From owner-freebsd-bugs@FreeBSD.ORG Fri Dec 28 13:20:01 2007 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id DDC4F16A478 for ; Fri, 28 Dec 2007 13:20:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id AE28913C4DD for ; Fri, 28 Dec 2007 13:20:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.2/8.14.2) with ESMTP id lBSDK1wL032769 for ; Fri, 28 Dec 2007 13:20:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.2/8.14.1/Submit) id lBSDK1v8032768; Fri, 28 Dec 2007 13:20:01 GMT (envelope-from gnats) Resent-Date: Fri, 28 Dec 2007 13:20:01 GMT Resent-Message-Id: <200712281320.lBSDK1v8032768@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Beat Gätzi Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id F33D016A421 for ; Fri, 28 Dec 2007 13:12:14 +0000 (UTC) (envelope-from beat@chruetertee.ch) Received: from marvin.chruetertee.ch (marvin.chruetertee.ch [217.150.245.55]) by mx1.freebsd.org (Postfix) with ESMTP id 826D913C4DD for ; Fri, 28 Dec 2007 13:12:14 +0000 (UTC) (envelope-from beat@chruetertee.ch) Received: from _HOSTNAME_ (BAEe074.bae.pppool.de [77.132.224.116]) (authenticated bits=0) by marvin.chruetertee.ch (8.13.6/8.13.6) with ESMTP id lBSCY4Fw015101 (version=TLSv1/SSLv3 cipher=DHE-DSS-AES256-SHA bits=256 verify=NO) for ; Fri, 28 Dec 2007 12:34:05 GMT (envelope-from beat@chruetertee.ch) Received: by _HOSTNAME_ (sSMTP sendmail emulation); Fri, 28 Dec 2007 13:34:13 +0100 Message-Id: <200712281234.lBSCY4Fw015101@marvin.chruetertee.ch> Date: Fri, 28 Dec 2007 13:34:13 +0100 From: "Beat Gaetzi" To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: Subject: conf/119098: [PATCH] Remove rc.conf reference to TCP_DROP_SYNFIN kernel option X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Beat Gätzi List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 28 Dec 2007 13:20:02 -0000 >Number: 119098 >Category: conf >Synopsis: [PATCH] Remove rc.conf reference to TCP_DROP_SYNFIN kernel option >Confidential: no >Severity: non-critical >Priority: low >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: update >Submitter-Id: current-users >Arrival-Date: Fri Dec 28 13:20:01 UTC 2007 >Closed-Date: >Last-Modified: >Originator: Beat Gätzi >Release: FreeBSD 8.0-CURRENT i386 >Organization: >Environment: System: FreeBSD daedalus.network.local 8.0-CURRENT FreeBSD 8.0-CURRENT #0: Mon Dec 3 13:00:30 CET 2007 root@daedalus.network.local:/usr/obj/usr/src/sys/GENERIC i386 >Description: The TCP_DROP_SYNFIN kernel option is now included in the kernel by default. Remove reference to this option from defaults/rc.conf and rc.conf(5). >How-To-Repeat: >Fix: --- synfin.patch begins here --- diff -Naur src.ori/etc/defaults/rc.conf src/etc/defaults/rc.conf --- src.ori/etc/defaults/rc.conf 2007-10-23 20:36:44.000000000 +0200 +++ src/etc/defaults/rc.conf 2007-12-28 13:12:00.000000000 +0100 @@ -163,8 +163,6 @@ tcp_extensions="YES" # Set to NO to turn off RFC1323 extensions. log_in_vain="0" # >=1 to log connects to ports w/o listeners. tcp_keepalive="YES" # Enable stale TCP connection timeout (or NO). -# For the following option you need to have TCP_DROP_SYNFIN set in your -# kernel. Please refer to LINT and NOTES for details. tcp_drop_synfin="NO" # Set to YES to drop TCP packets with SYN+FIN # NOTE: this violates the TCP specification icmp_drop_redirect="NO" # Set to YES to ignore ICMP REDIRECT packets diff -Naur src.ori/share/man/man5/rc.conf.5 src/share/man/man5/rc.conf.5 --- src.ori/share/man/man5/rc.conf.5 2007-11-04 18:08:19.000000000 +0100 +++ src/share/man/man5/rc.conf.5 2007-12-28 13:12:48.000000000 +0100 @@ -952,10 +952,6 @@ the SYN and FIN flags set. This prevents OS fingerprinting, but may break some legitimate applications. -This option is only available if the -kernel was built with the -.Dv TCP_DROP_SYNFIN -option. .It Va icmp_drop_redirect .Pq Vt bool Set to --- synfin.patch ends here --- >Release-Note: >Audit-Trail: >Unformatted: