5198 Want alternate global zone rule set for each ipf netstack5197 Global zone should be able to manage NGZ ipf stateReviewed by: Jerry Jelinek <jerry.jelinek@joyent.com>Reviewed by: Robert Mustac
5198 Want alternate global zone rule set for each ipf netstack5197 Global zone should be able to manage NGZ ipf stateReviewed by: Jerry Jelinek <jerry.jelinek@joyent.com>Reviewed by: Robert Mustacchi <rm@joyent.com>Reviewed by: Dan McDonald <danmcd@omniti.com>Reviewed by: Darren Reed <darrenr@fastmail.net>Approved by: Richard Lowe <richlowe@richlowe.net>
show more ...
4072 make clobber leaves trashReviewed by: Albert Lee <trisk@nexenta.com>Reviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Marcel Telka <marcel.telka@nexenta.com>Reviewed by: Richard Low
4072 make clobber leaves trashReviewed by: Albert Lee <trisk@nexenta.com>Reviewed by: Dan McDonald <danmcd@nexenta.com>Reviewed by: Marcel Telka <marcel.telka@nexenta.com>Reviewed by: Richard Lowe <richlowe@richlowe.net>Approved by: Garrett D'Amore <garrett@damore.org>
6772643 Packets dropped at ipfil_sendpkt if interface index is set at plumb time6891782 ipftest fails to run6897532 Race condition window arround fr_enable_active is still opened6897632 nic_event_
6772643 Packets dropped at ipfil_sendpkt if interface index is set at plumb time6891782 ipftest fails to run6897532 Race condition window arround fr_enable_active is still opened6897632 nic_event_v* hook should check if IPF is running before it will proceed further
6864230 hiho, hiho, it'ch chtime for CH to goPortions contributed by Rich Lowe
6803232 parsing empty config files results in an error6803834 regression test failure for legacy/i13
5008943 /etc/init.d/ipfboot pause/resume functionality broken5010756 "\" in configuration file does not work correctly6181489 ipfilter sends out confusing messages.6449288 Makefiles in usr/src/cmd
5008943 /etc/init.d/ipfboot pause/resume functionality broken5010756 "\" in configuration file does not work correctly6181489 ipfilter sends out confusing messages.6449288 Makefiles in usr/src/cmd/ipf are missing CDDL6449291 package prototype files in usr/src/pkgdefs/SUNWipfh missing CDDL6508325 stale pfil-related rules in Makefile.rules6661948 ipmon.pid file can be rendered invisible6714319 IPFilter causes failure of IPv6 compliance tests.6766614 fin_state costs more than it is worth6767239 fin_nat causes more trouble than it is worth6788299 Array overrun in ipfilter6789766 ipfs usage output is misleading6792026 ipnat panics in Divide zero exception
6617470 ipftest is reported as false positive by wsdiff
6749429 printing out of fragment information is confused6749445 ipfstat -f does not show ttl but rather expiration tick6783820 IPF preauth crash6730356 legacy test regressions: i2, i4, i11
6677460 ipfilter automatic flushing of state table entries needs to work the same as it does for NAT6566976 state limit check works when limit is reached only6566982 state limit is not check when i
6677460 ipfilter automatic flushing of state table entries needs to work the same as it does for NAT6566976 state limit check works when limit is reached only6566982 state limit is not check when inserting states via IOCTL
6743637 ipfstat prints certain certain counters two times6744095 fix c-style in ip_state.c in fr_matchstate() et. al.6744100 add a comment for CR 6653172 to fil.c6725139 OOW problem still present
6743637 ipfstat prints certain certain counters two times6744095 fix c-style in ip_state.c in fr_matchstate() et. al.6744100 add a comment for CR 6653172 to fil.c6725139 OOW problem still present after a patch 127888-09 has been applied6657378 IPF address pools does not match addresses reliably for IPv66726717 IPF persistent tunables still don't work with stack instances6743002 ipf_property_update() is too picky6731974 incorrect calculation in fr_pullup6749974 IPF does not know whether packet comes from local client (loopback) or from NIC interface
PSARC/2008/219 Committed API for packet interceptionPSARC/2008/335 Corrections for Committed API for packet interceptionPSARC/2008/557 Revision to net instance notification API4844507 Solaris need
PSARC/2008/219 Committed API for packet interceptionPSARC/2008/335 Corrections for Committed API for packet interceptionPSARC/2008/557 Revision to net instance notification API4844507 Solaris needs stable interface for packet filtering software6705155 ipf_stack_init() assumes kmem_alloc with KM_NOSLEEP never fails
6713984 if a nat entry is created, but the packet gets blocked, the entry should be removed6718524 ipfilter incorrectly tracks and handles orphan state table and nat table entries6742115 IPfilter:
6713984 if a nat entry is created, but the packet gets blocked, the entry should be removed6718524 ipfilter incorrectly tracks and handles orphan state table and nat table entries6742115 IPfilter: NAT entries added with SIOCSTPUT are ignored if no rules exist.6528443 ipnat -l shows more sessions than ipf_nattable_max
6726575 ipfilter needs to be able to do randomised port mapping6730614 random port numbers are in the wrong range of numbers
PSARC 2008/250 ipv6 NAT for IPFilter6600474 RFE: Need ipv6 support on NAT
6719268 enabling ipfilter causes up to 80% or more drop in packet throughput for multi-stream workloads6721215 ipfilter panic in ipf:fr_derefrule after restoring state table6723213 IPfilter: NAT su
6719268 enabling ipfilter causes up to 80% or more drop in packet throughput for multi-stream workloads6721215 ipfilter panic in ipf:fr_derefrule after restoring state table6723213 IPfilter: NAT suffers performance hit by holding exclusive locks longer than required
6505685 Problems with applying "to" rule in IP Filter6562635 TCP options are not processed correctly6562648 IPF may drop connection, which chooses to scale window6562721 IPF should also check SACK
6505685 Problems with applying "to" rule in IP Filter6562635 TCP options are not processed correctly6562648 IPF may drop connection, which chooses to scale window6562721 IPF should also check SACK when doing stateful inspection6595876 state timer should be reset when retransmission is seen6651775 ipf does not handle half estab. connections well (conn. hangs with connection match result 4/0)
6685076 ippool and other ipf utilities have possible race condition6685092 ipfilter list processing function(s) have unsafe edge case(s)
6677590 ON is now required to deliver license info via pkg copyright files6684249 third party license cleanup--HG--rename : usr/src/pkgdefs/SUNWdsdu/copyright => deleted_files/usr/src/pkgdefs/SUN
6677590 ON is now required to deliver license info via pkg copyright files6684249 third party license cleanup--HG--rename : usr/src/pkgdefs/SUNWdsdu/copyright => deleted_files/usr/src/pkgdefs/SUNWdsdu/copyrightrename : usr/src/pkgdefs/SUNWgrubS/copyright => deleted_files/usr/src/pkgdefs/SUNWgrubS/copyrightrename : usr/src/pkgdefs/SUNWipfr/copyright => deleted_files/usr/src/pkgdefs/SUNWipfr/copyrightrename : usr/src/pkgdefs/SUNWipfu/copyright => deleted_files/usr/src/pkgdefs/SUNWipfu/copyrightrename : usr/src/pkgdefs/SUNWlibsasl/copyright => deleted_files/usr/src/pkgdefs/SUNWlibsasl/copyright.inrename : usr/src/pkgdefs/SUNWpppdu/copyright => deleted_files/usr/src/pkgdefs/SUNWpppdu/copyrightrename : usr/src/pkgdefs/SUNWpppg/copyright => deleted_files/usr/src/pkgdefs/SUNWpppg/copyrightrename : usr/src/pkgdefs/SUNWpppgS/copyright => deleted_files/usr/src/pkgdefs/SUNWpppgS/copyrightrename : usr/src/pkgdefs/SUNWsndmr/copyright => deleted_files/usr/src/pkgdefs/SUNWsndmr/copyrightrename : usr/src/pkgdefs/SUNWsndmu/copyright => deleted_files/usr/src/pkgdefs/SUNWsndmu/copyrightrename : usr/src/pkgdefs/SUNWsshcu/copyright => deleted_files/usr/src/pkgdefs/SUNWsshcu/copyrightrename : usr/src/pkgdefs/SUNWsshdr/copyright => deleted_files/usr/src/pkgdefs/SUNWsshdr/copyrightrename : usr/src/pkgdefs/SUNWsshdu/copyright => deleted_files/usr/src/pkgdefs/SUNWsshdu/copyrightrename : usr/src/pkgdefs/SUNWsshr/copyright => deleted_files/usr/src/pkgdefs/SUNWsshr/copyrightrename : usr/src/pkgdefs/SUNWsshu/copyright => deleted_files/usr/src/pkgdefs/SUNWsshu/copyrightrename : usr/src/pkgdefs/SUNWtcpd/copyright => deleted_files/usr/src/pkgdefs/SUNWtcpd/copyrightrename : usr/src/pkgdefs/SUNWtcpdS/copyright => deleted_files/usr/src/pkgdefs/SUNWtcpdS/copyrightrename : usr/src/pkgdefs/SUNWtecla/copyright => deleted_files/usr/src/pkgdefs/SUNWtecla/copyrightrename : usr/src/uts/common/sys/i2o/THIRDPARTYLICENSE => deleted_files/usr/src/uts/common/sys/i2o/THIRDPARTYLICENSErename : usr/src/uts/common/sys/i2o/THIRDPARTYLICENSE.descrip => deleted_files/usr/src/uts/common/sys/i2o/THIRDPARTYLICENSE.descriprename : usr/src/pkgdefs/SUNWnetcat/copyright => usr/src/cmd/cmd-inet/usr.bin/nc/THIRDPARTYLICENSErename : usr/src/pkgdefs/SUNWcsl/copyright => usr/src/pkgdefs/SUNWcsl/lic_AMDrename : usr/src/pkgdefs/SUNWgrub/copyright => usr/src/pkgdefs/SUNWgrub/grubcreditsrename : usr/src/pkgdefs/SUNWgss/copyright => usr/src/pkgdefs/SUNWgss/gss_licenserename : usr/src/pkgdefs/SUNWocfh/copyright => usr/src/pkgdefs/SUNWocfh/copyright.inrename : usr/src/pkgdefs/SUNWroute/copyright => usr/src/pkgdefs/SUNWroute/copyright.inrename : usr/src/pkgdefs/common_files/copyright => usr/src/pkgdefs/license_files/cr_Sunrename : usr/src/pkgdefs/SUNWdrmr/LICENSE => usr/src/uts/common/io/drm/THIRDPARTYLICENSErename : usr/src/pkgdefs/SUNWpppd/copyright => usr/src/uts/common/io/ppp/THIRDPARTYLICENSE
PSARC/2007/666 Broadcast/multicast packet notification through pfhooks6633786 ipfilter with no mbcast not working as expected6645812 GLD packets are not flagged correctly as multicast/broadcast
6627912 ipnat -l still shows some inconsistent results
6603271 ipnat -l demonstrates inconsistent behavior and can cause system to hang or panic
6231883 ipfilter service lacks refresh method6561278 pressing 'q' to quit ipfstat -t will cause underlying bash and tcsh to terminate but not ksh
6455532 OSNet cleanup required in preparation for direct bindings--HG--rename : usr/src/cmd/bnu/strecpy.c => deleted_files/usr/src/cmd/bnu/strecpy.crename : usr/src/cmd/fs.d/ufs/mount/realpath.c
6455532 OSNet cleanup required in preparation for direct bindings--HG--rename : usr/src/cmd/bnu/strecpy.c => deleted_files/usr/src/cmd/bnu/strecpy.crename : usr/src/cmd/fs.d/ufs/mount/realpath.c => deleted_files/usr/src/cmd/fs.d/ufs/mount/realpath.crename : usr/src/cmd/lp/lib/lp/tinames.c => deleted_files/usr/src/cmd/lp/lib/lp/tinames.crename : usr/src/cmd/sgs/crle/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/crle/common/mapfile-versrename : usr/src/cmd/sgs/elfdump/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/elfdump/common/mapfile-versrename : usr/src/cmd/sgs/ldd/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/ldd/common/mapfile-versrename : usr/src/cmd/sgs/moe/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/moe/common/mapfile-versrename : usr/src/cmd/sgs/pvs/common/mapfile-vers => deleted_files/usr/src/cmd/sgs/pvs/common/mapfile-versrename : usr/src/lib/libsocket/amd64/byteorder.s => deleted_files/usr/src/lib/libsocket/amd64/byteorder.srename : usr/src/lib/libsocket/i386/byteorder.s => deleted_files/usr/src/lib/libsocket/i386/byteorder.srename : usr/src/cmd/sgs/ld/common/mapfile-vers => usr/src/cmd/sgs/ld/common/mapfile-intfrename : usr/src/cmd/sgs/mapfiles/Makefile => usr/src/common/mapfiles/Makefilerename : usr/src/cmd/sgs/mapfiles/amd64/Makefile => usr/src/common/mapfiles/amd64/Makefilerename : usr/src/cmd/sgs/mapfiles/amd64/map.above4G => usr/src/common/mapfiles/amd64/map.above4Grename : usr/src/cmd/sgs/mapfiles/amd64/map.below4G => usr/src/common/mapfiles/amd64/map.below4Grename : usr/src/cmd/sgs/mapfiles/common/Makefile => usr/src/common/mapfiles/common/Makefilerename : usr/src/cmd/mapfile_bssalign => usr/src/common/mapfiles/common/map.bssalignrename : usr/src/cmd/mapfile_execdata => usr/src/common/mapfiles/common/map.execdatarename : usr/src/lib/common/mapfile-filter => usr/src/common/mapfiles/common/map.filterrename : usr/src/cmd/mapfile_noexstk => usr/src/common/mapfiles/common/map.noexstkrename : usr/src/cmd/sgs/mapfiles/i386/Makefile => usr/src/common/mapfiles/i386/Makefilerename : usr/src/cmd/sgs/mapfiles/i386/map.default => usr/src/common/mapfiles/i386/map.defaultrename : usr/src/cmd/mapfile_noexdata => usr/src/common/mapfiles/i386/map.noexdatarename : usr/src/cmd/sgs/mapfiles/i386/map.pagealign => usr/src/common/mapfiles/i386/map.pagealignrename : usr/src/cmd/sgs/mapfiles/sparc/Makefile => usr/src/common/mapfiles/sparc/Makefilerename : usr/src/cmd/sgs/mapfiles/sparc/map.default => usr/src/common/mapfiles/sparc/map.defaultrename : usr/src/cmd/sgs/mapfiles/sparc/map.pagealign => usr/src/common/mapfiles/sparc/map.pagealignrename : usr/src/cmd/sgs/mapfiles/sparcv9/Makefile => usr/src/common/mapfiles/sparcv9/Makefilerename : usr/src/cmd/sgs/mapfiles/sparcv9/map.above4G => usr/src/common/mapfiles/sparcv9/map.above4Grename : usr/src/cmd/sgs/mapfiles/sparcv9/map.below4G => usr/src/common/mapfiles/sparcv9/map.below4Grename : usr/src/lib/libsocket/inet/byteorder.c => usr/src/lib/libc/sparc/gen/byteorder.c
6455242 nightly should be able to preserve all proto areas from a single build.6467531 nightly(1) needs option to generate OpenSolaris delivery--HG--rename : usr/src/pkgdefs/SUNWftpu/copyright =>
6455242 nightly should be able to preserve all proto areas from a single build.6467531 nightly(1) needs option to generate OpenSolaris delivery--HG--rename : usr/src/pkgdefs/SUNWftpu/copyright => usr/src/cmd/cmd-inet/usr.sbin/in.ftpd/LICENSE
PSARC 2006/366 IP Instances6289221 RFE: Need virtualized ip-stack for each local zone6512601 panic in ipsec_in_tag - allocation failure6514637 error message from dhcpagent: add_pkt_opt: option typ
PSARC 2006/366 IP Instances6289221 RFE: Need virtualized ip-stack for each local zone6512601 panic in ipsec_in_tag - allocation failure6514637 error message from dhcpagent: add_pkt_opt: option type 60 is missing required value6364643 RFE: allow persistent setting of interface flags per zone6307539 RFE: Invalid network address causes zone boot failure5041214 Allow IPMP configuration with zones5005887 RFE: zoneadmd should support plumbing an interface via DHCP4991139 RFE: zones should provide a mechanism to configure a defaultrouter for a zone6218378 zoneadmd doesn't set the netmask for non-loopback addresses hosted on lo04963280 zones: need to virtualize the IPv6 default address selection mechanism4963285 zones: need support of stateless address autoconfiguration for IPv65048068 zones don't boot if one of its interfaces has failed5057154 RFE: ability to change interface status from within a zone4963287 zones should support the plumbing of the first (and only) logical interface4978517 TCP privileged port space should be partitioned per zone5023347 zones don't work well with network routes other than default4963372 investigate whether global zone can act as a router for local zones6378364 RFE: Allow each zone to have its own virtual IPFilter
12