On Wed, Aug 20, 2008 at 12:12:07PM -0400, Will Young wrote: > I think a service manifest should describe network use very plainly > in terms of transport ports, RPC service, etc, and the intended locality > (i.e. loopback, subnet, org, global) and perhaps have smf turn this into > a new network form of FMRI. A bonus would be letting the service > register a mechanism for finding the subset of specific peers and other > micro-state for the network FMRIs it registered.
The idea that a service describes its networking patterns so that IPF can take them into account is very neat, but not sufficient to get rid of packet filtering rules: not everything is a service under SMF management.