55fea89d | 15-Aug-2023 |
Dan Cross |
15843 automation can fix many trailing whitespace cstyle nits Reviewed by: Andy Fiddaman <illumos@fiddaman.net> Approved by: Dan McDonald <danmcd@mnx.io> |
2d6eb4a5 | 23-Dec-2022 |
Toomas Soome |
15280 uts: remove pragma ident Reviewed by: Igor Kozhukhov <igor@dilos.org> Reviewed by: Yuri Pankov <yuri@aetern.org> Reviewed by: Marcel Telka <marcel@telka.sk> Approved by: Robert
15280 uts: remove pragma ident Reviewed by: Igor Kozhukhov <igor@dilos.org> Reviewed by: Yuri Pankov <yuri@aetern.org> Reviewed by: Marcel Telka <marcel@telka.sk> Approved by: Robert Mustacchi <rm@fingolfin.org>
show more ...
|
cec263d4 | 13-Apr-2022 |
Andy Fiddaman |
14630 ipf return-rst does not work without IP forwarding Reviewed by: Dan McDonald <danmcd@mnx.io> Approved by: Robert Mustacchi <rm@fingolfin.org> |
b22a70ab | 03-Jan-2018 |
Patrick Mooney |
12679 want viona driver for bhyve Portions contributed by: Ryan Zezeski <rpz@joyent.com> Portions contributed by: John Levon <john.levon@joyent.com> Portions contributed by: Jason King <j
12679 want viona driver for bhyve Portions contributed by: Ryan Zezeski <rpz@joyent.com> Portions contributed by: John Levon <john.levon@joyent.com> Portions contributed by: Jason King <jason.king@joyent.com> Portions contributed by: Robert Mustacchi <rm@joyent.com> Portions contributed by: Bryan Cantrill <bryan@joyent.com> Reviewed by: Ryan Zezeski <ryan@zinascii.com> Approved by: Dan McDonald <danmcd@joyent.com>
show more ...
|
ae7a42b1 | 22-Feb-2018 |
Toomas Soome |
9181 ipf: this use of "defined" may not be portable Reviewed by: Yuri Pankov <yuripv@yuripv.net> Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Alexander Pyhalov <apy
9181 ipf: this use of "defined" may not be portable Reviewed by: Yuri Pankov <yuripv@yuripv.net> Reviewed by: Andrew Stormont <andyjstormont@gmail.com> Reviewed by: Alexander Pyhalov <apyhalov@gmail.com> Approved by: Gordon Ross <gwr@nexenta.com>
show more ...
|
af5f29dd | 05-May-2017 |
Toomas Soome |
8164 ipf: bad preprocessor use and need FALLTHROUGH Reviewed by: Jason King <jason.brian.king+illumos@gmail.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Alexander Pyhal
8164 ipf: bad preprocessor use and need FALLTHROUGH Reviewed by: Jason King <jason.brian.king+illumos@gmail.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Alexander Pyhalov <apyhalov@gmail.com> Approved by: Hans Rosenfeld <hans.rosenfeld@joyent.com>
show more ...
|
5c5f1371 | 08-Jul-2012 |
Richard Lowe |
2976 remove useless offsetof() macros Reviewed by: Josef 'Jeff' Sipek <jeffpc@josefsipek.net> Reviewed by: Igor Kozhukhov <ikozhukhov@gmail.com> Reviewed by: Andy Stormont <andyjstormont@
2976 remove useless offsetof() macros Reviewed by: Josef 'Jeff' Sipek <jeffpc@josefsipek.net> Reviewed by: Igor Kozhukhov <ikozhukhov@gmail.com> Reviewed by: Andy Stormont <andyjstormont@gmail.com> Approved by: Dan McDonald <danmcd@omniti.com>
show more ...
|
94bdecd9 | 19-Sep-2014 |
Rob Gulewich |
5198 Want alternate global zone rule set for each ipf netstack 5197 Global zone should be able to manage NGZ ipf state Reviewed by: Jerry Jelinek <jerry.jelinek@joyent.com> Reviewed by: R
5198 Want alternate global zone rule set for each ipf netstack 5197 Global zone should be able to manage NGZ ipf state Reviewed by: Jerry Jelinek <jerry.jelinek@joyent.com> Reviewed by: Robert Mustacchi <rm@joyent.com> Reviewed by: Dan McDonald <danmcd@omniti.com> Reviewed by: Darren Reed <darrenr@fastmail.net> Approved by: Richard Lowe <richlowe@richlowe.net>
show more ...
|
1a5e258f | 08-Aug-2014 |
Josef 'Jeff' Sipek |
5045 use atomic_{inc,dec}_* instead of atomic_add_* Reviewed by: Matthew Ahrens <mahrens@delphix.com> Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Robert Mustacchi <rm@j
5045 use atomic_{inc,dec}_* instead of atomic_add_* Reviewed by: Matthew Ahrens <mahrens@delphix.com> Reviewed by: Garrett D'Amore <garrett@damore.org> Approved by: Robert Mustacchi <rm@joyent.com>
show more ...
|
9c70e5c3 | 16-May-2011 |
Richard Lowe |
1829 ipf and gcc4 could get along better Reviewed by: Jason King <jason.brian.king@gmail.com> Reviewed by: Joshua M. Clulow <josh@sysmgr.org> Reviewed by: Robert Mustacchi <rm@joyent.com>
1829 ipf and gcc4 could get along better Reviewed by: Jason King <jason.brian.king@gmail.com> Reviewed by: Joshua M. Clulow <josh@sysmgr.org> Reviewed by: Robert Mustacchi <rm@joyent.com> Approved by: Gordon Ross <gwr@nexenta.com>
show more ...
|
d0dd088c | 10-May-2010 |
Alexandr Nedvedicky |
6912962 Need to compute chksum for packet duped on loopback interface 6929403 IPF should discard packet silently on OOW event |
de22af4e | 26-Apr-2010 |
John Ojemann |
6918206 Packets double counted on with "call now" rules 6918859 pools should track bytes as well as packets for better usability 6921174 ippool -ld crashes if nodes are inserted with ioctl an
6918206 Packets double counted on with "call now" rules 6918859 pools should track bytes as well as packets for better usability 6921174 ippool -ld crashes if nodes are inserted with ioctl and policy rules are not in place
show more ...
|
231bdc74 | 25-Feb-2010 |
Zdenek Kotala |
6900850 Limit for number of states in the state table is too low by default 6910994 fr_checkstate function does not release ipf_state mutex in some cases |
e8d569f4 | 19-Nov-2009 |
Alexandr Nedvedicky |
6772643 Packets dropped at ipfil_sendpkt if interface index is set at plumb time 6891782 ipftest fails to run 6897532 Race condition window arround fr_enable_active is still opened 689763
6772643 Packets dropped at ipfil_sendpkt if interface index is set at plumb time 6891782 ipftest fails to run 6897532 Race condition window arround fr_enable_active is still opened 6897632 nic_event_v* hook should check if IPF is running before it will proceed further
show more ...
|
201a9dc8 | 22-Oct-2009 |
Alexandr Nedvedicky |
6859479 IPF dup-to prevents packets to be forwarded to destination |
14d3298e | 21-Sep-2009 |
Alexandr Nedvedicky |
6859313 large number of rules in ipfilter decreases throughput performance |
6ccacea7 | 17-Jun-2009 |
Alexandr Nedvedicky |
6845913 fr_make_icmp_*() uses TH_SYN/TH_FIN for testing fin_flx - it's not the intention 6827271 ipfilter TCP state emulation ends up in 5/0 state (Established/Closed) 6562745 Adapt a better
6845913 fr_make_icmp_*() uses TH_SYN/TH_FIN for testing fin_flx - it's not the intention 6827271 ipfilter TCP state emulation ends up in 5/0 state (Established/Closed) 6562745 Adapt a better TCP statemachine emulation (fr_tcp_age()) from upstream version
show more ...
|
72680cf5 | 16-Jun-2009 |
Darren Reed |
6688940 ipf module panicked in get_unit() on NULL pointer 6806909 panic[cpu1]/thread=c9089dc0: assertion failed: zoneid != ALL_ZONES, file: ../../common/inet/ip/ip.c 6770007 certain IPv6 NAT
6688940 ipf module panicked in get_unit() on NULL pointer 6806909 panic[cpu1]/thread=c9089dc0: assertion failed: zoneid != ALL_ZONES, file: ../../common/inet/ip/ip.c 6770007 certain IPv6 NAT rules send out packets with link-local address 6744109 incorrect processing of IPv6 fragments in IPfilter NAT v6 6807986 fin_flen serves no purpose. 6808921 some comments describing what cvwaitlock_t would be nice 6829227 ipfil_sendpkt() may trigger panic 6813307 memory leaks at frrequest
show more ...
