From: Mr Dash Four <mr.dash.four@googlemail.com>
To: Jozsef Kadlecsik <kadlec@blackhole.kfki.hu>
Cc: netfilter@vger.kernel.org, netfilter-devel@vger.kernel.org,
Patrick McHardy <kaber@trash.net>
Subject: Re: [ANNOUNCE] ipset 6.13 released
Date: Sun, 01 Jul 2012 14:17:14 +0100 [thread overview]
Message-ID: <4FF04DDA.3020609@googlemail.com> (raw)
In-Reply-To: <alpine.DEB.2.00.1207011446260.2486@blackhole.kfki.hu>
> Yes. You argue the meaning of a keyword. The meaning is well documented in
> the manpage, but it's totally counter-intuitive for you. Changing the
> meaning might break working firewalls. Therefore the meaning won't be
> changed.
>
This isn't simply a question of "meaning" - it is an issue caused by the
fact that you have introduced something which, it seems, wasn't properly
checked initially for whatever reason and that is causing a great deal
of inconsistency and inconvenience for people, like myself, who use
ipset on a daily basis.
When I match an incoming packet destined to an IP address for example, I
have to use, quite rightly, a "dst" designation, but when I match
against the interface to which this same IP address belongs to,
according to your man page, I have to use "src" instead - all this,
simply because you didn't check this properly when hash:net,iface was
first released and you can't be bothered, for one reason or another, to
change it simply because "this has been out for a long time"?
Do you think that all the network admins out there will have to remember
to use "dst" when matching on destination IP addresses, port numbers
etc, but use exactly the opposite designation - "src" - when matching on
the same destination interface that same IP address belongs to? Do you
not see how inconvenient and downright misleading this is? If you can't,
you are beyond hope, I am afraid.
Right, I am going to include Patrick in this as this whole saga is
becoming something of a monologue and I need a bit of clarity on this.
next prev parent reply other threads:[~2012-07-01 13:17 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-06-29 20:04 [ANNOUNCE] ipset 6.13 released Jozsef Kadlecsik
2012-06-30 18:47 ` Jan Engelhardt
2012-06-30 18:47 ` [PATCH] build: restore -version-info Jan Engelhardt
2012-06-30 22:05 ` Jozsef Kadlecsik
2012-06-30 22:15 ` Jan Engelhardt
2012-06-30 22:31 ` Jozsef Kadlecsik
2012-06-30 22:50 ` Jan Engelhardt
2012-07-01 12:11 ` Jozsef Kadlecsik
2012-07-01 16:03 ` Jan Engelhardt
2012-07-01 17:20 ` Jozsef Kadlecsik
2012-07-01 18:36 ` Jan Engelhardt
2012-07-01 20:45 ` Jozsef Kadlecsik
2012-07-01 10:46 ` [ANNOUNCE] ipset 6.13 released Mr Dash Four
2012-07-01 12:09 ` Jozsef Kadlecsik
2012-07-01 12:19 ` Mr Dash Four
2012-07-01 12:37 ` Jozsef Kadlecsik
2012-07-01 12:44 ` Mr Dash Four
2012-07-01 12:52 ` Jozsef Kadlecsik
2012-07-01 13:17 ` Mr Dash Four [this message]
2012-07-01 15:21 ` Jozsef Kadlecsik
2012-07-01 16:52 ` Mr Dash Four
2012-07-01 21:30 ` Neal Murphy
2012-07-01 21:55 ` Jan Engelhardt
2012-07-01 22:59 ` Neal Murphy
2012-07-01 22:58 ` Amos Jeffries
2012-07-01 22:58 ` Amos Jeffries
2012-07-02 7:54 ` Jozsef Kadlecsik
2012-07-02 13:11 ` Mr Dash Four
2012-07-02 13:26 ` Jozsef Kadlecsik
2012-07-02 14:28 ` Mr Dash Four
2012-07-02 20:26 ` Jozsef Kadlecsik
2012-07-10 16:27 ` Alex Bligh
2012-07-10 16:27 ` Alex Bligh
2012-07-01 18:32 ` Steven Kath
2012-07-01 13:21 ` Andreas Herz
2012-07-01 14:44 ` Jozsef Kadlecsik
2012-07-10 9:12 ` Andreas Herz
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4FF04DDA.3020609@googlemail.com \
--to=mr.dash.four@googlemail.com \
--cc=kaber@trash.net \
--cc=kadlec@blackhole.kfki.hu \
--cc=netfilter-devel@vger.kernel.org \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.