From owner-freebsd-virtualization@FreeBSD.ORG Thu Oct 16 08:52:02 2014 Return-Path: Delivered-To: freebsd-virtualization@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 1B516E85; Thu, 16 Oct 2014 08:52:02 +0000 (UTC) Received: from smtp.des.no (smtp.des.no [194.63.250.102]) by mx1.freebsd.org (Postfix) with ESMTP id CD367FC9; Thu, 16 Oct 2014 08:52:01 +0000 (UTC) Received: from nine.des.no (smtp.des.no [194.63.250.102]) by smtp-int.des.no (Postfix) with ESMTP id D7A2BC506; Thu, 16 Oct 2014 08:52:00 +0000 (UTC) Received: by nine.des.no (Postfix, from userid 1001) id 772C250BE; Thu, 16 Oct 2014 10:52:02 +0200 (CEST) From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= To: "Bjoern A. Zeeb" Subject: Re: Enabling VIMAGE by default for FreeBSD 11? References: <20141012182551.002b3cc0a45a56d3f34e6174@yamagi.org> <3B4471A7-CDF4-440D-BDD8-3D5B2256B8DD@lists.zabbadoz.net> <7EAA2A23-06F9-44C9-A3E1-62AA37EE5CDA@lists.zabbadoz.net> Date: Thu, 16 Oct 2014 10:52:02 +0200 In-Reply-To: <7EAA2A23-06F9-44C9-A3E1-62AA37EE5CDA@lists.zabbadoz.net> (Bjoern A. Zeeb's message of "Mon, 13 Oct 2014 01:07:55 +0000") Message-ID: <86d29so0r1.fsf@nine.des.no> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Cc: freebsd-net@freebsd.org, freebsd-virtualization@freebsd.org, freebsd-arch X-BeenThere: freebsd-virtualization@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: "Discussion of various virtualization techniques FreeBSD supports." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Oct 2014 08:52:02 -0000 "Bjoern A. Zeeb" writes: > Also if people are seriously thinking about virtualising pf we need to > import the openbsd/apple pf fix from a few years ago because otherwise > people in virtualised stacks with a /dev/pf can do ugly things. I > think it=E2=80=99s been this one: > http://cve.mitre.org/cgi-bin/cvename.cgi?name=3DCVE-2010-3830 There are other serious issues with our current pf (checksum corruption) which I think can only be resolved by importing a newer version. DES --=20 Dag-Erling Sm=C3=B8rgrav - des@des.no