Vadim Kurland
edd20761cc
build 3549
2011-06-10 15:29:40 -07:00
Vadim Kurland
feef1a1c30
see #2499 updated copyright in the "About" dialog
2011-06-10 15:27:08 -07:00
Vadim Kurland
d4a8546b6b
incremented DTD version to 22 necause changes made for keywords and DynamicGroup object are not backwards-compatible; removed contributed autoupgrade xslt script that is not being used anymore, see #2501
2011-06-10 15:26:06 -07:00
Vadim Kurland
b4b3c1ccad
see #2488 fixed new object menu issues
2011-06-06 21:56:00 -07:00
Vadim Kurland
729216be1f
see #2468 showing "new object" menu in the right place
2011-06-06 20:55:55 -07:00
Vadim Kurland
b1f1eddc72
see #2479 remove quotes from the file name spec
2011-06-05 23:08:17 -07:00
Vadim Kurland
2e1a499c18
see #2472 added warning for table "const" and "counters" keywords
2011-06-05 23:01:47 -07:00
Vadim Kurland
9ef6945109
see #2483 need to clear both host os and version QComboBox widgets
2011-06-05 22:55:39 -07:00
Vadim Kurland
3d87038f19
see #2480 fixed a bug: toggling negate flag in a rule element reset selection in the rule set view to the row 0 column 0
2011-06-05 22:52:10 -07:00
Vadim Kurland
3a2041d16d
per Mikes request, the GUI now opens rule set object of the firewall
...
when user opens the firewall or any of its children objects in the
editor. This includes any rule set, interface or any other child
object.
Also moved function Interface::getParentHost() from class Interface to
class Host as static FWObject* Host::getParentHost(FWObject *o). Its
behavior is now more logical, it returns non-NULL pointer only if an
object actually has a parent that is host, firewall or cluster. Old
function Interface::getParentHost() returned non-NULL pointer even
when object was not in the proper position in the tree.
Now this function can be used to get parent host/firewall/cluster for
any child object rather than only interface.
I had to fix bunch of problems in unit tests that got uncovered because
new function behaves in a more strict way (returns NULL when there is
no parent of correct type).
2011-06-05 21:38:46 -07:00
Vadim Kurland
c171994c82
see #2454 double click or keypress Enter on object "any" shows editor with our special comment but does not switch obejct tree to the "Standard objects" library; also made the tree switch to the right library both when user double clicks or hits Enter
2011-06-05 18:55:50 -07:00
Vadim Kurland
d9cd33f28b
see #2475 removing State_Active flag before drawing the row if the tree view does not have focus
2011-06-05 16:42:45 -07:00
Vadim Kurland
79ca86edb8
see #2468 object tree panel is not docable/floating window anymore
2011-06-05 10:29:51 -07:00
Vadim Kurland
9561f4b2c5
see #2475 more debugging, will test on Mac with latest Qt
2011-06-04 23:43:29 -07:00
Vadim Kurland
cbf51a1920
see #2468 changes to the toolbar above rules: moved buttons to the far right, removed "Currently Editing"
2011-06-04 22:08:37 -07:00
Vadim Kurland
86c58fff3b
see #2477 disable detection of dbus
2011-06-04 20:52:23 -07:00
Vadim Kurland
36a6472f95
fixing build on windows mingw: avoid token name "IN"
2011-06-04 20:36:07 -07:00
Vadim Kurland
b985fcacac
fixing build on windows mingw: avoid token name "CONST"
2011-06-04 20:32:37 -07:00
Vadim Kurland
c808c4ab93
see #2475 hardcoding inactive highlight color "silver" for ObjectTreeView
2011-06-04 20:18:00 -07:00
Vadim Kurland
cb71c53697
see #2474 whole rule is now highlighted when any cell is selected, using neutral color "silver" to highlight the rule while standard highlighting color is used to highlight selected object in the rule
2011-06-04 19:29:58 -07:00
Vadim Kurland
8d80e04420
FWWindow_editor.cpp (openEditor): this change is a part of the
...
