From sacadmin Tue Jul 27 14:58:14 2010
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6RLwE8H020563;
	Tue, 27 Jul 2010 14:58:14 -0700 (PDT)
Received: (from dr146992@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id o6RLwEtu020559;
	Tue, 27 Jul 2010 14:58:14 -0700 (PDT)
Date: Tue, 27 Jul 2010 14:58:14 -0700 (PDT)
From: Darren Reed <dr146992@sac.sfbay.sun.com>
Message-Id: <201007272158.o6RLwEtu020559@sac.sfbay.sun.com>
To: PSARC-record@sac.sfbay.sun.com
Subject: preauth removal from ipf [PSARC/2010/297 FastTrack timeout 08/03/2010]
Status: RO
Content-Length: 603


Template Version: @(#)sac_nextcase 1.70 03/30/10 SMI
This information is Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved.
1. Introduction
    1.1. Project/Component Working Name:
	 preauth removal from ipf
    1.2. Name of Document Author/Supplier:
	 Author:  Alexandr Nedvedicky
    1.3  Date of This Document:
	27 July, 2010
4. Technical Description
    See the case directory for more detail

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From darren.reed@oracle.com Tue Jul 27 15:00:54 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6RM0ss1020741
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 27 Jul 2010 15:00:54 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o6RM0rNj054053;
	Tue, 27 Jul 2010 16:00:53 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6800L03L5H8200@nwk-avmta-2.sfbay.sun.com>; Tue,
 27 Jul 2010 15:00:53 -0700 (PDT)
Received: from sca-ea-mail-4.sun.com ([192.18.43.22])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6800KWAL5G1D10@nwk-avmta-2.sfbay.sun.com>; Tue,
 27 Jul 2010 15:00:52 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by sca-ea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6RM0qIX011426;
 Tue, 27 Jul 2010 22:00:52 +0000 (GMT)
Received: from acsmt353.oracle.com (acsmt353.oracle.com [141.146.40.153])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o6RJ7MIg025552; Tue, 27 Jul 2010 22:00:51 +0000 (GMT)
Received: from abhmt006.oracle.com by acsmt353.oracle.com	with ESMTP id
 442189351280268014; Tue, 27 Jul 2010 15:00:14 -0700
Received: from mintslice.sfbay.sun.com (/129.146.106.55)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Tue,
 27 Jul 2010 15:00:14 -0700
Date: Tue, 27 Jul 2010 15:00:52 -0700
From: Darren Reed <darren.reed@oracle.com>
Subject: preauth removal from ipf [PSARC/2010/297 FastTrack timeout 08/03/2010]
To: PSARC-ext@sun.com, alexandr.nedvedicky@sun.com
Message-id: <4C4F5714.5020408@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt353.oracle.com [141.146.40.153]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090202.4C4F5714.0052:SCFMA4539814,ss=1,fgs=0
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-GB; rv:1.9.1.5) Gecko/20091206
 Thunderbird/3.0
Status: RO
Content-Length: 2599

I'm sponsoring this case for Alexandr Nedvedicky.
I've set the timeout for next Tuesday, August 3rd, 2010.

Darren

1.	Introducation

	This case removes a preauth keyword from ipfilter rule targets.  The
	preauth keyword interface stability level is uncomitted (volatile).

	The release binding is "patch" (it will be back-ported to Solaris 10 as
	a part of bugfix).

2.	Discussion

	The preauth keyword enables IPF administrator to fine tune policy even
	more by involving userland application to policy decision process. However
	the feature is not used by any of existing customers.  Furthermore we've
	discovered few flaws with its implementation, which would cause a deadlock,
	once feature will be enabled (preauth keyword used) by IPF admin. Since no
	such incident has been repored in recent six years, we can safely assume no
	one needs such feature. Killing a dead code is good thing to do.

3.	Interface table
	The preauth keyword, which is being removed is part of uncomitted
	interface.

4.	References
	6972603 remove preauth keyword

5.	Manual pages
	The diff is as follows:
	--- /usr/share/man/man4/ipf.4
	+++ ipf.4
	@@ -42,7 +42,7 @@
	 group     = [ "head" decnumber ] [ "group" decnumber ] .
	
	 block     = "block" [ return-icmp[return-code] | "return-rst" ] .
	-auth    = "auth" | "preauth" .
	+auth    = "auth" .
	 log  = "log" [ "body" ] [ "first" ] [ "or-block" ] [ "level" loglevel ] .
	 tag  = "set-tag" tagid
	 skip = "skip" decnumber .
	@@ -221,18 +221,6 @@
	 should be allowed through. Such a program might look at the source
	address and request some sort of authentication from the user (such as
	a password) before allowing the packet through or telling the kernel to
	drop it if the packet is from an unrecognized source.  .RE
	
