Page MenuHomeFreeBSD

pf: return per-address feedback from netlink table test
ClosedPublic

Authored by rcm on Tue, Sep 29, 8:09 PM.
Tags
None
Referenced Files
F174763001: D60146.id188128.diff
Mon, Oct 5, 8:13 PM
F174749142: D60146.id188307.diff
Mon, Oct 5, 5:38 PM
F174683169: D60146.id188128.diff
Mon, Oct 5, 4:16 AM
F174682211: D60146.id188128.diff
Mon, Oct 5, 4:09 AM
Unknown Object (File)
Sun, Oct 4, 9:43 AM
Unknown Object (File)
Sun, Oct 4, 1:38 AM
Unknown Object (File)
Sun, Oct 4, 12:25 AM
Unknown Object (File)
Sat, Oct 3, 9:53 PM

Details

Summary

The PFNL_CMD_TABLE_TEST_ADDRS reply carries only the match count, so
the per-address feedback from pfr_tst_addrs() is lost:
"pfctl -v -T test" lists nothing and "pfctl -vv -T test" reports
every address as "nomatch".

Return each address, as updated by pfr_tst_addrs(), in a nested
PF_TAS_ADDR attribute, and decode them into the caller's array in
libpfctl. PF_TA_ADDR is not reused: it shares its value with
PF_TAS_ASTATS, which older libpfctl would decode into an
uninitialised target. That target was also read when no reply was
parsed, so the match count could be garbage; initialise it.

Add a regression test.

Fixes: 281282e9357b ("pf: convert DIOCRTSTADDRS to netlink")
See also: https://redmine.pfsense.org/issues/17135
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

rcm requested review of this revision.Tue, Sep 29, 8:09 PM
This revision was not accepted when it landed; it landed in state Needs Review.Thu, Oct 1, 10:40 AM
This revision was automatically updated to reflect the committed changes.