From owner-freebsd-stable@FreeBSD.ORG Wed Sep 3 11:16:26 2014 Return-Path: Delivered-To: freebsd-stable@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 60EB484B for ; Wed, 3 Sep 2014 11:16:26 +0000 (UTC) Received: from mail.ijs.si (mail.ijs.si [IPv6:2001:1470:ff80::25]) by mx1.freebsd.org (Postfix) with ESMTP id 10B0A17B7 for ; Wed, 3 Sep 2014 11:16:26 +0000 (UTC) Received: from amavis-proxy-ori.ijs.si (localhost [IPv6:::1]) by mail.ijs.si (Postfix) with ESMTP id 3hp2f06Zwvz1Hp for ; Wed, 3 Sep 2014 13:16:24 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ijs.si; h= user-agent:message-id:references:in-reply-to:organization :subject:subject:from:from:date:date:content-transfer-encoding :content-type:content-type:mime-version:received:received :received:received; s=jakla2; t=1409742979; x=1412334980; bh=Z4g d/PVS2jKUt5jY1WSvoMGjQsdLuK18eHhyn0pN3Xk=; b=DlFG1krhjbfnT4zHpel qLa6fl+s+yN8xSb2EGpgWGFTlVMxvUY8HEePp1/jdpVFnoXIyBFEC0/4METtJ7/c l1nH2zJu+ylEoaHqM51ttpEVHpQ8x7SiNcjqXarmW2RsWNXv2HmT2abELDq5POgc IdeIBJ5DzW/kDYIwnY8GfGNE= X-Virus-Scanned: amavisd-new at ijs.si Received: from mail.ijs.si ([IPv6:::1]) by amavis-proxy-ori.ijs.si (mail.ijs.si [IPv6:::1]) (amavisd-new, port 10012) with ESMTP id RAYwGKCqJztS for ; Wed, 3 Sep 2014 13:16:19 +0200 (CEST) Received: from mildred.ijs.si (mailbox.ijs.si [IPv6:2001:1470:ff80::143:1]) by mail.ijs.si (Postfix) with ESMTP for ; Wed, 3 Sep 2014 13:16:19 +0200 (CEST) Received: from neli.ijs.si (neli.ijs.si [IPv6:2001:1470:ff80:88:21c:c0ff:feb1:8c91]) by mildred.ijs.si (Postfix) with ESMTP id 3hp2dv5KNPzFF for ; Wed, 3 Sep 2014 13:16:19 +0200 (CEST) Received: from sleepy.ijs.si ([2001:1470:ff80:e001::1:1]) by neli.ijs.si with HTTP (HTTP/1.1 POST); Wed, 03 Sep 2014 13:16:19 +0200 MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Transfer-Encoding: 7bit Date: Wed, 03 Sep 2014 13:16:19 +0200 From: Mark Martinec To: freebsd-stable@freebsd.org Subject: Re: [Bulk] Re: Stale NTP software included in FreeBSD (RELEASE/STABLE/CURRENT) Organization: J. Stefan Institute In-Reply-To: References: <20140903061024.GA14382@rwpc15.gfn.riverwillow.net.au> <5152f44f37895d107ae439997bc4cc3c@mailbox.ijs.si> Message-ID: X-Sender: Mark.Martinec+freebsd@ijs.si User-Agent: Roundcube Webmail/1.0.2 X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Sep 2014 11:16:26 -0000 >> Bug 2648 - 'restrict default' should imply both IP protocol families >> http://bugs.ntp.org/show_bug.cgi?id=2648 2014-09-03 13:08, je Axel napisal > Did you tried to add: > restrict default ignore > restrict -6 default ignore > > I follow steps described here: > http://support.ntp.org/bin/view/Support/AccessRestrictions I know, it is all described in that ntp PR. The point is that the 'restrict default' being equivalent to 'restrict -4 default' is contrary to documentation and is counterintuitive, leading to unintentionally leaving one address family unrestricted. The logic is made right in a later version of ntpd. Mark