Proposed Improvements to NPF
Josh Moyer <[email protected]> Sat, 7 Jun 2025 06:48:52 +0000
| Newsgroups | gmane.os.netbsd.devel.network |
|---|---|
| Message-ID | <DM6PR07MB42172117847857B907BD482FAC69A@DM6PR07MB4217.namprd07.prod.outlook.com> |
Dear tech-net,
My npf.conf is complex and unwieldy at 720 lines. I'm in need of
syntactical improvements to help me manage it. Necessity is the mother
of invention and, so, I am proposing these prioritized improvements to
npfctl's parser:
1: Allow for multiple interfaces per group.
2: Improve support for nesting/grouping with variables. (Crashes have
been observed here -- core available.)
3: DNS hostname lookup support. (Is this a bad idea from a remote
firewall rule manipulation attack type of perspective?)
I'm hoping to complete this work in 3-9 months. This will be my first
significant contribution to the project. What should I know and
consider before and as I work? I've read [1] and recent messages with
npf in the subject in tech-net, as well as some of [2].
[1] https://wiki.netbsd.org/projects/project/npf_improvements/
[2] /usr/src/usr.sbin/npf/(npfctl/)
Thanks in advance!
--
Kind regards,
_____
| * * | Josh Moyer (he/him) <[email protected]>
|*(*)*| http://jmoyer.nodomain.net/
\ - / http://www.nodomain.net/
\//
Love, Responsibility, Justice
Liebe, Verantwortung, Gerechtigkeit
Please don't eat the animals.
Thanks.