From owner-freebsd-pf@freebsd.org Sun Aug 14 12:55:30 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 1BDEEBB948C for ; Sun, 14 Aug 2016 12:55:30 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id F2B43114B for ; Sun, 14 Aug 2016 12:55:29 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7ECtTFP067553 for ; Sun, 14 Aug 2016 12:55:29 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 211796] missing htonl calls in pf range check Date: Sun, 14 Aug 2016 12:55:29 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: linimon@FreeBSD.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: cc Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 14 Aug 2016 12:55:30 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D211796 Mark Linimon changed: What |Removed |Added ---------------------------------------------------------------------------- CC| |kp@freebsd.org, | |melifaro@FreeBSD.org --- Comment #1 from Mark Linimon --- Adding the two most recent committers to pf.c into the Cc: list for comment. --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Sun Aug 14 18:18:47 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id B0ABABB92C4 for ; Sun, 14 Aug 2016 18:18:47 +0000 (UTC) (envelope-from tech-lists@zyxst.net) Received: from out2-smtp.messagingengine.com (out2-smtp.messagingengine.com [66.111.4.26]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 8B55B1C57 for ; Sun, 14 Aug 2016 18:18:47 +0000 (UTC) (envelope-from tech-lists@zyxst.net) Received: from compute6.internal (compute6.nyi.internal [10.202.2.46]) by mailout.nyi.internal (Postfix) with ESMTP id 910672032C for ; Sun, 14 Aug 2016 14:18:40 -0400 (EDT) Received: from web2 ([10.202.2.212]) by compute6.internal (MEProxy); Sun, 14 Aug 2016 14:18:40 -0400 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=zyxst.net; h= content-transfer-encoding:content-type:date:from:message-id :mime-version:subject:to:x-sasl-enc:x-sasl-enc; s=mesmtp; bh=yrU sKQdOYZ7aYRf6eVQ5xzmdQo0=; b=K6QCpCwAF2mFcrzlvho7n8KoA53ADHn5kVZ u+Heec/Zv144TbtNbD1OtFyVfMupVMSo/O11Q3B0ZjDsAQUT8VZVicbNkNhuQDrN lMEpwO6tK03Ls8NKYOJgrcznxhwql1SPMjPFiJqhVKubUcaIXV7YvGf9xYEpLB1C FMJd+joo= DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d= messagingengine.com; h=content-transfer-encoding:content-type :date:from:message-id:mime-version:subject:to:x-sasl-enc :x-sasl-enc; s=smtpout; bh=yrUsKQdOYZ7aYRf6eVQ5xzmdQo0=; b=Ty1RN ozS83SvRMYpUTo9jIrbFthWOG5YrZm6ULx7ls+LaEOSldWIX586Thn3/IIPffq8u t3xwxfFaHoZh0Zz6iFbnz0a6KcZ+QIOzVC5wj/xITZ1ndUggmRgAd3fTSshMuVYh hLcZKnm+fz9bIH/3+WI4Vyfv0xAb6MZoUoND3Q= Received: by mailuser.nyi.internal (Postfix, from userid 99) id 57564D05E4; Sun, 14 Aug 2016 14:18:40 -0400 (EDT) Message-Id: <1471198720.1262751.695015513.1B57B0B9@webmail.messagingengine.com> X-Sasl-Enc: VfDpFdTX1D0O9wbloWS924cuCmBitWb1pOqzAKLxvS9X 1471198720 From: John To: freebsd-pf@freebsd.org MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Type: text/plain X-Mailer: MessagingEngine.com Webmail Interface - ajax-71d1d584 Subject: PF advice for IPv6-only machine (freebsd-12) Date: Sun, 14 Aug 2016 19:18:40 +0100 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 14 Aug 2016 18:18:47 -0000 Hello list, This is my first attempt creating a PF ipv6-only firewall. Please can anyone look at it and offer any suggestions? It seems to work (in that if services are removed from the macro, they're no longer accessible from the outside), but I'm not sure that I've done Everything Right (tm) and that there aren't some silly mistakes, like redundant statements. I'd like to silently drop connection attempts to ports where there are no services, like one can do on ip4 with blackhole(4) but I haven't a clue how to do it on ipv6 with PF - is there a way? ### begins # macros ext_if = msk0 services = "{ 22, 3022 }" icmp_types = "{ echoreq, unreach }" icmp6_types = "{ unreach, toobig, timex, paramprob, echoreq, echorep, neighbradv, neighbrsol,\ routeradv, routersol }" set skip on lo set block-policy return set state-policy if-bound set loginterface $ext_if scrub in on ext_if all fragment reassemble # filter rules block in log all pass out all # keep alive rules pass out log quick proto 41 from ($ext_if) to any keep state pass in log quick proto 41 from any to ($ext_if) keep state # allow heartbeat ping pass in log quick on $ext_if inet6 proto { ipv6-icmp } from any to \ any keep state # pass tcp services pass in quick on $ext_if inet6 proto tcp from any to any port $services ### ends many thanks, -- J. From owner-freebsd-pf@freebsd.org Mon Aug 15 10:25:00 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3128CBB9423 for ; Mon, 15 Aug 2016 10:25:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 12B6F15F1 for ; Mon, 15 Aug 2016 10:25:00 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7FAOx2P067918 for ; Mon, 15 Aug 2016 10:24:59 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 209475] pf didn't check if enough free RAM for net.pf.states_hashsize Date: Mon, 15 Aug 2016 10:25:00 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 10.3-RELEASE X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: fnoyanisi@yahoo.com X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2016 10:25:00 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D209475 --- Comment #6 from fehmi noyan isi --- Hi, Somehow, I missed the notification for the latest comment! Sorry for the la= te reply.... It is possible to add a log warning message by using printf(9) or log(9), b= ut I have noticed that pf_initialize() does things quietly most of the times. Do you reckon using printf(9) or log(9) would be the proper approach for ad= ding a log warning message for the not enough memory condition? --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Mon Aug 15 12:13:42 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0A7D4BBBDF5 for ; Mon, 15 Aug 2016 12:13:42 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id EE6EB199B for ; Mon, 15 Aug 2016 12:13:41 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7FCDfCd086350 for ; Mon, 15 Aug 2016 12:13:41 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 211796] missing htonl calls in pf range check Date: Mon, 15 Aug 2016 12:13:41 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: commit-hook@freebsd.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 15 Aug 2016 12:13:42 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D211796 --- Comment #2 from commit-hook@freebsd.org --- A commit references this bug: Author: kp Date: Mon Aug 15 12:13:14 UTC 2016 New revision: 304152 URL: https://svnweb.freebsd.org/changeset/base/304152 Log: pf: Add missing byte-order swap to pf_match_addr_range Without this, rules using address ranges (e.g. "10.1.1.1 - 10.1.1.5") did= not match addresses correctly on little-endian systems. PR: 211796 Obtained from: OpenBSD (sthen) MFC after: 3 days Changes: head/sys/netpfil/pf/pf.c --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Tue Aug 16 09:26:40 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E9749BBB213 for ; Tue, 16 Aug 2016 09:26:40 +0000 (UTC) (envelope-from daemon-user@freebsd.org) Received: from reviews.nyi.freebsd.org (reviews.nyi.freebsd.org [IPv6:2610:1c1:1:607c::16:b]) by mx1.freebsd.org (Postfix) with ESMTP id C43BA1DF6 for ; Tue, 16 Aug 2016 09:26:40 +0000 (UTC) (envelope-from daemon-user@freebsd.org) Received: by reviews.nyi.freebsd.org (Postfix, from userid 1346) id 436B82394; Tue, 16 Aug 2016 09:26:40 +0000 (UTC) Date: Tue, 16 Aug 2016 09:26:40 +0000 To: freebsd-pf@freebsd.org From: "kristof (Kristof Provost)" Reply-to: D1944+331+90181aefda88703e@reviews.freebsd.org Subject: [Differential] D1944: PF and VIMAGE fixes Message-ID: <88b846b2443c28e29e1c78228458def9@localhost.localdomain> X-Priority: 3 X-Phabricator-Sent-This-Message: Yes X-Mail-Transport-Agent: MetaMTA X-Auto-Response-Suppress: All X-Phabricator-Mail-Tags: , , Thread-Topic: D1944: PF and VIMAGE fixes X-Herald-Rules: none X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: Precedence: bulk In-Reply-To: References: Thread-Index: NDc2NzM0MzY4OTdiYThiNTU1MjY2ZDZmMTJiIFey3FA= MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Type: text/plain; charset="utf-8" X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 16 Aug 2016 09:26:41 -0000 a3Jpc3RvZiBjb21tYW5kZWVyZWQgdGhpcyByZXZpc2lvbi4Ka3Jpc3RvZiBlZGl0ZWQgcmV2aWV3 ZXJzLCBhZGRlZDogbnZhc3MtZ214LmNvbTsgcmVtb3ZlZDoga3Jpc3RvZi4Ka3Jpc3RvZiBhZGRl ZCBhIGNvbW1lbnQuCgoKICBJJ20gY29tbWFuZGVlcmluZyB0aGlzIHNvIGl0IGNhbiBiZSBjbG9z ZWQsIGJlY2F1c2UgdGhlIHBhdGNoIGZybyBiekAgKGh0dHBzOi8vcmV2aWV3cy5mcmVlYnNkLm9y Zy9ENjkyNCkgaGFzIGJlZW4gaW5jbHVkZWQuCgpSRVZJU0lPTiBERVRBSUwKICBodHRwczovL3Jl dmlld3MuZnJlZWJzZC5vcmcvRDE5NDQKCkVNQUlMIFBSRUZFUkVOQ0VTCiAgaHR0cHM6Ly9yZXZp ZXdzLmZyZWVic2Qub3JnL3NldHRpbmdzL3BhbmVsL2VtYWlscHJlZmVyZW5jZXMvCgpUbzoga3Jp c3RvZiwgdHJvY2lueSwgZ25uLCB6ZWMsIHJvZHJpZ2MsIGdsZWJpdXMsIGVyaSwgYnosIG52YXNz LWdteC5jb20KQ2M6IHJ5YW5fdGltZXdhc3RlZC5tZSwgbW1vbGwsIGphdmllcl9vdmlfeWFob28u Y29tLCBmYXJyb2toaSwganVsaWFuLCByb2JhaywgZnJlZWJzZC12aXJ0dWFsaXphdGlvbi1saXN0 LCBmcmVlYnNkLXBmLWxpc3QsIGZyZWVic2QtbmV0LWxpc3QK From owner-freebsd-pf@freebsd.org Tue Aug 16 09:26:51 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 61EC7BBB252 for ; Tue, 16 Aug 2016 09:26:51 +0000 (UTC) (envelope-from daemon-user@freebsd.org) Received: from reviews.nyi.freebsd.org (reviews.nyi.freebsd.org [IPv6:2610:1c1:1:607c::16:b]) by mx1.freebsd.org (Postfix) with ESMTP id 39CDA1EF3 for ; Tue, 16 Aug 2016 09:26:51 +0000 (UTC) (envelope-from daemon-user@freebsd.org) Received: by reviews.nyi.freebsd.org (Postfix, from userid 1346) id 7CD222518; Tue, 16 Aug 2016 09:26:50 +0000 (UTC) Date: Tue, 16 Aug 2016 09:26:50 +0000 To: freebsd-pf@freebsd.org From: "kristof (Kristof Provost)" Reply-to: D1944+331+90181aefda88703e@reviews.freebsd.org Subject: [Differential] D1944: PF and VIMAGE fixes Message-ID: <8a72aeb2ff83b4c0a769eed4333e28f5@localhost.localdomain> X-Priority: 3 X-Phabricator-Sent-This-Message: Yes X-Mail-Transport-Agent: MetaMTA X-Auto-Response-Suppress: All X-Phabricator-Mail-Tags: Thread-Topic: D1944: PF and VIMAGE fixes X-Herald-Rules: none X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-To: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: X-Phabricator-Cc: Precedence: bulk In-Reply-To: References: Thread-Index: NDc2NzM0MzY4OTdiYThiNTU1MjY2ZDZmMTJiIFey3Fo= MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Type: text/plain; charset="utf-8" X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 16 Aug 2016 09:26:51 -0000 a3Jpc3RvZiBhYmFuZG9uZWQgdGhpcyByZXZpc2lvbi4KClJFVklTSU9OIERFVEFJTAogIGh0dHBz Oi8vcmV2aWV3cy5mcmVlYnNkLm9yZy9EMTk0NAoKRU1BSUwgUFJFRkVSRU5DRVMKICBodHRwczov L3Jldmlld3MuZnJlZWJzZC5vcmcvc2V0dGluZ3MvcGFuZWwvZW1haWxwcmVmZXJlbmNlcy8KClRv OiBrcmlzdG9mLCB0cm9jaW55LCBnbm4sIHplYywgcm9kcmlnYywgZ2xlYml1cywgZXJpLCBieiwg bnZhc3MtZ214LmNvbQpDYzogcnlhbl90aW1ld2FzdGVkLm1lLCBtbW9sbCwgamF2aWVyX292aV95 YWhvby5jb20sIGZhcnJva2hpLCBqdWxpYW4sIHJvYmFrLCBmcmVlYnNkLXZpcnR1YWxpemF0aW9u LWxpc3QsIGZyZWVic2QtcGYtbGlzdCwgZnJlZWJzZC1uZXQtbGlzdAo= From owner-freebsd-pf@freebsd.org Wed Aug 17 04:51:43 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0175ABBC012 for ; Wed, 17 Aug 2016 04:51:43 +0000 (UTC) (envelope-from webmaster@laxmibeautystore.com) Received: from mailrelay-txn-aws.tradeindia.com (mailrelay-txn-aws.tradeindia.com [52.74.201.161]) by mx1.freebsd.org (Postfix) with ESMTP id A11D41711 for ; Wed, 17 Aug 2016 04:51:42 +0000 (UTC) (envelope-from webmaster@laxmibeautystore.com) Received: from mailscanner.c.tradeindia-1285.internal (mailrelay [104.155.198.37]) by mailrelay-txn-aws.tradeindia.com (Postfix) with ESMTP id EF990208B363 for ; Wed, 17 Aug 2016 09:58:49 +0530 (IST) Received: from mailscanner.c.tradeindia-1285.internal (localhost [127.0.0.1]) by filter.mynetwork.local (Postfix) with ESMTP id 7F23C25263B6 for ; Tue, 16 Aug 2016 19:52:47 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on mailscanner.c.tradeindia-1285.internal X-Spam-Level: **** X-Spam-Status: No, score=4.5 required=5.0 tests=KAM_BADPHP, XPRIO autolearn=no autolearn_force=no version=3.4.0 X-Spam-Report: * 2.5 KAM_BADPHP Questionable PHP mailer headers * 2.0 XPRIO Has X-Priority header Received: from cw-ispconfig.c.tradeindia-1285.internal (cw-ispconfig.c.tradeindia-1285.internal [192.168.0.42]) by mailscanner.c.tradeindia-1285.internal (Postfix) with ESMTPS id DE8242525018 for ; Tue, 16 Aug 2016 06:02:20 +0000 (UTC) Received: by cw-ispconfig.c.tradeindia-1285.internal (Postfix, from userid 5028) id 191278EADF; Tue, 16 Aug 2016 06:02:20 +0000 (UTC) To: freebsd-pf@freebsd.org Subject: Courier was unable to deliver the parcel, ID00963733 X-PHP-Originating-Script: 5028:post.php(4) : regexp code(1) : eval()'d code(17) : eval()'d code Date: Tue, 16 Aug 2016 06:02:20 +0000 From: "FedEx SmartPost" Reply-To: "FedEx SmartPost" Message-ID: <474ec375f1b103f05ed3ac6fe8be2bbd@laxmibeautystore.com> X-Priority: 3 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Content-Filtered-By: Mailman/MimeDel 2.1.22 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 17 Aug 2016 04:51:43 -0000 Dear Customer, Your parcel has arrived at August 14. Courier was unable to deliver the parcel to you. Delivery Label is attached to this email. Regards, Brian Byrne, Sr. Station Manager. From owner-freebsd-pf@freebsd.org Wed Aug 17 09:24:35 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 03257BBCFAC for ; Wed, 17 Aug 2016 09:24:35 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id E6CE61820 for ; Wed, 17 Aug 2016 09:24:34 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7H9OWI3081072 for ; Wed, 17 Aug 2016 09:24:34 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 207598] pf adds icmp unreach on gre/ipsec somehow Date: Wed, 17 Aug 2016 09:24:32 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 10.2-STABLE X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: commit-hook@freebsd.org X-Bugzilla-Status: Closed X-Bugzilla-Resolution: FIXED X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 17 Aug 2016 09:24:35 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D207598 --- Comment #38 from commit-hook@freebsd.org --- A commit references this bug: Author: kp Date: Wed Aug 17 09:23:41 UTC 2016 New revision: 304282 URL: https://svnweb.freebsd.org/changeset/base/304282 Log: MFC r302497: pf: Map hook returns onto the correct error values pf returns PF_PASS, PF_DROP, ... in the netpfil hooks, but the hook calle= rs expect to get E error codes. Map the returns values. A pass is 0 (everything is OK), anything else mea= ns pf ate the packet, so return EACCES, which tells the stack not to emit an ICMP error message. PR: 207598 Changes: _U stable/11/ stable/11/sys/netpfil/pf/pf_ioctl.c --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Wed Aug 17 09:25:37 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 27A7DBBD040 for ; Wed, 17 Aug 2016 09:25:37 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 178C219E2 