From nobody Mon Oct 02 08:29:22 2023 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RzYyq2RXDz4vm9W; Mon, 2 Oct 2023 08:29:23 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RzYyq1L9Hz4KD9; Mon, 2 Oct 2023 08:29:23 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696235363; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=uMKt8BRuOd2Br+JBbSxyNVq/YpQxqzUdXeklQgXb/d8=; b=LArPq0DXmP1w+uFdUe5NmHNQgSUc8pmYCTK2YGD6ap070UnObk+VhlXFHuNQJQ0AdvbOTc vLKr1F4JWC5EECg/WCjJm8Jo3FMNCKW1uzNH26ryg/1aabJBvRDtzaXLnG6MI1h/hUSTsW v/1zSvJGdgtgLci9qen8+xExSnNSpp1zrRL4SqqikAXGLnlshq4MjJsqO82Xyxn/uk6WCH AeIvqC/MsrGyBLA0wBqBnMWc5dlOWYmsRnP/heY6lA52efreuVc1v9jeHPD9unebUQ1BOo +5d/qZTx6vUDEbS+o5yJ1Gyvcq/BKGiDCXVoNT7ZU+UaT0IoFRRDQDU+rcYMng== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1696235363; a=rsa-sha256; cv=none; b=e9scidsDohHIhv9FdYjAXQ5IshKlccnV/sn/XwDf3olU4jaT6vJGbboe0fiH4p02RdlzEk fwfnH1OstBYJW6aaABEh7VMLdZjJU88Zg5pj1VP2Gd0LH9nJdpqT7olykaZFP9h7f5dSg/ 19t3+6otoBEq7TfUSETEC5i7z/wqWLU0G5LYm7WvhPWzOTbAXvETm6nK8AYMB73mFYb+CK xpPdCoLiwoxigvpiLRrSZ9uVSKCRQQlMocX1YeeozKHEOeREzB1wPHu7MeqDBi60P9xBex hyNIJ8+GlOy968d8EaKUK3QNiOZGK+WReCcbzlEizvHVJQDllUZsaKB0F7/DHg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696235363; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=uMKt8BRuOd2Br+JBbSxyNVq/YpQxqzUdXeklQgXb/d8=; b=h7ALe05ZrY8gp9ItxaryFKRNKtzfZmUN2UuH6cMBJLK3zcCWwkHwQ9Emem6GP9DYD0FROQ RIwvOauUm3OUgoUYILAnlo/+fWYxbUDPZzWd6TO9FtoR2cSF4VhKDWGcGOWuM/WrzJidKP Ll/wZcXnw1vThK+L1y7KAx1uhmq8Elez0xF2rKHjgLC6a7A5AOo0FjPuMXbGSXwth1TEm0 fiu3aujV2qTLve8VcHHkUIa5GjTIK2LJmkeEPJIjfHC7P4TdPE1AuiYM51543SRF+fAhbb xyHz+lV5DA3ih4XASqR/l+ruc3DdDExvQ28WKpT4inB6mX8E1hlRmADt3OrznQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RzYyq0S8Kz14RW; Mon, 2 Oct 2023 08:29:23 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3928TMCZ086382; Mon, 2 Oct 2023 08:29:22 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3928TMPU086379; Mon, 2 Oct 2023 08:29:22 GMT (envelope-from git) Date: Mon, 2 Oct 2023 08:29:22 GMT Message-Id: <202310020829.3928TMPU086379@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Zhenlei Huang Subject: git: e31a331ddda6 - stable/13 - ipfw.8: Adjust section for loader tunables List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: zlei X-Git-Repository: src X-Git-Refname: refs/heads/stable/13 X-Git-Reftype: branch X-Git-Commit: e31a331ddda6ffcb711bb950794be5d53e537e2a Auto-Submitted: auto-generated The branch stable/13 has been updated by zlei: URL: https://cgit.FreeBSD.org/src/commit/?id=e31a331ddda6ffcb711bb950794be5d53e537e2a commit e31a331ddda6ffcb711bb950794be5d53e537e2a Author: Zhenlei Huang AuthorDate: 2023-09-28 04:58:44 +0000 Commit: Zhenlei Huang CommitDate: 2023-10-02 08:28:23 +0000 ipfw.8: Adjust section for loader tunables Move the descriptions of loader tunables from section 'SYSCTL VARIABLES' to section 'LOADER TUNABLES'. See also 49197c391b3d (ipfw: Add sysctl flag CTLFLAG_TUN to loader tunables). MFC after: 2 days Differential Revision: https://reviews.freebsd.org/D41981 (cherry picked from commit 12349f38898f231ca803dcf526bac88cb1b5cd2b) (cherry picked from commit bb6f9a95402a6c3ab8167481b81465f8ad5016fc) --- sbin/ipfw/ipfw.8 | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/sbin/ipfw/ipfw.8 b/sbin/ipfw/ipfw.8 index efc338d40007..4a9ded2b9867 100644 --- a/sbin/ipfw/ipfw.8 +++ b/sbin/ipfw/ipfw.8 @@ -1,5 +1,5 @@ .\" -.Dd April 25, 2023 +.Dd September 28, 2023 .Dt IPFW 8 .Os .Sh NAME @@ -3713,6 +3713,16 @@ or .Xr kenv 1 before ipfw module gets loaded. .Bl -tag -width indent +.It Va net.inet.ip.fw.enable : No 1 +Enables the firewall. +Setting this variable to 0 lets you run your machine without +firewall even if compiled in. +.It Va net.inet6.ip6.fw.enable : No 1 +provides the same functionality as above for the IPv6 case. +.It Va net.link.ether.ipfw : No 0 +Controls whether layer2 packets are passed to +.Nm . +Default is no. .It Va net.inet.ip.fw.default_to_accept : No 0 Defines ipfw last rule behavior. This value overrides @@ -4106,12 +4116,6 @@ Keep dynamic states on rule/set deletion. States are relinked to default rule (65535). This can be handly for ruleset reload. Turned off by default. -.It Va net.inet.ip.fw.enable : No 1 -Enables the firewall. -Setting this variable to 0 lets you run your machine without -firewall even if compiled in. -.It Va net.inet6.ip6.fw.enable : No 1 -provides the same functionality as above for the IPv6 case. .It Va net.inet.ip.fw.one_pass : No 1 When set, the packet exiting from the .Nm dummynet @@ -4128,10 +4132,6 @@ Enables verbose messages. Limits the number of messages produced by a verbose firewall. .It Va net.inet6.ip6.fw.deny_unknown_exthdrs : No 1 If enabled packets with unknown IPv6 Extension Headers will be denied. -.It Va net.link.ether.ipfw : No 0 -Controls whether layer2 packets are passed to -.Nm . -Default is no. .It Va net.link.bridge.ipfw : No 0 Controls whether bridged packets are passed to .Nm .