Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 20 Aug 2004 12:39:15 +0200
From:      Andre Oppermann <andre@freebsd.org>
To:        Maxim Sobolev <sobomax@portaone.com>
Cc:        cvs-all@FreeBSD.ORG
Subject:   Re: cvs commit: src/sys/netinet ip_fw_pfil.c
Message-ID:  <4125D4D3.A4C01DDD@freebsd.org>
References:  <200408191838.i7JIcNI9044040@repoman.freebsd.org> <41258B26.4060507@portaone.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Maxim Sobolev wrote:
> 
> Andre Oppermann wrote:
> > andre       2004-08-19 18:38:23 UTC
> >
> >   FreeBSD src repository
> >
> >   Modified files:
> >     sys/netinet          ip_fw_pfil.c
> >   Log:
> >   Give a useful error message if someone tries to compile IPFIREWALL into the
> >   kernel without specifying PFIL_HOOKS as well.
> 
> Can we just have PFIL_HOOKS enabled automagically when somebody tries to
> compile any sort of supported firewall (e.g. ipfw, pf or ipfilter) into
> kernel?

I have a patch ready to reduce the cost of unhooked pfil_hooks.  Then we
can simply remove the PFIL_HOOKS option and have it in permanently.

-- 
Andre



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4125D4D3.A4C01DDD>