GUI usability improvements: when user double clicks on a firewall
object to open it in the editor, rule set view panel switches to
the rule set of that firewall. To decide which rule set to show,
the program scans history of the objects the user opened before in
the same GUI session and shows that firewall's rule set they
opened last. If user never opened any rule sets of this firewall,
then the first Policy object is shown. See #2465 .
2011-06-04 17:04:29 -07:00
Vadim Kurland
5888835db7
see #2454 making "any" open in the editor upon double-click; added ChangeLog record
2011-06-04 16:16:48 -07:00
Vadim Kurland
56c18e3e1e
see #2454 now opening object "any" in the editor panel and showing some hand-holding text in existing "Comment" widget
2011-06-04 16:09:59 -07:00
Vadim Kurland
fcdfe6dfac
see #2451 Using keyboard arrows to navigate rules results in objects being opened in editor panel
2011-06-04 15:14:19 -07:00
Vadim Kurland
d42403db00
fixes #2450 Double-clicking on object in rule shifts keyboard focus to object tree
2011-06-04 14:36:21 -07:00
Vadim Kurland
e7dbf88530
fixes #2452 rename rule interface column default text to "any"
2011-06-04 14:31:08 -07:00
Vadim Kurland
a6fda88a54
see #2473 made text appear vertically aligned across different rule cells even when they dont have any icon, e.g. "any"
2011-06-04 14:25:35 -07:00
Vadim Kurland
99cd831b75
updated unit test files
2011-06-04 13:02:42 -07:00
Vadim Kurland
8cab8f0672
see #2470 added support for set skip with a list of interface names
2011-06-04 12:57:01 -07:00
Vadim Kurland
ffee2090a7
see #2471 fixed tcp service object dduplication when they have non-blank tcp flags
2011-06-04 12:31:14 -07:00
Vadim Kurland
55730e6f01
see #2403 , #2467 deduplicating AttachedNetwork object
2011-06-03 23:42:47 -07:00
Vadim Kurland
30ec7d1e72
see #2472 fixed import of table definitions without file name and with shortcut network defines
2011-06-03 23:34:25 -07:00
Vadim Kurland
6d6038370c
* applied patch to provide configure command line option to specify
...
path to ccache. Thanks to user "a. k. huettel " on SourceForge.
2011-06-03 20:39:38 -07:00
Vadim Kurland
f330822c8c
fixes #2460 resetting nat rule type in the importer; when rule type setting was left over, it affected the behavior of the compiler and broke it if user tried to single-rule compile some rules
2011-06-03 20:28:05 -07:00
Vadim Kurland
5180b43427
fixes #2469 using right attribute name for host os
2011-06-03 19:28:54 -07:00
Vadim Kurland
33259ebf81
see #2460 added test for the nat rule with multiple objects in TDst; looks like it works
2011-06-03 19:10:40 -07:00
Vadim Kurland
6a9fdbf3af
NATCompiler_pf.cpp (_expand_addr): see #2455 NAT Compiler for PF
...
should use "(interface)" syntax to the right of "->" in NAT rules.
This now works for all interfaces, including those that have ip
addresses in fwbuilder configuration, when interface object appears in
"Translated Source" in a nat rule. When firewall object appears in
"Translated Source", it gets replaced with a set of its interfaces
which also get translated into "-> (interface)".
2011-06-03 18:59:44 -07:00
Vadim Kurland
15bab71f49
* NATCompiler_ipt.cpp (compile): see #2456 Added support for
...
single object negation in "Inbound Interface" and "Outbound
Interface" columns in compiler for iptables.
* NATCompiler_pf.cpp (compile): see #2456 Added support for single
object negation in "Interface" rule element of PF NAT rules. Now
compiler can produce PF commands such as "nat on ! em0 ... " (for
PF <4.7) or "match on ! em0 ..." (for PF >= 4.7)
* Compiler.cpp (singleObjectNegation::processNext): moved rule
processor that processes single object negation in any rule
element to the base class Compiler.
