Page Menu
Home
FreeBSD
Search
Configure Global Search
Log In
Files
F174029906
D60146.diff
No One
Temporary
Actions
View File
Edit File
Delete File
View Transforms
Subscribe
Mute Notifications
Flag For Later
Award Token
Size
4 KB
Referenced Files
None
Subscribers
None
D60146.diff
View Options
diff --git a/lib/libpfctl/libpfctl.c b/lib/libpfctl/libpfctl.c
--- a/lib/libpfctl/libpfctl.c
+++ b/lib/libpfctl/libpfctl.c
@@ -3883,6 +3883,14 @@
#undef _OUT
SNL_DECLARE_PARSER(table_astats_parser, struct genlmsghdr, snl_f_p_empty, ap_table_get_astats);
+#define _OUT(_field) offsetof(struct nl_addrs, _field)
+static struct snl_attr_parser ap_table_test_addrs[] = {
+ { .type = PF_TAS_ASTATS_COUNT, .off = _OUT(total_count), .cb = snl_attr_get_uint32 },
+ { .type = PF_TAS_ADDR, .off = 0, .cb = snl_attr_get_pfr_addrs },
+};
+#undef _OUT
+SNL_DECLARE_PARSER(table_test_addrs_parser, struct genlmsghdr, snl_f_p_empty, ap_table_test_addrs);
+
int
pfctl_get_astats(struct pfctl_handle *h, const struct pfr_table *tbl,
struct pfr_astats *as, int *size, int flags)
@@ -4006,7 +4014,7 @@
struct snl_errmsg_data e = {};
struct nlmsghdr *hdr;
uint32_t seq_id;
- struct nl_astats attrs;
+ struct nl_addrs attrs = { .addrs = addrs, .max = size };
snl_init_writer(&h->ss, &nw);
hdr = snl_create_genl_msg_request(&nw, h->family_id,
@@ -4030,7 +4038,7 @@
}
while ((hdr = snl_read_reply_multi(&h->ss, seq_id, &e)) != NULL) {
- if (! snl_parse_nlmsg(&h->ss, hdr, &table_astats_parser, &attrs))
+ if (! snl_parse_nlmsg(&h->ss, hdr, &table_test_addrs_parser, &attrs))
continue;
}
diff --git a/sys/netpfil/pf/pf_nl.h b/sys/netpfil/pf/pf_nl.h
--- a/sys/netpfil/pf/pf_nl.h
+++ b/sys/netpfil/pf/pf_nl.h
@@ -527,6 +527,7 @@
PF_TAS_FLAGS = 3, /* u32 */
PF_TAS_ASTATS_COUNT = 4, /* u32 */
PF_TAS_ASTATS_ZEROED = 5, /* u32 */
+ PF_TAS_ADDR = 6, /* nested, pfr_addr_t */
};
enum pf_limit_rate_t {
diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -2539,6 +2539,10 @@
ghdr_new->cmd = PFNL_CMD_TABLE_TEST_ADDRS;
nlattr_add_u32(nw, PF_TAS_ASTATS_COUNT, attrs.nchange);
+ if (error == 0) {
+ for (size_t i = 0; i < attrs.addr_count; i++)
+ nlattr_add_pfr_addr(nw, PF_TAS_ADDR, &attrs.addrs[i]);
+ }
if (!nlmsg_end(nw))
return (ENOMEM);
diff --git a/tests/sys/netpfil/pf/table.sh b/tests/sys/netpfil/pf/table.sh
--- a/tests/sys/netpfil/pf/table.sh
+++ b/tests/sys/netpfil/pf/table.sh
@@ -949,6 +949,60 @@
pft_cleanup
}
+atf_test_case "test_verbose" "cleanup"
+test_verbose_head()
+{
+ atf_set descr 'Test pfctl -v -T test per-address feedback'
+ atf_set require.user root
+}
+
+test_verbose_body()
+{
+ pft_init
+
+ vnet_mkjail alcatraz
+ jexec alcatraz pfctl -e
+
+ pft_set_rules alcatraz \
+ "table <foo> persist { 192.0.2.1 198.51.100.0/24 !198.51.100.7 }" \
+ "pass all"
+
+ # -v lists only the matching addresses.
+ atf_check -s exit:2 -e match:"2/4 addresses match." \
+ -o match:"^M 192\.0\.2\.1$" \
+ -o match:"^M 198\.51\.100\.5$" \
+ -o not-match:"198\.51\.100\.7" \
+ -o not-match:"1\.2\.3\.4" \
+ jexec alcatraz pfctl -t foo -v -T test \
+ 192.0.2.1 198.51.100.5 198.51.100.7 1.2.3.4
+
+ # -vv lists every address and the table entry it matched.
+ atf_check -s exit:2 -e match:"2/4 addresses match." \
+ -o match:"^M 192\.0\.2\.1 192\.0\.2\.1$" \
+ -o match:"^M 198\.51\.100\.5 198\.51\.100\.0/24$" \
+ -o match:"^ 198\.51\.100\.7 !198\.51\.100\.7$" \
+ -o match:"^ 1\.2\.3\.4 nomatch$" \
+ jexec alcatraz pfctl -t foo -vv -T test \
+ 192.0.2.1 198.51.100.5 198.51.100.7 1.2.3.4
+
+ # libpfctl tests 256 addresses per request, check across requests.
+ for i in `seq 1 255`; do
+ echo "203.0.113.${i}"
+ done > addrs
+ echo "1.2.3.4" >> addrs
+ echo "198.51.100.5" >> addrs
+ atf_check -s exit:2 -e match:"1/257 addresses match." \
+ -o match:"^ 203\.0\.113\.255 nomatch$" \
+ -o match:"^ 1\.2\.3\.4 nomatch$" \
+ -o match:"^M 198\.51\.100\.5 198\.51\.100\.0/24$" \
+ jexec alcatraz pfctl -t foo -vv -T test -f $(pwd)/addrs
+}
+
+test_verbose_cleanup()
+{
+ pft_cleanup
+}
+
atf_test_case "show_no_counters" "cleanup"
show_no_counters_head()
{
@@ -1004,5 +1058,6 @@
atf_add_test_case "replace_verbose"
atf_add_test_case "load"
atf_add_test_case "test"
+ atf_add_test_case "test_verbose"
atf_add_test_case "show_no_counters"
}
File Metadata
Details
Attached
Mime Type
text/plain
Expires
Thu, Oct 1, 2:27 AM (4 h, 12 m)
Storage Engine
blob
Storage Format
Raw Data
Storage Handle
39986213
Default Alt Text
D60146.diff (4 KB)
Attached To
Mode
D60146: pf: return per-address feedback from netlink table test
Attached
Detach File
Event Timeline
Log In to Comment