From owner-cvs-src-old@FreeBSD.ORG Sun Feb 7 09:02:24 2010 Return-Path: Delivered-To: cvs-src-old@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id CDDEB10656A3 for ; Sun, 7 Feb 2010 09:02:24 +0000 (UTC) (envelope-from julian@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id A14468FC17 for ; Sun, 7 Feb 2010 09:02:24 +0000 (UTC) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.3/8.14.3) with ESMTP id o1792OuT090562 for ; Sun, 7 Feb 2010 09:02:24 GMT (envelope-from julian@repoman.freebsd.org) Received: (from svn2cvs@localhost) by repoman.freebsd.org (8.14.3/8.14.3/Submit) id o1792Oaq090561 for cvs-src-old@freebsd.org; Sun, 7 Feb 2010 09:02:24 GMT (envelope-from julian@repoman.freebsd.org) Message-Id: <201002070902.o1792Oaq090561@repoman.freebsd.org> X-Authentication-Warning: repoman.freebsd.org: svn2cvs set sender to julian@repoman.freebsd.org using -f From: Julian Elischer Date: Sun, 7 Feb 2010 09:00:22 +0000 (UTC) To: cvs-src-old@freebsd.org X-FreeBSD-CVS-Branch: RELENG_8 Subject: cvs commit: src/sys/net if_bridge.c if_enc.c if_ethersubr.c pfil.c src/sys/netgraph ng_bridge.c src/sys/netinet ip_fastfwd.c ip_input.c ip_output.c ip_var.h raw_ip.c src/sys/netinet/ipfw ip_fw2.c ip_fw_pfil.c src/sys/netinet6 ip6_forward.c ip6_input.c ... X-BeenThere: cvs-src-old@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: **OBSOLETE** CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 07 Feb 2010 09:02:24 -0000 julian 2010-02-07 09:00:22 UTC FreeBSD src repository Modified files: (Branch: RELENG_8) sys/net if_bridge.c if_enc.c if_ethersubr.c pfil.c sys/netgraph ng_bridge.c sys/netinet ip_fastfwd.c ip_input.c ip_output.c ip_var.h raw_ip.c sys/netinet/ipfw ip_fw2.c ip_fw_pfil.c sys/netinet6 ip6_forward.c ip6_input.c ip6_output.c ip6_var.h Log: SVN rev 203605 on 2010-02-07 09:00:22Z by julian MFC of 197952 and 198075 Virtualize the pfil hooks so that different jails may chose different packet filters. ALso allows ipfw to be enabled on on ejail and disabled on another. In 8.0 it's a global setting. and Unbreak the VIMAGE build with IPSEC, broken with r197952 by virtualizing the pfil hooks. For consistency add the V_ to virtualize the pfil hooks in here as well. Revision Changes Path 1.131.2.3 +21 -20 src/sys/net/if_bridge.c 1.14.2.2 +4 -4 src/sys/net/if_enc.c 1.270.2.2 +3 -3 src/sys/net/if_ethersubr.c 1.16.2.4 +48 -5 src/sys/net/pfil.c 1.36.2.2 +1 -1 src/sys/netgraph/ng_bridge.c 1.52.2.2 +5 -4 src/sys/netinet/ip_fastfwd.c 1.375.2.5 +10 -10 src/sys/netinet/ip_input.c 1.314.2.5 +2 -2 src/sys/netinet/ip_output.c 1.115.2.2 +9 -3 src/sys/netinet/ip_var.h 1.11.2.7 +51 -47 src/sys/netinet/ipfw/ip_fw2.c 1.4.2.3 +24 -12 src/sys/netinet/ipfw/ip_fw_pfil.c 1.220.2.6 +6 -6 src/sys/netinet/raw_ip.c 1.51.2.2 +2 -2 src/sys/netinet6/ip6_forward.c 1.132.2.3 +11 -10 src/sys/netinet6/ip6_input.c 1.137.2.3 +2 -2 src/sys/netinet6/ip6_output.c 1.55.2.2 +2 -1 src/sys/netinet6/ip6_var.h