Re: pf NAT and VNET Jails

From: NGie Cooper <yaneurabeya_at_gmail.com>
Date: Tue, 10 Nov 2015 13:45:21 -0800
On Tue, Nov 10, 2015 at 1:28 PM, Kristof Provost <kp_at_freebsd.org> wrote:
> On 2015-11-09 21:47:01 (-0500), Shawn Webb <shawn.webb_at_hardenedbsd.org> wrote:
>> I found the problem: it seems that the new Intel Haswell graphics
>> support (which I've been running with) is at odds somehow with pf NAT.
>> Removing Haswell graphics support means working pf NAT.
>>
> That's ... very strange.
>
> I've built the drm-i915-update-38 branch of http:////github.com/freebsd/freebsd-base-graphics.git,
> but still haven't managed to reproduce the problem.
> It is if course entirely possible that it would only manifest if the
> haswell graphics are actually in use. In that case there's little I can
> do as I don't have haswell hardware I could test on.

1. Add memguard(9) support to kernel.
2. Set the descriptions for the zones (as noted in the manpage) to
catch panics when either driver tries to touch eachothers' space.
Cheers,
-NGie
Received on Tue Nov 10 2015 - 20:45:22 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:41:00 UTC