From owner-freebsd-net@FreeBSD.ORG Thu Oct 16 17:49:03 2014 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 3C7B6E0D for ; Thu, 16 Oct 2014 17:49:03 +0000 (UTC) Received: from frv199.fwdcdn.com (frv199.fwdcdn.com [212.42.77.199]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id EDE1D760 for ; Thu, 16 Oct 2014 17:49:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ukr.net; s=ffe; h=Content-Transfer-Encoding:Content-Type:MIME-Version:References:In-Reply-To:Message-Id:Cc:To:Subject:From:Date; bh=poffVHFriwbO4eGAJ4/WSif1xv21ZW8AU7KbES3HJ64=; b=pvUl91nvZVCB4XTf3D9iCf0TF4hcE9m+bav7dTW5+lI4L+0Yyf3Z3CR4yqdvHBcoxpnFY7SC6cv3ILABlODXo2b1vxXMTFbtq3IEtcqqzm385f3U7hdq98vnFZfT9PMU5TDF+BB4vW9kWWgZYIv76bz6Va9jke34pJxMvu1UchE=; Received: from [10.10.10.34] (helo=frv34.fwdcdn.com) by frv199.fwdcdn.com with smtp ID 1XepAN-000Exx-Vw for freebsd-net@freebsd.org; Thu, 16 Oct 2014 20:48:47 +0300 Date: Thu, 16 Oct 2014 20:48:47 +0300 From: wishmaster Subject: Re[2]: Enabling VIMAGE by default for FreeBSD 11? To: Dag-Erling =?iso-8859-1?q?Sm=F8rgrav?= X-Mailer: mail.ukr.net 5.0 Message-Id: <1413481493.455723594.213mta8m@frv34.fwdcdn.com> In-Reply-To: <8638anzzgg.fsf@nine.des.no> References: <20141012182551.002b3cc0a45a56d3f34e6174@yamagi.org> <3B4471A7-CDF4-440D-BDD8-3D5B2256B8DD@lists.zabbadoz.net> <7EAA2A23-06F9-44C9-A3E1-62AA37EE5CDA@lists.zabbadoz.net> <86d29so0r1.fsf@nine.des.no> <8638anzzgg.fsf@nine.des.no> MIME-Version: 1.0 Received: from artemrts@ukr.net by frv34.fwdcdn.com; Thu, 16 Oct 2014 20:48:47 +0300 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: binary Content-Disposition: inline Cc: "Bjoern A. Zeeb" , freebsd-arch , freebsd-virtualization@freebsd.org, freebsd-net@freebsd.org X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.18-1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Oct 2014 17:49:03 -0000 --- Original message --- From: "Dag-Erling Smørgrav" Date: 16 October 2014, 20:39:22 > "Bjoern A. Zeeb" writes: > > Dag-Erling Smørgrav writes: > > > There are other serious issues with our current pf (checksum > > > corruption) which I think can only be resolved by importing a newer > > > version. > > Sorry, but you lost context. I was talking about security > > implications in VIMAGE context, not about random bugs. > > I realize that, but you're talking about patching our current pf, and I > think that's a waste of time; we should import a newer version instead > (which I assume already has those patches). > Forget about importing new version of PF from OS, which doesn't has virtualized inet stack. Cheers, w