> :>     then, as usual, IPFW with the new kernel and
> :>     old world fails utterly and now the fragging machine can't access the
> :Hear hear!!  I am >< tempted to have /sbin/ipfw moved to src/sys.
>     How about something like this (patch enclosed).  If there are no
>     objections I will commit it along with a documentation update, and
>     maybe also add some RC code give the sysad a chance to ipfw unbreak if
>     ipfw otherwise fails during the boot sequence.

How this could be helpful in a remote upgrade scenario that has
IPFW ABI incompatibility issues?

One alternative approach would be to not compile IPFW into a
kernel but rather have it loaded as a module.  Then, you
install new kernel, edit out ipfw_enable="YES" for the time
being, reboot with the new kernel, installworld, edit
ipfw_enable="YES" back in, reboot, and you're done.

