Home | History | Annotate | Line # | Download | only in blocklist
      1  1.3  christos # $NetBSD: TODO,v 1.3 2025/02/05 20:22:26 christos Exp $
      2  1.1  christos 
      3  1.1  christos - don't poll periodically, find the next timeout
      4  1.1  christos - use the socket also for commands? Or separate socket?
      5  1.1  christos - add functionality to the control program. Should it change the database
      6  1.1  christos   directly, or talk to the daemon to have it do it?
      7  1.1  christos - perhaps handle interfaces too instead of addresses for dynamic ip?
      8  1.1  christos   <bge0/4>? What to do with multiple addresses?
      9  1.1  christos - perhaps rate limit against DoS
     10  1.1  christos - perhaps instead of scanning the list have a sparse map by port?
     11  1.1  christos - do we want to use libnpf directly for efficiency?
     12  1.1  christos - add more daemons ftpd?
     13  1.1  christos - do we care about the db state becoming too large? 
     14  1.1  christos - instead of a yes = bump one, no = return to 0 interface, do we want
     15  1.1  christos   to have something more flexible like?
     16  1.1  christos 	+n
     17  1.1  christos 	-n
     18  1.1  christos 	block
     19  1.1  christos 	unblock
     20  1.1  christos - do we need an api in blocklistctl to perform maintenance
     21  1.1  christos - fix the blocklistctl output to be more user friendly
     22  1.2  christos 
     23  1.2  christos - figure out some way to do distributed operation securely (perhaps with
     24  1.2  christos   a helper daemon that authenticates local sockets and then communicates
     25  1.2  christos   local DB changes to the central server over a secure channel --
     26  1.2  christos   perhaps blocklistd-helper can have a back-end that can send updates to
     27  1.2  christos   a central server)
     28  1.2  christos 
     29  1.2  christos - add "blocklistd -l" to enable filter logging on all rules by default
     30  1.2  christos 
     31  1.2  christos - add some new options in the config file
     32  1.2  christos 
     33  1.2  christos 	"/all"	- block both TCP and UDP (on the proto field?)
     34  1.2  christos 
     35  1.2  christos 	"/log"	- enable filter logging (if not the default) (on the name field?)
     36  1.2  christos 	"/nolog"- disable filter logging (if not the default) (on the name field?)
     37  1.2  christos 
     38  1.2  christos   The latter two probably require a new parameter for blocklistd-helper.
     39  1.2  christos 
     40  1.2  christos - "blocklistd -f" should (also?) be a blocklistctl function!?!?!
     41  1.2  christos 
     42  1.2  christos - if blocklistd was started with '-r' then a SIGHUP should also do a
     43  1.2  christos   "control flush $rulename" and then re-add all the filter rules?
     44  1.2  christos 
     45  1.2  christos - should/could /etc/rc.conf.d/ipfilter be created with the following?
     46  1.2  christos 
     47  1.2  christos 	reload_postcmd=blocklistd_reload
     48  1.2  christos 	start_postcmd=blocklistd_start
     49  1.2  christos 	stop_precmd=blocklistd_stop
     50  1.2  christos 	blocklistd_reload ()
     51  1.2  christos 	{
     52  1.2  christos 		/etc/rc.d/blocklistd reload	# IFF SIGHUP does flush/re-add
     53  1.2  christos 		# /etc/rc.d/blocklistd restart
     54  1.2  christos 	}
     55  1.2  christos 	blocklistd_stop ()
     56  1.2  christos 	{
     57  1.2  christos 		/etc/rc.d/blocklistd stop
     58  1.2  christos 	}
     59  1.2  christos 	blocklistd_start ()
     60  1.2  christos 	{
     61  1.2  christos 		/etc/rc.d/blocklistd start
     62  1.2  christos 	}
     63  1.2  christos 
     64  1.2  christos   or is there a better way?
     65