Page MenuHomeFreeBSD

libpfctl: zero the counters before summing per-chunk results
AcceptedPublic

Authored by rcm on Wed, Sep 30, 2:38 PM.

Details

Reviewers
kp
Summary

The chunked table address functions (set, add, del, clr_astats) add
each chunk's result to the caller's counter without initialising it.
pfctl reuses nadd for the number of tables created, so a replace that
also creates the table is off by one:

pfctl -t foo -T replace 192.0.2.1

reports "2 addresses added".

Zero the counters first, as pfctl_test_addrs() already does. Remove
the workaround for the add case from pfctl (da64f6e047b5), which is
no longer needed.

Add a regression test.

Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped