Page MenuHomeFreeBSD

libpfctl: zero the counters before summing per-chunk results
ClosedPublic

Authored by rcm on Wed, Sep 30, 2:38 PM.
Tags
None
Referenced Files
F174168554: D60174.diff
Thu, Oct 1, 2:38 AM
F174165338: D60174.id188274.diff
Thu, Oct 1, 1:57 AM
F174154473: D60174.diff
Wed, Sep 30, 11:47 PM
F174153704: D60174.id188202.diff
Wed, Sep 30, 11:38 PM
F174152138: D60174.diff
Wed, Sep 30, 11:20 PM
F174150146: D60174.diff
Wed, Sep 30, 11:02 PM
F174145993: D60174.id188202.diff
Wed, Sep 30, 10:13 PM
F174145530: D60174.diff
Wed, Sep 30, 10:08 PM

Details

Summary

The chunked table address functions (set, add, del, clr_astats) add
each chunk's result to the caller's counter without initialising it.
pfctl reuses nadd for the number of tables created, so a replace that
also creates the table is off by one:

pfctl -t foo -T replace 192.0.2.1

reports "2 addresses added".

Zero the counters first, as pfctl_test_addrs() already does. Remove
the workaround for the add case from pfctl (da64f6e047b5), which is
no longer needed.

Add a regression test.

Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped