--- gvpe/NEWS 2011/03/06 13:49:49 1.98 +++ gvpe/NEWS 2013/07/05 10:04:21 1.108 @@ -1,16 +1,54 @@ GVPE NEWS +New option OPENSSL_NO_SSL_INTERN. If an application can be compiled + with this defined it will not be affected by any changes to ssl internal + structures. Add several utility functions to allow openssl application + to work with OPENSSL_NO_SSL_INTERN defined. + [Steve Henson] +TODO: bridge mode, finally? + - INCOMPATIBLE CHANGE: no longer enable udp protocol if no other protocols are enabled - this is necessary when you have nodes with completely unknown protocols, to force mediated connection requests. - - protocol version 0.1, compatible with older releases. + - INCOMPATIBLE CHANGE: dns transport protocol bumped to version 2. + - switch to using RSA_generate_key_ex, which is the undocumented + and needlessly more complicated replacement for the RSA_generate_key + function which is now deprecated. + - change public exponent for rsa keys from 65535 to 65537, for + efficiency reasons. + - nodes would sometimes declare transport endpoints valid despite + the protocol not being configured locally. + - core protocol version 0.1, compatible with older releases. + - new global configuration options: chroot, chuser, chuid, chgid, + to chroot to a specified or anonymous new root, and change user id. + - prefer inet_aton over gethostbyname, as the latter is not guaranteed + to "resolve" literal ip addresses. + - configure didn't detect openssl 1.0 because SHA1_version became private + (patch by TANIGUCHI Takaki). - fix a bug where nodes would tell the other side that it supports the same protocols as that other side, instead of its own. - - do not simply abort in some error cases in the dns transport. - - allow lowercase/uppercase alises for dns encodings that do - not rely on case. - add zlib when found, as openssl depends on it in newer versions. - work around append-bugs in uclibc by using an extra seek. + - new "include" directive for the config file. + - gvpectrl no longer evaluates any "on" directives. + - icmp and rawip protocols weren't upgradable to each other. + - major, but incremental, dns transport improvements: + - do not simply abort in some error cases in the dns transport, + but try to recover. + - allow lowercase/uppercase alises for base-n encodings that do + not rely on case. + - use base26 instead of base22 encoding for dns syn's, and + base36 instead of base22 for headers (saves one byte/packet). + - back off far quicker in dns tunnel when idling - increases + latency on an idle link somewhat, but avoids hundreds of + needless packets. + - poll more aggressively when idling in dns (poll once per + second as opposed to once per 5 seconds). + - reduce dns send payload size to allow greater rate of ack + messages (should help sack and ipv6). + - allow for ip options in rawip/icmp transports, even though gvpe + doesn't generate them. + - upgrade to libev 4 API. 2.24 Sat Feb 12 05:15:48 CET 2011 - protocol version 0.1, compatible with older releases.