AM Bug #141 (Resolved): Reserved names cannot be used for aliases or interfaces
Applied in changeset commit:"58b0abb3d3485dc5506e6b8e6ec29297e1c16244". Scott Ullrich
12:07 AM Bug #141 (New): Reserved names cannot be used for aliases or interfaces
no change. Chris Buechler
05:40 AM Revision 34cdf949: fix typo
Chris Buechler
05:11 AM Revision 58b0abb3: Correct typo Resolves #141
Scott Ullrich
04:55 AM Revision d823b81c: Use long php notation opener
Scott Ullrich
03:59 AM Revision 5f97f256: Do not remount ro twice
Scott Ullrich
03:57 AM Revision 48e29ac9: Download and verify the bogons md5 with the bogons files Ticket #141
Scott Ullrich
03:43 AM Revision 143048e3: Do not allow interface names as alias names Ticket #141
Scott Ullrich
03:41 AM Revision f76a479d: Do not allow reserved keywords as alias names Ticket #141
Scott Ullrich
02:24 AM Revision 20138aba: Only show files with .pat in them Resolves #171
Scott Ullrich
02:00 AM Revision b6693b01: use _SERVER[\'HTTP_HOST\']
Scott Ullrich
01:50 AM Revision 39d1c22d: Use _SERVER['HTTP_HOST'] instead of lanip Resolves #157
Scott Ullrich
01:43 AM Revision 5e9dd72a: Add is_URL()
Scott Ullrich
01:13 AM Revision 772d3121: Use ['name'] when looking up items
Scott Ullrich
12:40 AM Revision d2aa8cd6: Escape ' Ticket #143
Scott Ullrich
12:12 AM Revision 158d9aa6: Show ajax properly
Scott Ullrich
12:02 AM Revision b4bfd25d: Add disabled checkbox. Add code to check for disabled accounts.
Scott Ullrich

