Page MenuHomeFreeBSD

pf: Hash rule and pool addresses by type
Needs ReviewPublic

Authored by rcm on Fri, Oct 9, 6:55 PM.
Tags
None
Referenced Files
F175516038: D60545.id189281.diff
Sun, Oct 11, 9:29 AM
F175431344: D60545.diff
Sat, Oct 10, 7:39 PM
F175430365: D60545.id189281.diff
Sat, Oct 10, 7:31 PM
Unknown Object (File)
Sat, Oct 10, 9:22 AM
Unknown Object (File)
Sat, Oct 10, 6:37 AM
Unknown Object (File)
Fri, Oct 9, 10:12 PM
Unknown Object (File)
Fri, Oct 9, 10:05 PM

Details

Reviewers
kp
Summary

pf_hash_rule_addr() hashes the fields an address type uses, but leaves
out the prefix length of an interface address: "from ($if)/24" and
"from ($if)/25" hash the same. pf_hash_pool() hashes a pool address
as a whole struct, pointer union cleared.

Hash both the same way, by type, and include the prefix length of an
interface address. This changes the hash of every rule with an
interface address or a pool: "set keepcounters" starts such rules at
zero once, on the first load after the change, and until both pfsync
peers run this version their ruleset checksums differ, so a state one
imports from the other is bound to the default rule, as with any
difference between the rulesets.

Add a regression test.

Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

rcm requested review of this revision.Fri, Oct 9, 6:55 PM
sys/netpfil/pf/pf_ioctl.c
1372–1373

If struct pf_addr_wrap's member type was a enum you would not need the default: case. It will also allow the compiler to do more checks. Note that PF_ADD_* constants are already enum. It just needs a name.