Page MenuHomeFreeBSD
Feed Advanced Search

Sat, Nov 1

vegeta_tuxpowered.net updated the diff for D53515: pf: Add RELNOTES information about new features.

Remove the information about the new "scrub" syntax because that has been included in FreeBSD 14.

Sat, Nov 1, 1:17 PM
vegeta_tuxpowered.net requested review of D53515: pf: Add RELNOTES information about new features.
Sat, Nov 1, 1:03 PM

Thu, Oct 30

vegeta_tuxpowered.net committed rGee1f417a8609: pf: Check if source nodes use a valid redirection address (authored by vegeta_tuxpowered.net).
pf: Check if source nodes use a valid redirection address
Thu, Oct 30, 5:45 PM
vegeta_tuxpowered.net committed rG646798b67831: pf: Make nat-to and rdr-to work properly both on in and out rules (authored by vegeta_tuxpowered.net).
pf: Make nat-to and rdr-to work properly both on in and out rules
Thu, Oct 30, 5:45 PM
vegeta_tuxpowered.net closed D53231: pf: Check if source nodes use a valid redirection address.
Thu, Oct 30, 5:45 PM
vegeta_tuxpowered.net closed D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Thu, Oct 30, 5:45 PM

Wed, Oct 22

vegeta_tuxpowered.net updated the summary of D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Wed, Oct 22, 3:19 PM
vegeta_tuxpowered.net updated the diff for D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.

Don't forbid address translation on non-usual direction, since OpenBSD allows it too. Enable the test for nat-to on inbound direction.

Wed, Oct 22, 3:18 PM
vegeta_tuxpowered.net added inline comments to D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Wed, Oct 22, 11:01 AM

Tue, Oct 21

vegeta_tuxpowered.net updated the diff for D53231: pf: Check if source nodes use a valid redirection address.

Assert the rpool.

Tue, Oct 21, 8:56 AM
vegeta_tuxpowered.net updated the diff for D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.

Restore the proper patch

Tue, Oct 21, 8:54 AM
vegeta_tuxpowered.net updated the diff for D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Tue, Oct 21, 8:53 AM
vegeta_tuxpowered.net added inline comments to D53231: pf: Check if source nodes use a valid redirection address.
Tue, Oct 21, 8:48 AM
vegeta_tuxpowered.net requested review of D53231: pf: Check if source nodes use a valid redirection address.
Tue, Oct 21, 8:46 AM

Mon, Oct 20

vegeta_tuxpowered.net added inline comments to D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Mon, Oct 20, 2:50 PM
vegeta_tuxpowered.net updated the summary of D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Mon, Oct 20, 2:48 PM
vegeta_tuxpowered.net requested review of D53216: pf: Make nat-to and rdr-to work properly both on in and out rules.
Mon, Oct 20, 2:47 PM

Oct 1 2025

vegeta_tuxpowered.net committed rG013708fd3167: pf: Fix rule and state counters (authored by vegeta_tuxpowered.net).
pf: Fix rule and state counters
Oct 1 2025, 4:11 PM
vegeta_tuxpowered.net committed rGad428a318b60: pf: Fix interface counters for af-to rules (authored by vegeta_tuxpowered.net).
pf: Fix interface counters for af-to rules
Oct 1 2025, 4:11 PM
vegeta_tuxpowered.net committed rG048b8123ee87: pf: Always skip outbound filtering for inbound af-to rules (authored by vegeta_tuxpowered.net).
pf: Always skip outbound filtering for inbound af-to rules
Oct 1 2025, 4:11 PM
vegeta_tuxpowered.net committed rGf12dba5d1746: pf: Fix interface binding for af-to with route-to (authored by vegeta_tuxpowered.net).
pf: Fix interface binding for af-to with route-to
Oct 1 2025, 4:11 PM
vegeta_tuxpowered.net committed rGe345fb2e91bc: pf: Add pfsync protocol for FreeBSD 15 (authored by vegeta_tuxpowered.net).
pf: Add pfsync protocol for FreeBSD 15
Oct 1 2025, 4:11 PM

