16455 want TCP_MD5SIG socket optionReviewed by: Robert Mustacchi <rm+illumos@fingolfin.org>Reviewed by: Dan McDonald <danmcd@mnx.io>Approved by: Gordon Ross <gordon.w.ross@gmail.com>
15280 uts: remove pragma identReviewed by: Igor Kozhukhov <igor@dilos.org>Reviewed by: Yuri Pankov <yuri@aetern.org>Reviewed by: Marcel Telka <marcel@telka.sk>Approved by: Robert Mustacchi <rm@fi
15280 uts: remove pragma identReviewed by: Igor Kozhukhov <igor@dilos.org>Reviewed by: Yuri Pankov <yuri@aetern.org>Reviewed by: Marcel Telka <marcel@telka.sk>Approved by: Robert Mustacchi <rm@fingolfin.org>
show more ...
14443 resection manual pages per IPD4Reviewed by: Toomas Soome <tsoome@me.com>Reviewed by: Robert Mustacchi <rm@fingolfin.org>Reviewed by: Peter Tribble <peter.tribble@gmail.com>Reviewed by: Andy
14443 resection manual pages per IPD4Reviewed by: Toomas Soome <tsoome@me.com>Reviewed by: Robert Mustacchi <rm@fingolfin.org>Reviewed by: Peter Tribble <peter.tribble@gmail.com>Reviewed by: Andy Fiddaman <andy@omnios.org>Approved by: Dan McDonald <danmcd@joyent.com>
8988 SADB_ACQUIRE proposals don't include mechanism salt lengthReviewed by: Dan McDonald <danmcd@joyent.com>Reviewed by: Tim Kordas <tim.kordas@joyent.com>Reviewed by: Richard Lowe <richlowe@richl
8988 SADB_ACQUIRE proposals don't include mechanism salt lengthReviewed by: Dan McDonald <danmcd@joyent.com>Reviewed by: Tim Kordas <tim.kordas@joyent.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Gordon Ross <gordon.ross@nexenta.com>
8989 Allow IKEV2 pf_key(7P) key management cookies to be updated after setReviewed by: Dan McDonald <danmcd@joyent.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Gordon Ross <go
8989 Allow IKEV2 pf_key(7P) key management cookies to be updated after setReviewed by: Dan McDonald <danmcd@joyent.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Gordon Ross <gordon.ross@nexenta.com>
8927 sadb_x_kmc_t's KM cookie should be 64-bitsReviewed by: Jason King <jason.king@joyent.com>Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Yuri Pankov <yuripv@gmx.com>Approved by: Ri
8927 sadb_x_kmc_t's KM cookie should be 64-bitsReviewed by: Jason King <jason.king@joyent.com>Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Yuri Pankov <yuripv@gmx.com>Approved by: Richard Lowe <richlowe@richlowe.net>
7615 libbe: cleanup compile warningsReviewed by: Yuri Pankov <yuri.pankov@gmail.com>Reviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: Robert Mustacchi <rm@joyent.com>Approved by: Richard
7615 libbe: cleanup compile warningsReviewed by: Yuri Pankov <yuri.pankov@gmail.com>Reviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: Robert Mustacchi <rm@joyent.com>Approved by: Richard Lowe <richlowe@richlowe.net>
6324 Add an `ndp' tool for manipulating the neighbors tableReviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Alex Wilson <alex.wilson@joyent.com>Reviewed by: Dan McDonald <danmcd@omniti.co
6324 Add an `ndp' tool for manipulating the neighbors tableReviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Alex Wilson <alex.wilson@joyent.com>Reviewed by: Dan McDonald <danmcd@omniti.com>Approved by: Richard Lowe <richlowe@richlowe.net>
PSARC/2010/159 SIOCGIFHWADDR for PF_INET and PF_INET66948284 setsockopt on PF_PACKET socket fails for PACKET_MR_PROMISC option6948282 missing definitions in the packet.h header file4720634 program
PSARC/2010/159 SIOCGIFHWADDR for PF_INET and PF_INET66948284 setsockopt on PF_PACKET socket fails for PACKET_MR_PROMISC option6948282 missing definitions in the packet.h header file4720634 programmatic access to mac address for non-root applications
6965774 bound the interface index in IP to [1,65535]
PSARC 2010/166 layer-3 net properties for exclusive-IP zones6944327 need to support address and defrouter resources for exclusive-IP zones
6524578 <netinet/arp.h> and <net/if_arp.h> are too much of a good thing6931308 Documented method for setting HOST route for IPMP target selection does not work6937848 ipv6addrsel fails because the
6524578 <netinet/arp.h> and <net/if_arp.h> are too much of a good thing6931308 Documented method for setting HOST route for IPMP target selection does not work6937848 ipv6addrsel fails because the statically added NCE can get deleted.6937898 ARP/ND need to filter out Martian addresses correctly.
