Re: VIMAGE + ipfilter fix

2014-11-19 Thread Cy Schubert
In message , Craig Rodrigues writes: > Hi, > > Can folks take a look at this? > > https://reviews.freebsd.org/D1191 > > It fixes a crash in ipfilter when a VIMAGE kernel is booted. Tested here. It addresses the issue. Looking at pf however, global variables were made VIMAGE aware. I've been

Re: RFC: Enabling VIMAGE in GENERIC

2014-11-19 Thread Bjoern A. Zeeb
On 19 Nov 2014, at 23:14 , Craig Rodrigues wrote: > On Wed, Nov 19, 2014 at 11:59 AM, John-Mark Gurney wrote: > >> >> Yes, we need a man page talking about this feature first, how to enable >> it, compile it into the kernel, how to manage it, what subsystems it >> interacts w/, what sysctl no

Re: RFC: Enabling VIMAGE in GENERIC

2014-11-19 Thread Craig Rodrigues
On Wed, Nov 19, 2014 at 11:59 AM, John-Mark Gurney wrote: > > Yes, we need a man page talking about this feature first, how to enable > it, compile it into the kernel, how to manage it, what subsystems it > interacts w/, what sysctl nodes it provides, etc. > Marko, Do you have any text which ca

Re: RFC: Enabling VIMAGE in GENERIC

2014-11-19 Thread John-Mark Gurney
Alexander V. Chernikov wrote this message on Wed, Nov 19, 2014 at 16:07 +0400: > Can we have some wiki/man/docs on how particular subsystem should > interact with VNET first? Yes, we need a man page talking about this feature first, how to enable it, compile it into the kernel, how to manage it,

DANE & DNSSEC @ freebsd.org - good job!

2014-11-19 Thread Mark Martinec
Just want to say I was pleasantly surprised seeing that the mailer at freebsd.org now supports DANE [1]. Good job guys and gals!!! Nov 19 16:07:05 dorothy postfix/smtp[68423]: Verified TLS connection established to mx1.freebsd.org[2001:1900:2254:206a::19:1]:25: TLSv1.2 with cipher ECDHE-R

VIMAGE + ipfilter fix

2014-11-19 Thread Craig Rodrigues
Hi, Can folks take a look at this? https://reviews.freebsd.org/D1191 It fixes a crash in ipfilter when a VIMAGE kernel is booted. Thanks. -- Craig ___ freebsd-net@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-net To unsubs

Re: RFC: Enabling VIMAGE in GENERIC

2014-11-19 Thread Bjoern A. Zeeb
On 19 Nov 2014, at 03:28 , Craig Rodrigues wrote: > > (6) Ask clusteradm to run one of the machines they use > for PF firewalls + IPv6 with a VIMAGE enabled kernel, and provide > feedback. For people to use pf with VIMAGE we first MUST have the security fix imported that I pointed

Re: RFC: Enabling VIMAGE in GENERIC

2014-11-19 Thread Marko Zec
On Wed, 19 Nov 2014 16:07:46 +0400 "Alexander V. Chernikov" wrote: ... > Can we have some wiki/man/docs on how particular subsystem should > interact with VNET first? > This can probably help to make proper vnet fixes in less number of > attempts :) > > For example, even attach/detach is handled

Re: RFC: Enabling VIMAGE in GENERIC

2014-11-19 Thread Alexander V. Chernikov
On 19.11.2014 07:28, Craig Rodrigues wrote: On Mon, Nov 17, 2014 at 9:47 AM, Alfred Perlstein wrote: On 11/17/14, 3:02 AM, Warner Losh wrote: On Nov 17, 2014, at 12:46 AM, Craig Rodrigues wrote: (3) Take a pass through http://wiki.freebsd.org/VIMAGE/TODO and https://bugs.freeb