11/27/2009

11:52 PM Bug #160 (Resolved): Captive portal interfaces box doesn't expand
yeah this is ok now, not sure what happened to my sync earlier. Chris Buechler
11:26 PM Bug #160 (Feedback): Captive portal interfaces box doesn't expand
Maybe your gitsync is not working.
It works fine, here is a screenshot of a box sized 4.
http://yfrog.com/1d3at...
Scott Ullrich
06:13 PM Bug #160 (New): Captive portal interfaces box doesn't expand
No change (size is still 3 when you have 5 interfaces) Chris Buechler
05:25 PM Bug #160 (Resolved): Captive portal interfaces box doesn't expand
Applied in changeset commit:"685493b5dac9843554e3dead633e22fb40737a8c". Scott Ullrich
11:43 PM Revision e7d3b8f4: Add input validation to check if the gateway IP is in the local subnet for that interface.
Needs testing, no idea if this works for ppp or pppoe interfaces. Seth Mos
11:36 PM Bug #76 (Feedback): Changes needed to traffic shaper since its rewrite
most if not all of these items where fixed by Ermal recently. Scott Ullrich
11:26 PM Revision e489f87d: in_array() is needle, haystack. Not the othe way round which throws a wrong datatype warning.
Issue 166 Seth Mos
10:58 PM Bug #183 (Feedback): Bogons data isn't validated
Scott Ullrich
10:48 PM Bug #183: Bogons data isn't validated
It would make more sense to verify the file to the md5 that is now being generated at bogon-bn-nonagg.txt.md5 Scott Ullrich
07:48 PM Bug #183: Bogons data isn't validated
Patch provided in list thread mentioned above.
Chris Buechler
10:54 PM Revision f1a1997f: Return after setting account expired
Scott Ullrich
10:54 PM Revision 7dd044f2: Honor account expiration
Scott Ullrich
10:46 PM Revision 0a82fa9b: Allow expiration date to lie in the past which has the side effect of disabling the account Ticket #65
Scott Ullrich
10:44 PM Bug #141 (Feedback): Reserved names cannot be used for aliases or interfaces
Scott Ullrich
10:37 PM Bug #186 (Feedback): pptp can not unset radius issueips
I just tested this and the checkbox unchecked after posting. I even revisited the page and it was still unchecked. P... Scott Ullrich
05:29 AM Bug #186 (Closed): pptp can not unset radius issueips
if this flag is set once, the unset is not working in the gui Matthias Matthias
10:32 PM Bug #143 (Feedback): Apostrophe in alias description breaks mouse-over display
Please test with newer php 5.2.11 binary. Scott Ullrich
10:28 PM Revision 8512951f: Fixup the wireless graph, not sure if many people ever saw it, considering it was included in 1.2 and up but did not look very pretty.
Greatly enhanced the readability by setting up the default colors better and increasing the line thickness to 2. Seth Mos
10:22 PM Revision 85dd175d: Nuke alert. Resolves #125
Scott Ullrich
10:22 PM Revision 685493b5: Expand services -> captiveportal infterface box to match the number of interfaces present Resolves #160
Scott Ullrich
09:59 PM Revision a7dbeea9: Merge branch 'master' of git@rcs.pfsense.org:pfsense/mainline
Pierre POMES
09:57 PM Revision 46c5b763: Fix hostname checking when entering a dhcp static mapping and replace "." with "_" when writing "host-name" option in dhcpd.conf. Resolves #159
Pierre POMES
09:55 PM Revision 35b91f77: Add newline after set radius server Resolves #184
Scott Ullrich
09:53 PM Revision 1ee5d4b3: Call enable_rrd_graphing() on save Resolves #154 + previous commit
Scott Ullrich
09:50 PM Bug #171 (New): "LICENSE" shows up in L7 protocol list
Scott Ullrich
09:25 PM Bug #171 (Resolved): "LICENSE" shows up in L7 protocol list
Applied in changeset commit:"20138aba7214bbcc6e90a5787d33521f8f5ed4e3". Scott Ullrich
05:49 PM Bug #171 (New): "LICENSE" shows up in L7 protocol list
not fixed Chris Buechler
04:25 PM Bug #171 (Resolved): "LICENSE" shows up in L7 protocol list
Applied in changeset commit:"64fba8ec93fa47d284483e6da6a1989d6dd46ce6". Scott Ullrich
09:37 PM Revision 6e6233d0: Call enable_rrd_graphing(); when clicking save Ticket #154
Scott Ullrich
09:34 PM Revision 95dd7e9d: Set location of header request
Scott Ullrich
09:32 PM Revision fa6a664d: When working with one interface only, do not attempt to setup lan during setup wizard. Ticket #158
Scott Ullrich
09:24 PM Revision 64fba8ec: Do not show LICENSE in the list of shaper patterns. Resolves #171
Scott Ullrich
09:18 PM Bug #158 (Feedback): Setup wizard breaks single interface configurations
Scott Ullrich
09:17 PM Revision 4195c967: Correctly output only selected backup area when do not backup packages is selected. Resolves #168
Scott Ullrich
08:55 PM Bug #157 (Resolved): Setup wizard redirect broken
Applied in changeset commit:"39d1c22d8b6b570b386ec2050f6c7e7e63b4d48d". Scott Ullrich
08:46 PM Bug #157 (New): Setup wizard redirect broken
Scott Ullrich
08:46 PM Bug #157 (Feedback): Setup wizard redirect broken
Scott Ullrich
05:55 PM Bug #157 (New): Setup wizard redirect broken
this still doesn't work when accessing WAN side at least. Chris Buechler
04:21 PM Bug #157 (Resolved): Setup wizard redirect broken
I fixed this last week when fixing up requires. Just tested and it redirected to $myurl OK. Closing. Scott Ullrich
08:03 PM Revision 55c61326: Include neccessary files.
Ermal Luçi
07:40 PM Bug #134: Active mode FTP causes a panic
fixed Chris Buechler
07:18 PM Bug #6 (Feedback): Status -> Wireless display bugs
Seth commited a fix for this yesterday. Scott Ullrich
07:13 PM Todo #65 (Feedback): Ability to disable accounts
Scott Ullrich
07:03 PM Todo #65: Ability to disable accounts
Added bits in rb4bfd25 Scott Ullrich
06:34 PM Bug #173 (Feedback): Missing input validation for gateways
Seth Mos
06:31 PM Bug #173: Missing input validation for gateways
Seth Mos wrote:
The monitor IP check was caused by a incorrect variable name which was fixed in #166.
Adding code...
Seth Mos
06:23 PM Bug #173 (New): Missing input validation for gateways
Seth Mos
06:20 PM Bug #173 (Feedback): Missing input validation for gateways
. Seth Mos
06:22 PM Bug #166 (Feedback): Input validation on Gateway editor needs work
Hi Jim,
I added a fix in CVS, I use the in_array arguments in the wrong order and was using the wrong variable nam...
Seth Mos
06:19 PM Bug #125 (Feedback): Erroneous "interface not present" alert
Chris Buechler
06:18 PM Bug #125: Erroneous "interface not present" alert
needs testing Chris Buechler
05:25 PM Bug #125 (Resolved): Erroneous "interface not present" alert
Applied in changeset commit:"85dd175d043f248c590b18ced068dc9dbfb2054f". Scott Ullrich
06:15 PM Bug #154: New interface does not have RRD graphs created
fixed Chris Buechler
04:55 PM Bug #154 (Resolved): New interface does not have RRD graphs created
Applied in changeset commit:"1ee5d4b3a086e3ad429b128e31de32ae69ec3b2e". Scott Ullrich
06:07 PM Bug #168: Backup area
Looks to be resolved. Nuno: please test and verify Chris Buechler
04:20 PM Bug #168 (Resolved): Backup area
Applied in changeset commit:"4195c967cc25eefa2c1c5bc889788eacb4531fbd". Scott Ullrich
06:01 PM Bug #159: "." in hostname creates invalid dhcpd.conf
this is good now, thanks! Chris Buechler
05:00 PM Bug #159 (Resolved): "." in hostname creates invalid dhcpd.conf
Applied in changeset commit:"46c5b763ef26269b50d303fc62793c58a42eefb1". Pierre POMES
05:33 PM Bug #55 (Feedback): 2.0 / FreeBSD 8 needs wireless changes to work.
Seth and my self have been commiting changes. So far this seems to work. Needs more testing.
Scott Ullrich
05:00 PM Bug #184 (Resolved): pptp configuration missing newline in mpd.conf
Applied in changeset commit:"35b91f770335000fd362147948629128776c325f". Scott Ullrich
05:23 AM Bug #184 (Resolved): pptp configuration missing newline in mpd.conf
on enabling Radius authentifikation + Radius accounting there is a missing newline in the mpd.conf (after set radius ... Matthias Matthias
03:50 PM Revision 42bad812: Fix get_interface_mac function and rename local variable to function qinq interface configure.
Ermal Luçi
05:27 AM Feature #185 (Resolved): PPPoE server 'set radius me'
it would be nice to have a possibility to set the radius me ip from the gui for the accounting also to diable the com... Matthias Matthias
04:29 AM Revision 77456954: clarify text
Chris Buechler
04:25 AM Revision d8ba56f6: fix up text
Chris Buechler
02:23 AM Revision 4c86a165: add captiveportal.inc
Scott Ullrich
02:18 AM Revision 5a7d827b: Add ipsec.inc and vpn.inc
Scott Ullrich
12:39 AM Bug #170: Shaper multi-all wizard doesn't work
this is fixed Chris Buechler
 

Also available in: Atom