git: 75c0a8376204 - main - pf: convert DIOCOSFPFLUSH DIOCOSFPGET DIOCOSFPADD to netlink
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Fri, 25 Sep 2026 15:45:56 UTC
The branch main has been updated by kp:
URL: https://cgit.FreeBSD.org/src/commit/?id=75c0a83762047c6c95c4bdd6b07bad005dc1d99e
commit 75c0a83762047c6c95c4bdd6b07bad005dc1d99e
Author: Kristof Provost <kp@FreeBSD.org>
AuthorDate: 2026-09-24 17:20:15 +0000
Commit: Kristof Provost <kp@FreeBSD.org>
CommitDate: 2026-09-25 15:45:43 +0000
pf: convert DIOCOSFPFLUSH DIOCOSFPGET DIOCOSFPADD to netlink
Sponsored by: Rubicon Communications, LLC ("Netgate")
---
lib/libpfctl/libpfctl.c | 134 +++++++++++++++++++++++++++++++++++++++++
lib/libpfctl/libpfctl.h | 4 ++
sbin/pfctl/parse.y | 2 +-
sbin/pfctl/pfctl_osfp.c | 11 ++--
sbin/pfctl/pfctl_parser.h | 2 +-
sys/netpfil/pf/pf_nl.c | 149 ++++++++++++++++++++++++++++++++++++++++++++++
sys/netpfil/pf/pf_nl.h | 21 +++++++
7 files changed, 315 insertions(+), 8 deletions(-)
diff --git a/lib/libpfctl/libpfctl.c b/lib/libpfctl/libpfctl.c
index c9b27e4f5cbe..26fcb6f50045 100644
--- a/lib/libpfctl/libpfctl.c
+++ b/lib/libpfctl/libpfctl.c
@@ -4477,6 +4477,140 @@ out:
return (e.error);
}
+int
+pfctl_flush_fingerprints(struct pfctl_handle *h)
+{
+ struct snl_writer nw;
+ struct snl_errmsg_data e = {};
+ struct nlmsghdr *hdr;
+ uint32_t seq_id;
+
+ snl_init_writer(&h->ss, &nw);
+ hdr = snl_create_genl_msg_request(&nw, h->family_id,
+ PFNL_CMD_OSFP_FLUSH);
+
+ if ((hdr = snl_finalize_msg(&nw)) == NULL) {
+ e.error = ENXIO;
+ goto out;
+ }
+
+ seq_id = hdr->nlmsg_seq;
+
+ if (! snl_send_message(&h->ss, hdr)) {
+ e.error = ENXIO;
+ goto out;
+ }
+
+ while ((hdr = snl_read_reply_multi(&h->ss, seq_id, &e)) != NULL) {
+ }
+
+out:
+ snl_clear_lb(&h->ss);
+ return (e.error);
+}
+
+#define _OUT(_field) offsetof(struct pf_osfp_ioctl, _field)
+static struct snl_attr_parser ap_osfp[] = {
+ { .type = PF_OFP_IDX, .off = _OUT(fp_getnum), .cb = snl_attr_get_uint32 },
+ { .type = PF_OFP_OS_OS, .off = _OUT(fp_os.fp_os), .cb = snl_attr_get_uint32 },
+ { .type = PF_OFP_OS_ENFLAGS, .off = _OUT(fp_os.fp_enflags), .cb = snl_attr_get_uint32 },
+ { .type = PF_OFP_OS_CLASS, .off = _OUT(fp_os.fp_class_nm), .arg_u32 = PF_OSFP_LEN, .cb = snl_attr_copy_string},
+ { .type = PF_OFP_OS_VERSION, .off = _OUT(fp_os.fp_version_nm), .arg_u32 = PF_OSFP_LEN, .cb = snl_attr_copy_string },
+ { .type = PF_OFP_OS_SUBTYPE, .off = _OUT(fp_os.fp_subtype_nm), .arg_u32 = PF_OSFP_LEN, .cb = snl_attr_copy_string },
+ { .type = PF_OFP_TCPOPTS, .off = _OUT(fp_tcpopts), .cb = snl_attr_get_uint64 },
+ { .type = PF_OFP_WSIZE, .off = _OUT(fp_wsize), .cb = snl_attr_get_uint16 },
+ { .type = PF_OFP_PSIZE, .off = _OUT(fp_psize), .cb = snl_attr_get_uint16 },
+ { .type = PF_OFP_MSS, .off = _OUT(fp_mss), .cb = snl_attr_get_uint16 },
+ { .type = PF_OFP_FLAGS, .off = _OUT(fp_flags), .cb = snl_attr_get_uint16 },
+ { .type = PF_OFP_OPTCNT, .off = _OUT(fp_optcnt), .cb = snl_attr_get_uint8 },
+ { .type = PF_OFP_WSCALE, .off = _OUT(fp_wscale), .cb = snl_attr_get_uint8 },
+ { .type = PF_OFP_TTL, .off = _OUT(fp_ttl), .cb = snl_attr_get_uint8 },
+};
+#undef _OUT
+SNL_DECLARE_PARSER(osfp_parser, struct genlmsghdr, snl_f_p_empty, ap_osfp);
+
+int
+pfctl_get_fingerprint(struct pfctl_handle *h, int idx, struct pf_osfp_ioctl *fp)
+{
+ struct snl_writer nw;
+ struct snl_errmsg_data e = {};
+ struct nlmsghdr *hdr;
+ uint32_t seq_id;
+
+ snl_init_writer(&h->ss, &nw);
+ hdr = snl_create_genl_msg_request(&nw, h->family_id,
+ PFNL_CMD_OSFP_GET);
+
+ snl_add_msg_attr_u32(&nw, PF_OFP_IDX, idx);
+
+ if ((hdr = snl_finalize_msg(&nw)) == NULL) {
+ e. error = ENXIO;
+ goto out;
+ }
+
+ seq_id = hdr->nlmsg_seq;
+
+ if (! snl_send_message(&h->ss, hdr)) {
+ e.error = ENXIO;
+ goto out;
+ }
+
+ while ((hdr = snl_read_reply_multi(&h->ss, seq_id, &e)) != NULL) {
+ if (! snl_parse_nlmsg(&h->ss, hdr, &osfp_parser, fp))
+ continue;
+ }
+
+out:
+ snl_clear_lb(&h->ss);
+ return (e.error);
+}
+
+int
+pfctl_add_fingerprint(struct pfctl_handle *h, struct pf_osfp_ioctl *fp)
+{
+ struct snl_writer nw;
+ struct snl_errmsg_data e = {};
+ struct nlmsghdr *hdr;
+ uint32_t seq_id;
+
+ snl_init_writer(&h->ss, &nw);
+ hdr = snl_create_genl_msg_request(&nw, h->family_id,
+ PFNL_CMD_OSFP_ADD);
+
+ snl_add_msg_attr_u32(&nw, PF_OFP_OS_OS, fp->fp_os.fp_os);
+ snl_add_msg_attr_u32(&nw, PF_OFP_OS_ENFLAGS, fp->fp_os.fp_enflags);
+ snl_add_msg_attr_string(&nw, PF_OFP_OS_CLASS, fp->fp_os.fp_class_nm);
+ snl_add_msg_attr_string(&nw, PF_OFP_OS_VERSION, fp->fp_os.fp_version_nm);
+ snl_add_msg_attr_string(&nw, PF_OFP_OS_SUBTYPE, fp->fp_os.fp_subtype_nm);
+ snl_add_msg_attr_u64(&nw, PF_OFP_TCPOPTS, fp->fp_tcpopts);
+ snl_add_msg_attr_u16(&nw, PF_OFP_WSIZE, fp->fp_wsize);
+ snl_add_msg_attr_u16(&nw, PF_OFP_PSIZE, fp->fp_psize);
+ snl_add_msg_attr_u16(&nw, PF_OFP_MSS, fp->fp_mss);
+ snl_add_msg_attr_u16(&nw, PF_OFP_FLAGS, fp->fp_flags);
+ snl_add_msg_attr_u8(&nw, PF_OFP_OPTCNT, fp->fp_optcnt);
+ snl_add_msg_attr_u8(&nw, PF_OFP_WSCALE, fp->fp_wscale);
