Ahead of v13.0, the FreeBSD team talks it and about Linux
theregister.com
theregister.com
> "It's phenomenal to me that code I've written in the last 20 years gets used in all sorts of places that I would not have thought of. My son's PS4 runs my code all the time. That's just bizarre. That's great."
It must be really cool to see that and be able to tell your son, "I made that".
I’m getting killed in default-deny model of Linux firewalls. Just cannot block packets going toward a specific process.
That sounds _awesome_ and I would really like to know more about that feature. While searching the man pages for ipfw(8)[0] and pc.conf(5)[1], I couldn't find anything about filtering by process ID. The closest thing I could find was the capability in pf to filter by process user/group. Is there more you can share about this?
[0] https://www.freebsd.org/cgi/man.cgi?query=ipfw&apropos=0&sek...
[1] https://www.freebsd.org/cgi/man.cgi?query=pf.conf&apropos=0&...
EDIT: The parent comment where this quote came from was deleted.
It's possible there's some other mechanism implied here that permits attaching rules to tagged processes or groups. Maybe they were implicating per-process routing tables or jails, which actually create inheritable contexts amenable to long-term identifiers for ruleset reference, and aren't literally per PID.
It seems more likely they were just referring to UID/GID, but I guess iptables has had an ancillary module for that for quite awhile. In any event, I can't find the quote so it definitely seems it was wrong or at least misleading and they simply retracted it.
I suppose you're right that PID filtering is both prone to problems and not actually available as a feature. On the other hand, Windows is able to offer per-process filtering via it's local firewall - not quite via PIDs but instead by specifying the filesystem path to the process binary. So, it must be possible to implement in some way for non-Windows.