From owner-freebsd-questions@FreeBSD.ORG Tue Nov 16 20:27:35 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id BEAD116A4CE for ; Tue, 16 Nov 2004 20:27:35 +0000 (GMT) Received: from obsecurity.dyndns.org (CPE0050040655c8-CM00111ae02aac.cpe.net.cable.rogers.com [69.194.102.143]) by mx1.FreeBSD.org (Postfix) with ESMTP id 657CC43D4C for ; Tue, 16 Nov 2004 20:27:35 +0000 (GMT) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id A611651281; Tue, 16 Nov 2004 12:30:37 -0800 (PST) Date: Tue, 16 Nov 2004 12:30:37 -0800 From: Kris Kennaway To: "Matthew T. Lager" Message-ID: <20041116203037.GB17125@xor.obsecurity.org> References: <200411160054.39582.giulianocm@uol.com.br> <20041116031937.GA32097@xor.obsecurity.org> <1733.24.25.209.32.1100585671.squirrel@24.25.209.32> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="U+BazGySraz5kW0T" Content-Disposition: inline In-Reply-To: <1733.24.25.209.32.1100585671.squirrel@24.25.209.32> User-Agent: Mutt/1.4.2.1i cc: Giuliano Cardozo Medalha cc: freebsd-questions@freebsd.org cc: Kris Kennaway Subject: Re: MPSAFE - Warning X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 16 Nov 2004 20:27:35 -0000 --U+BazGySraz5kW0T Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Mon, Nov 15, 2004 at 10:14:31PM -0800, Matthew T. Lager wrote: > I too receive this error. I require the use of KAME IPSEC. Basiclly, > services such as IPV6 and IPSEC require the kernel to be GIANT locked, > which is incompatable with MPSAFE. 5.3 forces MPSAFE to 0 if the system is > GIANT locked, hence the warning. >=20 > I backed down to 5.2.1 and ran IPSEC with no problems. Just to be clear, there's no danger in running IPv6 or KAME IPSEC in 5.3, you just won't get any benefits from running it on a SMP machine (neither will you in 5.2.1 or 4.x). > I actually did > experience many issues with my IPSEC tunnel in 5.3. Any problems you observed are presumably orthogonal to the Giant-ness, so you ideally should report them so they can be analyzed. Kris --U+BazGySraz5kW0T Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (FreeBSD) iD8DBQFBmmNsWry0BWjoQKURAv/BAJwIt1Cbtah1xXVS+VuGBdTtbSqyzgCeNtlK MAAIjqYlNti31lJs7Z5yvjw= =7bVD -----END PGP SIGNATURE----- --U+BazGySraz5kW0T--