Sep 28 2025

vegeta_tuxpowered.net committed rG7cd3854f827f: pf: Fix interface counters for af-to rules (authored by vegeta_tuxpowered.net).
pf: Fix interface counters for af-to rules
Sep 28 2025, 5:29 PM
vegeta_tuxpowered.net committed rG6353f5d9a5c6: pf: Fix rule and state counters (authored by vegeta_tuxpowered.net).
pf: Fix rule and state counters
Sep 28 2025, 5:29 PM
vegeta_tuxpowered.net committed rG938ae26ffda8: pf: Always skip outbound filtering for inbound af-to rules (authored by vegeta_tuxpowered.net).
pf: Always skip outbound filtering for inbound af-to rules
Sep 28 2025, 5:29 PM
vegeta_tuxpowered.net closed D52448: pf: Fix interface counters for af-to rules.
Sep 28 2025, 5:29 PM
vegeta_tuxpowered.net closed D52447: pf: Fix rule and state counters.
Sep 28 2025, 5:29 PM
vegeta_tuxpowered.net closed D52446: pf: Always skip outbound filtering for inbound af-to rules.
Sep 28 2025, 5:28 PM

Sep 23 2025

vegeta_tuxpowered.net committed rG42441d342071: pf: Fix interface binding for af-to with route-to (authored by vegeta_tuxpowered.net).
pf: Fix interface binding for af-to with route-to
Sep 23 2025, 10:12 AM
vegeta_tuxpowered.net committed rG99475087d63b: pf: Add pfsync protocol for FreeBSD 15 (authored by vegeta_tuxpowered.net).
pf: Add pfsync protocol for FreeBSD 15
Sep 23 2025, 10:12 AM
vegeta_tuxpowered.net closed D52445: pf: Fix interface binding for af-to with route-to.
Sep 23 2025, 10:12 AM
vegeta_tuxpowered.net closed D52176: pf: Add pfsync protocol for FreeBSD 15.
Sep 23 2025, 10:12 AM

Sep 17 2025

vegeta_tuxpowered.net abandoned D41479: Draft: Forwarding: Use the next hop installed by pfil_mbuf_in.
Sep 17 2025, 3:48 PM
vegeta_tuxpowered.net abandoned D41517: Draft: pf: Switch pf_route() to PACKET_TAG_IPFORWARD tag.
Sep 17 2025, 3:48 PM
vegeta_tuxpowered.net added inline comments to D52445: pf: Fix interface binding for af-to with route-to.
Sep 17 2025, 3:43 PM
vegeta_tuxpowered.net updated the diff for D52445: pf: Fix interface binding for af-to with route-to.
Sep 17 2025, 3:42 PM

Sep 16 2025

vegeta_tuxpowered.net added inline comments to D52447: pf: Fix rule and state counters.
Sep 16 2025, 4:25 PM
vegeta_tuxpowered.net updated the diff for D52447: pf: Fix rule and state counters.
Sep 16 2025, 4:25 PM
vegeta_tuxpowered.net added inline comments to D52445: pf: Fix interface binding for af-to with route-to.
Sep 16 2025, 8:50 AM

Sep 9 2025

vegeta_tuxpowered.net updated the diff for D52176: pf: Add pfsync protocol for FreeBSD 15.

Fix the altq_queues test.

Sep 9 2025, 6:29 PM
vegeta_tuxpowered.net updated the diff for D52176: pf: Add pfsync protocol for FreeBSD 15.

Update the man page for pfsync.

Sep 9 2025, 6:21 PM
vegeta_tuxpowered.net updated the diff for D52176: pf: Add pfsync protocol for FreeBSD 15.

Fix struct alignment. Add a test for rt_af, document why it can't check all cases yet.

Sep 9 2025, 6:20 PM
vegeta_tuxpowered.net abandoned D46864: WIP: pf: Fix table counters.
Sep 9 2025, 1:25 PM
vegeta_tuxpowered.net requested review of D52448: pf: Fix interface counters for af-to rules.
Sep 9 2025, 1:23 PM
vegeta_tuxpowered.net requested review of D52447: pf: Fix rule and state counters.
Sep 9 2025, 1:22 PM
vegeta_tuxpowered.net requested review of D52446: pf: Always skip outbound filtering for inbound af-to rules.
Sep 9 2025, 1:20 PM
vegeta_tuxpowered.net requested review of D52445: pf: Fix interface binding for af-to with route-to.
Sep 9 2025, 1:19 PM

Aug 30 2025

vegeta_tuxpowered.net closed D50781: pf: Add prefer-ipv6-nexthop option for route-to pools.
Aug 30 2025, 4:44 AM

Aug 29 2025

vegeta_tuxpowered.net committed rG65c318630123: pf: Add prefer-ipv6-nexthop option for route-to pools (authored by vegeta_tuxpowered.net).
pf: Add prefer-ipv6-nexthop option for route-to pools
Aug 29 2025, 9:28 AM

Aug 28 2025

vegeta_tuxpowered.net added inline comments to D52176: pf: Add pfsync protocol for FreeBSD 15.
Aug 28 2025, 2:24 PM
vegeta_tuxpowered.net updated the diff for D52176: pf: Add pfsync protocol for FreeBSD 15.

Remove syncing of altq queue names, sync their IDs instead. The queue names are very long and if queues are kept identical on both routers, it will still work fine. Improve locking in tagname2tag().

Aug 28 2025, 2:09 PM

Aug 27 2025

vegeta_tuxpowered.net requested review of D52176: pf: Add pfsync protocol for FreeBSD 15.
Aug 27 2025, 9:30 AM

Aug 22 2025

vegeta_tuxpowered.net updated the diff for D50781: pf: Add prefer-ipv6-nexthop option for route-to pools.

Fixed spelling mistakes, added pfctl tests.

Aug 22 2025, 8:59 AM

Aug 8 2025

vegeta_tuxpowered.net retitled D50781: pf: Add prefer-ipv6-nexthop option for route-to pools from pf: Add RFC5549 support for route-to to pf: Add prefer-ipv6-nexthop option for route-to pools.
Aug 8 2025, 3:36 PM
vegeta_tuxpowered.net updated the diff for D50781: pf: Add prefer-ipv6-nexthop option for route-to pools.
Aug 8 2025, 3:36 PM
vegeta_tuxpowered.net added a reviewer for D51800: [pfil loop prevention experiment 4/5] pfil: Provide looping prevention mechanism: kp.
Aug 8 2025, 9:34 AM
vegeta_tuxpowered.net added a reviewer for D51799: [pfil loop prevention experiment 3/5] pf: Remove default_actions from pf_test(): kp.
Aug 8 2025, 9:34 AM
vegeta_tuxpowered.net added a reviewer for D51798: [pfil loop prevention experiment 2/5] pf tests: Add test for dummynet in pre- and post-routing scenario: kp.
Aug 8 2025, 9:34 AM

Aug 7 2025

vegeta_tuxpowered.net added a reviewer for D51800: [pfil loop prevention experiment 4/5] pfil: Provide looping prevention mechanism: glebius.
Aug 7 2025, 8:15 PM
vegeta_tuxpowered.net updated the summary of D51801: [pfil loop prevention experiment 5/5] pf: Simplify af-to, route-to and dummynet reinjection.
Aug 7 2025, 5:34 PM
vegeta_tuxpowered.net added inline comments to D51801: [pfil loop prevention experiment 5/5] pf: Simplify af-to, route-to and dummynet reinjection.
Aug 7 2025, 5:33 PM
vegeta_tuxpowered.net added inline comments to D51800: [pfil loop prevention experiment 4/5] pfil: Provide looping prevention mechanism.
Aug 7 2025, 5:17 PM
vegeta_tuxpowered.net requested review of D51801: [pfil loop prevention experiment 5/5] pf: Simplify af-to, route-to and dummynet reinjection.
Aug 7 2025, 5:16 PM
vegeta_tuxpowered.net requested review of D51800: [pfil loop prevention experiment 4/5] pfil: Provide looping prevention mechanism.
Aug 7 2025, 4:56 PM
vegeta_tuxpowered.net requested review of D51799: [pfil loop prevention experiment 3/5] pf: Remove default_actions from pf_test().
Aug 7 2025, 4:49 PM
vegeta_tuxpowered.net requested review of D51798: [pfil loop prevention experiment 2/5] pf tests: Add test for dummynet in pre- and post-routing scenario.
Aug 7 2025, 4:46 PM
vegeta_tuxpowered.net retitled D51797: [pfil loop prevention experiment 1/5] pf tests: Add tests for syncookies and synproxy with route-to from pfil loop prevention experiment ; pf tests: Add tests for syncookies and synproxy with route-to to [pfil loop prevention experiment 1/5] pf tests: Add tests for syncookies and synproxy with route-to.
Aug 7 2025, 4:44 PM
vegeta_tuxpowered.net requested review of D51797: [pfil loop prevention experiment 1/5] pf tests: Add tests for syncookies and synproxy with route-to.
Aug 7 2025, 4:44 PM
vegeta_tuxpowered.net added a comment to D51789: pf: Add AF ifdefs in pf_pdesc_to_dnflow().
In D51789#1183098, @kp wrote:

No objection, but things just build even on LINT-NOINET6 kernels without this change, so I'm not sure what the motivation is.

Aug 7 2025, 1:45 PM
vegeta_tuxpowered.net requested review of D51789: pf: Add AF ifdefs in pf_pdesc_to_dnflow().
Aug 7 2025, 12:06 PM
vegeta_tuxpowered.net committed rG5bbdd368c7b1: pf tests: Improve tests for af-to (authored by vegeta_tuxpowered.net).
pf tests: Improve tests for af-to
Aug 7 2025, 11:58 AM
vegeta_tuxpowered.net closed D51788: pf tests: Improve tests for af-to.
Aug 7 2025, 11:58 AM
vegeta_tuxpowered.net requested review of D51788: pf tests: Improve tests for af-to.
Aug 7 2025, 8:40 AM

Aug 5 2025

vegeta_tuxpowered.net closed D51659: pf: Use different address family for source and redirection address.
Aug 5 2025, 10:06 AM

Aug 1 2025

vegeta_tuxpowered.net committed rGd2761422eb0a: pf: Use different address family for source and redirection address (authored by vegeta_tuxpowered.net).
pf: Use different address family for source and redirection address
Aug 1 2025, 10:17 AM
vegeta_tuxpowered.net committed rG539da08f5567: pfctl: Use sa_family_t for af instead of int (authored by vegeta_tuxpowered.net).
pfctl: Use sa_family_t for af instead of int
Aug 1 2025, 10:17 AM
vegeta_tuxpowered.net closed D51658: pfctl: Use sa_family_t for af instead of int.
Aug 1 2025, 10:16 AM
vegeta_tuxpowered.net updated the summary of D51659: pf: Use different address family for source and redirection address.
Aug 1 2025, 9:08 AM
vegeta_tuxpowered.net updated the diff for D51659: pf: Use different address family for source and redirection address.

Trim too long lines, update comments.