|
a1173273 | 22-May-2009 |
Alexandr Nedvedicky |
6747420 ipfilter fr_send_reset()/fr_send_icmp() does not work for loopback clients |
33f2fefd | 27-Jan-2009 |
Darren Reed |
5008943 /etc/init.d/ipfboot pause/resume functionality broken 5010756 "\" in configuration file does not work correctly 6181489 ipfilter sends out confusing messages. 6449288 Makefiles in
5008943 /etc/init.d/ipfboot pause/resume functionality broken 5010756 "\" in configuration file does not work correctly 6181489 ipfilter sends out confusing messages. 6449288 Makefiles in usr/src/cmd/ipf are missing CDDL 6449291 package prototype files in usr/src/pkgdefs/SUNWipfh missing CDDL 6508325 stale pfil-related rules in Makefile.rules 6661948 ipmon.pid file can be rendered invisible 6714319 IPFilter causes failure of IPv6 compliance tests. 6766614 fin_state costs more than it is worth 6767239 fin_nat causes more trouble than it is worth 6788299 Array overrun in ipfilter 6789766 ipfs usage output is misleading 6792026 ipnat panics in Divide zero exception
show more ...
|
43412a42 | 29-Dec-2008 |
Darren Reed |
6749429 printing out of fragment information is confused 6749445 ipfstat -f does not show ttl but rather expiration tick 6783820 IPF preauth crash 6730356 legacy test regressions: i2, i4,
6749429 printing out of fragment information is confused 6749445 ipfstat -f does not show ttl but rather expiration tick 6783820 IPF preauth crash 6730356 legacy test regressions: i2, i4, i11
show more ...
|
ea8244dc | 20-Nov-2008 |
John Ojemann |
6677460 ipfilter automatic flushing of state table entries needs to work the same as it does for NAT 6566976 state limit check works when limit is reached only 6566982 state limit is not chec
6677460 ipfilter automatic flushing of state table entries needs to work the same as it does for NAT 6566976 state limit check works when limit is reached only 6566982 state limit is not check when inserting states via IOCTL
show more ...
|
e2511460 | 26-Sep-2008 |
John Ojemann |
6748749 IPF: deletes NAT entry too early - packets sent by return-rst rule are sent untranslated 6752593 IPfilter: nat_touched and is_touched are no longer used, so they can be removed from head
6748749 IPF: deletes NAT entry too early - packets sent by return-rst rule are sent untranslated 6752593 IPfilter: nat_touched and is_touched are no longer used, so they can be removed from header file(s)
show more ...
|
40cdc2e8 | 26-Sep-2008 |
Alexandr Nedvedicky |
6743637 ipfstat prints certain certain counters two times 6744095 fix c-style in ip_state.c in fr_matchstate() et. al. 6744100 add a comment for CR 6653172 to fil.c 6725139 OOW problem st
6743637 ipfstat prints certain certain counters two times 6744095 fix c-style in ip_state.c in fr_matchstate() et. al. 6744100 add a comment for CR 6653172 to fil.c 6725139 OOW problem still present after a patch 127888-09 has been applied 6657378 IPF address pools does not match addresses reliably for IPv6 6726717 IPF persistent tunables still don't work with stack instances 6743002 ipf_property_update() is too picky 6731974 incorrect calculation in fr_pullup 6749974 IPF does not know whether packet comes from local client (loopback) or from NIC interface
show more ...
|
7ddc9b1a | 08-Sep-2008 |
Darren Reed |
PSARC/2008/219 Committed API for packet interception PSARC/2008/335 Corrections for Committed API for packet interception PSARC/2008/557 Revision to net instance notification API 4844507
PSARC/2008/219 Committed API for packet interception PSARC/2008/335 Corrections for Committed API for packet interception PSARC/2008/557 Revision to net instance notification API 4844507 Solaris needs stable interface for packet filtering software 6705155 ipf_stack_init() assumes kmem_alloc with KM_NOSLEEP never fails
show more ...
|