PSARC 2009/306 Brussels II - ipadm and libipadmPSARC 2010/080 Brussels II addendum6827318 Brussels Phase II aka ipadm(1m)6731945 need BSD getifaddrs() API6909065 explicitly disallow non-contiguou
PSARC 2009/306 Brussels II - ipadm and libipadmPSARC 2010/080 Brussels II addendum6827318 Brussels Phase II aka ipadm(1m)6731945 need BSD getifaddrs() API6909065 explicitly disallow non-contiguous netmasks in the next minor release6853922 ifconfig dumps core when ether address is non-hexadecimal.6815806 ipReasmTimeout value should be variable6567083 nd_getset has some dead and confusing code.6884466 remove unused tcp/sctp ndd tunables6928813 Comments at odds with default value of tcp_time_wait_interval6236982 ifconfig usesrc lets adapter use itself as source address6936855 modifying the ip6_strict_src_multihoming to non-zero value will unbind V4 IREs
6913056 Panic when running dladm add-bridge while interfaces are busy6887616 VLAN creation using default_tag ID with 'dladm create-vnic' error msg is confusing6889722 TRILL should utilize socket no
6913056 Panic when running dladm add-bridge while interfaces are busy6887616 VLAN creation using default_tag ID with 'dladm create-vnic' error msg is confusing6889722 TRILL should utilize socket notsupp stub downcalls in sockfs/sock_notsupp.c
6900905 bridging mac_register failure results in bad trap panic6900907 bridging is missing required mac_init_ops call
PSARC/2008/693 VRRPPSARC/2009/388 VRRP Update6288572 RFE: VRRP implementation desired for Solaris
PSARC/2009/331 IP Datapath RefactoringPSARC/2008/522 EOF of 2001/070 IPsec HW Acceleration supportPSARC/2009/495 netstat -r flags for blackhole and reject routesPSARC 2009/496 EOF of XRESOLVPSARC
PSARC/2009/331 IP Datapath RefactoringPSARC/2008/522 EOF of 2001/070 IPsec HW Acceleration supportPSARC/2009/495 netstat -r flags for blackhole and reject routesPSARC 2009/496 EOF of XRESOLVPSARC/2009/494 IP_DONTFRAG socket optionPSARC/2009/515 fragmentation controls for ping and traceroute6798716 ip_newroute delenda est6798739 ARP and IP are too separate6807265 IPv4 ip2mac() support6756382 Please remove Venus IPsec HWACCEL code6880632 sendto/sendmsg never returns EHOSTUNREACH in Solaris6748582 sendmsg() return OK, but doesn't send message using IPv4-mapped x IPv6 addr1119790 TCP and path mtu discovery4637227 should support equal-cost multi-path (ECMP)5078568 getsockopt() for IPV6_PATHMTU on a non-connected socket should not succeed6419648 "AR* contract private note" should be removed as part of ATM SW EOL6274715 Arp could keep the old entry in the cache while it waits for an arp response6605615 Remove duplicated TCP/IP opt_set/opt_get code; use conn_t6874677 IP_TTL can be used to send with ttl zero4034090 arp should not let you delete your own entry6882140 Implement IP_DONTFRAG socket option6883858 Implement ping -D option; traceroute -F should work for IPv6 and shared-IP zones1119792 TCP/IP black hole detection is broken on receiver4078796 Directed broadcast forwarding code has problems4104337 restrict the IPPROTO_IP and IPPROTO_IPV6 options based on the socket family4203747 Source address selection for source routed packets4230259 pmtu is increased every ip_ire_pathmtu_interval timer value.4300533 When sticky option ipv6_pktinfo set to bogus address subsequent connect time out4471035 ire_delete_cache_gw is called through ire_walk unnecessarily4514572 SO_DONTROUTE socket option doesn't work with IPv64524980 tcp_lookup_ipv4() should compare the ifindex against tcpb->tcpb_bound_if4532714 machine fails to switch quickly among failed default routes4634219 IPv6 path mtu discovery is