git: 219ce3063840 - main - pf: convert DIOCRINADEFINE to netlink
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 25 Sep 2026 15:45:53 UTC
The branch main has been updated by kp:
URL: https://cgit.FreeBSD.org/src/commit/?id=219ce30638405481cf56ebc6921ac891ce9f9909
commit 219ce30638405481cf56ebc6921ac891ce9f9909
Author: Kristof Provost <kp@FreeBSD.org>
AuthorDate: 2026-09-23 15:42:44 +0000
Commit: Kristof Provost <kp@FreeBSD.org>
CommitDate: 2026-09-25 15:45:43 +0000
pf: convert DIOCRINADEFINE to netlink
Sponsored by: Rubicon Communications, LLC ("Netgate")
---
lib/libpfctl/libpfctl.c | 94 ++++++++++++++++++++++++++++++++++++++++++++++++
lib/libpfctl/libpfctl.h | 3 ++
sbin/pfctl/pfctl.c | 2 +-
sbin/pfctl/pfctl_radix.c | 29 ---------------
sbin/pfctl/pfctl_table.c | 4 +--
sys/netpfil/pf/pf_nl.c | 63 ++++++++++++++++++++++++++++++++
sys/netpfil/pf/pf_nl.h | 11 ++++++
7 files changed, 174 insertions(+), 32 deletions(-)
diff --git a/lib/libpfctl/libpfctl.c b/lib/libpfctl/libpfctl.c
index 50d85a7869c9..c9b27e4f5cbe 100644
--- a/lib/libpfctl/libpfctl.c
+++ b/lib/libpfctl/libpfctl.c
@@ -4051,6 +4051,100 @@ pfctl_test_addrs(struct pfctl_handle *h, const struct pfr_table *tbl,
return (ret);
}
+struct nl_ina_define {
+ uint32_t nadd;
+ uint32_t naddr;
+};
+
+#define _OUT(_field) offsetof(struct nl_ina_define, _field)
+static struct snl_attr_parser ap_ina_define[] = {
+ { .type = PF_ID_NADD, .off = _OUT(nadd), .cb = snl_attr_get_uint32 },
+ { .type = PF_ID_NADDR, .off = _OUT(naddr), .cb = snl_attr_get_uint32 },
+};
+#undef _OUT
+SNL_DECLARE_PARSER(ina_define_parser, struct genlmsghdr, snl_f_p_empty, ap_ina_define);
+
+static int
+_pfctl_ina_define(struct pfctl_handle *h, struct pfr_table *tbl,
+ struct pfr_addr *addr, int size, int *nadd, int *naddr,
+ int ticket, int flags)
+{
+ struct snl_writer nw;
+ struct snl_errmsg_data e = {};
+ struct nlmsghdr *hdr;
+ struct nl_ina_define attrs = {};
+ uint32_t seq_id;
+
+ assert(size <= 256);
+
+ snl_init_writer(&h->ss, &nw);
+ hdr = snl_create_genl_msg_request(&nw, h->family_id,
+ PFNL_CMD_INA_DEFINE);
+
+ snl_add_msg_attr_table(&nw, PF_ID_TABLE, tbl);
+ snl_add_msg_attr_u32(&nw, PF_ID_TICKET, ticket);
+ snl_add_msg_attr_u32(&nw, PF_ID_FLAGS, flags);
+ for (int i = 0; i < size; i++)
+ snl_add_msg_attr_pfr_addr(&nw, PF_ID_ADDR, &addr[i]);
+
+ if ((hdr = snl_finalize_msg(&nw)) == NULL) {
+ e.error = ENXIO;
+ goto out;
+ }
+
+ seq_id = hdr->nlmsg_seq;
+
+ if (! snl_send_message(&h->ss, hdr)) {
+ e.error = ENXIO;
+ goto out;
+ }
+
+ while ((hdr = snl_read_reply_multi(&h->ss, seq_id, &e)) != NULL) {
+ if (! snl_parse_nlmsg(&h->ss, hdr, &ina_define_parser, &attrs))
+ continue;
+ }
+
+ if (*nadd)
+ *nadd = attrs.nadd;
+ if (*naddr)
+ *naddr = attrs.naddr;
+
+out:
+ snl_clear_lb(&h->ss);
+ return (e.error);
+}
+
+int
+pfctl_ina_define(struct pfctl_handle *h, struct pfr_table *tbl,
+ struct pfr_addr *addr, int size, int *nadd, int *naddr,
+ int ticket, int flags)
+{
+ int ret;
+ int off = 0;
+ int partial_add, partial_addr;
+ int chunk_size;
+
+ if (nadd)
+ *nadd = 0;
+ if (naddr)
+ *naddr = 0;
+
+ do {
+ chunk_size = MIN(size - off, 256);
