Date: Mon, 09 Jul 2012 17:08:13 +0900 (JST) From: Hiroki Sato <hrs@FreeBSD.org> To: melifaro@FreeBSD.org Cc: svn-src-head@FreeBSD.org, svn-src-all@FreeBSD.org, src-committers@FreeBSD.org Subject: Re: svn commit: r238277 - in head: etc/defaults etc/rc.d sbin/ipfw share/man/man5 sys/netinet/ipfw Message-ID: <20120709.170813.339720376082380726.hrs@allbsd.org> In-Reply-To: <4FFA894D.9050104@FreeBSD.org> References: <201207090716.q697GJ7A001973@svn.freebsd.org> <4FFA894D.9050104@FreeBSD.org>
next in thread | previous in thread | raw e-mail | index | archive | help
----Security_Multipart(Mon_Jul__9_17_08_13_2012_866)-- Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit "Alexander V. Chernikov" <melifaro@FreeBSD.org> wrote in <4FFA894D.9050104@FreeBSD.org>: me> On 09.07.2012 11:16, Hiroki Sato wrote: me> > Author: hrs me> > Date: Mon Jul 9 07:16:19 2012 me> > New Revision: 238277 me> > URL: http://svn.freebsd.org/changeset/base/238277 me> > me> > Log: me> > Make ipfw0 logging pseudo-interface clonable. It can be created me> > automatically me> > by $firewall_logif rc.conf(5) variable at boot time or manually by me> > ifconfig(8) me> > after a boot. me> > me> > Discussed on: freebsd-ipfw@ me> Em, well, I thought "discussed" means some kind of consensus? me> There was an alternative implementation proposed in -ipfw with no me> comments from you side. Additionally, there can be other (still not me> discussed) solutions like making this interface as loadable module me> (like pf do). I meant there was no strong objection. I am sorry for not commenting your implementation, but at least for ipfw0 it is difficult to decouple ifnet and bpf because the primary consumer is tcpdump(8), which depends on NET_RT_IFLIST to find the target. Probably your solution can be used for usbdump(8). The reason why I committed the patch now is there are reports that these pseudo interfaces made some applications confused and/or caused some performance degradation on 9.0R, and wanted to fix it in some way. I am still open for more sophisticated implementation and have no objection to replace mine with it. Do you have an idea about converting it with a loadable module? -- Hiroki ----Security_Multipart(Mon_Jul__9_17_08_13_2012_866)-- Content-Type: application/pgp-signature Content-Transfer-Encoding: 7bit -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (FreeBSD) iEYEABECAAYFAk/6kW0ACgkQTyzT2CeTzy2FygCgkA6HqiidVRcLOgXBA+Aipi3H Vp4AoNE4Tfbhmi4xE3n/IzPe1+K9jr65 =Qzyy -----END PGP SIGNATURE----- ----Security_Multipart(Mon_Jul__9_17_08_13_2012_866)----
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20120709.170813.339720376082380726.hrs>