broken when using routing header4691581 udp broadcast handling causes too many replicas4708405 mcast is broken on machines when all interfaces are IFF_POINTOPOINT4770457 netstat/route: source address of interface routes pretends to be gateway address4786974 use routing table to determine routes/interface for multicast4792619 An ip_fanout_udp_ipc_v6() routine might lead to some simpler code4816115 Nuke ipsec_out_use_global_policy4862844 ipsec offload corner case4867533 tcp_rq and tcp_wq are redundant4868589 NCEs should be shared across an IPMP group4872093 unplumbing an improper virtual interface panics in ip_newroute_get_dst_ill()4901671 FireEngine needs some cleanup4907617 IPsec identity latching should be done before sending SYN-ACK4941461 scopeid and IPV6_PKTINFO with UDP/ICMP connect() does not work properly4944981 ip does nothing with IP6I_NEXTHOP4963353 IPv4 and IPv6 proto fanout codes could be brought closer4963360 consider passing zoneid using ip6i_t instead of ipsec_out_t in NDP4963734 new ip6_asp locking is used incorrectly in ip_newroute_v6()5008315 IPv6 code passes ip6i_t to IPsec code instead of ip6_t5009636 memory leak in ip_fanout_proto_v6()5092337 tcp/udp option handling can use some cleanup5035841 Solaris can fail to create a valid broadcast ire5043747 ar_query_xmit: Could not find the ace5051574 tcp_check_policy is missing some checks6305037 full hardware checksum is discarded when there're more than 2 mblks in the chain6311149 ip.c needs to be put through a woodchipper4708860 Unable to reassemble CGTP fragmented multicast packets6224628 Large IPv6 packets with IPsec protection sometimes have length mismatch.6213243 Solaris does not currently support Dead Gateway Detection5029091 duplicate code in IP's input path for TCP/UDP/SCTP4674643 through IPv6 CGTP routes, the very first packet is sent only after a while6207318 Multiple default routes do not round robin connections to routers.4823410 IP has an inconsistent view of link mtu5105520 adding interface route to down interface causes ifconfig hang5105707 advanced sockets API introduced some dead code6318399 IP option handling for icmp and udp is too complicated6321434 Every dropped packet in IP should use ip_drop_packet()6341693 ifconfig mtu should operate on the physical interface, not individual ipif's6352430 The credentials attached to an mblk are not particularly useful6357894 uninitialised ipp_hoplimit needs to be cleaned up.6363568 ip_xmit_v6() may be missing IRE releases in error cases6364828 ip_rput_forward needs a makeover6384416 System panics when running as multicast forwarder using multicast tunnels6402382 TX: UDP v6 slowpath is not modified to handle mac_exempt conns6418413 assertion failed ipha->ipha_ident == 0||ipha->ipha_ident == 0xFFFF6420916 assertion failures in ipv6 wput path6430851 use of b_prev to store ifindex is not 100% safe6446106 IPv6 packets stored in nce->nce_qd_mp will be sent with incorrect tcp/udp checksums6453711 SCTP OOTB sent as if genetated by global zone6465212 ARP/IP merge should remove ire_freemblk.esballoc6490163 ip_input() could misbehave if the first mblk's size is not big enough6496664 missing ipif_refrele leads to reference leak and deferred crash in ip_wput_ipsec_out_v66504856 memory leak in ip_fanout_proto_v6() when using link local outer tunnel addresses6507765 IRE cache hash function performs badly6510186 IP_FORWARD_PROG bit is easily overlooked6514727 cgtp ipv6 failure on snv546528286 MULTIRT (CGTP) should offload checksum to hardware6533904 SCTP: doesn't support traffic class for IPv66539415 TX: ipif source selection is flawed for unlabeled gateways6539851 plumbed unworking nic blocks sending broadcast packets6564468 non-solaris SCTP stack over rawip socket: netstat command counts rawipInData not rawipOutDatagrams6568511 ipIfStatsOutDiscards not bumped when discarding an ipsec packet on the wrong NIC6584162 tcp_g_q_inactive() makes incorrect use of taskq_dispatch()6603974 round-robin default with many interfaces causes infinite temporary IRE thrashing6611750 ilm_lookup_ill_index_v4 was born an orphan6618423 ip_wput_frag_mdt sends out packets that void pfhooks6620964 IRE max bucket count calculations performed in ip_ire_init() are flawed6626266 various _broadcasts seem redundant6638182 IP_PKTINFO + SO_DONTROUTE + CIPSO IP option == panic6647710 IPv6 possible DoS vulnerability6657357 nce should be kmem_cache alloc'ed from an nce_cache.6685131 ilg_add -> conn_ilg_alloc interacting with conn_ilg[] walkers can cause panic.6730298 adding 0.0.0.0 key with mask != 0 causes 'route delete default' to fail6730976 vni and ipv6 doesn't quite work.6740956 assertion failed: mp->b_next == 0L && mp->b_prev == 0L in nce_queue_mp_common()6748515 BUMP_MIB() is occasionally done on the wrong ill6753250 ip_output_v6() `notv6' error path has an errant ill_refrele()6756411 NULL-pointer dereference in ip_wput_local()6769582 IP must forward packet returned from FW-HOOK6781525 bogus usesrc usage leads directly to panic6422839 System paniced in ip_multicast_loopback due to NULL pointer dereference6785521 initial IPv6 DAD solicitation is dropped in ip_newroute_ipif_v6()6787370 ipnet devices not seeing forwarded IP packets on outgoing interface6791187 ip*dbg() calls in ip_output_options() claim to originate from ip_wput()6794047 nce_fp_mp prevents sharing of NCEs across an IPMP group6797926 many unnecessary ip0dbg() in ip_rput_data_v66846919 Packet queued for ND gets sent in the clear.6856591 ping doesn't send packets with DF set6861113 arp module has incorrect dependency path for hook module6865664 IPV6_NEXTHOP does not work with TCP socket6874681 No ICMP time exceeded when a router receives packet with ttl = 06880977 ip_wput_ire() uses over 1k of stack6595433 IPsec performance could be significantly better when calling hw crypto provider synchronously6848397 ifconfig down of an interface can hang.6849602 IPV6_PATHMTU size issue for UDP6885359 Add compile-time option for testing pure IPsec overhead6889268 Odd loopback source address selection with IPMP6895420 assertion failed: connp->conn_helper_info == NULL6851189 Routing-related panic occurred during reboot on T2000 system running snv_1176896174 Post-async-encryption, AH+ESP packets may have misinitialized ipha/ip66896687 iptun presents IPv6 with an MTU < 12806897006 assertion failed: ipif->ipif_id != 0 in ip_sioctl_slifzone_restart
PSARC/2008/252 Labeled IPsec phase 16886771 Labeled IPsec phase 16808727 Alignment error panic in tsol_can_accept_raw()6894979 nightly -0 + -p builds then destroys SUNW0on
PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers6704686 IPsec/ESP needs to support Combined mode ciphers6704682 IPsec/ESP should use AES-CCM6884664 IPsec/ESP should support AES
PSARC 2009/513 Changes to IPsec ESP to support Combined mode ciphers6704686 IPsec/ESP needs to support Combined mode ciphers6704682 IPsec/ESP should use AES-CCM6884664 IPsec/ESP should support AES-GCM Mode6840342 ipsecalgs out of memory error6764184 tab instead of space in sadb.h
PSARC/2009/232 Solaris Packet CapturePSARC/2009/403 kstats for ipnet6824047 every downcall function should have a "notsupported" function6822740 RFE: provide PF_PACKET for developers on OpenSolari
