1 1.3 christos # $NetBSD: TODO,v 1.3 2025/02/05 20:22:26 christos Exp $ 2 1.1 christos 3 1.1 christos - don't poll periodically, find the next timeout 4 1.1 christos - use the socket also for commands? Or separate socket? 5 1.1 christos - add functionality to the control program. Should it change the database 6 1.1 christos directly, or talk to the daemon to have it do it? 7 1.1 christos - perhaps handle interfaces too instead of addresses for dynamic ip? 8 1.1 christos <bge0/4>? What to do with multiple addresses? 9 1.1 christos - perhaps rate limit against DoS 10 1.1 christos - perhaps instead of scanning the list have a sparse map by port? 11 1.1 christos - do we want to use libnpf directly for efficiency? 12 1.1 christos - add more daemons ftpd? 13 1.1 christos - do we care about the db state becoming too large? 14 1.1 christos - instead of a yes = bump one, no = return to 0 interface, do we want 15 1.1 christos to have something more flexible like? 16 1.1 christos +n 17 1.1 christos -n 18 1.1 christos block 19 1.1 christos unblock 20 1.1 christos - do we need an api in blocklistctl to perform maintenance 21 1.1 christos - fix the blocklistctl output to be more user friendly 22 1.2 christos 23 1.2 christos - figure out some way to do distributed operation securely (perhaps with 24 1.2 christos a helper daemon that authenticates local sockets and then communicates 25 1.2 christos local DB changes to the central server over a secure channel -- 26 1.2 christos perhaps blocklistd-helper can have a back-end that can send updates to 27 1.2 christos a central server) 28 1.2 christos 29 1.2 christos - add "blocklistd -l" to enable filter logging on all rules by default 30 1.2 christos 31 1.2 christos - add some new options in the config file 32 1.2 christos 33 1.2 christos "/all" - block both TCP and UDP (on the proto field?) 34 1.2 christos 35 1.2 christos "/log" - enable filter logging (if not the default) (on the name field?) 36 1.2 christos "/nolog"- disable filter logging (if not the default) (on the name field?) 37 1.2 christos 38 1.2 christos The latter two probably require a new parameter for blocklistd-helper. 39 1.2 christos 40 1.2 christos - "blocklistd -f" should (also?) be a blocklistctl function!?!?! 41 1.2 christos 42 1.2 christos - if blocklistd was started with '-r' then a SIGHUP should also do a 43 1.2 christos "control flush $rulename" and then re-add all the filter rules? 44 1.2 christos 45 1.2 christos - should/could /etc/rc.conf.d/ipfilter be created with the following? 46 1.2 christos 47 1.2 christos reload_postcmd=blocklistd_reload 48 1.2 christos start_postcmd=blocklistd_start 49 1.2 christos stop_precmd=blocklistd_stop 50 1.2 christos blocklistd_reload () 51 1.2 christos { 52 1.2 christos /etc/rc.d/blocklistd reload # IFF SIGHUP does flush/re-add 53 1.2 christos # /etc/rc.d/blocklistd restart 54 1.2 christos } 55 1.2 christos blocklistd_stop () 56 1.2 christos { 57 1.2 christos /etc/rc.d/blocklistd stop 58 1.2 christos } 59 1.2 christos blocklistd_start () 60 1.2 christos { 61 1.2 christos /etc/rc.d/blocklistd start 62 1.2 christos } 63 1.2 christos 64 1.2 christos or is there a better way? 65