+ snl_add_msg_attr_u8(&nw, PF_OFP_TTL, fp->fp_ttl);
+
+ if ((hdr = snl_finalize_msg(&nw)) == NULL) {
+ e. error = ENXIO;
+ goto out;
+ }
+
+ seq_id = hdr->nlmsg_seq;
+
+ if (! snl_send_message(&h->ss, hdr)) {
+ e.error = ENXIO;
+ goto out;
+ }
+
+ while ((hdr = snl_read_reply_multi(&h->ss, seq_id, &e)) != NULL) {
+ }
+
+out:
+ snl_clear_lb(&h->ss);
+ return (e.error);
+}
+
static const struct snl_hdr_parser *all_parsers[] = {
&begin_addrs_parser,
&clear_states_parser,
diff --git a/lib/libpfctl/libpfctl.h b/lib/libpfctl/libpfctl.h
index b6efea7a1961..ef73d0469236 100644
--- a/lib/libpfctl/libpfctl.h
+++ b/lib/libpfctl/libpfctl.h
@@ -704,4 +704,8 @@ struct pfctl_source_clear {
};
int pfctl_source_clear(struct pfctl_handle *h, struct pfctl_source_clear *);
+int pfctl_flush_fingerprints(struct pfctl_handle *h);
+int pfctl_get_fingerprint(struct pfctl_handle *h, int idx, struct pf_osfp_ioctl *fp);
+int pfctl_add_fingerprint(struct pfctl_handle *h, struct pf_osfp_ioctl *fp);
+
#endif
diff --git a/sbin/pfctl/parse.y b/sbin/pfctl/parse.y
index 7e9d81da6ed9..1505e566f3ba 100644
--- a/sbin/pfctl/parse.y
+++ b/sbin/pfctl/parse.y
@@ -6953,7 +6953,7 @@ expand_rule(struct pfctl_rule *r, bool keeprule,
}
if (src_os && src_os->os) {
- r->os_fingerprint = pfctl_get_fingerprint(src_os->os);
+ r->os_fingerprint = pfctl_find_fingerprint(src_os->os);
if ((pf->opts & PF_OPT_VERBOSE2) &&
r->os_fingerprint == PF_OSFP_NOMATCH)
fprintf(stderr,
diff --git a/sbin/pfctl/pfctl_osfp.c b/sbin/pfctl/pfctl_osfp.c
index 5770c8343a46..b1c1908cb3fc 100644
--- a/sbin/pfctl/pfctl_osfp.c
+++ b/sbin/pfctl/pfctl_osfp.c
@@ -263,7 +263,7 @@ pfctl_file_fingerprints(int dev, int opts, const char *fp_filename)
void
pfctl_clear_fingerprints(int dev, int opts)
{
- if (ioctl(dev, DIOCOSFPFLUSH))
+ if (pfctl_flush_fingerprints(pfh) != 0)
pfctl_err(opts, 1, "DIOCOSFPFLUSH");
}
@@ -293,9 +293,8 @@ pfctl_load_fingerprints(int dev, int opts)
for (i = 0; i >= 0; i++) {
memset(&io, 0, sizeof(io));
- io.fp_getnum = i;
- if (ioctl(dev, DIOCOSFPGET, &io)) {
- if (errno == EBUSY)
+ if ((errno = pfctl_get_fingerprint(pfh, i, &io)) != 0) {
+ if (errno == ENOENT)
break;
warn("DIOCOSFPGET");
return (1);
@@ -324,7 +323,7 @@ pfctl_show_fingerprints(int opts)
/* Lookup a fingerprint */
pf_osfp_t
-pfctl_get_fingerprint(const char *name)
+pfctl_find_fingerprint(const char *name)
{
struct name_entry *nm, *class_nm, *version_nm, *subtype_nm;
pf_osfp_t ret = PF_OSFP_NOMATCH;
@@ -628,7 +627,7 @@ add_fingerprint(int dev, int opts, struct pf_osfp_ioctl *fp)
