<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src-test2/sys/modules/pf, branch release/6.3.0_cvs</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src-test2/atom?h=release%2F6.3.0_cvs</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src-test2/atom?h=release%2F6.3.0_cvs'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/'/>
<updated>2008-01-15T15:46:22Z</updated>
<entry>
<title>This commit was manufactured by cvs2svn to create tag</title>
<updated>2008-01-15T15:46:22Z</updated>
<author>
<name>cvs2svn</name>
<email>cvs2svn@FreeBSD.org</email>
</author>
<published>2008-01-15T15:46:22Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=5cd221028ba5e7ada35a0dd196fb642b44f197d1'/>
<id>urn:sha1:5cd221028ba5e7ada35a0dd196fb642b44f197d1</id>
<content type='text'>
'RELENG_6_3_0_RELEASE'.

This commit was manufactured to restore the state of the 6.3-RELEASE image.
</content>
</entry>
<entry>
<title>MFC the firewall labeling changes.</title>
<updated>2006-09-19T15:45:22Z</updated>
<author>
<name>Christian S.J. Peron</name>
<email>csjp@FreeBSD.org</email>
</author>
<published>2006-09-19T15:45:22Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=5e26e428cf4e45807167ca05a29d6b45ad9b1f62'/>
<id>urn:sha1:5e26e428cf4e45807167ca05a29d6b45ad9b1f62</id>
<content type='text'>
This fixes kernel panics which occur when the firewall sends out a packet.
This can happen for keep alives, or instances when the firewall is
configured to return RST or ICMP unreach packets. These panics occured
only if MLS, BIBA or LOMAC security policies were loaded.

Approved by:	re@ (kensmith)
Submitted by:	mlaier (with changes)
</content>
</entry>
<entry>
<title>MFC in the pf and pflog modules:</title>
<updated>2006-03-22T15:56:32Z</updated>
<author>
<name>Yaroslav Tykhiy</name>
<email>ytykhiy@gmail.com</email>
</author>
<published>2006-03-22T15:56:32Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=97bd3c767532dc638274ff8885af5d9b8d63d9ca'/>
<id>urn:sha1:97bd3c767532dc638274ff8885af5d9b8d63d9ca</id>
<content type='text'>
pf: Respect KERNBUILDDIR.
both: Don't depend on DEV_*.

Approved by:	re (scottl)
</content>
</entry>
<entry>
<title>MFC:</title>
<updated>2006-03-06T16:10:19Z</updated>
<author>
<name>Max Laier</name>
<email>mlaier@FreeBSD.org</email>
</author>
<published>2006-03-06T16:10:19Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=c6563059d36c4fc2e3a1d2ce7f0a851ec70eecb6'/>
<id>urn:sha1:c6563059d36c4fc2e3a1d2ce7f0a851ec70eecb6</id>
<content type='text'>
  Make pflog a seperate module.  As a result pflog_packet() becomes a
  function pointer that is declared in pf_ioctl.c

  Requested by:   yar (as part of the module build reorg)

Approved by:	re (scottl)
</content>
</entry>
<entry>
<title>Let kmod.mk create an empty .h file.</title>
<updated>2005-06-05T05:30:37Z</updated>
<author>
<name>Ruslan Ermilov</name>
<email>ru@FreeBSD.org</email>
</author>
<published>2005-06-05T05:30:37Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=50fc7005c20823fdf77128bdf75390a3450192d0'/>
<id>urn:sha1:50fc7005c20823fdf77128bdf75390a3450192d0</id>
<content type='text'>
</content>
</entry>
<entry>
<title>NOINET6 -&gt; NO_INET6</title>
<updated>2004-12-21T10:49:29Z</updated>
<author>
<name>Ruslan Ermilov</name>
<email>ru@FreeBSD.org</email>
</author>
<published>2004-12-21T10:49:29Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=731db6a428d2389caf3795ff50f1895f04b80899'/>
<id>urn:sha1:731db6a428d2389caf3795ff50f1895f04b80899</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Removed -Wall from CFLAGS.</title>
<updated>2004-09-01T07:39:12Z</updated>
<author>
<name>Ruslan Ermilov</name>
<email>ru@FreeBSD.org</email>
</author>
<published>2004-09-01T07:39:12Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=5eadd7403e8fb0def69f6baae24594ca2e5e9bb7'/>
<id>urn:sha1:5eadd7403e8fb0def69f6baae24594ca2e5e9bb7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Get rid of the RANDOM_IP_ID option and make it a sysctl.  NetBSD</title>
<updated>2004-08-14T15:32:40Z</updated>
<author>
<name>David Malone</name>
<email>dwmalone@FreeBSD.org</email>
</author>
<published>2004-08-14T15:32:40Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=1f44b0a1b539198ce55bf97e73d51ded20a55ab4'/>
<id>urn:sha1:1f44b0a1b539198ce55bf97e73d51ded20a55ab4</id>
<content type='text'>
have already done this, so I have styled the patch on their work:

        1) introduce a ip_newid() static inline function that checks
        the sysctl and then decides if it should return a sequential
        or random IP ID.

        2) named the sysctl net.inet.ip.random_id

        3) IPv6 flow IDs and fragment IDs are now always random.
        Flow IDs and frag IDs are significantly less common in the
        IPv6 world (ie. rarely generated per-packet), so there should
        be smaller performance concerns.

The sysctl defaults to 0 (sequential IP IDs).

Reviewed by:	andre, silby, mlaier, ume
Based on:	NetBSD
MFC after:	2 months
</content>
</entry>
<entry>
<title>Commit pf version 3.5 and link additional files to the kernel build.</title>
<updated>2004-06-16T23:24:02Z</updated>
<author>
<name>Max Laier</name>
<email>mlaier@FreeBSD.org</email>
</author>
<published>2004-06-16T23:24:02Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=7c1fe9533390e3a906df00201ee6c66cbac7a031'/>
<id>urn:sha1:7c1fe9533390e3a906df00201ee6c66cbac7a031</id>
<content type='text'>
Version 3.5 brings:
 - Atomic commits of ruleset changes (reduce the chance of ending up in an
   inconsistent state).
 - A 30% reduction in the size of state table entries.
 - Source-tracking (limit number of clients and states per client).
 - Sticky-address (the flexibility of round-robin with the benefits of
   source-hash).
 - Significant improvements to interface handling.
 - and many more ...
</content>
</entry>
<entry>
<title>Make pf* modules respect NOINET6 from make.conf(5) in order to build them</title>
<updated>2004-04-06T15:12:50Z</updated>
<author>
<name>Max Laier</name>
<email>mlaier@FreeBSD.org</email>
</author>
<published>2004-04-06T15:12:50Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src-test2/commit/?id=1ffe5d762b1dba2d7bf54e412484286ccd02d1d4'/>
<id>urn:sha1:1ffe5d762b1dba2d7bf54e412484286ccd02d1d4</id>
<content type='text'>
for INET6-less kernel.

Requested by:	many
Approved by:	bms(mentor)
</content>
</entry>
</feed>
