| 63220460 | 21-Jan-2022 |
Kristof Provost <[email protected]> |
libpfctl: fix creatorid endianness
We provide the hostid (which is the state creatorid) to the kernel as a big endian number (see pfctl/pfctl.c pfctl_set_hostid()), so convert it back to system endi
libpfctl: fix creatorid endianness
We provide the hostid (which is the state creatorid) to the kernel as a big endian number (see pfctl/pfctl.c pfctl_set_hostid()), so convert it back to system endianness when we get it from the kernel.
This avoids a confusing mismatch between the value the user configures and the value displayed in the state.
MFC after: 3 weeks Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D33989
(cherry picked from commit 735748f30aad80593e2b7f5f5f175d64484c5eeb)
show more ...
|
| c298e0a0 | 04-Sep-2021 |
Kristof Provost <[email protected]> |
pfctl: print counters in decimal
795d78a46713 pfctl: Don't use PRIu64 mistakenly changed these to be printed as hexadecimal numbers.
Reported by: Florian Smeets MFC after: 4 days Sponsored by: Rubi
pfctl: print counters in decimal
795d78a46713 pfctl: Don't use PRIu64 mistakenly changed these to be printed as hexadecimal numbers.
Reported by: Florian Smeets MFC after: 4 days Sponsored by: Rubicon Communications, LLC ("Netgate")
(cherry picked from commit 846a6e8f9ab25df4e06d28c05fb66060d803c9ba)
show more ...
|
| a80a3afc | 29-Aug-2021 |
Dimitry Andric <[email protected]> |
Fix -Wformat errors in pfctl on 32-bit architectures
Use PRIu64 to printf(3) uint64_t quantities, otherwise this will result in "error: format specifies type 'unsigned long' but the argument has typ
Fix -Wformat errors in pfctl on 32-bit architectures
Use PRIu64 to printf(3) uint64_t quantities, otherwise this will result in "error: format specifies type 'unsigned long' but the argument has type 'uint64_t' (aka 'unsigned long long') [-Werror,-Wformat]" on 32-bit architectures.
Fixes: 80078d9d38fd MFC after: 1 week
(cherry picked from commit 5b8f07b12f8477f1679013d6b3abdab8d33c7243)
show more ...
|
| d4c7ab9b | 24-Aug-2021 |
Kristof Provost <[email protected]> |
pfctl: build fix
Fix the build issue introduced in e59eff9ad328 (pfctl: fix killing states by ID)
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate")
(cherry picked from commit
pfctl: build fix
Fix the build issue introduced in e59eff9ad328 (pfctl: fix killing states by ID)
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate")
(cherry picked from commit 9ce320820e6d760df11a88de11fbae024c18d23c)
show more ...
|
| 2f0a8079 | 19-May-2021 |
Kristof Provost <[email protected]> |
pfctl tests: Test fairq configuration
We used to have a bug where pfctl could crash setting fairq queues. Test this case and ensure it does not crash pfctl.
Reviewed by: donner MFC after: 1 week Sp
pfctl tests: Test fairq configuration
We used to have a bug where pfctl could crash setting fairq queues. Test this case and ensure it does not crash pfctl.
Reviewed by: donner MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30348
(cherry picked from commit 9938fcaa6565a660c555a0e9c712842ba1a2d31c)
show more ...
|
| a4ceb1e1 | 18-May-2021 |
Kristof Provost <[email protected]> |
pfctl: Fix crash on ALTQ configuration
The following config could crash pfctl: altq on igb0 fairq bandwidth 1Gb queue { qLink } queue qLink fairq(default)
That happens because when we're parsing
pfctl: Fix crash on ALTQ configuration
The following config could crash pfctl: altq on igb0 fairq bandwidth 1Gb queue { qLink } queue qLink fairq(default)
That happens because when we're parsing the parent queue (on igb0) it doesn't have a parent, and the check in eval_pfqueue_fairq() checks pa->parent rather than parent.
This was changed in eval_pfqueue_hfsc() in 1d34c9dac8624c5c315ae39ad3ae8e5879b23256, but not for fairq.
Reviewed by: pkelsey MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30346
(cherry picked from commit 26705a39e51eaf5b32efa98fb86df2d4ecfbdc61)
show more ...
|
| 48d771e5 | 12-May-2021 |
Kristof Provost <[email protected]> |
pf: Track the original kif for floating states
Track (and display) the interface that created a state, even if it's a floating state (and thus uses virtual interface 'all').
MFC after: 1 week Spons
pf: Track the original kif for floating states
Track (and display) the interface that created a state, even if it's a floating state (and thus uses virtual interface 'all').
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30245
(cherry picked from commit d0fdf2b28f9b981d2cb98e9da8a715e046ef1e92)
show more ...
|
| 59f8fc3f | 10-May-2021 |
Kristof Provost <[email protected]> |
pfctl: Use DIOCGETSTATESNV
Migrate to using the new nvlist-based DIOCGETSTATESNV call to obtain the states list.
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential
pfctl: Use DIOCGETSTATESNV
Migrate to using the new nvlist-based DIOCGETSTATESNV call to obtain the states list.
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30244
(cherry picked from commit bc941291473d8a2164e4ffc3f3e7e6a356cbe747)
show more ...
|
| a9620e7c | 30-Apr-2021 |
Kristof Provost <[email protected]> |
pf: Allow states to by killed per 'gateway'
This allows us to kill states created from a rule with route-to/reply-to set. This is particularly useful in multi-wan setups, where one of the WAN links
pf: Allow states to by killed per 'gateway'
This allows us to kill states created from a rule with route-to/reply-to set. This is particularly useful in multi-wan setups, where one of the WAN links goes down.
Submitted by: Steven Brown Obtained from: https://github.com/pfsense/FreeBSD-src/pull/11/ MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30058
(cherry picked from commit abbcba9cf5b1c26e837f00e0fbc205652cb05e51)
show more ...
|
| 714762da | 28-Apr-2021 |
Kristof Provost <[email protected]> |
pfctl: Optionally show gateway information for states
When showing the states, in very verbose mode, also display the gateway (i.e. the target for route-to/reply-to).
Submitted by: Steven Brown Rev
pfctl: Optionally show gateway information for states
When showing the states, in very verbose mode, also display the gateway (i.e. the target for route-to/reply-to).
Submitted by: Steven Brown Reviewed by: donner MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30051
(cherry picked from commit cc948296e632e023f9374ccee68b5710f2ad54a9)
show more ...
|
| 327310fc | 29-Apr-2021 |
Kristof Provost <[email protected]> |
pfctl: Start using DIOCKILLSTATESNV
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30055
(cherry picked from commit 2a00
pfctl: Start using DIOCKILLSTATESNV
MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D30055
(cherry picked from commit 2a00c4db93b8db0c326a57363ca8a690ef6ab082)
show more ...
|