Re: 12.0-BETA1 vnet with pf firewall

2018-11-02 Thread Marek Zarychta
On Fri, Nov 02, 2018 at 02:20:53PM +, Bjoern A. Zeeb wrote: > On 28 Oct 2018, at 22:07, Marek Zarychta wrote: > > > Some time ago I submitted a PR about this, but I was unaware that the > > case of failure during loading ipsec.ko is caused by the presence of > > already loaded pf.ko > > > > ht

Re: 12.0-BETA1 vnet with pf firewall

2018-11-02 Thread Bjoern A. Zeeb
On 28 Oct 2018, at 22:07, Marek Zarychta wrote: Some time ago I submitted a PR about this, but I was unaware that the case of failure during loading ipsec.ko is caused by the presence of already loaded pf.ko https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=228854 This bug and the current re

Re: 12.0-BETA1 vnet with pf firewall

2018-10-30 Thread Rodney W. Grimes
> On 30 Oct 2018, at 14:14, Rodney W. Grimes wrote: > > >> On 30 Oct 2018, at 14:29, Bjoern A. Zeeb wrote: > >>> On 30 Oct 2018, at 12:23, Kristof Provost wrote: > I?m not too familiar with this part of the vnet code, but it looks > to me like we?ve got more per-vnet variables that was o

Re: 12.0-BETA1 vnet with pf firewall

2018-10-30 Thread Bjoern A. Zeeb
On 30 Oct 2018, at 14:14, Rodney W. Grimes wrote: On 30 Oct 2018, at 14:29, Bjoern A. Zeeb wrote: On 30 Oct 2018, at 12:23, Kristof Provost wrote: I?m not too familiar with this part of the vnet code, but it looks to me like we?ve got more per-vnet variables that was originally anticipated, so

Re: 12.0-BETA1 vnet with pf firewall

2018-10-30 Thread Rodney W. Grimes
> On 30 Oct 2018, at 14:29, Bjoern A. Zeeb wrote: > > On 30 Oct 2018, at 12:23, Kristof Provost wrote: > >> I?m not too familiar with this part of the vnet code, but it looks > >> to me like we?ve got more per-vnet variables that was originally > >> anticipated, so we may need to just increase th

Re: 12.0-BETA1 vnet with pf firewall

2018-10-30 Thread Kristof Provost
On 30 Oct 2018, at 14:29, Bjoern A. Zeeb wrote: On 30 Oct 2018, at 12:23, Kristof Provost wrote: I’m not too familiar with this part of the vnet code, but it looks to me like we’ve got more per-vnet variables that was originally anticipated, so we may need to just increase the allocated space.

Re: 12.0-BETA1 vnet with pf firewall

2018-10-30 Thread Bjoern A. Zeeb
On 30 Oct 2018, at 12:23, Kristof Provost wrote: On 29 Oct 2018, at 4:41, Kristof Provost wrote: So we panic because we dereference a NULL pointer in strncmp(), which happens because nprogtab = 13 but ef->progtab[12] has NULL pointers. I cannot reproduce your panic trying to load both pf, and

Re: 12.0-BETA1 vnet with pf firewall

2018-10-30 Thread Kristof Provost
On 29 Oct 2018, at 4:41, Kristof Provost wrote: So we panic because we dereference a NULL pointer in strncmp(), which happens because nprogtab = 13 but ef->progtab[12] has NULL pointers. It’s not clear to me why that happens, but it’s something to go on. I do wonder if this isn’t a bit of a re

Re: 12.0-BETA1 vnet with pf firewall

2018-10-28 Thread Kristof Provost
On 28 Oct 2018, at 14:39, Rodney W. Grimes wrote: Bjoern A. Zeeb wrote: On 28 Oct 2018, at 15:31, Ernie Luzar wrote: Tested with host running ipfilter and vnet running pf. Tried loading pf from host console or from vnet console using kldload pf.ko command and get this error message; linker_

Re: 12.0-BETA1 vnet with pf firewall

2018-10-28 Thread Marek Zarychta
W dniu 28.10.2018 o 22:39, Rodney W. Grimes pisze: >> Bjoern A. Zeeb wrote: >>> On 28 Oct 2018, at 15:31, Ernie Luzar wrote: >>> Tested with host running ipfilter and vnet running pf. Tried loading pf from host console or from vnet console using kldload pf.ko command and get this

Re: 12.0-BETA1 vnet with pf firewall

2018-10-28 Thread Rodney W. Grimes
> Bjoern A. Zeeb wrote: > > On 28 Oct 2018, at 15:31, Ernie Luzar wrote: > > > >> Tested with host running ipfilter and vnet running pf. Tried loading > >> pf from host console or from vnet console using kldload pf.ko command > >> and get this error message; > >> > >> linker_load_file: /boot/ker

Re: 12.0-BETA1 vnet with pf firewall

2018-10-28 Thread Kristof Provost
> On 28 Oct 2018, at 12:56, Ernie Luzar wrote: > > Bjoern A. Zeeb wrote: >>> On 28 Oct 2018, at 15:31, Ernie Luzar wrote: >>> Tested with host running ipfilter and vnet running pf. Tried loading pf >>> from host console or from vnet console using kldload pf.ko command and get >>> this error m

Re: 12.0-BETA1 vnet with pf firewall

2018-10-28 Thread Ernie Luzar
Bjoern A. Zeeb wrote: On 28 Oct 2018, at 15:31, Ernie Luzar wrote: Tested with host running ipfilter and vnet running pf. Tried loading pf from host console or from vnet console using kldload pf.ko command and get this error message; linker_load_file: /boot/kernel/pf.ko-unsupported file type

Re: 12.0-BETA1 vnet with pf firewall

2018-10-28 Thread Bjoern A. Zeeb
On 28 Oct 2018, at 15:31, Ernie Luzar wrote: Tested with host running ipfilter and vnet running pf. Tried loading pf from host console or from vnet console using kldload pf.ko command and get this error message; linker_load_file: /boot/kernel/pf.ko-unsupported file type. Looks like the 12.0