From nobody Mon Oct 02 00:50:46 2023 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RzMnf4FmWz4w2mY; Mon, 2 Oct 2023 00:50:46 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RzMnf3cgqz4r2g; Mon, 2 Oct 2023 00:50:46 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696207846; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=NfV5+sgWPIDv1TEugCl4VAFNFgwzUjNN4OHrbSac2vs=; b=weEmm9r9mX2gSV4LfBLUiPDU8ZiGZEsxNpB0ok71R00AaovMP8ye4kUDPccwpKye4S8Ydw HYWbMSL9TK3vVFzrwhjI3y2Lje0//43b5mSvHg68ZoOBd3GKpO8NBdcjcC3W1Ivx1nZEUv LKVbDUBLZKr05ygRXli9TeGpXEFsNG/qEMXtscHOouQKA5B4tTi2fDMQafDknq8tFngsss 6PBZUTRzP110+28PmVyMjCHZF0nyNLzskI1iPmPTx9EWbbRu1lRWxYFAdpXrTOZNKwpWAg ku6UBys//Y+xtX3VnDi3Fuby3ubKTjhLEAr7/eepuuSSDt8WKgrh4NBZR0ic8A== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1696207846; a=rsa-sha256; cv=none; b=AUs8kJYe6YjAjJG9WVSKLfO7eKNfrrtta2ZJcJh47jQyi0/hfAtjiZtq0NY80Sgl90BK47 fwfgF+HYLVZFolIxwMkNu6HMrAI3GqrFhD8HLtiYGTI3zI8YBgJp+TLTw9GRn1YQYdlKUz VRmrYzsc0wXvEAHpvzZRCFx70JqAXoIQPXkbs8jlhP7uyvdSIpPv3FZB1wnCIRdBdUxnPH cG/yxq4vCB72z67ev+pkOH971dintlZ+uBkVN04Ys4sUtjk2TUdHnU4i/EyH/sw+k50VwH uaqpI5pB4JmpC+0NA9bWwCQmiM4ACLAIOLcMkSk1W35pnr5pq0ye5gZQdJe/tw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696207846; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=NfV5+sgWPIDv1TEugCl4VAFNFgwzUjNN4OHrbSac2vs=; b=ixYgj1ttwz6FUNpkc2ZaB6ADZPn4VHS2GOkzBGlLz0txytugj9Rwun9/BlWl0lONAUt1iS 5CyaY8mhya29mqBFWwbtpOC8GXDMwkW01+iP6IK1pO9H4ScouWZ+F+rBt+p38aTGeoNHft AyESZ68RBY2stVq5DlU42dtyz/F1/XnjRHaKtuYAmpMa1SJ6+X6swILs2NYGlSTMhVUMU9 bC35eylM8IwJCTvnjIscwbWIR2j2pRQO1/9s8vj6R70hqxv36+6nnZHFdg7UiYpxFAlelw xgS2Wr7fplveZb8gmGdrQvKNnMMHuRqMtrJd5Q18SAu1yrcoPwrsXJdX8oflzQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RzMnf2jhyzrj9; Mon, 2 Oct 2023 00:50:46 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3920okxY029300; Mon, 2 Oct 2023 00:50:46 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3920okTA029297; Mon, 2 Oct 2023 00:50:46 GMT (envelope-from git) Date: Mon, 2 Oct 2023 00:50:46 GMT Message-Id: <202310020050.3920okTA029297@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Zhenlei Huang Subject: git: bb6f9a95402a - stable/14 - ipfw.8: Adjust section for loader tunables List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-branches@freebsd.org X-BeenThere: dev-commits-src-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: zlei X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: bb6f9a95402a6c3ab8167481b81465f8ad5016fc Auto-Submitted: auto-generated The branch stable/14 has been updated by zlei: URL: https://cgit.FreeBSD.org/src/commit/?id=bb6f9a95402a6c3ab8167481b81465f8ad5016fc commit bb6f9a95402a6c3ab8167481b81465f8ad5016fc Author: Zhenlei Huang AuthorDate: 2023-09-28 04:58:44 +0000 Commit: Zhenlei Huang CommitDate: 2023-10-02 00:49:38 +0000 ipfw.8: Adjust section for loader tunables Move the descriptions of loader tunables from section 'SYSCTL VARIABLES' to section 'LOADER TUNABLES'. See also 49197c391b3d (ipfw: Add sysctl flag CTLFLAG_TUN to loader tunables). MFC after: 2 days Differential Revision: https://reviews.freebsd.org/D41981 (cherry picked from commit 12349f38898f231ca803dcf526bac88cb1b5cd2b) --- sbin/ipfw/ipfw.8 | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/sbin/ipfw/ipfw.8 b/sbin/ipfw/ipfw.8 index 1a042ae2bbbf..e62b8d6efc95 100644 --- a/sbin/ipfw/ipfw.8 +++ b/sbin/ipfw/ipfw.8 @@ -1,5 +1,5 @@ .\" -.Dd April 25, 2023 +.Dd September 28, 2023 .Dt IPFW 8 .Os .Sh NAME @@ -3761,6 +3761,16 @@ or .Xr kenv 1 before ipfw module gets loaded. .Bl -tag -width indent +.It Va net.inet.ip.fw.enable : No 1 +Enables the firewall. +Setting this variable to 0 lets you run your machine without +firewall even if compiled in. +.It Va net.inet6.ip6.fw.enable : No 1 +provides the same functionality as above for the IPv6 case. +.It Va net.link.ether.ipfw : No 0 +Controls whether layer2 packets are passed to +.Nm . +Default is no. .It Va net.inet.ip.fw.default_to_accept : No 0 Defines ipfw last rule behavior. This value overrides @@ -4154,12 +4164,6 @@ Keep dynamic states on rule/set deletion. States are relinked to default rule (65535). This can be handly for ruleset reload. Turned off by default. -.It Va net.inet.ip.fw.enable : No 1 -Enables the firewall. -Setting this variable to 0 lets you run your machine without -firewall even if compiled in. -.It Va net.inet6.ip6.fw.enable : No 1 -provides the same functionality as above for the IPv6 case. .It Va net.inet.ip.fw.one_pass : No 1 When set, the packet exiting from the .Nm dummynet @@ -4176,10 +4180,6 @@ Enables verbose messages. Limits the number of messages produced by a verbose firewall. .It Va net.inet6.ip6.fw.deny_unknown_exthdrs : No 1 If enabled packets with unknown IPv6 Extension Headers will be denied. -.It Va net.link.ether.ipfw : No 0 -Controls whether layer2 packets are passed to -.Nm . -Default is no. .It Va net.link.bridge.ipfw : No 0 Controls whether bridged packets are passed to .Nm .