From nobody Tue Oct 3 03:37:25 2023 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4S03RT3wxnz4vdcT; Tue, 3 Oct 2023 03:37:25 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4S03RT3LZXz4TWR; Tue, 3 Oct 2023 03:37:25 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696304245; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=2ghrNR5ZmxhsmLRoi/ES58RFHptSMgj0g+P3TlySjkQ=; b=izuSCiZTwjGJ2f1Q2V2TRQbnoFvLyL2IJQKxnrpasWcsVDGvfmqP1By4D3mUDK6QaVTAxj 1nDmh3zYT3Y+kIU0MBbHo9vzjmIfNw3aDn57qK7DggY1JoNNg4mOZAyQa17x9iIzomxVU8 fPAS7HQaLNcjawWe+Js5ESiwDsbBJGHqiFtlh4fMQvFgMf4hT70vaZ7mRhNkKi0wg++KzZ /7GZa0N+GgllGy6EHIGCkkoSIRXNfd/yQiZE/kfemTsrgOth14HZdyW/9XbGo9nNa+EjR5 wmmIHHQC3Hd57qyuqNpUmNuCw2WLHQIax/LYouwvUflDEIc9ZbUDVDD+KAeo9w== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1696304245; a=rsa-sha256; cv=none; b=yEIJktroEAiMcbraNnO+kYJXwroIX9JrLZIDJXD2yLC1ziMC+OrtcmDbhUawKhSFMUarWG 2N+jhvr3m53/m52KJb+IEfpoUbbIeSQlmXSBDDPcHtxA0l/vRNQ6rkvme5aSphLGKjc/fb dVM/Gb7WntpeK+4L/V/v2EDUr7VvpEbItHq6UF+XxMRN+zlU+gZ4Ai4ZnkcWwLsuoO72wm e8Kw3IHZy7xI77ZIfOkydpQr/bocKUM2TyQ4E7F10bIXd4IUoQjCrk3xtKOWcNx+0s2NbQ c3KSH2BTW1BlrkRAFOdVW/3hlhSm2/h6BI0/nCDl0gK8TwFaHH9WirikNAmLdw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696304245; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=2ghrNR5ZmxhsmLRoi/ES58RFHptSMgj0g+P3TlySjkQ=; b=N50psH3HNBZFYqW8iT89rZNUtR185c1VXCtUaX1wXl2GhA0u289RRJzm5FJARApg2hX1aP qIrlq/ZXh4TEOKMK1Iks3HatULtnZnD9JRI1aur/MVom3f8rbeFeTrYSzfPG2B3J/1Kxx/ kdUufpFgVFbL2pKIumPcqnSv2FRHoMCExGb+u2jJZItdpR/8oc/SmXwC80FRs+7T0qqMyg zj/ON7C1diQqD9k4EdAIL92kx+AERf1+b9rgxUAUl6rdvDN1d1+fM7NoFMwVSJ3pCV33EB HVtr+TOHRGyJmxCGgYNy+dUW7Jui1N75tWTeADPWUcrWLacZsvrWS5p2z6hjnA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4S03RT2PX7zfPQ; Tue, 3 Oct 2023 03:37:25 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3933bPL0003086; Tue, 3 Oct 2023 03:37:25 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3933bPeJ003083; Tue, 3 Oct 2023 03:37:25 GMT (envelope-from git) Date: Tue, 3 Oct 2023 03:37:25 GMT Message-Id: <202310030337.3933bPeJ003083@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Zhenlei Huang Subject: git: cc30510aeb78 - releng/14.0 - ipfw.8: Adjust section for loader tunables List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: zlei X-Git-Repository: src X-Git-Refname: refs/heads/releng/14.0 X-Git-Reftype: branch X-Git-Commit: cc30510aeb78d6013dfa9c137144543c2db0e4c8 Auto-Submitted: auto-generated The branch releng/14.0 has been updated by zlei: URL: https://cgit.FreeBSD.org/src/commit/?id=cc30510aeb78d6013dfa9c137144543c2db0e4c8 commit cc30510aeb78d6013dfa9c137144543c2db0e4c8 Author: Zhenlei Huang AuthorDate: 2023-09-28 04:58:44 +0000 Commit: Zhenlei Huang CommitDate: 2023-10-03 03:34:16 +0000 ipfw.8: Adjust section for loader tunables Move the descriptions of loader tunables from section 'SYSCTL VARIABLES' to section 'LOADER TUNABLES'. See also 49197c391b3d (ipfw: Add sysctl flag CTLFLAG_TUN to loader tunables). MFC after: 2 days Approved by: re (gjb) Differential Revision: https://reviews.freebsd.org/D41981 (cherry picked from commit 12349f38898f231ca803dcf526bac88cb1b5cd2b) (cherry picked from commit bb6f9a95402a6c3ab8167481b81465f8ad5016fc) --- sbin/ipfw/ipfw.8 | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/sbin/ipfw/ipfw.8 b/sbin/ipfw/ipfw.8 index 1a042ae2bbbf..e62b8d6efc95 100644 --- a/sbin/ipfw/ipfw.8 +++ b/sbin/ipfw/ipfw.8 @@ -1,5 +1,5 @@ .\" -.Dd April 25, 2023 +.Dd September 28, 2023 .Dt IPFW 8 .Os .Sh NAME @@ -3761,6 +3761,16 @@ or .Xr kenv 1 before ipfw module gets loaded. .Bl -tag -width indent +.It Va net.inet.ip.fw.enable : No 1 +Enables the firewall. +Setting this variable to 0 lets you run your machine without +firewall even if compiled in. +.It Va net.inet6.ip6.fw.enable : No 1 +provides the same functionality as above for the IPv6 case. +.It Va net.link.ether.ipfw : No 0 +Controls whether layer2 packets are passed to +.Nm . +Default is no. .It Va net.inet.ip.fw.default_to_accept : No 0 Defines ipfw last rule behavior. This value overrides @@ -4154,12 +4164,6 @@ Keep dynamic states on rule/set deletion. States are relinked to default rule (65535). This can be handly for ruleset reload. Turned off by default. -.It Va net.inet.ip.fw.enable : No 1 -Enables the firewall. -Setting this variable to 0 lets you run your machine without -firewall even if compiled in. -.It Va net.inet6.ip6.fw.enable : No 1 -provides the same functionality as above for the IPv6 case. .It Va net.inet.ip.fw.one_pass : No 1 When set, the packet exiting from the .Nm dummynet @@ -4176,10 +4180,6 @@ Enables verbose messages. Limits the number of messages produced by a verbose firewall. .It Va net.inet6.ip6.fw.deny_unknown_exthdrs : No 1 If enabled packets with unknown IPv6 Extension Headers will be denied. -.It Va net.link.ether.ipfw : No 0 -Controls whether layer2 packets are passed to -.Nm . -Default is no. .It Va net.link.bridge.ipfw : No 0 Controls whether bridged packets are passed to .Nm .