f96a0cef | 02-Mar-2021 |
Richard Lowe |
13762 stop passing MFLAGS to make(1) Reviewed by: Toomas Soome <tsoome@me.com> Reviewed by: Andy Fiddaman <andy@omnios.org> Reviewed by: Jason King <jason.brian.king@gmail.com> Approv
13762 stop passing MFLAGS to make(1) Reviewed by: Toomas Soome <tsoome@me.com> Reviewed by: Andy Fiddaman <andy@omnios.org> Reviewed by: Jason King <jason.brian.king@gmail.com> Approved by: Dan McDonald <danmcd@joyent.com>
show more ...
|
ef1266ef | 24-May-2020 |
Toomas Soome |
13597 ipf: variable may be used uninitialized in this function Reviewed by: Dan McDonald <danmcd@joyent.com> Reviewed by: Robert French <robert@robertdfrench.me> Approved by: Joshua M. Cl
13597 ipf: variable may be used uninitialized in this function Reviewed by: Dan McDonald <danmcd@joyent.com> Reviewed by: Robert French <robert@robertdfrench.me> Approved by: Joshua M. Clulow <josh@sysmgr.org>
show more ...
|
64410b34 | 24-May-2020 |
Toomas Soome |
13543 ipf: symbol 'thishost' is multiply-defined Reviewed by: C Fraire <cfraire@me.com> Reviewed by: Andy Fiddaman <andy@omniosce.org> Approved by: Dan McDonald <danmcd@joyent.com> |
85f4cb87 | 11-Feb-2018 |
Richard Lowe |
13184 Stop translating ld(1) options through cw(1) Reviewed by: Jason King <jason.brian.king+illumos@gmail.com> Reviewed by: Igor Kozhukhov <igor@dilos.org> Approved by: Robert Mustacchi
13184 Stop translating ld(1) options through cw(1) Reviewed by: Jason King <jason.brian.king+illumos@gmail.com> Reviewed by: Igor Kozhukhov <igor@dilos.org> Approved by: Robert Mustacchi <rm@fingolfin.org>
show more ...
|
ae7a42b1 | 22-Feb-2018 |
Toomas Soome |
9181 ipf: this use of "defined" may not be portable Reviewed by: Yuri Pankov <yuripv@yuripv.net> Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Alexander Pyhalov <apy
9181 ipf: this use of "defined" may not be portable Reviewed by: Yuri Pankov <yuripv@yuripv.net> Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Alexander Pyhalov <apyhalov@gmail.com> Approved by: Gordon Ross <gwr@nexenta.com>
show more ...
|
d7c57852 | 12-Aug-2017 |
Gary Mills |
8485 Remove set but unused variables in usr/src/cmd Reviewed by: Toomas Soome <tsoome@me.com> Reviewed by: Andy Stormont <astormont@racktopsystems.com> Reviewed by: Yuri Pankov <yuripv@gm
8485 Remove set but unused variables in usr/src/cmd Reviewed by: Toomas Soome <tsoome@me.com> Reviewed by: Andy Stormont <astormont@racktopsystems.com> Reviewed by: Yuri Pankov <yuripv@gmx.com> Approved by: Dan McDonald <danmcd@joyent.com>
show more ...
|
d5767f31 | 15-Feb-2017 |
Toomas Soome |
8334 ipf: self-comparison always evaluates to false Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Approved by: Dan McDonald <danmcd@
8334 ipf: self-comparison always evaluates to false Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Approved by: Dan McDonald <danmcd@joyent.com>
show more ...
|
af5f29dd | 05-May-2017 |
Toomas Soome |
8164 ipf: bad preprocessor use and need FALLTHROUGH Reviewed by: Jason King <jason.brian.king+illumos@gmail.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Alexander Pyhal
8164 ipf: bad preprocessor use and need FALLTHROUGH Reviewed by: Jason King <jason.brian.king+illumos@gmail.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Alexander Pyhalov <apyhalov@gmail.com> Approved by: Hans Rosenfeld <hans.rosenfeld@joyent.com>
show more ...
|
94bdecd9 | 19-Sep-2014 |
Rob Gulewich |
5198 Want alternate global zone rule set for each ipf netstack 5197 Global zone should be able to manage NGZ ipf state Reviewed by: Jerry Jelinek <jerry.jelinek@joyent.com> Reviewed by: R
5198 Want alternate global zone rule set for each ipf netstack 5197 Global zone should be able to manage NGZ ipf state Reviewed by: Jerry Jelinek <jerry.jelinek@joyent.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Dan McDonald <danmcd@omniti.com> Reviewed by: Darren Reed <darrenr@fastmail.net> Approved by: Richard Lowe <richlowe@richlowe.net>
show more ...
|
b6805bf7 | 23-Aug-2013 |
Gordon Ross |
4072 make clobber leaves trash Reviewed by: Albert Lee <trisk@nexenta.com> Reviewed by: Dan McDonald <danmcd@nexenta.com> Reviewed by: Marcel Telka <marcel.telka@nexenta.com> Reviewed
4072 make clobber leaves trash Reviewed by: Albert Lee <trisk@nexenta.com> Reviewed by: Dan McDonald <danmcd@nexenta.com> Reviewed by: Marcel Telka <marcel.telka@nexenta.com> Reviewed by: Richard Lowe <richlowe@richlowe.net> Approved by: Garrett D'Amore <garrett@damore.org>
show more ...
|
e8d569f4 | 19-Nov-2009 |
Alexandr Nedvedicky |
6772643 Packets dropped at ipfil_sendpkt if interface index is set at plumb time 6891782 ipftest fails to run 6897532 Race condition window arround fr_enable_active is still opened 689763
6772643 Packets dropped at ipfil_sendpkt if interface index is set at plumb time 6891782 ipftest fails to run 6897532 Race condition window arround fr_enable_active is still opened 6897632 nic_event_v* hook should check if IPF is running before it will proceed further
show more ...
|
24fe0b3b | 29-Jul-2009 |
jmcp |
6864230 hiho, hiho, it'ch chtime for CH to go Portions contributed by Rich Lowe |
22929378 | 13-Feb-2009 |
Darren Reed |
6803232 parsing empty config files results in an error 6803834 regression test failure for legacy/i13 |
33f2fefd | 27-Jan-2009 |
Darren Reed |
5008943 /etc/init.d/ipfboot pause/resume functionality broken 5010756 "\" in configuration file does not work correctly 6181489 ipfilter sends out confusing messages. 6449288 Makefiles in
5008943 /etc/init.d/ipfboot pause/resume functionality broken 5010756 "\" in configuration file does not work correctly 6181489 ipfilter sends out confusing messages. 6449288 Makefiles in usr/src/cmd/ipf are missing CDDL 6449291 package prototype files in usr/src/pkgdefs/SUNWipfh missing CDDL 6508325 stale pfil-related rules in Makefile.rules 6661948 ipmon.pid file can be rendered invisible 6714319 IPFilter causes failure of IPv6 compliance tests. 6766614 fin_state costs more than it is worth 6767239 fin_nat causes more trouble than it is worth 6788299 Array overrun in ipfilter 6789766 ipfs usage output is misleading 6792026 ipnat panics in Divide zero exception
show more ...
|
16070783 | 19-Jan-2009 |
Vladimir Kotal |
6617470 ipftest is reported as false positive by wsdiff |
43412a42 | 29-Dec-2008 |
Darren Reed |
6749429 printing out of fragment information is confused 6749445 ipfstat -f does not show ttl but rather expiration tick 6783820 IPF preauth crash 6730356 legacy test regressions: i2, i4,
6749429 printing out of fragment information is confused 6749445 ipfstat -f does not show ttl but rather expiration tick 6783820 IPF preauth crash 6730356 legacy test regressions: i2, i4, i11
show more ...
