3 ms·
>The biggest advantage of FreeBSD over Linux in area of networking is the ability to filter inbound network packets by process ID. That sounds _awesome_ and I
by 1MachineElf 6y ago
>The biggest advantage of FreeBSD over Linux in area of networking is the ability to filter inbound network packets by process ID.
That sounds _awesome_ and I would really like to know more about that feature. While searching the man pages for ipfw(8)[0] and pc.conf(5)[1], I couldn't find anything about filtering by process ID. The closest thing I could find was the capability in pf to filter by process user/group. Is there more you can share about this?
[0] https://www.freebsd.org/cgi/man.cgi?query=ipfw&apropos=0&sektion=8&manpath=FreeBSD+13.0-current&arch=default&format=html https://www.freebsd.org/cgi/man.cgi?query=ipfw&apropos=0&sek...
[1] https://www.freebsd.org/cgi/man.cgi?query=pf.conf&apropos=0&sektion=5&manpath=FreeBSD+13.0-current&arch=default&format=html https://www.freebsd.org/cgi/man.cgi?query=pf.conf&apropos=0&...
EDIT: The parent comment where this quote came from was deleted.
- wahern 6y agoThat seems like a mistake or typo. It doesn't even make sense as PIDs are ephemeral and recycled, and installing per-PID rules would be inherently race prone, unless installed by the process itself. It would effectively be a fundamentally broken design. It's possible there's some other mechanism implied here that permits attaching rules to tagged processes or groups. Maybe they were implicating per-process routing tables or jails, which actually create inheritable contexts amenable to long-term identifiers for ruleset reference, and aren't literally per PID. It seems more likely they were just referring to UID/GID, but I guess iptables has had an ancillary module for that for quite awhile. In any event, I can't find the quote so it definitely seems it was wrong or at least misleading and they simply retracted it.
- coretx 6y agoParent might like Bell Labs https://9p.io/plan9/ https://9p.io/plan9/ Unix - where not everything is a file, but a network socket.
- 1MachineElf 6y agoI certainly do. My pet project for this summer will be standing up a TuringPi (v1)[0] with 7 instances of networked Plan 9 (or 9front[1]). I'll certainly try exploring this area once that's ready. [0] https://docs.turingpi.com/specs https://docs.turingpi.com/specs [1] http://fqa.9front.org/fqa1.html http://fqa.9front.org/fqa1.html
- 1MachineElf 6y agoIndeed, I hadn't realized that the parent comment I was replying to had been deleted. Furthermore, I wasn't aware that a deleted parent comment on HN would move my own to the parent's level. I suppose you're right that PID filtering is both prone to problems and not actually available as a feature. On the other hand, Windows is able to offer per-process filtering via it's local firewall - not quite via PIDs but instead by specifying the filesystem path to the process binary. So, it must be possible to implement in some way for non-Windows.