Commit 3eef3635 authored by Avery Pennarun's avatar Avery Pennarun Committed by Brian May

ipfw: don't use 'log' parameter.

I guess we were causing the kernel to syslog on every single packet on
MacOS.  Oops.
parent f1c79c7e
...@@ -394,11 +394,11 @@ def do_ipfw(port, dnsport, family, subnets, udp): ...@@ -394,11 +394,11 @@ def do_ipfw(port, dnsport, family, subnets, udp):
in sorted(subnets, key=lambda s: s[1], reverse=True): in sorted(subnets, key=lambda s: s[1], reverse=True):
if sexclude: if sexclude:
ipfw('add', sport, 'skipto', xsport, ipfw('add', sport, 'skipto', xsport,
'log', 'tcp', 'tcp',
'from', 'any', 'to', '%s/%s' % (snet, swidth)) 'from', 'any', 'to', '%s/%s' % (snet, swidth))
else: else:
ipfw('add', sport, 'fwd', '127.0.0.1,%d' % port, ipfw('add', sport, 'fwd', '127.0.0.1,%d' % port,
'log', 'tcp', 'tcp',
'from', 'any', 'to', '%s/%s' % (snet, swidth), 'from', 'any', 'to', '%s/%s' % (snet, swidth),
'not', 'ipttl', '42', 'keep-state', 'setup') 'not', 'ipttl', '42', 'keep-state', 'setup')
...@@ -440,12 +440,12 @@ def do_ipfw(port, dnsport, family, subnets, udp): ...@@ -440,12 +440,12 @@ def do_ipfw(port, dnsport, family, subnets, udp):
for f, ip in filter(lambda i: i[0] == family, nslist): for f, ip in filter(lambda i: i[0] == family, nslist):
# relabel and then catch outgoing DNS requests # relabel and then catch outgoing DNS requests
ipfw('add', sport, 'divert', sport, ipfw('add', sport, 'divert', sport,
'log', 'udp', 'udp',
'from', 'any', 'to', '%s/32' % ip, '53', 'from', 'any', 'to', '%s/32' % ip, '53',
'not', 'ipttl', '42') 'not', 'ipttl', '42')
# relabel DNS responses # relabel DNS responses
ipfw('add', sport, 'divert', sport, ipfw('add', sport, 'divert', sport,
'log', 'udp', 'udp',
'from', 'any', str(dnsport), 'to', 'any', 'from', 'any', str(dnsport), 'to', 'any',
'not', 'ipttl', '42') 'not', 'ipttl', '42')
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment