Robert Mustacchi via illumos-developer
2014-10-01 21:08:07 UTC
The following is a set of thee bugs/RFEs that we've made to IPF over
time at Joyent. This covers 5197-5200. These are three separate changes:
1) 5200 - Simple bug fix by Jerry Jelinek
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/5200/index.html
2) 5199 - Another simple bug fix by Rob Gulewich
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/5199/index.html
3) 5197/5198 - This is a rather large improvement to IPF by Rob
Gulewich. It allows the global zone to administer the ipf rule sets in
the non-global zones and additionally gives the global zone a logically
separate rule set that it can put in place for the zone/netstack. The
zone/netstack cannot itself observe this rule set which means that a
super user in the zone cannot disable it, but can still put their own
restrictions in place. For example, imagine a global zone policy where
by all netstacks had blocked port 25 access, but then the NGZ can
establish whatever it needs for its services.
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/5198/index.html
And finally a webrev with everything together:
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/all/index.html
Thanks,
Robert
-------------------------------------------
illumos-developer
Archives: https://www.listbox.com/member/archive/182179/=now
RSS Feed: https://www.listbox.com/member/archive/rss/182179/21175072-86d49504
Modify Your Subscription: https://www.listbox.com/member/?member_id=21175072&id_secret=21175072-abdf7b7e
Powered by Listbox: http://www.listbox.com
time at Joyent. This covers 5197-5200. These are three separate changes:
1) 5200 - Simple bug fix by Jerry Jelinek
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/5200/index.html
2) 5199 - Another simple bug fix by Rob Gulewich
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/5199/index.html
3) 5197/5198 - This is a rather large improvement to IPF by Rob
Gulewich. It allows the global zone to administer the ipf rule sets in
the non-global zones and additionally gives the global zone a logically
separate rule set that it can put in place for the zone/netstack. The
zone/netstack cannot itself observe this rule set which means that a
super user in the zone cannot disable it, but can still put their own
restrictions in place. For example, imagine a global zone policy where
by all netstacks had blocked port 25 access, but then the NGZ can
establish whatever it needs for its services.
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/5198/index.html
And finally a webrev with everything together:
https://us-east.manta.joyent.com/rmustacc/public/webrevs/ipf/all/index.html
Thanks,
Robert
-------------------------------------------
illumos-developer
Archives: https://www.listbox.com/member/archive/182179/=now
RSS Feed: https://www.listbox.com/member/archive/rss/182179/21175072-86d49504
Modify Your Subscription: https://www.listbox.com/member/?member_id=21175072&id_secret=21175072-abdf7b7e
Powered by Listbox: http://www.listbox.com