Commit Graph

13044 Commits

Author SHA1 Message Date
Renato Botelho
b73e9bc28b Merge pull request #1431 from phil-davis/patch-1 2015-01-12 11:49:22 -02:00
Ermal LUÇI
9d89f78096 Use this generation now of committing pipes directly and only rules to put on ruleset to avoid memory pressure and the timelimit will than be enforced by the caller 2015-01-12 12:27:54 +01:00
Ermal LUÇI
fe9ec12b48 Revert "Ticket #3932 Use array_map to get more parallelism when there are many entries. This makes it not reach the execution timeout with large entries."
This reverts commit 7077addc5a.
2015-01-12 12:25:45 +01:00
Ermal LUÇI
fd9e606614 Actually improve the previous resource leak commit since the function is there but it was not being used during init_rules process. 2015-01-12 12:21:05 +01:00
Ermal LUÇI
18f4d6c90d * Try to autodetect if the execution limit needs to be raised on big number of passthrough entries.
Set the time limit to 0 and restore it back to default value when this is detected.

* Do not leak pipes when reloading ruleset for CP since this will consume available descriptors.
  This has been noted before but considered fixed, this is the real fix actually for dnpipes.
2015-01-12 12:17:00 +01:00
Ermal LUÇI
c80ad8a892 Do not override the passwd string. First it prevents the md5 working if the crypt() check fails and also is useless to override it since the parameter is passed by value and not by reference. 2015-01-12 11:43:21 +01:00
Ermal LUÇI
7077addc5a Ticket #3932 Use array_map to get more parallelism when there are many entries. This makes it not reach the execution timeout with large entries. 2015-01-12 10:38:17 +01:00
Ermal LUÇI
384deecb5c Fix inherent issues with isset and empty values set as true by our parser. This made the piep configuration to be wrong at least for passthrough entries. Ticket #3932 2015-01-12 09:27:17 +01:00
Phil Davis
2d375e8156 Fix cut paste brain fade 2015-01-11 21:00:59 +05:45
Phil Davis
8d848bdfdf Do not return disabled dynamic gateways
When a dynamic gateway is disabled (by the user through the webGUI), it was still being returned by return_gateways_array(). But when called like that, disabled gateways should not be returned. The first part of the routine was correctly skipping disabled gateways, but then the later part would effectively re-generate those dynamic gateways on-the-fly and not realise they should be skipped because they were disabled.
This code now remembers gateway details of all the gateways, including skipped ones, so the dynamic gateway code can easily realise all gateways that have been already processed, even those that were processed and skipped.
Forum: https://forum.pfsense.org/index.php?topic=86565.0
It fixes Gateway Status Widget - now if a dynamic gateway is disabled, it does not appear on the display.
This will also stop disabled dynamic gateways from being returned to other callers. So there may/will be impacts on other parts of the system when a user disables a dynamic gateway. e.g. filter.inc - a gateway that has been disabled by a user canot be used in rules any more.
2015-01-11 20:54:31 +05:45
Ermal LUÇI
7de6a47f1d Fixes #3281 do not undo any changes already done for gif/gre interface. 2015-01-10 22:34:47 +01:00
Ermal LUÇI
e821f30e7d Fixes #4177 convert password to base64 to be submitted to avoid issues with special chars in shell and HTTP GET parameter passing. Probably should add POST support to fcgicli. 2015-01-10 22:17:28 +01:00
Phil Davis
1d8c79cc1e Restart PHP-FPM allow to setup ini file
I was just using console menu option 16 Restart PHP-FPM and it hung on a nanoBSD system.
I found /tmp/php_errors.txt with this in it:
"override rw-r--r--  root/wheel for /usr/local/etc/php.ini?"
Flying blind at the console I entered "y", then /tmp/php_errors.txt had this:
--------
rm: /usr/local/etc/php.ini: Read-only file system
override rw-r--r--  root/wheel for /usr/local/lib/php.ini?
--------
Pressed return at the console and it proceeded, presumably without re-writing php.ini

It works much better when the file system is mounted RW :)
2015-01-10 21:38:50 +05:45
Ermal LUÇI
e8cb8b2937 Let the kernel handle REQID rather than handling it manually. The connection name is the one needed here. 2015-01-09 22:32:26 +01:00
jim-p
526e6c06f8 Add tracker and label to IPv4 Link-Local block rules. 2015-01-09 16:07:28 -05:00
Chris Buechler
3529ac320d After the other set of changes had unexpected complications, let's back this out too. Revert "PEAR static method call warning"
This reverts commit 4751f76a67.
2015-01-09 01:13:34 -06:00
Chris Buechler
23ca569527 This broke a variety of things. Revert "Deprecated and non-static method messages"
This reverts commit 91b9a02fb1.
2015-01-09 00:40:01 -06:00
Chris Buechler
79ac2ee0d2 Merge pull request #1427 from phil-davis/PEAR-static-methods 2015-01-09 00:20:25 -06:00
Chris Buechler
e8e494f30d disable this PHP error logging, errors that are really significant end up with a crash report, this is more noise than useful at this stage in 2.2. 2015-01-09 00:17:10 -06:00
Phil Davis
4751f76a67 PEAR static method call warning
Forum https://forum.pfsense.org/index.php?topic=86478.0
PEAR is used by
IPv6.inc
auth.inc
captiveportal.inc
radius.inc
xmlrpc_client.inc
radius_accounting.inc
radius_authentication.inc

