Commit Graph

1453 Commits

Author SHA1 Message Date
Michael Rash
d79fcea6d7 [client] minor bug fix to add --spoof-source synonym for --spoof-src to match man page 2014-01-17 21:10:36 -05:00
Michael Rash
94cc77fda6 added fwknop.spec update to ChangeLog.git 2014-01-12 22:29:04 -05:00
Michael Rash
177290c5c3 updated fwknop.spec file release note for 2.6.0 2014-01-12 22:27:38 -05:00
Michael Rash
56966ee832 added Coverity finds/fixes to ChangeLog.git for 2.6.0 2014-01-12 21:41:54 -05:00
Michael Rash
cf6a38ea0d [server] better checking for read() return value flagged by Coverity 2014-01-12 21:40:20 -05:00
Michael Rash
05d6e1c4a7 [server] fixed copy-and-paste NULL check bug found by Coverity 2014-01-12 21:08:55 -05:00
Michael Rash
431caa287a added ChangeLog.git to show changes since 2.5.1 2014-01-11 23:33:53 -05:00
Michael Rash
825c361958 Merge branch 'master' of https://github.com/mrash/fwknop 2014-01-11 15:21:10 -05:00
Damien Stuart
1e1729905e Bumped libfko and protocol versions to 2.0.1. Added dependencies for this version to the fwknop.spec file. 2014-01-11 10:58:01 -05:00
Michael Rash
a347be354d merged android4.4_support branch 2014-01-10 22:46:54 -05:00
Michael Rash
551b243007 (Marek Wrzosek) Update docs to reflect random 'digits' use instead of 'bytes'
Suggested doc update to fwknop man pages to accurately describe the usage
of digits instead of bytes for SPA random data.  About 53 bits of entropy
are actually used, although this is in addition to the 64-bit random salt
in for key derivation used by PBKDF1 in Rjindael CBC mode.
2014-01-02 20:47:41 -05:00
Michael Rash
6add06f76c bumped version to 2.6.0 2014-01-01 22:27:07 -05:00
Michael Rash
3820b64394 [libfko] ensure a NULL HMAC key is properly handled 2014-01-01 19:45:38 -05:00
Michael Rash
34a3808b99 [test suite] minor display_ctx() call position update 2014-01-01 19:45:02 -05:00
Michael Rash
f5fd8de482 [test suite] better loop output for fko-wrapper 2014-01-01 14:07:39 -05:00
Michael Rash
3adb359932 minor README update 2014-01-01 13:42:13 -05:00
Michael Rash
227d0ab947 [libfko] ensure NULL is handled properly for all fko_get_* functions 2013-12-31 23:27:05 -05:00
Michael Rash
7aa6d37fff [libfko] added NULL check for fko_set_spa_data() data arg 2013-12-30 21:56:08 -05:00
Michael Rash
5022beaf12 [libfko] < 0 checks not needed for size_t vars which are unsigned 2013-12-30 21:09:27 -05:00
Michael Rash
297d7d00fe [libfko] enc key NULL checks with fko-wrapper test support 2013-12-29 22:44:16 -05:00
Michael Rash
0c6911941b [libfko] reject negative length values
Integer lengths that are negative are never valid.  This commit also
extends the fuzzing capabilities of the test/fko-wrapper code to
validate libfko calls with negative length arguments, and one crash
scenario with a negative length for the encryption key was found (and
fixed) this way.
2013-12-29 21:05:04 -05:00
Michael Rash
d09e278646 added fko-wrapper no valgrind script 2013-12-29 20:02:56 -05:00
Michael Rash
283c72e463 [test suite] run fko-wrapper without valgrind, closes #113 2013-12-29 19:59:16 -05:00
Michael Rash
8a7ca121e9 [test suite] use ctx_update() where possible for fko-wrapper 2013-12-28 15:22:01 -05:00
Michael Rash
bf9fa57ca8 [test suite] added 'getset' versions of fko_ int/short wrapper functions 2013-12-28 14:56:35 -05:00
Michael Rash
8f3ea42b3f [test suite] update fko-wrapper to use constants from fko.h 2013-12-28 14:20:11 -05:00
Michael Rash
4c42d5575e [test suite] added ctx_update() function to fko-wrapper test 2013-12-28 14:10:47 -05:00
Michael Rash
05eb4ebb7b [test suite] call FKO functions via function pointers (interim commit) 2013-12-27 23:24:05 -05:00
Michael Rash
bd0b8a1953 [android] updated README file, added project/sdk.paths file 2013-12-26 20:44:35 -05:00
Michael Rash
db58f2008e [android] Added test/conf/hmac_android_access.conf file to Makefile.am 2013-12-23 23:16:03 -05:00
Michael Rash
509dcf93dd [android] added HMAC test along with non-legacy Rijndael test 2013-12-23 23:15:11 -05:00
Michael Rash
8fdb5d6395 [android] added ant.properties file 2013-12-23 22:51:26 -05:00
Michael Rash
171da60f23 [android] added project.properties file 2013-12-23 22:44:53 -05:00
Michael Rash
3b330f2036 [android] Makefile.am minor script path update 2013-12-23 22:40:18 -05:00
Michael Rash
e25d05f050 [android] update Makefile.am for latest Android directory tree 2013-12-23 22:39:21 -05:00
Michael Rash
204bc6e58f [android] add HMAC support (currently optional) 2013-12-23 22:29:51 -05:00
Michael Rash
dc19e07d65 [android] update to copy fko.h and associated files to jni/fwknop/ via get_libfko_header.sh 2013-12-23 20:38:04 -05:00
Michael Rash
8dfd57677a added Gerry Reno 2013-12-22 21:12:26 -05:00
Michael Rash
d43d2fc817 [android] applied Gerry Reno's patch for Android-4.4 2013-12-22 15:25:32 -05:00
Michael Rash
8ed0d9d8d9 Fix 'string literal' warning for Android client
Under Android-4.4 this commit fixes the following warning:

     [exec] jni/./fwknop/fwknop_client.c: In function 'Java_com_max2idea_android_fwknop_Fwknop_sendSPAPacket':
     [exec] jni/./fwknop/fwknop_client.c:181:5: error: format not a string literal and no format arguments [-Werror=format-security]
     [exec] cc1: some warnings being treated as errors
2013-12-22 15:10:23 -05:00
Michael Rash
6cba5d2ec9 [test suite] bug fix for python FKO extension library path (found on Fedora 19) 2013-12-16 22:33:55 -05:00
Michael Rash
919f25f85d [server] fw_initialize() vs. fw_config_init() bug fix for use_masquerade 2013-12-14 19:41:00 -05:00
Michael Rash
92cdb47ff7 [server] added FORCE_MASQUERADE to fwknopd(8) man page, closes #101
This commit completes the addition of generalized NAT (both DNAT and
SNAT) capabilities to access.conf stanzas.
2013-12-14 15:44:39 -05:00
Michael Rash
3a2c33cd3c Added Les Aker to credits file 2013-12-12 15:57:10 -06:00
Michael Rash
3b2cd063fe [server] pcap_dispatch() packet count default to 100
Updated pcap_dispatch() default packet count from zero to 100.
This change was made to ensure backwards compatibility with older
versions of libpcap per the pcap_dispatch() man page, and also because
some of a report from Les Aker of an unexpected crash on Arch Linux with
libpcap-1.5.1 that is fixed by this change (closes #110).
2013-12-10 22:24:39 -06:00
Michael Rash
aeed8323f7 [test suite] multi-packet pcap test for pcap_dispatch() validation
This commit adds a new pcap file to the test suite with an SPA packet after
99 other garbage packets.  This can be used for pcap_dispatch() testing,
though this is not meant to be super instensive - it is just to ensure that
if a PCAP_DISPATCH_COUNT of, say, 10 is selected that the SPA is still seen
by fwknopd.  This commit is in support of #110.
2013-12-10 21:56:20 -06:00
Michael Rash
5f50ac22db [server] use SIGKILL if necessary for -K
This change sends SIGKILL to fwknopd under -K if SIGTERM does not do the job
first.  This can be necessary in some cases if libpcap does not properly handle
a packet count of zero in pcap_dispatch() (see github issue #110).  On a side
note, the default packet dispatch count of zero will likely be changed because
of that issue too.
2013-12-10 14:35:38 -06:00
Michael Rash
3ef9e5645b [test suite] added masquerade exception for non-Linux systems 2013-12-05 23:37:10 -05:00
Michael Rash
0319b72334 [test suite] added missing config files 2013-12-05 23:01:12 -05:00
Michael Rash
46b5f2ecaf [server] added the ability to use FORCE_MASQUERADE to access.conf stanzas 2013-12-05 23:00:19 -05:00