2011-06-03 17:54:14 -07:00
Vadim Kurland
22b812fd4a
see #2438 fixed grammar to match 1024:65535
2011-06-03 08:57:21 -07:00
Vadim Kurland
3b130a090a
realistic test file for scrub commands for PF v4.6 and newer
2011-06-02 22:15:29 -07:00
Vadim Kurland
02b51d5dae
set version to 5.0.0 build 3547
2011-06-02 21:31:57 -07:00
Vadim Kurland
b86900cc54
see #2464 implemented import of "set timeout" commands
2011-06-02 11:38:13 -07:00
Vadim Kurland
d825133481
removing failed attempt to parse ifconfig output
2011-06-02 10:33:40 -07:00
Vadim Kurland
58eb1a865e
see #2394 using InterfaceProperties class to guess where WORD is an interface name or host name; Lexer generates IPV6 token for "1000:1010" port range configuration, could not find a way to fix this in the lexer so using this token to parse port ranges in the parser; added unit test for host "from" and "to" matches, including interface name and host name matches
2011-06-01 23:44:53 -07:00
Vadim Kurland
d1f83311f1
see #2461 parser and importer for ifconfig output. Linux ifconfig import works, BSD ifconfig import does not
2011-05-31 23:04:57 -07:00
Vadim Kurland
52ea731f92
refactored useful classes AddressSpec, PortSpec, InterfaceSpec, IcmpSpec and RouteSpec to separate modules so they can be used with other installers
2011-05-31 16:31:05 -07:00
Vadim Kurland
564500768e
see #2458 , #2459 import of "rdr", "no nat", "no rdr" rules
2011-05-31 12:55:55 -07:00
Vadim Kurland
fd7c3601ba
see #2449 unit test for nat rules
2011-05-30 22:03:35 -07:00
Vadim Kurland
f9f78fe7bd
using "port 1000:*" in PF nat commands
2011-05-30 21:59:40 -07:00
Vadim Kurland
2f3f509dfe
see #2449 better error message for "source-hash" with options
2011-05-30 21:58:06 -07:00
Vadim Kurland
1ed2581dd1
see #2449 import of "nat" rules. First implementation. Restrictions are listed in ChangeLog
2011-05-30 21:49:46 -07:00
Vadim Kurland
3a6c3dfa09
fixed unit tests ; fixed import of port ranges
2011-05-29 23:41:02 -07:00
Vadim Kurland
ee6723a05d
fixes #2429 fixed common error message shown when importer could not create firewall object
2011-05-29 21:49:18 -07:00
Vadim Kurland
2f075efd81
added unit test files
2011-05-29 21:48:51 -07:00
Vadim Kurland
5da32dfb2c
added unit tests skeleton for PF import; fixed warning that appeared at the end of import, saying no rules have been created
2011-05-29 21:39:44 -07:00
Vadim Kurland
77560a735b
see #2446 fixed deduplication of address table objects
2011-05-29 14:33:21 -07:00
Vadim Kurland
ba53d7b8f5
see #2447 implemented import of parameters for action "block"
2011-05-29 13:38:36 -07:00
Vadim Kurland
3a88a0cbc5
user-specified parameter for action Reject takes precedence over automatically determined action based on the protocol. If user chooses one of the icmp responses, it should be used even with tcp (we used to force return-rst in that case)
2011-05-29 13:36:55 -07:00
Vadim Kurland
aac598f1cc
see #2445 fixed import of tcp/udp ports defined by names; still need to test all possible names to make sure mappings work
2011-05-28 09:27:27 -07:00
Vadim Kurland
a3a07b4b42
see #2394 documenting import limitations in ChangeLog
2011-05-27 14:50:28 -07:00
Vadim Kurland
ef3102aa6a
added .gitignore for PF import tests
2011-05-27 14:45:08 -07:00
Vadim Kurland
83fc99f076
see #2435 tcp flags parsing
2011-05-27 14:35:37 -07:00
Vadim Kurland
8082f602b3
see #2436 fixed handling of the synproxy state option, minor tweaks to the grammar
2011-05-27 12:37:44 -07:00
Vadim Kurland