I have just changed this 1 function to "public static"

Also used are:
PEAR::raiseError
PEAR::loadExtension (already has "static function")

Not sure if PEAR::raiseError will throw a similar "static method" call
warning, not game to touch it.
2015-01-09 10:04:28 +05:45
Ermal LUÇI
2ecb2dafa5 Catch packets on all iunterfaces and send them out the correct one. Fixes #4174 2015-01-08 22:49:36 +01:00
Phil Davis
91b9a02fb1 Deprecated and non-static method messages
Fix various files that can emit messages like:
PHP Strict Standards:  Non-static method SimplePie_Misc::array_unique()
should not be called statically, assuming $this from incompatible
context in /etc/inc/simplepie/simplepie.inc on line 5508
php-fpm[16262]: /rc.newipsecdns: PHP ERROR: Type: 8192, File:
/etc/inc/shaper.inc, Line: 4365, Message: Assigning the return value of
new by reference is deprecated

Some of these style messages have been reported on the forum, e.g.
https://forum.pfsense.org/index.php?topic=86448.0

I had RSS widget on, and simplepie sent the system beserk telling about
all this stuff.
2015-01-09 01:20:05 +05:45
Renato Botelho
6d1907a3d2 Improve URL and URL ports alias update data:
- Move redundant code to a function parse_aliases_file(). Before the max
number of items was not being respected when URL content is updated,
only when alias was saved. Same was happening with ip/subnet/port
validation and user could end up with a bad pf.conf
- Remove unused variables

These changes were based on Pull Request #1264. It should fix #4189

Submitted by:▸  PiBa-NL
2015-01-08 16:16:47 -02:00
jim-p
725d54bd9a Change OpenVPN CARP VIP test to be more accurate. The client should also not be run if the VIP is in the INIT state. 2015-01-08 10:41:37 -05:00
Renato Botelho
ae952a031c Unobsolete libcurl.so.4 since it's installed by recent versions of curl package 2015-01-08 12:26:19 -02:00
Renato Botelho
d10a166240 Fix check for cookies, the way it was implemented didn't work because it would need a refresh to check if cookie was set or not. Use javascript to do a simple test 2015-01-08 11:08:11 -02:00
Renato Botelho
ce997e6a88 Add a value to cookie, otherwise it's not set. Before my last change parameters were out of order and expiration time was being set as value. It should fix #4069 2015-01-08 10:15:18 -02:00
Ermal LUÇI
3d031b2716 This is not the place for this setting and werid its here! 2015-01-08 12:33:39 +01:00
Chris Buechler
21e2561f47 some lagg modes are missing vlanmtu, but work fine with VLANs. Work around it for now at least. Ticket #4186 2015-01-08 00:03:59 -06:00
Chris Buechler
564978ad5c Merge pull request #1425 from stilez/patch-2 2015-01-07 23:28:34 -06:00
Chris Buechler
2a691e343b fix strongswan conf file generation with ipcomp. Ticket #4182 2015-01-07 20:59:21 -06:00
Ermal LUÇI
f8e23dc8c4 Fixes #4188 use the same reqid over same phase1 but different phase2 connections. The dashboard will be fixed with the ticket already open. This should fix a lot of instabilities reported on the forums for people having a dozen or more tunnels 2015-01-08 00:48:20 +01:00
stilez
b17ac4f780 "Like with like" - move a few functions to better places in the code (they are placed strangely)
A few functions such as ipcmp(), subnet_expand(), and check_subnets_overlap()  are in illogical places - away from all the other ip comparison and subnet basic functions and in the middle of alias handling and interface enumeration. 

