Commit Graph

25034 Commits

Author SHA1 Message Date
Phil Davis
4e34cdf3bf Handle release number in installer
This code just looked wrong. It was considering 10.1-RELEASE-p6 to be release number "1" and comparing it to "9".
These changes to do what it seems to intend. This will make that UFS+J stuff appear, if that is of any consequence.
2015-03-23 08:15:57 -03:00
Jose Luis Duran
c2b0382055 Use none instead of a whitespace in sshd_config
Use the `none` keyword instead of a whitespace to disable the FreeBSD version in sshd_config.
2015-03-20 16:04:11 -03:00
Chris Buechler
c1ef7cfb41 Add option for wireless standard "auto", to omit "mode" entirely from ifconfig. This shouldn't be necessary, but specifying mode has proven to trigger driver problems that don't exist if it's left unspecified (such as FreeBSD PR 198680). Chosing "auto" fixes ath(4) BSS mode issues otherwise preventing it from connecting. 2015-03-18 23:52:46 -05:00
Jared Dillard
57413f7fd1 change the location of jquery-ui images in each theme's css file 2015-03-18 14:07:43 -05:00
Renato Botelho
8f553334ba Bump version to 2.2.2-DEVELOPMENT 2015-03-18 14:06:52 -03:00
Phil Davis
5372d26d9d Cleanup code path when adding a new user
1) Only attempt to delete the oldusername if it actually was non-empty - at the moment errors are logged in the system log when adding a new user, because the code was trying to delete the user name "".
2) Call local_user_set() first to create (change, whatever) the user record. This makes the user record exist for a new user. Then call local_user_set_groups() to sort out what groups the user should be in or not in. The existing code would fail to add a new user to the specified group/s because local_user_set_groups() was called too early, before the user actually existed.

Typical system log errors from the old code:
Mar 18 17:10:31 	php-fpm[9542]: /system_usermanager.php: Tried to remove user but got user pw instead. Bailing.
Mar 18 17:10:31 	php-fpm[9542]: /system_usermanager.php: The command '/usr/sbin/pw groupmod admins -g 1999 -M '0,2003,2006,2008' 2>&1' returned exit code '67', the output was 'pw: user `2008' does not exist'

From looking at the code history, I think this has been this way for a long time, not a new bug at all.