	-.sp
	-.ne 2
	-.mk
	-.na
	-\fB\fBpreauth\fR\fR
	-.ad
	-.RS 14n
	-.rt
	-Tells the filter that, for packets of this class, it should look in
	the pre-authenticated list for further clarification. If no further
	matching rule is found, the packet will be dropped (the
	\fBFR_PREAUTH\fR is not the same as \fBFR_PASS\fR). If a further
	-matching rule is found, the result from that
	rule is used in instead. This might be used in a situation where a
	person logs in to the firewall and it sets up some temporary rules
	defining the access for that person.
	-.RE
	-
	 .sp
	 .LP
	 The word following the action keyword must be either \fBin\fR or
	\fBout\fR. Each packet moving through the kernel is either inbound or
	outbound.  "Inbound" means that a packet has just been received on an
	interface and is moving towards the kernel's protocol


From garrett@damore.org Tue Jul 27 15:18:45 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o6RMIjVW021269
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 27 Jul 2010 15:18:45 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o6RMIhmA004168
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 27 Jul 2010 17:18:44 -0500 (CDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L6800M01LZ87N00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 27 Jul 2010 15:18:44 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L6800KR7LZ71D30@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 27 Jul 2010 15:18:44 -0700 (PDT)
Received: from relay41i.sun.com ([192.5.209.70])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o6RMIJ55018462	for
 <PSARC-ext@sun.com>; Tue, 27 Jul 2010 22:18:43 +0000 (GMT)
Received: from mms49es.mms.us.syntegra.com ([160.41.221.232] [160.41.221.232])
 by relay41i.sun.com with ESMTP id BT-MMP-303510 for PSARC-ext@sun.com; Tue,
 27 Jul 2010 22:17:52 +0000 (Z)
Received: from relay44i.sun.com (relay44i.sun.com [192.5.209.118])
 by mms49es.mms.us.syntegra.com with ESMTP id BT-MMP-48130956 for
 PSARC-ext@sun.com; Tue, 27 Jul 2010 22:17:52 +0000 (Z)
Received: from oproxy3-pub.bluehost.com ([69.89.21.8] [69.89.21.8])
 by relay4i.sun.com id BT-MMP-3612681 for PSARC-ext@sun.com; Tue,
 27 Jul 2010 22:17:52 +0000 (Z)
Received: (qmail 30180 invoked by uid 0); Tue, 27 Jul 2010 22:17:51 +0000
Received: from unknown (HELO box374.bluehost.com) (69.89.31.174)
 by oproxy3.bluehost.com with SMTP; Tue, 27 Jul 2010 22:17:51 +0000
Received: from cpe-75-82-74-133.socal.res.rr.com
 ([75.82.74.133] helo=[192.168.251.102])	by box374.bluehost.com with esmtpsa
 (SSLv3:AES256-SHA:256)	(Exim 4.69)	(envelope-from <garrett@damore.org>)
	id 1OdsT9-0000R9-Dl; Tue, 27 Jul 2010 16:17:51 -0600
Date: Tue, 27 Jul 2010 15:17:51 -0700
From: "Garrett D'Amore" <garrett@damore.org>
Subject: Re: preauth removal from ipf [PSARC/2010/297 FastTrack timeout
 08/03/2010]
In-reply-to: <4C4F5714.5020408@oracle.com>
To: Darren Reed <darren.reed@oracle.com>
Cc: PSARC-ext@sun.com, alexandr.nedvedicky@sun.com
Message-id: <1280269071.6326.43.camel@velocity>
MIME-version: 1.0
X-Mailer: Evolution 2.28.3
Content-type: text/plain
Content-transfer-encoding: 7BIT
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=default; d=damore.org;
	h=Received:Subject:From:To:Cc:In-Reply-To:References:Content-Type:Date:Message-ID:Mime-Version:X-Mailer:Content-Transfer-Encoding:X-Identified-User;
	b=ri2FH3efB9xXfqeSUqnpEqb4JxcH+hSY2AIKeOrwKydrW9ZDbcXw7TAi5JHKeLrCGU6xprwiSoDEh/7mNgYt2uz/wQgNFINm9eNfWzJfA5HUNJ6TNMIJnz6+csQVpH/d;
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Identified-User: {2225:box374.bluehost.com:damoreor:damore.org} {sentby:smtp
 auth 75.82.74.133 authed with garrett+damore.org}
X-Antispam: No, score=3.0/5.0, scanned in 0.189sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <4C4F5714.5020408@oracle.com>
Status: RO
Content-Length: 18

+1.

	- Garrett