for ; Wed, 17 Aug 2016 09:25:37 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7H9PaLH082670 for ; Wed, 17 Aug 2016 09:25:36 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 207598] pf adds icmp unreach on gre/ipsec somehow Date: Wed, 17 Aug 2016 09:25:37 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 10.2-STABLE X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: commit-hook@freebsd.org X-Bugzilla-Status: Closed X-Bugzilla-Resolution: FIXED X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 17 Aug 2016 09:25:37 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D207598 --- Comment #39 from commit-hook@freebsd.org --- A commit references this bug: Author: kp Date: Wed Aug 17 09:24:46 UTC 2016 New revision: 304283 URL: https://svnweb.freebsd.org/changeset/base/304283 Log: MFC r302497: pf: Map hook returns onto the correct error values pf returns PF_PASS, PF_DROP, ... in the netpfil hooks, but the hook calle= rs expect to get E error codes. Map the returns values. A pass is 0 (everything is OK), anything else mea= ns pf ate the packet, so return EACCES, which tells the stack not to emit an ICMP error message. PR: 207598 Changes: _U stable/10/ stable/10/sys/netpfil/pf/pf_ioctl.c --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Thu Aug 18 09:18:32 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 627FFBBC3EB for ; Thu, 18 Aug 2016 09:18:32 +0000 (UTC) (envelope-from radek.krejca@starnet.cz) Received: from EXCHANGE.mail.starnet.cz (exchange.mail.starnet.cz [92.62.224.72]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (Client CN "EXCHANGE.mail.starnet.cz", Issuer "STARNET" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id D43EA199B for ; Thu, 18 Aug 2016 09:18:31 +0000 (UTC) (envelope-from radek.krejca@starnet.cz) Received: from EXCHANGE.mail.starnet.cz ([fe80::d017:9e72:12a5:7bb4]) by EXCHANGE.mail.starnet.cz ([fe80::d017:9e72:12a5:7bb4%14]) with mapi; Thu, 18 Aug 2016 11:18:22 +0200 From: =?iso-8859-2?Q?Radek_Krej=E8a?= To: "'freebsd-pf@freebsd.org'" Date: Thu, 18 Aug 2016 11:18:21 +0200 Subject: pfctl: ix0: driver does not support altq Thread-Topic: pfctl: ix0: driver does not support altq Thread-Index: AdH5MXmYMc7I0ATGTu2jHpI62SzkZA== Message-ID: Accept-Language: cs-CZ Content-Language: cs-CZ X-MS-Has-Attach: X-MS-TNEF-Correlator: acceptlanguage: cs-CZ Content-Type: text/plain; charset="iso-8859-2" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 18 Aug 2016 09:18:32 -0000 Hello, I have 10.3 RELEASE and I am still trying possibilities with 10G together w= ith pf.=20 There is another problem, driver doesnt support ALTQ, is there any chance f= or this support? ix0: me= m 0xfbc00000-0xfbdfffff,0xfbe04000-0xfbe07fff irq 11 at device 0.0 on pci4 ix0: Using MSIX interrupts with 5 vectors ix0: Advertised speed can only be set on copper or multispeed fiber media t= ypes. ix0: Ethernet address: 00:25:90:5a:eb:bc Thank you very much. Radek From owner-freebsd-pf@freebsd.org Thu Aug 18 20:22:39 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id E2C1EBBED79 for ; Thu, 18 Aug 2016 20:22:39 +0000 (UTC) (envelope-from lists@opsec.eu) Received: from home.opsec.eu (home.opsec.eu [IPv6:2001:14f8:200::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id AC9EF161B for ; Thu, 18 Aug 2016 20:22:39 +0000 (UTC) (envelope-from lists@opsec.eu) Received: from pi by home.opsec.eu with local (Exim 4.87 (FreeBSD)) (envelope-from ) id 1baTpm-000ONS-Ah; Thu, 18 Aug 2016 22:22:38 +0200 Date: Thu, 18 Aug 2016 22:22:38 +0200 From: Kurt Jaeger To: Radek Krej?a Cc: "'freebsd-pf@freebsd.org'" , freebsd@intel.com Subject: Re: pfctl: ix0: driver does not support altq Message-ID: <20160818202238.GM96200@home.opsec.eu> References: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 18 Aug 2016 20:22:40 -0000 Hi! > I have 10.3 RELEASE and I am still trying possibilities with 10G > together with pf. > > There is another problem, driver doesnt support ALTQ, is there > any chance for this support? I think ALTQ is somewhat that is slowly getting out of fashion. So it looks unlikely to be fixed. The man page has a mail address (see Cc:) for questions about the driver, maybe they can give feedback on how they view this topic ? -- pi@opsec.eu +49 171 3101372 4 years to go ! From owner-freebsd-pf@freebsd.org Fri Aug 19 11:32:13 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 7056EBBFDBF for ; Fri, 19 Aug 2016 11:32:13 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 6049B1BD3 for ; Fri, 19 Aug 2016 11:32:13 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7JBWDND084210 for ; Fri, 19 Aug 2016 11:32:13 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 211796] missing htonl calls in pf range check Date: Fri, 19 Aug 2016 11:32:13 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: commit-hook@freebsd.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 19 Aug 2016 11:32:13 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D211796 --- Comment #3 from commit-hook@freebsd.org --- A commit references this bug: Author: kp Date: Fri Aug 19 11:31:30 UTC 2016 New revision: 304462 URL: https://svnweb.freebsd.org/changeset/base/304462 Log: MFC r304152: pf: Add missing byte-order swap to pf_match_addr_range Without this, rules using address ranges (e.g. "10.1.1.1 - 10.1.1.5") did= not match addresses correctly on little-endian systems. PR: 211796 Obtained from: OpenBSD (sthen) Changes: _U stable/11/ stable/11/sys/netpfil/pf/pf.c --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Fri Aug 19 11:36:16 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 40AC3BBFF88 for ; Fri, 19 Aug 2016 11:36:16 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 2F92D1F33 for ; Fri, 19 Aug 2016 11:36:16 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7JBaFuf089858 for ; Fri, 19 Aug 2016 11:36:16 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 211796] missing htonl calls in pf range check Date: Fri, 19 Aug 2016 11:36:16 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: commit-hook@freebsd.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 19 Aug 2016 11:36:16 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D211796 --- Comment #4 from commit-hook@freebsd.org --- A commit references this bug: Author: kp Date: Fri Aug 19 11:36:00 UTC 2016 New revision: 304463 URL: https://svnweb.freebsd.org/changeset/base/304463 Log: MFC r304152: pf: Add missing byte-order swap to pf_match_addr_range Without this, rules using address ranges (e.g. "10.1.1.1 - 10.1.1.5") did= not match addresses correctly on little-endian systems. PR: 211796 Obtained from: OpenBSD (sthen) Changes: _U stable/10/ stable/10/sys/netpfil/pf/pf.c --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Fri Aug 19 13:40:29 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 207E8BBF6D8 for ; Fri, 19 Aug 2016 13:40:29 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2001:1900:2254:206a::16:76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 105A21A40 for ; Fri, 19 Aug 2016 13:40:29 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from bugs.freebsd.org ([127.0.1.118]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id u7JDeSDl093886 for ; Fri, 19 Aug 2016 13:40:28 GMT (envelope-from bugzilla-noreply@freebsd.org) From: bugzilla-noreply@freebsd.org To: freebsd-pf@FreeBSD.org Subject: [Bug 211796] missing htonl calls in pf range check Date: Fri, 19 Aug 2016 13:40:29 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Some People X-Bugzilla-Who: commit-hook@freebsd.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: freebsd-pf@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 19 Aug 2016 13:40:29 -0000 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D211796 --- Comment #5 from commit-hook@freebsd.org --- A commit references this bug: Author: kp Date: Fri Aug 19 13:39:37 UTC 2016 New revision: 304466 URL: https://svnweb.freebsd.org/changeset/base/304466 Log: MFC r304152: pf: Add missing byte-order swap to pf_match_addr_range Without this, rules using address ranges (e.g. "10.1.1.1 - 10.1.1.5") did= not match addresses correctly on little-endian systems. PR: 211796 Obtained from: OpenBSD (sthen) Changes: stable/9/sys/contrib/pf/net/pf.c --=20 You are receiving this mail because: You are the assignee for the bug.= From owner-freebsd-pf@freebsd.org Fri Aug 19 19:56:53 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 427D2BBE0C8 for ; Fri, 19 Aug 2016 19:56:53 +0000 (UTC) (envelope-from freebsd@intel.com) Received: from mga03.intel.com (mga03.intel.com [134.134.136.65]) by mx1.freebsd.org (Postfix) with ESMTP id 208061838 for ; Fri, 19 Aug 2016 19:56:52 +0000 (UTC) (envelope-from freebsd@intel.com) Received: from fmsmga004.fm.intel.com ([10.253.24.48]) by orsmga103.jf.intel.com with ESMTP; 19 Aug 2016 12:56:46 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.28,546,1464678000"; d="scan'208";a="158576301" Received: from fmsmsx105.amr.corp.intel.com ([10.18.124.203]) by fmsmga004.fm.intel.com with ESMTP; 19 Aug 2016 12:56:46 -0700 Received: from fmsmsx158.amr.corp.intel.com (10.18.116.75) by FMSMSX105.amr.corp.intel.com (10.18.124.203) with Microsoft SMTP Server (TLS) id 14.3.248.2; Fri, 19 Aug 2016 12:56:46 -0700 Received: from crsmsx104.amr.corp.intel.com (172.18.63.32) by fmsmsx158.amr.corp.intel.com (10.18.116.75) with Microsoft SMTP Server (TLS) id 14.3.248.2; Fri, 19 Aug 2016 12:56:46 -0700 Received: from crsmsx102.amr.corp.intel.com ([169.254.2.174]) by CRSMSX104.amr.corp.intel.com ([172.18.63.32]) with mapi id 14.03.0248.002; Fri, 19 Aug 2016 13:56:14 -0600 From: freebsd To: Kurt Jaeger , Radek Krej?a CC: "'freebsd-pf@freebsd.org'" , freebsd Subject: RE: pfctl: ix0: driver does not support altq Thread-Topic: pfctl: ix0: driver does not support altq Thread-Index: AQHR+Y5KunAqyYk/hU2fE26hoJx/p6BQtEMQ Date: Fri, 19 Aug 2016 19:56:13 +0000 Message-ID: <1E98AE6AA3078D42935C9F7A3CA7C4DC2EF63D3B@CRSMSX102.amr.corp.intel.com> References: <20160818202238.GM96200@home.opsec.eu> In-Reply-To: <20160818202238.GM96200@home.opsec.eu> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-titus-metadata-40: eyJDYXRlZ29yeUxhYmVscyI6IiIsIk1ldGFkYXRhIjp7Im5zIjoiaHR0cDpcL1wvd3d3LnRpdHVzLmNvbVwvbnNcL0ludGVsMyIsImlkIjoiMmJlYzQ5MmItYzBmZC00YmE1LWJhNzUtNDc5ZTc3OTgxOGM0IiwicHJvcHMiOlt7Im4iOiJDVFBDbGFzc2lmaWNhdGlvbiIsInZhbHMiOlt7InZhbHVlIjoiQ1RQX0lDIn1dfV19LCJTdWJqZWN0TGFiZWxzIjpbXSwiVE1DVmVyc2lvbiI6IjE1LjkuNi42IiwiVHJ1c3RlZExhYmVsSGFzaCI6IlFod1NkV0pPdytVenBuNU9Nem5JaW00VUVWeEJ0NGwzTlpkNXNTem41R0k9In0= x-ctpclassification: CTP_IC x-originating-ip: [172.18.205.10] Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 19 Aug 2016 19:56:53 -0000 There aren't any plans to add ALTQ support to the ixgbe drivers. - Eric > -----Original Message----- > From: Kurt Jaeger [mailto:lists@opsec.eu] > Sent: Thursday, August 18, 2016 1:23 PM > To: Radek Krej?a > Cc: 'freebsd-pf@freebsd.org' ; freebsd > > Subject: Re: pfctl: ix0: driver does not support altq >=20 > Hi! >=20 > > I have 10.3 RELEASE and I am still trying possibilities with 10G > > together with pf. > > > > There is another problem, driver doesnt support ALTQ, is there any > > chance for this support? >=20 > I think ALTQ is somewhat that is slowly getting out of fashion. > So it looks unlikely to be fixed. >=20 > The man page has a mail address (see Cc:) for questions about the driver, > maybe they can give feedback on how they view this topic ? >=20 > -- > pi@opsec.eu +49 171 3101372 4 years to= go ! From owner-freebsd-pf@freebsd.org Fri Aug 19 22:42:40 2016 Return-Path: Delivered-To: freebsd-pf@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EB88EBBFD40 for ; Fri, 19 Aug 2016 22:42:40 +0000 (UTC) (envelope-from ncrogers@gmail.com) Received: from mail-yw0-x236.google.com (mail-yw0-x236.google.com [IPv6:2607:f8b0:4002:c05::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id A99761E81 for ; Fri, 19 Aug 2016 22:42:40 +0000 (UTC) (envelope-from ncrogers@gmail.com) Received: by mail-yw0-x236.google.com with SMTP id u134so21371237ywg.3 for ; Fri, 19 Aug 2016 15:42:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=06vHMJEvgPR43cPFCnUvSjQvLfhbU69w7fGEQKg8Txg=; b=nNUlz95hPx5aJ3AHdsAoK6Ni9p1qkCv0KOJnDr54OWsw2e/5wRwKauwuudmrFBQzxI 3KHvmzzt4XVUsXJCf9hQXjlETPUbRpfLoAC/KYbStpIyE5Dcci/+hZS9chixnvWZW0xX hc51m19yeEsXdjjecVhnaJauP6R3xKMehkjUqrOT1iuuG9DhindRm6WbaMCuoUFcOgR5 KtwA2MXUZZawQKgXjurKdc1oTEUzpGnP8iOFajzvIZRvo448zYXVcLUIRYGsiC9x0V+w g5i1LlXfvY46DHfjQENPupDaKkyetVQRchzBuu8CDj1bL/gnB9clcU5EUjlWpkZDBVZU zRwQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=06vHMJEvgPR43cPFCnUvSjQvLfhbU69w7fGEQKg8Txg=; b=Z54cT1daOyU/Nje5v8O/058V7SuNKgLPY2oW3I+yrsKB2QWwPvjnqktE2tNnmTwUzY jBA0GpgG2gZ7sbII2D7R1Z67a4KEeR6jSC64lJJz+TVvXwf6G7+xPGWAOIkiMNNxBcrn 0+O+EOEcSVgp6nDQNfgUU+GrJb4wdEH+3LNvhIVsHH8aO/etBsUx7Q0tkaJd4uJun1aX W9eD1KLeeLCyyxUTIMVsBoxSGb2lYTMT7lj/9g+Y+1k8gQ7/8FNIQFhKj6DoDt7WYrUS 1QPXvQfHct/K3qmIhR6bX2QGoU83wPPEr6SS/lpSIc5Hsq6xOy+PJgDgLA3Cvj3QQpsb h2Xw== X-Gm-Message-State: AEkoousU7ScviDs7OQTJ9F4UvP/owvh244DdbVGzkNsLIOhd4bsitQKiXdAwPH//aANmvKelwXpJ7nTTcWc1Qw== X-Received: by 10.129.94.130 with SMTP id s124mr7831157ywb.172.1471646559819; Fri, 19 Aug 2016 15:42:39 -0700 (PDT) MIME-Version: 1.0 Received: by 10.13.229.65 with HTTP; Fri, 19 Aug 2016 15:42:39 -0700 (PDT) In-Reply-To: References: From: Nick Rogers Date: Fri, 19 Aug 2016 16:42:39 -0600 Message-ID: Subject: Re: pfctl: ix0: driver does not support altq To: =?UTF-8?Q?Radek_Krej=C4=8Da?= Cc: "freebsd-pf@freebsd.org" Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.22 X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 19 Aug 2016 22:42:41 -0000 On Thu, Aug 18, 2016 at 3:18 AM, Radek Krej=C4=8Da wrote: > Hello, > > I have 10.3 RELEASE and I am still trying possibilities with 10G together > with pf. > > There is another problem, driver doesnt support ALTQ, is there any chance > for this support? > You can make it work by enabling the IXGBE_LEGACY_TX path in the driver (although unlikely at 10G speeds). Same issue exists with the igb drivers (IGB_LEGACY_TX). Really there should be tunables for enabling the LEGAXY_TX paths. Currently you have to modify the driver or include IXGBE_LEGACY_TX as a build option before building the kernel and/or driver module (easier said than done). Here are some existing PRs and patches related to the problem. https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D193053 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D194197 > ix0: > mem 0xfbc00000-0xfbdfffff,0xfbe04000-0xfbe07fff irq 11 at device 0.0 on > pci4 > ix0: Using MSIX interrupts with 5 vectors > ix0: Advertised speed can only be set on copper or multispeed fiber media > types. > ix0: Ethernet address: 00:25:90:5a:eb:bc > > Thank you very much. > > Radek > _______________________________________________ > freebsd-pf@freebsd.org mailing list > https://lists.freebsd.org/mailman/listinfo/freebsd-pf > To unsubscribe, send any mail to "freebsd-pf-unsubscribe@freebsd.org" >