afdc3707de
fixes #2442 pre-processor removed the very last "\n" from the input stream which broke parser
2011-05-27 12:35:33 -07:00
Vadim Kurland
adde1d534c
see #2436 setting stateless/stateful rule option depending on combination of the "state" keyword and user-chosen version
2011-05-27 12:20:30 -07:00
Vadim Kurland
3b229be520
see #2436 , #2435 added GUI controls to let user choose host OS and version as part of the PF import process. Using this information to configure firewall object
2011-05-27 11:38:29 -07:00
Vadim Kurland
765060c29c
see #2403 added test case file; fixed import of icmp services, added test case file; other fixes
2011-05-26 22:30:07 -07:00
Vadim Kurland
e89cc24466
see #2403 added ability to import clause en0:network; stubbed import of en0:broadcast
2011-05-26 21:29:12 -07:00
Vadim Kurland
e10ab65393
see #2394 creating policy rules with src and dst populated; parsing and creating address tables and groups of addresses
2011-05-25 23:57:27 -07:00
Vadim Kurland
439f8240ba
see #2394 checking pf.conf file before import to determine if it is designed in the style not using keyword "quick". We can not import config like that
2011-05-24 23:01:41 -07:00
Vadim Kurland
12abcf9533
minimal grammar to match "from" and "to", both addresses and ports
2011-05-22 23:17:05 -07:00
Vadim Kurland
9be69950eb
preprocessor for the pf.conf file: unfolging long lines and macro substitutions
2011-05-21 20:12:39 -07:00
Vadim Kurland
64661383cc
Merge branch 'development' into pf_import
2011-05-20 16:22:19 -07:00
Vadim Kurland
bf41a75454
build 3544
2011-05-20 10:33:22 -07:00
Vadim Kurland
ad73a04eae
fixes #2421 windows build failure
2011-05-17 13:56:25 -07:00
Vadim Kurland
24314576f4
see #2420 fixed the function (forgot to return value)
2011-05-17 12:45:48 -07:00
Vadim Kurland
c91740d366
build 3543
2011-05-17 12:00:43 -07:00
Vadim Kurland
ea7f28e1ef
* FWObjectDatabase_tree_ops.cpp (merge): see #2420 "Crash when
...
selecting New Firewall and existing firewall has interface that is
locked". Fixed GUI crash that happened on some operations if an
object in the tree was locked. For example, if the user locked an
interface of one of the firewall objects that then proceeded to
create new firewall object, the GUI would crash. The problem was
not limited to locking specifically interface objects.
2011-05-17 11:56:21 -07:00
Vadim Kurland
6dcf4026c6
see #2408 catching exceptions in FWBApplication::notify()
2011-05-17 10:56:16 -07:00
Vadim Kurland
2e11bc22da
pf import: first draft of the grammar (still does nothing useful), importer class skeleton
2011-05-17 10:05:33 -07:00
Vadim Kurland
25bf50d6a0
fixes #2401 fixed typo
2011-05-15 23:04:01 -07:00
Vadim Kurland
4eb655a9ea
see #2415 call notify() from undo/redo methods of FWCmdRuleNegateRE command
2011-05-15 23:01:59 -07:00
Vadim Kurland
ac4e1bfb62
see #2411 implemented import of iptables rules with target CLASSIFY
2011-05-15 22:47:55 -07:00
Vadim Kurland
b13e56d7d3
see #2414 permit menu item delete for the AttachedNetworks object
2011-05-15 22:26:46 -07:00
Vadim Kurland
edd7f352d0
see #2413 , #2414 do not allow user to copy/paste or duplicate AttachedNetworks object
2011-05-15 19:25:31 -07:00
Vadim Kurland
d2e74f445d
minor tweak for the test - added "catch all" rule in ipv6 branch to make sure it compiles for ipv6
2011-05-15 12:04:24 -07:00
Vadim Kurland
7739ebbcd2
adding missing files
2011-05-15 10:48:58 -07:00
Vadim Kurland
04545f9818
applied patch per SF bug 3302219
...
"unit tests are badly portable"
2011-05-14 22:47:37 -07:00
Vadim Kurland
e149666e51
updated unit test data files
2011-05-14 22:16:46 -07:00
Vadim Kurland
1199fd926a
see #2405 "Tag and classify actions dont work properly with branches".
...
When branching rule points to a rule set that has rules with Tag and
Classify options, branching should occur in mangle table even when
checkbox "create branch in mangle table" is not checked. The fix in
this change is tentative as it creates branch in chains PREROUTING,
POSTROUTING and OUTPUT. Since target CLASSIFY is only allowed in
POSTROUTING, this may create conflict. Need to test more.
2011-05-14 15:46:23 -07:00
Vadim Kurland
c8cc37a6f1
see #1580 re-ran tests
2011-05-14 15:45:10 -07:00
Vadim Kurland
f0dc79359e
* AttachedNetworks.cpp (AttachedNetworks): see #1580 New object
...
type: network object that automatically matches subnets an
interface is attached to. The object can be a child of an
interface. The object is optional and is not created automatically
for all interfaces; user can add it using context menu associated
with an interface. Dialog for this object allows editing of the
name and comment. List of network addresses represented by this
object is always generated automatically. Compiler for PF
translates this object to "en0:network" construct that is
supported by PF. Compiler for iptables expands it to the list of
ipv4 and ipv6 networks defined by the addresses of the parent
interface if interface has static addresses. If interface is
confgiured as "dynamic" and has no address in fwbuilder, then
compiler treats AttachedNetworks object as run-time and uses shell
function to determine network addresses during activation of the
firewall script. Compilers for other firewall platforms always
treat this object as compile-time and abort if it is used with
dynamic interface.
2011-05-14 14:44:00 -07:00
Vadim Kurland
6f9add86c3
* PolicyCompiler_ipt.cpp (processNext): see #2402 "Tag action
...
should be done in PREROUTING so it can be acted on later". If a
rule has both tagging and classification options, the rule should
be split so that iptables command doing tagging goes in PREROUTING
and rule doing classification goes into POSTROUTING chain.
;
2011-05-13 18:21:56 -07:00
Vadim Kurland
a787f35fd0
see #2401 "Deprecating
...
Route option for iptables"
2011-05-13 16:14:34 -07:00
Vadim Kurland
2b67a0a491
see #2399 , #2340 rules that require tagging, classification or routing are now split so that regular actions such as Accept are implemented using normal rules in the table "filter" and rules in table "mangle" only implement tagging, classification and routing. See ChangeLog for longer description
2011-05-13 13:06:42 -07:00
Vadim Kurland
dd061e548f
version 4.3.0.3542 bumped up build number since 3541 was released as 4.2.2
2011-05-11 22:48:10 -07:00
Vadim Kurland
83cc8b4b3f
merge from the latest changes in release-4.2.1
2011-05-11 22:43:01 -07:00
Vadim Kurland
a2d64c733a
set version to 4.2.2
...
see #2395 , #2396 need to call fixTree() to fix pointers to the root of the tree after merge()
2011-05-11 09:53:11 -07:00
Vadim Kurland
e706c96473
v 4.3.0.3541; merged from multiple_actions
2011-05-10 16:33:34 -07:00
Vadim Kurland
7ef3e583e5
see #2367 added test cases for options tag, classify and route and combinations - test object firewall111
2011-05-10 14:57:12 -07:00