|
ea8244dc | 20-Nov-2008 |
John Ojemann |
6677460 ipfilter automatic flushing of state table entries needs to work the same as it does for NAT 6566976 state limit check works when limit is reached only 6566982 state limit is not chec
6677460 ipfilter automatic flushing of state table entries needs to work the same as it does for NAT 6566976 state limit check works when limit is reached only 6566982 state limit is not check when inserting states via IOCTL
show more ...
|
40cdc2e8 | 26-Sep-2008 |
Alexandr Nedvedicky |
6743637 ipfstat prints certain certain counters two times 6744095 fix c-style in ip_state.c in fr_matchstate() et. al. 6744100 add a comment for CR 6653172 to fil.c 6725139 OOW problem st
6743637 ipfstat prints certain certain counters two times 6744095 fix c-style in ip_state.c in fr_matchstate() et. al. 6744100 add a comment for CR 6653172 to fil.c 6725139 OOW problem still present after a patch 127888-09 has been applied 6657378 IPF address pools does not match addresses reliably for IPv6 6726717 IPF persistent tunables still don't work with stack instances 6743002 ipf_property_update() is too picky 6731974 incorrect calculation in fr_pullup 6749974 IPF does not know whether packet comes from local client (loopback) or from NIC interface
show more ...
|
7ddc9b1a | 08-Sep-2008 |
Darren Reed |
PSARC/2008/219 Committed API for packet interception PSARC/2008/335 Corrections for Committed API for packet interception PSARC/2008/557 Revision to net instance notification API 4844507
PSARC/2008/219 Committed API for packet interception PSARC/2008/335 Corrections for Committed API for packet interception PSARC/2008/557 Revision to net instance notification API 4844507 Solaris needs stable interface for packet filtering software 6705155 ipf_stack_init() assumes kmem_alloc with KM_NOSLEEP never fails
show more ...
|
5b48165c | 28-Aug-2008 |
John Ojemann |
6713984 if a nat entry is created, but the packet gets blocked, the entry should be removed 6718524 ipfilter incorrectly tracks and handles orphan state table and nat table entries 6742115 IP
6713984 if a nat entry is created, but the packet gets blocked, the entry should be removed 6718524 ipfilter incorrectly tracks and handles orphan state table and nat table entries 6742115 IPfilter: NAT entries added with SIOCSTPUT are ignored if no rules exist. 6528443 ipnat -l shows more sessions than ipf_nattable_max
show more ...
|
ab073b32 | 01-Aug-2008 |
dr146992 |
6726575 ipfilter needs to be able to do randomised port mapping 6730614 random port numbers are in the wrong range of numbers |
d6c23f6f | 24-Jul-2008 |
yx160601 |
PSARC 2008/250 ipv6 NAT for IPFilter 6600474 RFE: Need ipv6 support on NAT |
cbded9ae | 18-Jul-2008 |
dr146992 |
6719268 enabling ipfilter causes up to 80% or more drop in packet throughput for multi-stream workloads 6721215 ipfilter panic in ipf:fr_derefrule after restoring state table 6723213 IPfilter
6719268 enabling ipfilter causes up to 80% or more drop in packet throughput for multi-stream workloads 6721215 ipfilter panic in ipf:fr_derefrule after restoring state table 6723213 IPfilter: NAT suffers performance hit by holding exclusive locks longer than required
show more ...
|
f17d2b41 | 15-May-2008 |
an207044 |
6505685 Problems with applying "to" rule in IP Filter 6562635 TCP options are not processed correctly 6562648 IPF may drop connection, which chooses to scale window 6562721 IPF should als
6505685 Problems with applying "to" rule in IP Filter 6562635 TCP options are not processed correctly 6562648 IPF may drop connection, which chooses to scale window 6562721 IPF should also check SACK when doing stateful inspection 6595876 state timer should be reset when retransmission is seen 6651775 ipf does not handle half estab. connections well (conn. hangs with connection match result 4/0)
show more ...
|
786c7074 | 30-Apr-2008 |
jojemann |
6685076 ippool and other ipf utilities have possible race condition 6685092 ipfilter list processing function(s) have unsafe edge case(s) |