FreeBSD src
Go to file
Kristof Provost 22893e5840 bridge: default to not filtering L3
Change the default for net.link.bridge.pfil_member and
net.link.bridge.pfil_bridge to zero.

That is, default to not calling layer 3 firewalls on the bridge or its
member interfaces.

With either of these enabled the bridge will, during L2 processing,
remove the Ethernet header from packets, feed them to L3 firewalls,
re-add the Ethernet header and send them out.

Not only does this interact very poorly with firewalls which defer
packets, or reassemble and refragment IPv6, it also causes considerable
confusion for users, because the firewall gets called in unexpected
ways.

For example, a bridge which contains a bhyve tap and the host's LAN
interface. We'd expect traffic between the LAN and bhyve VM to pass, no
matter what (layer 3) firewall rules are set on the host. That's not the
case as long as pfil_bridge or pfil_member are set.

Reviewed by:	Zhenlei Huang
MFC:		never
Differential Revision:	https://reviews.freebsd.org/D37009
2022-10-24 08:52:21 +02:00
.cirrus-ci Cirrus-CI: add some timing info on pkg install failure 2021-08-04 15:02:00 -04:00
.github .github: Attempt to fix and increase robustness of macOS action 2022-06-30 21:03:26 +01:00
bin sh: when loading profile, read only .sh files. 2022-10-22 19:05:31 +02:00
cddl libdtrace: Fix some CPU register number definitions to match the kernel 2022-10-12 16:06:37 -04:00
contrib unbound: Reapply Vendor import 1.17.0 2022-10-16 14:08:33 -07:00
crypto ssh: update to OpenSSH 9.1p1 2022-10-19 10:27:11 -04:00
etc kinst: Add a rudimentary regression test case 2022-10-11 18:19:55 -04:00
gnu libdialog: Bump shared library version to 10. 2021-10-27 09:30:24 -07:00
include netlink: add headers installation 2022-10-01 16:31:58 +00:00
kerberos5 pkgbase: split kerberos binaries and libs 2022-08-03 11:02:28 +01:00
lib libc: Make elf_aux_info() return an error if AT_USRSTACK* is undefined 2022-10-18 18:11:26 -04:00
libexec rtld: remove unused macro FPTR_TARGET 2022-10-22 05:15:06 +03:00
release release: link from /boot/msdos to efi 2022-10-11 13:19:52 -06:00
rescue rescue: Link libzutil after libzfs. 2022-10-03 16:10:42 -07:00
sbin Increase the maximum size of the journaled soft-updates journal. 2022-10-21 11:00:00 -07:00
secure ssh: update to OpenSSH 9.1p1 2022-10-19 10:27:11 -04:00
share xhci(4): Fix spelling in manual page. 2022-10-21 07:48:30 +02:00
stand stand/efi: Call md_copymodules based on __LP64__ to fix 32-bit arm 2022-10-22 19:47:25 -06:00
sys bridge: default to not filtering L3 2022-10-24 08:52:21 +02:00
targets Put OPIE to rest. 2022-10-02 03:37:29 +02:00
tests fusefs: fix VOP_ADVLOCK with SEEK_END 2022-10-18 19:11:49 -06:00
tools stress2: Added a regression test for D37024 2022-10-24 09:48:09 +02:00
usr.bin w: cosmetic fixes. 2022-10-21 16:37:44 +00:00
usr.sbin bhyve: Handle snapshots of unconfigured virtio-net devices 2022-10-23 14:50:43 -04:00
.arcconfig arcanist: use FreeBSD/git project repository instead of FreeBSD/svn 2022-08-23 14:16:41 +00:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.cirrus.yml Cirrus-CI: move QEMU pkg installation to test script 2022-09-07 13:32:12 -04:00
.clang-format clang-format: Add bitset loop macros 2021-09-21 12:08:01 -04:00
.gitattributes Add a basic clang-format configuration file 2019-06-07 15:23:52 +00:00
.gitignore gitignore: Ignore compile_commands.events.json 2022-05-30 10:43:25 -04:00
COPYRIGHT Welcome 2022, update copyrights. 2022-01-01 09:49:49 -07:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS Remove myself from bhyve maintenance; ENOTIME. 2021-11-19 07:09:30 +10:00
Makefile Makefile: replace mergemaster references with etcupdate 2022-10-06 20:19:16 +02:00
Makefile.inc1 Rename MACHINE_ABI and TARGET_ABI 2022-10-05 17:27:44 +01:00
Makefile.libcompat Install working pkgconfig .pc files for compat libraries 2022-08-11 23:18:34 +01:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc ithread(9): update functions to current day 2022-10-15 15:49:33 -03:00
README.md README.md: update gnu directory description 2021-12-17 08:45:31 -05:00
RELNOTES RELNOTES: Add an entry for dtrace_kinst(4) 2022-10-11 18:19:55 -04:00
UPDATING LinuxKPI: move pm_message_t from kernel.h to pm.h 2022-06-10 14:05:12 +00:00

FreeBSD Source:

This is the top level of the FreeBSD source directory.

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), FreeBSD handbook on building userland, and Handbook for kernels for more information, including setting make(1) variables.

Source Roadmap:

Directory Description
bin System/user commands.
cddl Various commands and libraries under the Common Development and Distribution License.
contrib Packages contributed by 3rd parties.
crypto Cryptography stuff (see crypto/README).
etc Template files for /etc.
gnu Commands and libraries under the GNU General Public License (GPL) or Lesser General Public License (LGPL). Please see gnu/COPYING and gnu/COPYING.LIB for more information.
include System include files.
kerberos5 Kerberos5 (Heimdal) package.
lib System libraries.
libexec System daemons.
release Release building Makefile & associated tools.
rescue Build system for statically linked /rescue utilities.
sbin System commands.
secure Cryptographic libraries and commands.
share Shared resources.
stand Boot loader sources.
sys Kernel sources.
sys/arch/conf Kernel configuration files. GENERIC is the configuration used in release builds. NOTES contains documentation of all possible entries.
tests Regression tests which can be run by Kyua. See tests/README for additional information.
tools Utilities for regression testing and miscellaneous tasks.
usr.bin User commands.
usr.sbin System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see FreeBSD Handbook.