+ ret = _pfctl_ina_define(h, tbl, &addr[off], chunk_size,
+ &partial_add, &partial_addr, ticket, flags);
+ if (ret != 0)
+ break;
+ if (nadd)
+ *nadd += partial_add;
+ if (naddr)
+ *naddr += partial_addr;
+ off += chunk_size;
+ } while (off < size);
+
+ return (ret);
+}
+
static void
snl_add_msg_attr_limit_rate(struct snl_writer *nw, uint32_t type,
const struct pfctl_limit_rate *rate)
diff --git a/lib/libpfctl/libpfctl.h b/lib/libpfctl/libpfctl.h
index 3080209ec7a0..b6efea7a1961 100644
--- a/lib/libpfctl/libpfctl.h
+++ b/lib/libpfctl/libpfctl.h
@@ -601,6 +601,9 @@ int pfctl_clr_astats(struct pfctl_handle *h, const struct pfr_table *tbl,
struct pfr_addr *addr, int size, int *nzero, int flags);
int pfctl_test_addrs(struct pfctl_handle *h, const struct pfr_table *tbl,
struct pfr_addr *addr, int size, int *nmatch, int flags);
+int pfctl_ina_define(struct pfctl_handle *h, struct pfr_table *tbl,
+ struct pfr_addr *addr, int size, int *nadd, int *naddr,
+ int ticket, int flags);
struct pfctl_limit_rate {
unsigned int limit;
diff --git a/sbin/pfctl/pfctl.c b/sbin/pfctl/pfctl.c
index b650c2fcba0d..146a1241d78d 100644
--- a/sbin/pfctl/pfctl.c
+++ b/sbin/pfctl/pfctl.c
@@ -2471,7 +2471,7 @@ pfctl_load_tables(struct pfctl *pf, char *path, struct pfctl_anchor *a,
path, anchor_path);
}
ukt = (struct pfr_uktable *)kt;
- e = pfr_ina_define(&ukt->pfrukt_t, ukt->pfrukt_addrs.pfrb_caddr,
+ e = pfctl_ina_define(pfh, &ukt->pfrukt_t, ukt->pfrukt_addrs.pfrb_caddr,
ukt->pfrukt_addrs.pfrb_size, NULL, NULL,
pf->anchor->ruleset.tticket,
ukt->pfrukt_init_addr ? PFR_FLAG_ADDRSTOO : 0);
diff --git a/sbin/pfctl/pfctl_radix.c b/sbin/pfctl/pfctl_radix.c
index db6153941cca..d99923e4fb67 100644
--- a/sbin/pfctl/pfctl_radix.c
+++ b/sbin/pfctl/pfctl_radix.c
@@ -235,35 +235,6 @@ pfr_tst_addrs(struct pfr_table *tbl, struct pfr_addr *addr, int size,
return (ret);
}
-int
-pfr_ina_define(struct pfr_table *tbl, struct pfr_addr *addr, int size,
- int *nadd, int *naddr, int ticket, int flags)
-{
- struct pfioc_table io;
-
- if (tbl == NULL || size < 0 || (size && addr == NULL)) {
- DBGPRINT("%s %p %d %p\n", __func__, tbl, size, addr);
- errno = EINVAL;
- return (-1);
- }
- bzero(&io, sizeof io);
- io.pfrio_flags = flags;
- io.pfrio_table = *tbl;
- io.pfrio_buffer = addr;
- io.pfrio_esize = sizeof(*addr);
- io.pfrio_size = size;
- io.pfrio_ticket = ticket;
- if (ioctl(dev, DIOCRINADEFINE, &io)) {
- pfr_report_error(tbl, &io, "define inactive set table");
- return (-1);
- }
- if (nadd != NULL)
- *nadd = io.pfrio_nadd;
- if (naddr != NULL)
- *naddr = io.pfrio_naddr;
- return (0);
-}
-
/* interface management code */
int
diff --git a/sbin/pfctl/pfctl_table.c b/sbin/pfctl/pfctl_table.c
index 1af1538387c7..c1fc7899efe1 100644
--- a/sbin/pfctl/pfctl_table.c
+++ b/sbin/pfctl/pfctl_table.c
@@ -615,8 +615,8 @@ pfctl_define_table(char *name, int flags, int addrs, const char *anchor,
if (ukt != NULL)
return (0);
- return (pfr_ina_define(tbl, ab->pfrb_caddr, ab->pfrb_size, NULL, NULL,
- ticket, addrs ? PFR_FLAG_ADDRSTOO : 0));
+ return (pfctl_ina_define(pfh, tbl, ab->pfrb_caddr, ab->pfrb_size, NULL,
+ NULL, ticket, addrs ? PFR_FLAG_ADDRSTOO : 0));
}
void
diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
index ef047da9965b..c1c34451e73c 100644
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -2885,6 +2885,60 @@ pf_handle_source_clear(struct nlmsghdr *hdr, struct nl_pstate *npt)
return (error);
}
+struct nl_parsed_ina_define {
+ struct pfr_table table;
+ struct nl_parsed_table_addrs addrs;
+ size_t addr_count;
+ uint32_t ticket;
+ uint32_t flags;
+};
+
+#define _OUT(_field) offsetof(struct nl_parsed_ina_define, _field)
+static const struct nlattr_parser nla_ina_define_parser[] = {
+ { .type = PF_ID_TABLE, .off = _OUT(table), .arg = &nested_table_parser, .cb = nlattr_get_nested },
+ { .type = PF_ID_TICKET, .off = _OUT(ticket), .cb = nlattr_get_uint32 },
+ { .type = PF_ID_FLAGS, .off = _OUT(flags), .cb = nlattr_get_uint32 },
+ { .type = PF_ID_ADDR, .off = _OUT(addrs), .cb = nlattr_get_pfr_addr },
+};
+NL_DECLARE_PARSER(ina_define_parser, struct genlmsghdr, nlf_p_empty, nla_ina_define_parser);
+
+static int
+pf_handle_ina_define(struct nlmsghdr *hdr, struct nl_pstate *npt)
+{
+ struct nl_parsed_ina_define attrs = { 0 };
+ struct nl_writer *nw = npt->nw;
+ struct genlmsghdr *ghdr_new;
+ int nadd, naddr;
+ int error;
+
+ error = nl_parse_nlmsg(hdr, &ina_define_parser, npt, &attrs);
+ if (error != 0)
+ return (error);
+
+ PF_RULES_WLOCK();
+ error = pfr_ina_define(&attrs.table, attrs.addrs.addrs,
+ attrs.addrs.addr_count, &nadd, &naddr,
+ attrs.ticket, attrs.flags | PFR_FLAG_USERIOCTL);
+ PF_RULES_WUNLOCK();
+
+ if (error != 0)
+ return (error);
+
+ if (!nlmsg_reply(nw, hdr, sizeof(struct genlmsghdr)))
+ return (ENOMEM);
+
+ ghdr_new = nlmsg_reserve_object(nw, struct genlmsghdr);
+ ghdr_new->cmd = PFNL_CMD_INA_DEFINE;
+
+ nlattr_add_u32(nw, PF_ID_NADD, nadd);
+ nlattr_add_u32(nw, PF_ID_NADDR, naddr);
+
+ if (!nlmsg_end(nw))
+ return (ENOMEM);
+
+ return (0);
+}
+
static const struct nlhdr_parser *all_parsers[] = {
&state_parser,
&addrule_parser,
@@ -2905,6 +2959,7 @@ static const struct nlhdr_parser *all_parsers[] = {
&source_limiter_parser,
&source_parser,
&source_clear_parser,
+ &ina_define_parser,
};
static uint16_t family_id;
@@ -3286,6 +3341,14 @@ static const struct genl_cmd pf_cmds[] = {
.cmd_priv = PRIV_NETINET_PF,
.cmd_securelevel = 4,
},
+ {
+ .cmd_num = PFNL_CMD_INA_DEFINE,
+ .cmd_name = "INA_DEFINE",
+ .cmd_cb = pf_handle_ina_define,
+ .cmd_flags = GENL_CMD_CAP_DO | GENL_CMD_CAP_HASPOL,
+ .cmd_priv = PRIV_NETINET_PF,
+ .cmd_securelevel = 3,
+ },
};
void
diff --git a/sys/netpfil/pf/pf_nl.h b/sys/netpfil/pf/pf_nl.h
index 4d0186ea86a5..d730fc12da5a 100644
--- a/sys/netpfil/pf/pf_nl.h
+++ b/sys/netpfil/pf/pf_nl.h
@@ -83,6 +83,7 @@ enum {
PFNL_CMD_SOURCE_NGET = 45,
PFNL_CMD_SOURCE_CLEAR = 46,
PFNL_CMD_TABLE_TEST_ADDRS = 47,
+ PFNL_CMD_INA_DEFINE = 48,
__PFNL_CMD_MAX,
};
#define PFNL_CMD_MAX (__PFNL_CMD_MAX -1)
@@ -593,6 +594,16 @@ enum pf_source_clear_t {
PF_SC_ADDR = 5, /* in6_addr */
};
+enum pf_ina_define_t {
+ PF_ID_UNSPEC,
+ PF_ID_TABLE = 1, /* pfr_table */
+ PF_ID_TICKET = 2, /* u32 */
+ PF_ID_FLAGS = 3, /* u32 */
+ PF_ID_ADDR = 4, /* pfr_addr */
+ PF_ID_NADD = 5, /* u32 */
+ PF_ID_NADDR = 6, /* u32 */
+};
+
#ifdef _KERNEL
void pf_nl_register(void);