From owner-svn-src-head@freebsd.org Fri Apr 28 05:32:28 2017 Return-Path: Delivered-To: svn-src-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 250F0D5471C; Fri, 28 Apr 2017 05:32:28 +0000 (UTC) (envelope-from glebius@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id EB3F8E87; Fri, 28 Apr 2017 05:32:27 +0000 (UTC) (envelope-from glebius@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id v3S5WRw7075706; Fri, 28 Apr 2017 05:32:27 GMT (envelope-from glebius@FreeBSD.org) Received: (from glebius@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id v3S5WQ7Z075704; Fri, 28 Apr 2017 05:32:26 GMT (envelope-from glebius@FreeBSD.org) Message-Id: <201704280532.v3S5WQ7Z075704@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: glebius set sender to glebius@FreeBSD.org using -f From: Gleb Smirnoff Date: Fri, 28 Apr 2017 05:32:26 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org Subject: svn commit: r317544 - head/usr.sbin/bhyve X-SVN-Group: head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-head@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: SVN commit messages for the src tree for head/-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Apr 2017 05:32:28 -0000 Author: glebius Date: Fri Apr 28 05:32:26 2017 New Revision: 317544 URL: https://svnweb.freebsd.org/changeset/base/317544 Log: - For security reasons by default listen on localhost address, not on wildcard. [1] - Move the default port assignment from pci_fbuf.c to rfb.c, to avoid polluting pci_fbuf.c with network things. Suggested by: grehan Modified: head/usr.sbin/bhyve/pci_fbuf.c head/usr.sbin/bhyve/rfb.c Modified: head/usr.sbin/bhyve/pci_fbuf.c ============================================================================== --- head/usr.sbin/bhyve/pci_fbuf.c Fri Apr 28 05:13:27 2017 (r317543) +++ head/usr.sbin/bhyve/pci_fbuf.c Fri Apr 28 05:32:26 2017 (r317544) @@ -365,8 +365,6 @@ pci_fbuf_init(struct vmctx *ctx, struct sc->fsc_pi = pi; - sc->rfb_port = 5900; - error = pci_fbuf_parse_opts(sc, opts); if (error != 0) goto done; Modified: head/usr.sbin/bhyve/rfb.c ============================================================================== --- head/usr.sbin/bhyve/rfb.c Fri Apr 28 05:13:27 2017 (r317543) +++ head/usr.sbin/bhyve/rfb.c Fri Apr 28 05:32:26 2017 (r317544) @@ -897,11 +897,11 @@ rfb_init(char *hostname, int port, int w sin.sin_len = sizeof(sin); sin.sin_family = AF_INET; - sin.sin_port = htons(port); + sin.sin_port = port ? htons(port) : htons(5900); if (hostname && strlen(hostname) > 0) inet_pton(AF_INET, hostname, &(sin.sin_addr)); else - sin.sin_addr.s_addr = htonl(INADDR_ANY); + sin.sin_addr.s_addr = htonl(INADDR_LOOPBACK); if (bind(rc->sfd, (struct sockaddr *)&sin, sizeof(sin)) < 0) { perror("bind");