Aug 1 2025, 9:07 AM

Jul 31 2025

vegeta_tuxpowered.net updated the diff for D51659: pf: Use different address family for source and redirection address.
Jul 31 2025, 5:59 PM
vegeta_tuxpowered.net updated the diff for D51659: pf: Use different address family for source and redirection address.
Jul 31 2025, 5:55 PM
vegeta_tuxpowered.net requested review of D51659: pf: Use different address family for source and redirection address.
Jul 31 2025, 5:54 PM
vegeta_tuxpowered.net requested review of D51658: pfctl: Use sa_family_t for af instead of int.
Jul 31 2025, 5:51 PM

Jul 13 2025

vegeta_tuxpowered.net committed rG2b2ac1aa9a34: pf tests: Fix rdr pass test to really use 'pass … rdr-to' syntax (authored by vegeta_tuxpowered.net).
pf tests: Fix rdr pass test to really use 'pass … rdr-to' syntax
Jul 13 2025, 2:48 PM
vegeta_tuxpowered.net committed rGc46bf1e3c9c5: pf tests: Add jail configuration for route_to and ipv6-nexthop tests (authored by vegeta_tuxpowered.net).
pf tests: Add jail configuration for route_to and ipv6-nexthop tests
Jul 13 2025, 1:12 PM
vegeta_tuxpowered.net committed rG04dcbb44340f: pf: Prevent infinite looping over tables in round-robin pools (authored by vegeta_tuxpowered.net).
pf: Prevent infinite looping over tables in round-robin pools
Jul 13 2025, 1:12 PM
vegeta_tuxpowered.net closed D50779: pf: Prevent infinite looping over tables in round-robin pools.
Jul 13 2025, 1:12 PM
vegeta_tuxpowered.net closed D50764: pf tests: Add jail configuration for route_to and rfc5549 tests.
Jul 13 2025, 1:12 PM
vegeta_tuxpowered.net committed rGcbd06dd2afd5: pf: Fix error handling when pf_map_addr() fails (authored by vegeta_tuxpowered.net).
pf: Fix error handling when pf_map_addr() fails
Jul 13 2025, 11:53 AM
vegeta_tuxpowered.net closed D50763: pf: Fix error handling when pf_map_addr() fails.
Jul 13 2025, 11:53 AM

Jul 12 2025

vegeta_tuxpowered.net added inline comments to D50763: pf: Fix error handling when pf_map_addr() fails.
Jul 12 2025, 3:28 PM
vegeta_tuxpowered.net updated the diff for D50763: pf: Fix error handling when pf_map_addr() fails.
Jul 12 2025, 3:28 PM
vegeta_tuxpowered.net updated the diff for D50763: pf: Fix error handling when pf_map_addr() fails.
Jul 12 2025, 3:25 PM
vegeta_tuxpowered.net updated the diff for D50763: pf: Fix error handling when pf_map_addr() fails.
Jul 12 2025, 3:24 PM
vegeta_tuxpowered.net closed D50762: pf: Don't return src node and hash from pf_map_addr_sn.

I have pushed the commit without proper footer by mistake, so I'm closing this manually.

Jul 12 2025, 2:34 PM
vegeta_tuxpowered.net closed D50768: pf: Don't access sk and nk before they are allocated.
Jul 12 2025, 2:32 PM
vegeta_tuxpowered.net committed rG16a9f31b8aae: pf: Don't access sk and nk before they are allocated (authored by vegeta_tuxpowered.net).
pf: Don't access sk and nk before they are allocated
Jul 12 2025, 2:32 PM
vegeta_tuxpowered.net committed rGdedb4d3597e5: pf: Don't return src node and hash from pf_map_addr_sn (authored by vegeta_tuxpowered.net).
pf: Don't return src node and hash from pf_map_addr_sn
Jul 12 2025, 2:20 PM

Jul 4 2025

vegeta_tuxpowered.net added a comment to D50781: pf: Add prefer-ipv6-nexthop option for route-to pools.
In D50781#1159156, @kp wrote:

really dislike the 'RFC5549' naming of the flag and variables. Unfortunately I don't immediately have a better suggestion.

Jul 4 2025, 2:00 PM

Jun 10 2025

vegeta_tuxpowered.net requested review of D50781: pf: Add prefer-ipv6-nexthop option for route-to pools.
Jun 10 2025, 7:45 PM