git: 9eddf7dd87df - main - net-mgmt/nagios-pf-plugin: fix build on FreeBSD 15+

From: Rene Ladan <rene_at_FreeBSD.org>
Date: Wed, 16 Sep 2026 21:50:04 UTC
The branch main has been updated by rene:

URL: https://cgit.FreeBSD.org/ports/commit/?id=9eddf7dd87dfa63edde409b82273742b00b1344a

commit 9eddf7dd87dfa63edde409b82273742b00b1344a
Author:     Oleksandr Kryvulia <o.kryvulia@flex-it.com.ua>
AuthorDate: 2026-09-16 21:46:30 +0000
Commit:     Rene Ladan <rene@FreeBSD.org>
CommitDate: 2026-09-16 21:49:26 +0000

    net-mgmt/nagios-pf-plugin: fix build on FreeBSD 15+
    
    PR:             294009
    Approved by:    maintainer timeout (never replied)
    MFH:            2026Q3
---
 net-mgmt/nagios-pf-plugin/Makefile                 |  19 ++-
 .../{patch-check_pf.c => extra-patch-check_pf.c}   |   0
 .../files/extra-patch-check_pf_15.c                | 149 +++++++++++++++++++++
 net-mgmt/nagios-pf-plugin/files/patch-Makefile     |  16 ++-
 4 files changed, 177 insertions(+), 7 deletions(-)

diff --git a/net-mgmt/nagios-pf-plugin/Makefile b/net-mgmt/nagios-pf-plugin/Makefile
index 6be3e41d1e66..5beffaae66e9 100644
--- a/net-mgmt/nagios-pf-plugin/Makefile
+++ b/net-mgmt/nagios-pf-plugin/Makefile
@@ -1,17 +1,20 @@
 PORTNAME=	nagios-pf-plugin
 PORTVERSION=	0.1
-PORTREVISION=	3
+PORTREVISION=	4
 CATEGORIES=	net-mgmt
 
 MAINTAINER=	rand@iteris.com
 COMMENT=	Nagios plugin for checking PF
 WWW=		https://github.com/kian/nagios-pf-plugin/
 
-# https://reviews.freebsd.org/D41651
-BROKEN_FreeBSD_15=	requires no longer supported ioctl(DIOCGETSTATUS)
+.include <bsd.port.options.mk>
 
-DEPRECATED=	dead upstream, broken on FreeBSD 15
-EXPIRATION_DATE=	2026-03-31
+.if ${OPSYS} == FreeBSD && ${OSVERSION} >= 1500000
+LIB_DEPENDS=	libpfctl.so:net/libpfctl
+
+CFLAGS+=	-I${LOCALBASE}/include
+LDFLAGS+=	-L${LOCALBASE}/lib -lpfctl
+.endif
 
 USE_GITHUB=	yes
 GH_ACCOUNT=	kian
@@ -20,6 +23,12 @@ GH_TAGNAME=	2aba423
 PLIST_FILES=	libexec/nagios/check_pf
 SUB_FILES=	pkg-message
 
+.if ${OPSYS} == FreeBSD && ${OSVERSION} < 1500000
+EXTRA_PATCHES=	${PATCHDIR}/extra-patch-check_pf.c
+.else
+EXTRA_PATCHES=	${PATCHDIR}/extra-patch-check_pf_15.c
+.endif
+
 pre-install:
 	@${MKDIR} ${STAGEDIR}${PREFIX}/libexec/nagios
 
