From owner-svn-src-all@FreeBSD.ORG Thu Oct 17 13:30:30 2013 Return-Path: Delivered-To: svn-src-all@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTP id 736576CB; Thu, 17 Oct 2013 13:30:30 +0000 (UTC) (envelope-from gavin@FreeBSD.org) Received: from mail-gw11.york.ac.uk (mail-gw11.york.ac.uk [144.32.129.150]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id 37C562F8D; Thu, 17 Oct 2013 13:30:30 +0000 (UTC) Received: from ury.york.ac.uk ([144.32.64.162]:37666) by mail-gw11.york.ac.uk with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.76) (envelope-from ) id 1VWnef-0003JU-LC; Thu, 17 Oct 2013 14:30:21 +0100 Date: Thu, 17 Oct 2013 14:30:21 +0100 (BST) From: Gavin Atkinson X-X-Sender: gavin@thunderhorn.york.ac.uk To: Hiroki Sato Subject: Re: svn commit: r256256 - in head: . etc etc/defaults etc/rc.d share/man/man5 usr.sbin/jail In-Reply-To: <20131015.142229.509071744045645883.hrs@allbsd.org> Message-ID: References: <525CB6E8.9080407@wemm.org> <20131015.130325.1303921217567498427.hrs@allbsd.org> <20131015.142229.509071744045645883.hrs@allbsd.org> User-Agent: Alpine 2.00 (BSF 1167 2008-08-23) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Cc: svn-src-head@FreeBSD.org, remko@FreeBSD.org, src-committers@FreeBSD.org, svn-src-all@FreeBSD.org, peter@wemm.org X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 17 Oct 2013 13:30:30 -0000 On Tue, 15 Oct 2013, Hiroki Sato wrote: > Hiroki Sato wrote > in <20131015.130325.1303921217567498427.hrs@allbsd.org>: > > hr> Peter Wemm wrote > hr> in <525CB6E8.9080407@wemm.org>: > hr> > hr> pe> Note how they're all on bge0 and the lo1|127.x is ignored. > hr> pe> > hr> pe> There's some other problems I haven't pinned down yet. Something has > hr> pe> changed radically with source address selection and some standard setups > hr> pe> from 7.x through 10.x (as of a few months ago) don't work anymore. I > hr> pe> haven't yet figured out how to do the per-jail lo1|127.x thing in the new > hr> pe> scheme even with an old rc.d/jail - anything attempting to bind to localhost > hr> pe> gets remapped to the public, fully exposed address. > hr> pe> > hr> pe> I'm still looking. > hr> > hr> Can you test the attached patch? > > Okay, I think r256498 should fix these issues. Please let me know if > you still have a problem. Just to follow up on this: r256498 does indeed seem to fix all the issues I saw. Thanks, Gavin