/* Linked to the sys/net/pf_osfp.c. Call pf_osfp_add() */
if ((errno = pf_osfp_add(fp)))
#else
- if ((opts & PF_OPT_NOACTION) == 0 && ioctl(dev, DIOCOSFPADD, fp))
+ if ((opts & PF_OPT_NOACTION) == 0 && (errno = pfctl_add_fingerprint(pfh, fp)) != 0)
#endif /* FAKE_PF_KERNEL */
{
if (errno == EEXIST) {
diff --git a/sbin/pfctl/pfctl_parser.h b/sbin/pfctl/pfctl_parser.h
index 631a6b9a32ea..5b2ff95f88c9 100644
--- a/sbin/pfctl/pfctl_parser.h
+++ b/sbin/pfctl/pfctl_parser.h
@@ -368,7 +368,7 @@ int pfctl_define_table(char *, int, int, const char *, struct pfr_buffer *,
void pfctl_clear_fingerprints(int, int);
int pfctl_file_fingerprints(int, int, const char *);
-pf_osfp_t pfctl_get_fingerprint(const char *);
+pf_osfp_t pfctl_find_fingerprint(const char *);
int pfctl_load_fingerprints(int, int);
char *pfctl_lookup_fingerprint(pf_osfp_t, char *, size_t);
void pfctl_show_fingerprints(int);
diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
index c1c34451e73c..2f99d1e7c845 100644
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -2900,6 +2900,7 @@ static const struct nlattr_parser nla_ina_define_parser[] = {
{ .type = PF_ID_FLAGS, .off = _OUT(flags), .cb = nlattr_get_uint32 },
{ .type = PF_ID_ADDR, .off = _OUT(addrs), .cb = nlattr_get_pfr_addr },
};
+#undef _OUT
NL_DECLARE_PARSER(ina_define_parser, struct genlmsghdr, nlf_p_empty, nla_ina_define_parser);
static int
@@ -2939,6 +2940,129 @@ pf_handle_ina_define(struct nlmsghdr *hdr, struct nl_pstate *npt)
return (0);
}
+static int
+pf_handle_osfp_flush(struct nlmsghdr *hdr, struct nl_pstate *npt)
+{
+ struct nl_writer *nw = npt->nw;
+ struct genlmsghdr *ghdr_new;
+
+ PF_RULES_WLOCK();
+ pf_osfp_flush();
+ PF_RULES_WUNLOCK();
+
+ if (!nlmsg_reply(nw, hdr, sizeof(struct genlmsghdr)))
+ return (ENOMEM);
+
+ ghdr_new = nlmsg_reserve_object(nw, struct genlmsghdr);
+ ghdr_new->cmd = PFNL_CMD_OSFP_FLUSH;
+
+ if (!nlmsg_end(nw))
+ return (ENOMEM);
+
+ return (0);
+}
+
+#define _OUT(_field) offsetof(struct pf_osfp_ioctl, _field)
+static const struct nlattr_parser nla_osfp_parser[] = {
+ { .type = PF_OFP_IDX, .off = _OUT(fp_getnum), .cb = nlattr_get_uint32 },
+ { .type = PF_OFP_OS_OS, .off = _OUT(fp_os.fp_os), .cb = nlattr_get_uint32 },
+ { .type = PF_OFP_OS_ENFLAGS, .off = _OUT(fp_os.fp_enflags), .cb = nlattr_get_uint32 },
+ { .type = PF_OFP_OS_CLASS, .off = _OUT(fp_os.fp_class_nm), .arg = (void *)PF_OSFP_LEN, .cb = nlattr_get_chara },
+ { .type = PF_OFP_OS_VERSION, .off = _OUT(fp_os.fp_version_nm), .arg = (void *)PF_OSFP_LEN, .cb = nlattr_get_chara },