diff --git a/net-mgmt/nagios-pf-plugin/files/patch-check_pf.c b/net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf.c
similarity index 100%
rename from net-mgmt/nagios-pf-plugin/files/patch-check_pf.c
rename to net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf.c
diff --git a/net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf_15.c b/net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf_15.c
new file mode 100644
index 000000000000..00f5f9fa4959
--- /dev/null
+++ b/net-mgmt/nagios-pf-plugin/files/extra-patch-check_pf_15.c
@@ -0,0 +1,149 @@
+--- check_pf.c.orig	2012-07-30 18:13:57 UTC
++++ check_pf.c
+@@ -23,6 +23,7 @@
+ #include <net/pfvar.h>
+ 
+ #include <err.h>
++#include <libpfctl.h>
+ #include <limits.h>
+ #include <stdio.h>
+ #include <stdlib.h>
+@@ -60,16 +61,20 @@ main(int argc, char *argv[])
+ int 
+ main(int argc, char *argv[])
+ {
+-	struct pf_status    ps;
+-	struct pfioc_limit  pl;
++	struct pfctl_handle	*dev;
++	struct pfctl_status *ps;
+ 	const char          *errstr;
+ 	const char          *pf_device;
+ 	const char          *msg;
++	char                *pctindex;
+ 	float               percent;
+-	int                 ch, wflag, cflag, dev;
+-	int                 states_warning; 
+-	int                 states_critical;
++	int                 ch, wflag, cflag;
++	unsigned long       states_warning; 
++	unsigned long       states_critical;
++	int                 default_warn_percent=DEFAULT_WARN_PERCENT;
++	int                 default_crit_percent=DEFAULT_CRIT_PERCENT;
+ 	int                 ret;
++	unsigned int		pl;
+ 
+ 	pf_device = "/dev/pf"; 
+ 
+@@ -85,16 +90,30 @@ main(int argc, char *argv[])
+ 			help();
+ 			break;
+ 		case 'w':
+-			wflag = 1;
+-			states_warning = strtonum(optarg, 0, UINT_MAX, &errstr);
++			pctindex = strchr(optarg, '%');
++			if(pctindex) {
++				/* Ends in a %, treat as a percentage */
++				*pctindex = '\0';
++				default_warn_percent = strtonum(optarg, 0, 100, &errstr);
++			} else {
++				wflag = 1;
++				states_warning = strtonum(optarg, 0, UINT_MAX, &errstr);
++			}
+ 			if (errstr) {
+ 				printf("PF UNKNOWN - -w is %s: %s\n", errstr, optarg);
+ 				return (STATE_UNKNOWN);
+ 			}
+ 			break;
+ 		case 'c':
+-			cflag = 1;
+-			states_critical = strtonum(optarg, 0, UINT_MAX, &errstr);
++			pctindex = strchr(optarg, '%');
++			if(pctindex) {
++				/* Ends in a %, treat as a percentage */
++				*pctindex = '\0';
++				default_crit_percent = strtonum(optarg, 0, 100, &errstr);
++			} else {
++				cflag = 1;
++				states_critical = strtonum(optarg, 0, UINT_MAX, &errstr);
++			}
+ 			if (errstr) {
+ 				printf("PF UNKNOWN - -c is %s: %s\n", errstr, optarg);
+ 				return (STATE_UNKNOWN);
+@@ -107,48 +126,46 @@ main(int argc, char *argv[])
+ 	argc -= optind;
+ 	argv += optind;
+ 	
+-	dev = open(pf_device, O_RDONLY);
+-	if (dev == -1) {
++	dev = pfctl_open(pf_device);
++	if (dev == NULL) {
+ 		printf("PF UNKNOWN - open(\"%s\") failed\n", pf_device);
