Page MenuHomeFreeBSD

pf: Support killing 'matching' states
ClosedPublic

Authored by kp on May 3 2021, 2:51 PM.
Tags
None
Referenced Files
F142576460: D30092.id88872.diff
Wed, Jan 21, 4:58 AM
Unknown Object (File)
Sat, Jan 17, 9:32 PM
Unknown Object (File)
Thu, Jan 15, 5:52 AM
Unknown Object (File)
Wed, Jan 14, 4:12 PM
Unknown Object (File)
Tue, Jan 13, 3:44 AM
Unknown Object (File)
Fri, Dec 26, 11:10 AM
Unknown Object (File)
Dec 18 2025, 4:05 PM
Unknown Object (File)
Dec 17 2025, 12:54 PM

Details

Summary

Optionally also kill states that match (i.e. are the NATed state or
opposite direction state entry for) the state we're killing.

See also https://redmine.pfsense.org/issues/8555

Submitted by: Steven Brown
Obtained from: https://github.com/pfsense/FreeBSD-src/pull/11/
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

kp requested review of this revision.May 3 2021, 2:51 PM

Minor man page nit.

sbin/pfctl/pfctl.8
340

Line break after the sentence stop needed here.

Manpage looks good now.
I guess upstream will incorporate it, too.

In D30092#675436, @bcr wrote:

I guess upstream will incorporate it, too.

We are upstream. The patch was originally submitted against pfsense, but we're the pfsense upstream, so they'll get it as part of their usual sync operations.

Right, I thought it was the other way around, but this makes more sense. :-)

This revision was not accepted when it landed; it landed in state Needs Review.May 7 2021, 8:15 PM
This revision was automatically updated to reflect the committed changes.