Subject: Re: ipfilter loading.
To: Ty Sarna <tsarna@endicor.com>
From: Andrew Gillham <gillhaa@ghost.whirlpool.com>
List: tech-kern
Date: 04/29/1997 14:31:59
Ty Sarna wrote:
>
> In article <199704290426.VAA29059@lestat.nas.nasa.gov> you write:
> > Besides, if that change broke your firewall, I'd assert that your firewall
> > was too fragile in the first place.
>
> Run any anonymous ftp servers, Jason? Do you have "ftp" in
> /etc/ftpchroot? What if I go and remove the special-casing of "ftp"
> chroot on you, and now your whole system is open? Guess your anonymous
> ftp server was just too fragile...
Please, there is a difference with introducing a bug in a "release"
of NetBSD, and changing source in -current. I 100% agree with Jason
that a firewall that "breaks" because of a commit to -current is
too fragile. That is an obvious one. Running an anonymous ftp server
on -current, and *blindly* supping changes is pretty fragile also.
-Andrew
--
-----------------------------------------------------------------
Andrew Gillham | This space left blank
gillham@whirlpool.com | inadvertently.
I speak for myself, not for my employer. | Contact the publisher.