Discussed in forum: https://forum.pfsense.org/index.php?topic=90700.msg501766#msg501766
2015-03-18 10:58:58 -03:00
Phil Davis
b13f7a8c58 Do not allow VLAN tag zero
At the moment you can make a VLAN with tag 0. The input validation does not catch it because when $_POST['tag'] = "0" that evaluates to false by PHP.
Always make the checks on 'tag' value whenever the 'tag' key is set at all. If the (required) 'tag' key is not set, then that is already checked for by do_input_validation().
2015-03-18 10:57:31 -03:00
Phil Davis
08b02994b1 Use subnet address in OPT net rules
Example: LAN IP 10.0.1.1/24 OPT1 IP 10.0.2.1/24
Rules with SRC or DST LANnet correctly have 10.0.0.0/24 (the subnet base address) in /tmp/rules.debug
Rules with SRC or DST OPT1net have 10.0.2.1/24 (the OPT1 IP address with OPT1 net mask) in /tmp/rules.debug
It still works (I think) because actually 10.0.2.1/24 and 10.0.2.0/24 interpreted as a subnet still describes the same set of IP addresses, but it looks odd, as reported by: https://forum.pfsense.org/index.php?topic=90096.msg498474#msg498474
Same issue with IPv6 for OPT1net rules.
This fixes the rule generation to that OPT1net uses the base subnet address in the rule, in the same way that LANnet and WANnet does.
2015-03-16 08:21:41 -03:00
Phil Davis
06144727b0 pfSsh.php readline function return value
This just looks wrong. But I guess the code path never comes through here because function readline() already exists in the environment of this script.
2015-03-16 08:16:07 -03:00
Renato Botelho
54aac08057 It's time for 2.2.1-RELEASE 2015-03-13 10:14:08 -03:00
Chris Buechler
ae2db699d6 txpower was disabled for good reason it would appear, it triggers syntax errors in some configurations. Disable it again since it's been disabled for years, and comment out the user-facing config portion for now since it doesn't do anything. Ticket #4516 2015-03-13 03:15:10 -05:00
Chris Buechler
9b65fdd0ce Apply WME input validation to all modes, not just hostap. Ticket #4516 2015-03-13 03:07:50 -05:00
Chris Buechler
e4909df4de Default to 11ng if an option hasn't been configured. Previously we let the browser pick the first in the list (the first the card reported as available), which ended up being 802.11b. Ticket #4516 2015-03-13 02:54:30 -05:00
Chris Buechler
771ca94f69 Default to WPA2, AES for new wireless interface configs. Ticket #4516 2015-03-13 02:29:56 -05:00
Chris Buechler
4d84e32362 Auto-size the interface box on the bridge edit page. 2015-03-13 01:19:47 -05:00
Chris Buechler
1cabb79c28 touch up interfaces.php text 2015-03-13 00:15:05 -05:00
Chris Buechler
33e85f856a Require WPA PSK where WPA-PSK is enabled. Clean up some other text. Ticket #4516 2015-03-12 23:43:31 -05:00
Chris Buechler
3c53b38b03 clean up input errors text 2015-03-12 23:25:51 -05:00
Chris Buechler
e2d36ad626 add missing double == in ipsec.inc 2015-03-12 22:06:42 -05:00
Phil Davis
580f4f3f83 Missin double equals in captiveportal.inc
Looking at where this is nested inside various if statements, I do not think this error did too much harm - only to the $mac['descr'] - in this particular code flow $username is not used for important stuff after this point.
Conflicts:
	etc/inc/captiveportal.inc
2015-03-12 22:03:09 -05:00
Chris Buechler
ec253cd500 Fix up text, remove "only for Atheros" since the option is only shown if a compatible card exists. 2015-03-12 21:01:42 -05:00
Chris Buechler
f5fb15b928 "Auto" channel with hostap doesn't work correctly at the moment, force choosing a specific channel with hostap mode for now. 2015-03-12 20:56:31 -05:00
Chris Buechler
1483a8137f Set txpower since that seems to work fine now. Explicitly set authmode wpa here, though it's also handled by the supplicant/authenticator. Ticket #4516 2015-03-12 20:45:11 -05:00
Renato Botelho
e691957fca Do not start filterdns during boot until a proper fix is done. Ticket #4296 2015-03-12 21:09:55 -03:00
Chris Buechler
80271fb308 add more wireless validation. Ticket #4516 2015-03-12 18:53:31 -05:00
Chris Buechler
22ec33b9d6 Add more validation for wireless config settings. Ticket #4516 2015-03-12 18:22:25 -05:00
Chris Buechler
bda6c6bf4f Add more input validation for wireless parameters. Ticket #4516 2015-03-12 16:48:36 -05:00
Chris Buechler
b00b6c066c Touch up wifi text 2015-03-12 15:07:47 -05:00
Chris Buechler
ad073d9aec If we bail not being able to find the P1 source, log an error. 2015-03-12 14:49:15 -05:00
Phil Davis
7f951c6306 White space in ipsec.inc 2015-03-12 01:32:30 -05:00
Phil Davis
4385f8706a White space in filter.inc
Conflicts:
	etc/inc/filter.inc
2015-03-12 01:29:06 -05:00
Chris Buechler
38b3fab701 use-compression is no longer a valid config option in lighttpd, it can't be enabled. This just throws an error in the log, remove it. 2015-03-12 00:53:23 -05:00
Chris Buechler
74c749be3a Fix IPsec on CARP IPs, broken when fixing IPsec with gateway groups and VIPs. 2015-03-12 00:09:28 -05:00
Chris Buechler
3d67c650ef clean up unique IDs text a bit. 2015-03-11 22:00:43 -05:00
Chris Buechler
1ca17c45c1 Move libstrongswan-unity.so when Unity plugin is disabled so it can't modify the P2. Workaround for Ticket #4178
Conflicts:
	etc/inc/vpn.inc
2015-03-11 20:41:56 -05:00
Renato Botelho
934c88ee95 Proper fix #4443, do not unset carp entry when content differ, also set correct real interface and use subnet to check IP protocol 2015-03-11 20:51:46 -03:00
Renato Botelho
3f5e998c9c Detect when broken rc.firmware is running, fix it and restart. This should fix #4328 2015-03-11 19:14:27 -03:00
Renato Botelho
b6c04ed838 Remove -U from mtree call used to restore files permissions, this is replacing symlink targets by the old values. Ticket #4328 2015-03-11 17:47:05 -03:00
Renato Botelho
c8a4eb4056 Save vip interface and subnet to use to delete old vips from secondary nodes. Fixes #4446 2015-03-11 16:02:59 -03:00
Renato Botelho
b01d44a3f3 Revert "Use a consistent variable name here. related to Ticket #4446"
This reverts commit 0e7954b8a3.
2015-03-11 16:02:59 -03:00
Chris Buechler
87ca92d03c add granular control of state timeouts. Ticket #4509 2015-03-11 13:22:17 -05:00
Renato Botelho
cd8ce13c29 Explicit disable ssl.use-compression on lighty config. It should fix #4230 2015-03-11 14:09:31 -03:00
Renato Botelho
8304fb462a Remove BEAST protection option since default cipher is now good and works with hifn cards 2015-03-11 14:04:38 -03:00
Renato Botelho
3d50cb09c6 Add a log message when hostres SNMP module is ignored on APU boards 2015-03-11 10:05:38 -03:00
Renato Botelho
9f9bdb77f3 Disable SNMP hostres module on APU boards until we figure out why it's crashing on this specific board. Ticket #4403 2015-03-11 09:47:09 -03:00
Phil Davis
1b2af00760 Fix password box cursor position
Similar to
dedc40f7de
The password field shows the little lock icon, but the text input area
starts over the top of the icon and as I type in the field the password
"dots" go over the lock icon in each of these data entry places.
Changing the field name/id to not be "password" but to be "passwordfld",
"passwordfld1" "passwordfld2" and the like fixes it. Something does not
like the field being called just "password".
In interfaces.php I also changed the field "username" to be
"ppp_username". This standardized it to work in a similar way to
pppoe_username pptp_username fields. It looks easier to understand for
me.
2015-03-11 08:29:49 -03:00
Phil Davis
90c39f4e3f Pencil symbols
These are places in the GUI where the cursor sits not in the far left
side of the input box and there is odd-looking white space to the left
of the cursor. Normally there would be a little input graphic in the
white space to the left of the cursor (a pencil, a computer screen, a
lock symbol...)
This change makes the pencil be displayed in all those places.
2015-03-11 08:28:33 -03:00
Chris Buechler
bf57f6ba35 update description after adaptive start/end default change. 2015-03-11 01:37:10 -05:00
Chris Buechler
17a003206d Leave adaptive.start and end at their defaults (60% and 120% of the state limit, respectively) if not user-overridden. 2015-03-11 01:31:50 -05:00
Chris Buechler
bd583dc2f0 Update cipher-list in web interface to prefer PFS. Ticket #4230 2015-03-11 00:24:59 -05:00