No change to functional code, just moving to earlier in the file (next to other IP compare and subnet functions) for ease of future contributors.
2015-01-07 23:39:36 +00:00
Ermal LUÇI
0759fdd8d0 Correct the sense of the check by default unity is enabled 2015-01-07 22:31:12 +01:00
Ermal LUÇI
4a076e36d3 Provide an advanced setting to be able to disable Unity Plugin(Cisco extensions) 2015-01-07 22:07:00 +01:00
Ermal LUÇI
5324ea38a1 Move to specifically specifying the ID type apart when an ip address to have strongswan do proper behaviour. Also for DynDNS names use the dns type id so strongswan does the resolving by its own. 2015-01-07 21:02:39 +01:00
Chris Buechler
b9f290bd27 Don't hard code the target IP in auto-generated outbound NAT rules, use
previous behavior of setting it to the interface IP.
2015-01-07 13:25:37 -06:00
Ermal LUÇI
ad451a81b8 split is deprecated move to explode 2015-01-07 20:18:40 +01:00
Chris Buechler
e57a3e4087 fix spelling of compression 2015-01-07 12:47:26 -06:00
Ermal LUÇI
40cc36d165 Fixes #4182 by properly managing IPcomp on ipsec tunnels.
Also retires IPsec force reloading advanced sysctl since its useless nowdays with strongswan and remove its call on rc.newipsecdns.
2015-01-07 16:35:04 +01:00
Renato Botelho
4ab1ffa0b0 Fix #4146:
OpenVPN create the tun/tap interface and, when set an IP address to
it, mark it as UP. In some scenarios, when TAP is set as bridge and
doesn't have an IP address set on it, it never goes up and tunnel
doesn't work.

If rc.newwanip is called for this TAP interface, UP flag is set, but,
rc.newwanip is not executed when system is booting.

Since it's always rename the interface and add it the group, make sure
it's up here.
2015-01-07 09:24:04 -02:00
Chris Buechler
be2d7eb7c6 Log PHP errors. Ticket #4143 2015-01-07 00:53:24 -06:00
Ermal LUÇI
00b56e047b Enforce subnet check here to avoid any issues resulting from function call. 2015-01-06 22:54:20 +01:00
Renato Botelho
b56862141e Remove useless check, CARP does not depend of interface having another IP set before 2015-01-06 18:54:37 -02:00
Renato Botelho
3bad469105 Remove some extra spaces 2015-01-06 15:16:38 -02:00
Renato Botelho
3f49965498 Fix typo on variable name 2015-01-06 15:15:55 -02:00
stilez
e89d2995bb Tighten and IPv6-ify gen_subnet() etc
Tightens, canonicalises and improves for IPv6, the functions
gen_subnet(), gen_subnetv6(), gen_subnet_max(), gen_subnetv6_max()

Changes are transparent to calling code.

Issues:

1) gen_subnet() and gen_subnet_max() will validate both IPv4 and IPv6 as valid args, but will then try to process an IPv6 subnet bitwise as x32 LONG without further checking, causing erroneous but apparently valid responses.

2) None of the functions properly sanitise their input: if $bits is >32 or >128, or even a non-integer, erroneous results will be passed back to the calling code as valid data without checking, again causing erroneous but apparently valid responses.

3) 3 of the 4 functions return an empty string for invalid but gen_subnetv6_max() returns a numeric value for invalid. Both responses loose-evaluate as False, but consistency is better.

Fixes and improvements:

1) The unspecified functions gen_subnet() and gen_subnet_max() now handle all args correctly, and don't mishandle if unexpectedly passed IPv6 or bad data.

2) Names are now canonical: gen_subnet(), gen_subnet_max() are now IPv4/v6 agnostic, and IPv4-only versions gen_subnetv4() and gen_subnetv4_max() are added as expected to exist, to match existing functions gen_subnetv6() and gen_subnetv6_max().

3) The return value for bad args is made consistent (empty string = False).

4) gen_subnetv6_max() now uses Net_IPv6's Ip2Bin() and Bin2Ip() functions and simple string manipulation rather than bitwise operations, so it's guaranteed 32-bit safe (compared to 128-bit bitwise operations in current code which seem less certain?)

5) Changes are transparent - the canonical functions still work exactly as before on IPv4 (only with proper bad arg validation) but also now work on IPv6 transparently, and on arbitrary IPv4/IPv6 data, similar to other functions like is_ipaddr().

Tested and handles valid but uncommon edge cases of /0, /32 (IPv4) and /128 (IPv6) correctly. Also avoids inet_ntop/pton if that's a real issue (previous PR comment had asked to avoid these functions)
2015-01-06 15:14:51 -02:00
Renato Botelho
57f5889472 Revert "FreeBSD fails to set advskew back to 0 after you set it to any other"
A patch was added to allow set advskew back to 0

This reverts commit eea2ad5d61.
2015-01-06 11:44:28 -02:00
Renato Botelho
39c502347d Add secure flag when necessary to cookie_test, as we do for session cookie, to avoid false positives in common vulnerabilities scanners. It fixes #4069 2015-01-06 10:00:37 -02:00
Chris Buechler
386788e25f Merge pull request #1419 from phil-davis/patch-2 2015-01-05 12:57:30 -06:00