+ 		return (STATE_UNKNOWN);
+ 	}
+ 
+-	memset(&ps, 0, sizeof(struct pf_status));
+-	if (ioctl(dev, DIOCGETSTATUS, &ps) == -1) {
+-		printf("PF UNKNOWN - ioctl failed (DIOCGETSTATUS)\n");
++	ps = pfctl_get_status_h(dev);
++	if (ps  == NULL) {
++		printf("pfctl_get_status failure.\n");
+ 		return (STATE_UNKNOWN);
+ 	}
+ 
+-	memset(&pl, 0, sizeof(struct pfioc_limit));
+-	pl.index = PF_LIMIT_STATES;
+-	if (ioctl(dev, DIOCGETLIMIT, &pl) == -1) {
+-		printf("PF UNKNOWN - ioctl failed (DIOCGETLIMIT)\n");
++	if (pfctl_get_limit(dev,PF_LIMIT_STATES, &pl) != 0) {
++		printf("PF UNKNOWN - pfctl_get_limit failed\n");
+ 		return (STATE_UNKNOWN);
+ 	}
+ 
+ 	/* default thresholds will be based on the current state limit */
+ 	if (!wflag)
+-		states_warning = pl.limit * DEFAULT_WARN_PERCENT / 100;
++		states_warning = pl * default_warn_percent / 100;
+ 
+ 	if (!cflag)
+-		states_critical = pl.limit * DEFAULT_CRIT_PERCENT / 100;
++		states_critical = pl * default_crit_percent / 100;
+ 
+ 	if (states_warning >= states_critical) {
+ 		printf("PF UNKNOWN - <warning> must be less than <critical>\n");
+ 		return (STATE_UNKNOWN);
+ 	}
+ 
+-	percent = (float)ps.states / (float)pl.limit * 100.0;
++	percent = (float)ps->states / (float)pl * 100.0;
+ 
+-	if (ps.running != 1) {
++	if (ps->running != 1) {
+ 		printf("PF CRITICAL - status: Disabled\n");
+ 		return (STATE_CRITICAL);
+ 	}
+ 
+-	if (ps.states >= states_critical) {
++	if (ps->states >= states_critical) {
+ 		msg = "CRITICAL";
+ 		ret = STATE_CRITICAL;
+-	} else if (ps.states >= states_warning) {
++	} else if (ps->states >= states_warning) {
+ 		msg = "WARNING";
+ 		ret = STATE_WARNING;
+ 	} else {
+@@ -156,9 +173,12 @@ main(int argc, char *argv[])
+ 		ret = STATE_OK;
+ 	}
+ 
+-	printf("PF %s - states: %u (%.1f%% - limit: %u) | states=%u;%u;%u;%u;%u\n",
+-	    msg, ps.states, percent, pl.limit,
+-	    ps.states, states_warning, states_critical, 0, pl.limit);
++	printf("PF %s - states: %lu (%.1f%% - limit: %u) | states=%lu;%lu;%lu;%u;%u\n",
++	    msg, ps->states, percent, pl,
++	    ps->states, states_warning, states_critical, 0, pl);
++	
++	pfctl_free_status(ps);
++	pfctl_close(dev);
+ 
+ 	return (ret);
+ }
diff --git a/net-mgmt/nagios-pf-plugin/files/patch-Makefile b/net-mgmt/nagios-pf-plugin/files/patch-Makefile
index c43550e29c9d..59fed58ef520 100644
--- a/net-mgmt/nagios-pf-plugin/files/patch-Makefile
+++ b/net-mgmt/nagios-pf-plugin/files/patch-Makefile
@@ -1,7 +1,19 @@
 --- Makefile.orig	2012-07-30 18:13:57 UTC
 +++ Makefile
-@@ -14,7 +14,7 @@
- 	$(CC) $(CFLAGS) -o $(PROGRAM) $(PROGRAM).c
+@@ -4,17 +4,17 @@ CC = cc
+ #
+ 
+ CC = cc
+-CFLAGS  = -Wall
++CFLAGS  += -Wall
+ PROGRAM = check_pf
+ DESTDIR = /usr/local/libexec/nagios/
+ 
+ all:	$(PROGRAM)
+ 
+ $(PROGRAM):  
+-	$(CC) $(CFLAGS) -o $(PROGRAM) $(PROGRAM).c
++	$(CC) $(CFLAGS) -W$(LDFLAGS) -o $(PROGRAM) $(PROGRAM).c
  
  install:
 -	install -m 755 -o root -g wheel $(PROGRAM) $(DESTDIR)/$(PROGRAM)