+ { .type = PF_OFP_OS_SUBTYPE, .off = _OUT(fp_os.fp_subtype_nm), .arg = (void *)PF_OSFP_LEN, .cb = nlattr_get_chara },
+ { .type = PF_OFP_TCPOPTS, .off = _OUT(fp_tcpopts), .cb = nlattr_get_uint64 },
+ { .type = PF_OFP_WSIZE, .off = _OUT(fp_wsize), .cb = nlattr_get_uint16 },
+ { .type = PF_OFP_PSIZE, .off = _OUT(fp_psize), .cb = nlattr_get_uint16 },
+ { .type = PF_OFP_MSS, .off = _OUT(fp_mss), .cb = nlattr_get_uint16 },
+ { .type = PF_OFP_FLAGS, .off = _OUT(fp_flags), .cb = nlattr_get_uint16 },
+ { .type = PF_OFP_OPTCNT, .off = _OUT(fp_optcnt), .cb = nlattr_get_uint8 },
+ { .type = PF_OFP_WSCALE, .off = _OUT(fp_wscale), .cb = nlattr_get_uint8 },
+ { .type = PF_OFP_TTL, .off = _OUT(fp_ttl), .cb = nlattr_get_uint8 },
+};
+#undef _OUT
+NL_DECLARE_PARSER(osfp_parser, struct genlmsghdr, nlf_p_empty, nla_osfp_parser);
+
+static int
+pf_handle_osfp_get(struct nlmsghdr *hdr, struct nl_pstate *npt)
+{
+ struct pf_osfp_ioctl attrs = {};
+ struct nl_writer *nw = npt->nw;
+ struct genlmsghdr *ghdr_new;
+ int error;
+
+ PF_RULES_RLOCK_TRACKER;
+
+ error = nl_parse_nlmsg(hdr, &osfp_parser, npt, &attrs);
+ if (error != 0)
+ return (error);
+
+ PF_RULES_RLOCK();
+ error = pf_osfp_get(&attrs);
+ PF_RULES_RUNLOCK();
+ if (error != 0) {
+ /*
+ * pf_osfp_get() returns EBUSY if the index is not found.
+ * Let's be a bit more sensible.
+ */
+ return (ENOENT);
+ }
+
+ if (!nlmsg_reply(nw, hdr, sizeof(struct genlmsghdr)))
+ return (ENOMEM);
+
+ ghdr_new = nlmsg_reserve_object(nw, struct genlmsghdr);
+ ghdr_new->cmd = PFNL_CMD_OSFP_GET;
+
+ nlattr_add_u32(nw, PF_OFP_OS_OS, attrs.fp_os.fp_os);
+ nlattr_add_u32(nw, PF_OFP_OS_ENFLAGS, attrs.fp_os.fp_enflags);
+ nlattr_add_string(nw, PF_OFP_OS_CLASS, attrs.fp_os.fp_class_nm);
+ nlattr_add_string(nw, PF_OFP_OS_VERSION, attrs.fp_os.fp_version_nm);
+ nlattr_add_string(nw, PF_OFP_OS_SUBTYPE, attrs.fp_os.fp_subtype_nm);
+ nlattr_add_u64(nw, PF_OFP_TCPOPTS, attrs.fp_tcpopts);
+ nlattr_add_u16(nw, PF_OFP_WSIZE, attrs.fp_wsize);
+ nlattr_add_u16(nw, PF_OFP_PSIZE, attrs.fp_psize);
+ nlattr_add_u16(nw, PF_OFP_MSS, attrs.fp_mss);
+ nlattr_add_u16(nw, PF_OFP_FLAGS, attrs.fp_flags);
+ nlattr_add_u8(nw, PF_OFP_OPTCNT, attrs.fp_optcnt);
+ nlattr_add_u8(nw, PF_OFP_WSCALE, attrs.fp_wscale);
+ nlattr_add_u8(nw, PF_OFP_TTL, attrs.fp_ttl);
+
+ if (!nlmsg_end(nw))
+ return (ENOMEM);
+
+ return (0);
+}
+
+static int
+pf_handle_osfp_add(struct nlmsghdr *hdr, struct nl_pstate *npt)
+{
+ struct pf_osfp_ioctl attrs = {};
+ struct nl_writer *nw = npt->nw;
+ struct genlmsghdr *ghdr_new;
+ int error;
+
+ error = nl_parse_nlmsg(hdr, &osfp_parser, npt, &attrs);
+ if (error != 0)
+ return (error);
+
+ PF_RULES_WLOCK();
+ error = pf_osfp_add(&attrs);
+ PF_RULES_WUNLOCK();
+ if (error != 0)
+ return (error);
+
+ if (!nlmsg_reply(nw, hdr, sizeof(struct genlmsghdr)))
+ return (ENOMEM);
+
+ ghdr_new = nlmsg_reserve_object(nw, struct genlmsghdr);
+ ghdr_new->cmd = PFNL_CMD_OSFP_ADD;
+
+ if (!nlmsg_end(nw))
+ return (ENOMEM);
+
+ return (0);
+}
+
static const struct nlhdr_parser *all_parsers[] = {
&state_parser,
&addrule_parser,
@@ -2960,6 +3084,7 @@ static const struct nlhdr_parser *all_parsers[] = {
&source_parser,
&source_clear_parser,
&ina_define_parser,
+ &osfp_parser,
};
static uint16_t family_id;
@@ -3349,6 +3474,30 @@ static const struct genl_cmd pf_cmds[] = {
.cmd_priv = PRIV_NETINET_PF,
.cmd_securelevel = 3,
},
+ {
+ .cmd_num = PFNL_CMD_OSFP_FLUSH,
+ .cmd_name = "OSFP_FLUSH",
+ .cmd_cb = pf_handle_osfp_flush,
+ .cmd_flags = GENL_CMD_CAP_DO | GENL_CMD_CAP_HASPOL,
+ .cmd_priv = PRIV_NETINET_PF,
+ .cmd_securelevel = 3,
+ },
+ {
+ .cmd_num = PFNL_CMD_OSFP_GET,
+ .cmd_name = "OSFP_GET",
+ .cmd_cb = pf_handle_osfp_get,
+ .cmd_flags = GENL_CMD_CAP_DUMP | GENL_CMD_CAP_HASPOL,
+ .cmd_priv = PRIV_NETINET_PF,
+ .cmd_securelevel = 3,
+ },
+ {
+ .cmd_num = PFNL_CMD_OSFP_ADD,
+ .cmd_name = "OSFP_ADD",
+ .cmd_cb = pf_handle_osfp_add,
+ .cmd_flags = GENL_CMD_CAP_DO | GENL_CMD_CAP_HASPOL,
+ .cmd_priv = PRIV_NETINET_PF,
+ .cmd_securelevel = 3,
+ },
};
void
diff --git a/sys/netpfil/pf/pf_nl.h b/sys/netpfil/pf/pf_nl.h
index d730fc12da5a..2b6785b6ffca 100644
--- a/sys/netpfil/pf/pf_nl.h
+++ b/sys/netpfil/pf/pf_nl.h
@@ -84,6 +84,9 @@ enum {
PFNL_CMD_SOURCE_CLEAR = 46,
PFNL_CMD_TABLE_TEST_ADDRS = 47,
PFNL_CMD_INA_DEFINE = 48,
+ PFNL_CMD_OSFP_FLUSH = 49,
+ PFNL_CMD_OSFP_GET = 50,
+ PFNL_CMD_OSFP_ADD = 51,
__PFNL_CMD_MAX,
};
#define PFNL_CMD_MAX (__PFNL_CMD_MAX -1)
@@ -604,6 +607,24 @@ enum pf_ina_define_t {
PF_ID_NADDR = 6, /* u32 */
};
+enum pf_osfp_t {
+ PF_OFP_UNSPEC,
+ PF_OFP_IDX = 1, /* u32 */
+ PF_OFP_OS_OS = 2, /* u32 */
+ PF_OFP_OS_ENFLAGS = 3, /* u32 */
+ PF_OFP_OS_CLASS = 4, /* string */
+ PF_OFP_OS_VERSION = 5, /* string */
+ PF_OFP_OS_SUBTYPE = 6, /* string */
+ PF_OFP_TCPOPTS = 7, /* u64 */
+ PF_OFP_WSIZE = 8, /* u16 */
+ PF_OFP_PSIZE = 9, /* u16 */
+ PF_OFP_MSS = 10, /* u16 */
+ PF_OFP_FLAGS = 11, /* u16 */
+ PF_OFP_OPTCNT = 12, /* u8 */
+ PF_OFP_WSCALE = 13, /* u8 */
+ PF_OFP_TTL = 14, /* u8 */
+};
+
#ifdef _KERNEL
void pf_nl_register(void);