From nobody Mon Sep 21 15:45:17 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hpSH15kSyz6sn60 for ; Mon, 21 Sep 2026 15:45:17 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hpSH138rZz4g58 for ; Mon, 21 Sep 2026 15:45:17 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790005517; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WbiMbWf89v4qDCeXbHH4WIdpV/Bh8yELbfuzA5PNT1c=; b=bqdud4WLM8Bo0rC6hNvutecbMF0o5A5PDQf5+CKaLfh7VQotZwsfVELX6lAd+ZOpd4p6uD yqFw1erJuzED3VoiWVBEPj5HDpUS14afpv+3cbCdk/QcrGAyO2jkoDr+9NZu+JPq4T3DBB QQ7+ZcinuTp7Wnq3A1+YHOhH5NkJoMfVHIWsZg/yHCm2gWZNtWC7eRYgKUK/rq8aFgywa5 tAqKzx1HA3moFbuGSJSnIx4U/JnrlUBrQ97Vd5jIBcqAx/i5eYiN7pITBpq/ThvjaTKYAe ihTknnuKv7S4IBT2oLgFKcpZIyW1MOiopn3wF/DcMtVW5bbAYMUneODQG5+j8Q== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790005517; b=g9NPpsLSkXZ7IqgFHqd3zwWZIjCqB3pfOepLduDVbct+J2SvM+zDIQZyzgJ+TgxKJn/u68 B+atGtJ2p5c5OlBNmvUUw4zc8PGBbTKtLBMNkj3vm2EwUfSUePFjSptnnJ4UKl0HQN0poU LIs8XTc6G++9A+5JhZDABX8WKe7Azy5uBaGFyRE9MezTc+RLBGpwMii/mkP6iIFEy7iNws LARq3mTrNFTgUnzCmfwdGim6Da2gw6mLdI9l/HLYGIYTM/lC+I21p+n8FebzLJKfIBbo2N Ori8qH10abNQk6pk+hipfb+wABQZNPxumSGOLy35TLOa9ZIlrgaC+YkxdH7MqQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790005517; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=WbiMbWf89v4qDCeXbHH4WIdpV/Bh8yELbfuzA5PNT1c=; b=r+2H4EnCGeuDbeqCFynzaH6NZpspWgIqPqZipiaMidp0xo0talTlWCyj+uxmBFSdH+9zO8 QjGfpCsxDGu9fRx7EH235IQ1r8FJpqS5G1tsYFiXQsYHDFEhfKqHeDrvcNyd/En0H5F2wP AOMFozNzMSyKJHlxN89Qg0Mu3Xk1LL7OaXOJw47eOLh0O+j/67AsVaqybTr4JwDnYixd6q lJNBtF9fkLYqxJm+paOIYJhbjNFcZ6X/3mpcDeQNHqe3yhQIjehd7gx5brZhJh248VHtA5 5v5WP4zqeXa9RBeL49d7tLnXPgbkPnIZ5BT0f2eiA6fWuVHElx8NqW3HJN9saw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hpSH11XSSzQyR for ; Mon, 21 Sep 2026 15:45:17 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 333af by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 21 Sep 2026 15:45:17 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: 6a34abbe9766 - main - pfsync: when importing a state clear take the interface name into account List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 6a34abbe976626019d61d9d08a624f4ed14ddbd0 Auto-Submitted: auto-generated Date: Mon, 21 Sep 2026 15:45:17 +0000 Message-Id: <6ab1510d.333af.69e452bb@gitrepo.freebsd.org> The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=6a34abbe976626019d61d9d08a624f4ed14ddbd0 commit 6a34abbe976626019d61d9d08a624f4ed14ddbd0 Author: Kristof Provost AuthorDate: 2026-09-21 11:39:39 +0000 Commit: Kristof Provost CommitDate: 2026-09-21 15:44:51 +0000 pfsync: when importing a state clear take the interface name into account When one pfsync host clears states it informs its peers about this. While processing such messages, in pfsync_in_clr() we failed to take the interface name into account. This meant that if one host cleared states on one interface the peers would clear all states, not just those on the affected interface. Actually check for the interface in pfsync_in_clr() Sponsored by: Rubicon Communications, LLC ("Netgate") --- sys/netpfil/pf/if_pfsync.c | 16 +++++--- tests/sys/netpfil/pf/pfsync.sh | 86 ++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 96 insertions(+), 6 deletions(-) diff --git a/sys/netpfil/pf/if_pfsync.c b/sys/netpfil/pf/if_pfsync.c index db7db987197b..b2b6217f530d 100644 --- a/sys/netpfil/pf/if_pfsync.c +++ b/sys/netpfil/pf/if_pfsync.c @@ -1143,6 +1143,7 @@ static int pfsync_in_clr(struct mbuf *m, int offset, int count, int flags, int action) { struct pfsync_clr *clr; + struct pfi_kkif *kif = NULL; struct mbuf *mp; int len = sizeof(*clr) * count; int i, offp; @@ -1159,7 +1160,7 @@ pfsync_in_clr(struct mbuf *m, int offset, int count, int flags, int action) creatorid = clr[i].creatorid; if (clr[i].ifname[0] != '\0' && - pfi_kkif_find(clr[i].ifname) == NULL) + (kif = pfi_kkif_find(clr[i].ifname)) == NULL) continue; for (int i = 0; i <= V_pf_hashmask; i++) { @@ -1168,11 +1169,14 @@ pfsync_in_clr(struct mbuf *m, int offset, int count, int flags, int action) relock: PF_HASHROW_LOCK(ih); LIST_FOREACH(s, &ih->states, entry) { - if (s->creatorid == creatorid) { - s->state_flags |= PFSTATE_NOSYNC; - pf_remove_state(s); - goto relock; - } + if (s->creatorid != creatorid) + continue; + if (kif != NULL && kif != s->kif) + continue; + + s->state_flags |= PFSTATE_NOSYNC; + pf_remove_state(s); + goto relock; } PF_HASHROW_UNLOCK(ih); } diff --git a/tests/sys/netpfil/pf/pfsync.sh b/tests/sys/netpfil/pf/pfsync.sh index c68a280c362a..c3914383a627 100644 --- a/tests/sys/netpfil/pf/pfsync.sh +++ b/tests/sys/netpfil/pf/pfsync.sh @@ -1657,6 +1657,91 @@ rt_af_cleanup() pfsynct_cleanup } +atf_test_case "flush_by_intf" "cleanup" +flush_by_intf_head() +{ + atf_set descr 'Test flushing states by interface' + atf_set require.user root +} + +flush_by_intf_body() +{ + pfsynct_init + + epair_sync=$(vnet_mkepair) + epair_one=$(vnet_mkepair) + epair_two=$(vnet_mkepair) + + vnet_mkjail one ${epair_one}a ${epair_sync}a + vnet_mkjail two ${epair_two}a ${epair_sync}b + + # pfsync interface + jexec one ifconfig ${epair_sync}a 192.0.2.1/24 up + jexec one ifconfig ${epair_one}a name epair_foo + jexec one ifconfig epair_foo 198.51.100.1/24 up + jexec one ifconfig pfsync0 \ + syncdev ${epair_sync}a \ + maxupd 1 \ + up + jexec two ifconfig ${epair_sync}b 192.0.2.2/24 up + jexec two ifconfig ${epair_two}a name epair_foo + jexec two ifconfig epair_foo 198.51.100.2/24 up + jexec two ifconfig pfsync0 \ + syncdev ${epair_sync}b \ + maxupd 1 \ + up + + jexec one pfctl -e + pft_set_rules one \ + "set state-policy if-bound" \ + "set skip on ${epair_sync}a" \ + "pass out keep state" + jexec two pfctl -e + pft_set_rules two \ + "set state-policy if-bound" \ + "set skip on ${epair_sync}b" \ + "pass out keep state" + + ifconfig ${epair_one}b 198.51.100.254/24 up + + ping -c 1 -S 198.51.100.254 198.51.100.1 + + # Give pfsync time to do its thing + sleep 2 + + if ! jexec two pfctl -s states | grep icmp | grep 198.51.100.1 | \ + grep 198.51.100.254 ; then + atf_fail "state not found on synced host" + fi + + # Now flush states in one, with an interface specified + # (Note the interface must exist on both hosts for the bug to manifest) + jexec one pfctl -i lo0 -Fs + + sleep 2 + + if ! jexec two pfctl -s states | grep icmp | grep 198.51.100.1 | \ + grep 198.51.100.254 ; then + atf_fail "state was removed on synced host!" + fi + + # Now flush on the interface the state is actually on, this should get passed to + # the peer. + jexec one pfctl -i epair_foo -Fs + + sleep 2 + + if jexec two pfctl -s states | grep icmp | grep 198.51.100.1 | \ + grep 198.51.100.254 ; then + atf_fail "state was not removed on synced host!" + fi +} + +flush_by_intf_cleanup() +{ + pfsynct_cleanup +} + atf_init_test_cases() { atf_add_test_case "basic" @@ -1681,4 +1766,5 @@ atf_init_test_cases() atf_add_test_case "tag" atf_add_test_case "altq_queues" atf_add_test_case "rt_af" + atf_add_test_case "flush_by_intf" }