From owner-cvs-src-old@FreeBSD.ORG Sun Oct 11 06:00:36 2009 Return-Path: Delivered-To: cvs-src-old@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 8C4D210656A5 for ; Sun, 11 Oct 2009 06:00:36 +0000 (UTC) (envelope-from julian@FreeBSD.org) Received: from repoman.freebsd.org (repoman.freebsd.org [IPv6:2001:4f8:fff6::29]) by mx1.freebsd.org (Postfix) with ESMTP id 756538FC25 for ; Sun, 11 Oct 2009 06:00:36 +0000 (UTC) Received: from repoman.freebsd.org (localhost [127.0.0.1]) by repoman.freebsd.org (8.14.3/8.14.3) with ESMTP id n9B60aQJ067814 for ; Sun, 11 Oct 2009 06:00:36 GMT (envelope-from julian@repoman.freebsd.org) Received: (from svn2cvs@localhost) by repoman.freebsd.org (8.14.3/8.14.3/Submit) id n9B60aRs067813 for cvs-src-old@freebsd.org; Sun, 11 Oct 2009 06:00:36 GMT (envelope-from julian@repoman.freebsd.org) Message-Id: <200910110600.n9B60aRs067813@repoman.freebsd.org> X-Authentication-Warning: repoman.freebsd.org: svn2cvs set sender to julian@repoman.freebsd.org using -f From: Julian Elischer Date: Sun, 11 Oct 2009 05:59:43 +0000 (UTC) To: cvs-src-old@freebsd.org X-FreeBSD-CVS-Branch: HEAD Subject: cvs commit: src/sys/net if_bridge.c if_ethersubr.c pfil.c src/sys/netgraph ng_bridge.c src/sys/netinet ip_fastfwd.c ip_input.c ip_output.c ip_var.h raw_ip.c src/sys/netinet/ipfw ip_fw2.c ip_fw_pfil.c src/sys/netinet6 ip6_forward.c ip6_input.c ... X-BeenThere: cvs-src-old@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: **OBSOLETE** CVS commit messages for the src tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 11 Oct 2009 06:00:36 -0000 julian 2009-10-11 05:59:43 UTC FreeBSD src repository Modified files: sys/net if_bridge.c if_ethersubr.c pfil.c sys/netgraph ng_bridge.c sys/netinet ip_fastfwd.c ip_input.c ip_output.c ip_var.h raw_ip.c sys/netinet/ipfw ip_fw2.c ip_fw_pfil.c sys/netinet6 ip6_forward.c ip6_input.c ip6_output.c ip6_var.h Log: SVN rev 197952 on 2009-10-11 05:59:43Z by julian Virtualize the pfil hooks so that different jails may chose different packet filters. ALso allows ipfw to be enabled on on ejail and disabled on another. In 8.0 it's a global setting. Sitting aroung in tree waiting to commit for: 2 months MFC after: 2 months Revision Changes Path 1.133 +21 -20 src/sys/net/if_bridge.c 1.271 +3 -3 src/sys/net/if_ethersubr.c 1.17 +48 -5 src/sys/net/pfil.c 1.37 +1 -1 src/sys/netgraph/ng_bridge.c 1.54 +5 -4 src/sys/netinet/ip_fastfwd.c 1.376 +10 -10 src/sys/netinet/ip_input.c 1.318 +2 -2 src/sys/netinet/ip_output.c 1.116 +9 -3 src/sys/netinet/ip_var.h 1.16 +51 -47 src/sys/netinet/ipfw/ip_fw2.c 1.6 +24 -12 src/sys/netinet/ipfw/ip_fw_pfil.c 1.222 +6 -6 src/sys/netinet/raw_ip.c 1.52 +2 -2 src/sys/netinet6/ip6_forward.c 1.135 +11 -10 src/sys/netinet6/ip6_input.c 1.139 +2 -2 src/sys/netinet6/ip6_output.c 1.56 +2 -1 src/sys/netinet6/ip6_var.h