Page MenuHomeFreeBSD

D60146.diff
No OneTemporary

D60146.diff

diff --git a/lib/libpfctl/libpfctl.c b/lib/libpfctl/libpfctl.c
--- a/lib/libpfctl/libpfctl.c
+++ b/lib/libpfctl/libpfctl.c
@@ -3883,6 +3883,14 @@
#undef _OUT
SNL_DECLARE_PARSER(table_astats_parser, struct genlmsghdr, snl_f_p_empty, ap_table_get_astats);
+#define _OUT(_field) offsetof(struct nl_addrs, _field)
+static struct snl_attr_parser ap_table_test_addrs[] = {
+ { .type = PF_TAS_ASTATS_COUNT, .off = _OUT(total_count), .cb = snl_attr_get_uint32 },
+ { .type = PF_TAS_ADDR, .off = 0, .cb = snl_attr_get_pfr_addrs },
+};
+#undef _OUT
+SNL_DECLARE_PARSER(table_test_addrs_parser, struct genlmsghdr, snl_f_p_empty, ap_table_test_addrs);
+
int
pfctl_get_astats(struct pfctl_handle *h, const struct pfr_table *tbl,
struct pfr_astats *as, int *size, int flags)
@@ -4006,7 +4014,7 @@
struct snl_errmsg_data e = {};
struct nlmsghdr *hdr;
uint32_t seq_id;
- struct nl_astats attrs;
+ struct nl_addrs attrs = { .addrs = addrs, .max = size };
snl_init_writer(&h->ss, &nw);
hdr = snl_create_genl_msg_request(&nw, h->family_id,
@@ -4030,7 +4038,7 @@
}
while ((hdr = snl_read_reply_multi(&h->ss, seq_id, &e)) != NULL) {
- if (! snl_parse_nlmsg(&h->ss, hdr, &table_astats_parser, &attrs))
+ if (! snl_parse_nlmsg(&h->ss, hdr, &table_test_addrs_parser, &attrs))
continue;
}
diff --git a/sys/netpfil/pf/pf_nl.h b/sys/netpfil/pf/pf_nl.h
--- a/sys/netpfil/pf/pf_nl.h
+++ b/sys/netpfil/pf/pf_nl.h
@@ -527,6 +527,7 @@
PF_TAS_FLAGS = 3, /* u32 */
PF_TAS_ASTATS_COUNT = 4, /* u32 */
PF_TAS_ASTATS_ZEROED = 5, /* u32 */
+ PF_TAS_ADDR = 6, /* nested, pfr_addr_t */
};
enum pf_limit_rate_t {
diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -2539,6 +2539,10 @@
ghdr_new->cmd = PFNL_CMD_TABLE_TEST_ADDRS;
nlattr_add_u32(nw, PF_TAS_ASTATS_COUNT, attrs.nchange);
+ if (error == 0) {
+ for (size_t i = 0; i < attrs.addr_count; i++)
+ nlattr_add_pfr_addr(nw, PF_TAS_ADDR, &attrs.addrs[i]);
+ }
if (!nlmsg_end(nw))
return (ENOMEM);
diff --git a/tests/sys/netpfil/pf/table.sh b/tests/sys/netpfil/pf/table.sh
--- a/tests/sys/netpfil/pf/table.sh
+++ b/tests/sys/netpfil/pf/table.sh
@@ -949,6 +949,60 @@
pft_cleanup
}
+atf_test_case "test_verbose" "cleanup"
+test_verbose_head()
+{
+ atf_set descr 'Test pfctl -v -T test per-address feedback'
+ atf_set require.user root
+}
+
+test_verbose_body()
+{
+ pft_init
+
+ vnet_mkjail alcatraz
+ jexec alcatraz pfctl -e
+
+ pft_set_rules alcatraz \
+ "table <foo> persist { 192.0.2.1 198.51.100.0/24 !198.51.100.7 }" \
+ "pass all"
+
+ # -v lists only the matching addresses.
+ atf_check -s exit:2 -e match:"2/4 addresses match." \
+ -o match:"^M 192\.0\.2\.1$" \
+ -o match:"^M 198\.51\.100\.5$" \
+ -o not-match:"198\.51\.100\.7" \
+ -o not-match:"1\.2\.3\.4" \
+ jexec alcatraz pfctl -t foo -v -T test \
+ 192.0.2.1 198.51.100.5 198.51.100.7 1.2.3.4
+
+ # -vv lists every address and the table entry it matched.
+ atf_check -s exit:2 -e match:"2/4 addresses match." \
+ -o match:"^M 192\.0\.2\.1 192\.0\.2\.1$" \
+ -o match:"^M 198\.51\.100\.5 198\.51\.100\.0/24$" \
+ -o match:"^ 198\.51\.100\.7 !198\.51\.100\.7$" \
+ -o match:"^ 1\.2\.3\.4 nomatch$" \
+ jexec alcatraz pfctl -t foo -vv -T test \
+ 192.0.2.1 198.51.100.5 198.51.100.7 1.2.3.4
+
+ # libpfctl tests 256 addresses per request, check across requests.
+ for i in `seq 1 255`; do
+ echo "203.0.113.${i}"
+ done > addrs
+ echo "1.2.3.4" >> addrs
+ echo "198.51.100.5" >> addrs
+ atf_check -s exit:2 -e match:"1/257 addresses match." \
+ -o match:"^ 203\.0\.113\.255 nomatch$" \
+ -o match:"^ 1\.2\.3\.4 nomatch$" \
+ -o match:"^M 198\.51\.100\.5 198\.51\.100\.0/24$" \
+ jexec alcatraz pfctl -t foo -vv -T test -f $(pwd)/addrs
+}
+
+test_verbose_cleanup()
+{
+ pft_cleanup
+}
+
atf_test_case "show_no_counters" "cleanup"
show_no_counters_head()
{
@@ -1004,5 +1058,6 @@
atf_add_test_case "replace_verbose"
atf_add_test_case "load"
atf_add_test_case "test"
+ atf_add_test_case "test_verbose"
atf_add_test_case "show_no_counters"
}

File Metadata

Mime Type
text/plain
Expires
Thu, Oct 1, 2:27 AM (4 h, 12 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
39986213
Default Alt Text
D60146.diff (4 KB)

Event Timeline