Page MenuHomeFreeBSD

pf: return per-address feedback from netlink table test
Needs ReviewPublic

Authored by rcm on Tue, Sep 29, 8:09 PM.
Tags
None
Referenced Files
F174035656: D60146.diff
Wed, Sep 30, 3:23 AM
F174033988: D60146.id.diff
Wed, Sep 30, 3:05 AM
F174029906: D60146.diff
Wed, Sep 30, 2:27 AM
F174022136: D60146.diff
Wed, Sep 30, 1:09 AM

Details

Reviewers
kp
Summary

The PFNL_CMD_TABLE_TEST_ADDRS reply carries only the match count, so
the per-address feedback from pfr_tst_addrs() is lost:
"pfctl -v -T test" lists nothing and "pfctl -vv -T test" reports
every address as "nomatch".

Return each address, as updated by pfr_tst_addrs(), in a nested
PF_TAS_ADDR attribute, and decode them into the caller's array in
libpfctl. PF_TA_ADDR is not reused: it shares its value with
PF_TAS_ASTATS, which older libpfctl would decode into an
uninitialised target. That target was also read when no reply was
parsed, so the match count could be garbage; initialise it.

Add a regression test.

Fixes: 281282e9357b ("pf: convert DIOCRTSTADDRS to netlink")
See also: https://redmine.pfsense.org/issues/17135
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped