Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 4 Jan 2000 23:34:31 +0100
From:      Szilveszter Adam <sziszi@petra.hos.u-szeged.hu>
To:        freebsd-stable@FreeBSD.ORG
Subject:   Re: enabling bridge-support in rc.conf?
Message-ID:  <20000104233431.C17628@petra.hos.u-szeged.hu>
In-Reply-To: <200001042201.XAA35186@dorifer.heim3.tu-clausthal.de>
References:  <84tkp8$4tk$1@atlantis.rz.tu-clausthal.de> <200001042201.XAA35186@dorifer.heim3.tu-clausthal.de>

next in thread | previous in thread | raw e-mail | index | archive | help
On Tue, Jan 04, 2000 at 11:01:43PM +0100, Oliver Fromme wrote:

> That's something completely different.  If you break your box
> by configuring your Linux support, that's your problem.  But
> enabling bridging affects the whole network, and it can cause
> _very_ bad things if you don't know exactly what you're doing.
> If you create loops in the topology by bridging, you're doomed.
> The manpage contains a warning about this.  Enabling bridging
> by default without user intervention is a very bad thing.
> 
> And what's the problem with sysctl anyway?

Just to get it clear: I did not suggest it to be enabled without user
intervention. All I
had in mind was to move this particular parameter to rc.conf (or similar)
instead of the sysctl. Sorry if this did not came through, but this is the
$SUBJECT of this thread so I thought it was obvious.

The problem with sysctls is only one: They tend to be badly documented.
After all, grepping through the source is not always an option and this may
or may not have to do with the admin's level of experience. It may also be
space constraints, not having the source, etc. 

> 
>  > For example the docs up to this day ignore the tool 'mergemaster'
>  > although it has become a standard util from a third-party app.
> 
> Did you write the docs and sent them to the FreeBSD docs folks?
> That's what send-pr is for.   _Someone_ has to write the docs,
> otherwise they don't exist.  Docs don't fall from the sky.  

I could not agree more. I did not write this to start a rant against the
-doc people. I am on that mailing list as well and know how hard they are
working. I wish I had more time on my hands so that I could submit some
docs... but this is examination time for us at University and since my major is
not in the least computer-related, this is quite a distraction. Maybe a
couple of weeks later... until then, I will try to polish my SGML/DocBook 
skills and improve my English, both of which are critical now:-) 

> 
>  > BTW I see another similar case: why do you need a sysctl in order to allow
>  > ordinary users to mount/umount removable media?
> 
> Because it would be a security hole if it was enabled by
> default.  It should only be enabled if the admin knows exactly
> what he/she is doing.  Just like bridging.

Same goes here. I did not say it be enabled by default. But documented and
more easily accessible. I bet any vendor would not know that
automounting CDs was actually possible using BSD so they say: see, Linux is
more developed and more suited to the mass market. Advocacy and marketing does 
not end with listings of kernel features... 

> 
> (As far as bridging is concerened, I think this is even an RFC
> requirement.)

Yes, I think, too. Someone already submitted the number, unless I am mistaken.

Regards and have a nice evening, everybody!

Szilveszter ADAM
-- 
-------------------------------------------------------------------------------
* Szilveszter ADAM * JATE Szeged * email: sziszi@petra.hos.u-szeged.hu *
* Homepage : none * alternate email: cc@flanker.itl.net.ua *
* Finger sziszi@petra.hos.u-szeged.hu for PGP key. *
* I prefer using the door instead of Windows(tm)... *            


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-stable" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20000104233431.C17628>