Page MenuHomeFreeBSD

Decode pfsync packets on network interfaces
ClosedPublic

Authored by email_luiz.eng.br on Nov 8 2023, 1:25 PM.
Tags
None
Referenced Files
F132259366: D42504.id129864.diff
Wed, Oct 15, 6:46 AM
Unknown Object (File)
Sat, Oct 11, 3:03 AM
Unknown Object (File)
Fri, Sep 19, 8:45 PM
Unknown Object (File)
Sep 13 2025, 4:13 PM
Unknown Object (File)
Sep 7 2025, 12:00 AM
Unknown Object (File)
Aug 25 2025, 8:36 AM
Unknown Object (File)
Aug 25 2025, 7:27 AM
Unknown Object (File)
Aug 25 2025, 6:56 AM
Subscribers

Details

Summary

Looks like when print-ip-demux.c was introduced on ee67461e, the pfsync_ip_print function was missed, causing tcpdump to treat pfsync packets on network interfaces as an unknown protocol.

Sponsored by: InnoGames GmbH

Test Plan
make -C /usr/src/usr.sbin/tcpdump clean
make -C /usr/src/usr.sbin/tcpdump
make -C /usr/src/usr.sbin/tcpdump install
tcpdump -i vtnet0 'ip[9:1]==0xf0' or 'ip6[6:1]==0xf0'

The output should show packets properly decoded instead of this:

14:13:58.861597 IP 192.0.0.1 > 192.0.0.2:  ip-proto-240 216
14:13:58.861618 IP 192.0.0.1 > 192.0.0.2:  ip-proto-240 300
14:13:58.954208 IP 192.0.0.1 > 192.0.0.2:  ip-proto-240 132

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

I enclosed the code with a #ifdef HAVE_NET_IF_PFLOG_H to allow for building with WITHOUT_PF=1

This revision was not accepted when it landed; it landed in state Needs Review.Nov 8 2023, 5:00 PM
This revision was automatically updated to reflect the committed changes.