PSARC/2009/232 Solaris Packet CapturePSARC/2009/403 kstats for ipnet6824047 every downcall function should have a "notsupported" function6822740 RFE: provide PF_PACKET for developers on OpenSolaris6822741 RFE: Solaris needs BPF to improve the packet capture story6867683 RFE: need to be able to retrieve physical interface flags
PSARC 2009/373 Clearview IP TunnelingPSARC 2009/410 Datalink Administration from Non-Global Zones6858533 Clearview IP Tunneling4861777 *snoop* cannot snoop on tunnel interfaces5010680 M_IOCTL int
PSARC 2009/373 Clearview IP TunnelingPSARC 2009/410 Datalink Administration from Non-Global Zones6858533 Clearview IP Tunneling4861777 *snoop* cannot snoop on tunnel interfaces5010680 M_IOCTL interface between ip and tun is horribly wrong5029727 tun prints bogus debug messages when receiving multicast packets on 6to4 tunnels6835873 dlpi_walk() silently fails in an exclusive zone4152864 must not allow two tunnels to have the same tsrc/tdst pair6855902 link and flow kstats are too promiscuous6218826 need to be able to tunnel into a zone4505468 network interface names can confuse, lie, and deceive4524756 tun_wproc() takes up too much stack6417373 tun_wproc_mdata assertion failures4627970 scalability problems with IP in IP tunnels4674797 ifparse_ifspec() will not correctly parse ipv6 tunnels6509231 dladm should show links in exclusive stack zone4793233 tun driver should include addr in DL_PHYS_ADDR_ACK for non-zero lengths6795831 ZONE_*_DATALINK syscalls should take datalink_id_t as argument6791472 mac module doesn't allow MAC addresses < 6 bytes6618091 Race condition trips ASSERT() in tun.c's SIOCSLIFNAME path6837580 bogus mi_active check in mac_set_mtu()6868083 libinetutil: ofmt_open()'s template argument should be const6870313 libdladm: needless dladm_init_linkprop() in i_dladm_aggr_up()6872221 panic in dls_devnet_close() if "mtu" property is being set4289774 Change to the interface-id does not change IPv6 link-local address6873561 unable to create links with 31 character link names6874666 changing a link property can accidentally destroy it6874682 removing a link attribute corrupts the attribute list6875167 IPCL_ISV6 conn flag is set but never used6881764 itp reference leak in ipsec_construct_inverse_acquire()6881951 dladm delete-vlan can no longer delete persistent-only VLANs--HG--rename : usr/src/uts/common/inet/tun.h => usr/src/uts/common/inet/iptun.hrename : usr/src/uts/common/inet/ip/tun.c => usr/src/uts/common/inet/iptun/iptun.crename : usr/src/uts/intel/tun/Makefile => usr/src/uts/intel/iptun/Makefilerename : usr/src/uts/sparc/tun/Makefile => usr/src/uts/sparc/iptun/Makefile
6881494 Move SUNWdladmint files to existing packages for SFW TRILL build
PSARC 2007/596 RBridges: Routing BridgesPSARC 2008/055 Solaris BridgingPSARC 2009/344 Bridging Updates6223953 Solaris should provide layer 2 bridging6770623 bogus error messages generated by dlad
PSARC 2007/596 RBridges: Routing BridgesPSARC 2008/055 Solaris BridgingPSARC 2009/344 Bridging Updates6223953 Solaris should provide layer 2 bridging6770623 bogus error messages generated by dladm should be cleaned up
6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there
6848192 get_ipsa_pair() does not always follow bucket lock entry rules, could potentially deadlock.6846548 PF_KEY diagnostics need to be more specific6853208 ipsecalgs(1m) does not cope when there are no algorithms registered.6856693 sadb_update_sa() checks for duplicate SADB_UPDATE messages in the wrong place.6846547 Faulty PF_KEY replies should not cause in.iked to halt
PSARC 2009/200 Solaris Simnet6827930 Simulated network driver
12