Page MenuHomeFreeBSD

if_bridge(4): Complete bpf auditing of local traffic over the bridge
ClosedPublic

Authored by kevans on Mar 29 2019, 7:17 PM.
Tags
None
Referenced Files
F163385730: D19757.id58018.diff
Wed, Jul 22, 5:56 PM
Unknown Object (File)
Wed, Jul 8, 10:37 PM
Unknown Object (File)
Jun 19 2026, 2:14 AM
Unknown Object (File)
Jun 19 2026, 2:11 AM
Unknown Object (File)
Jun 9 2026, 4:15 PM
Unknown Object (File)
Jun 9 2026, 4:09 PM
Unknown Object (File)
Jun 8 2026, 11:14 PM
Unknown Object (File)
May 21 2026, 9:11 AM
Subscribers

Details

Summary

There were two remaining "gaps" in auditing local bridge traffic with bpf(4):

Locally originated outbound traffic from a member interface is invisible to the bridge's bpf(4) interface. Inbound traffic locally destined to a member interface is invisible to the member's bpf(4) interface.

I call these "gaps" because they don't affect conventional bridge setups. Alas, being able to establish an audit trail of all locally destined traffic for setups that can function like this is surely not a bad thing.

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable