From nobody Wed Sep 30 23:31:21 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hwBBd32dpz6tS2Z for ; Wed, 30 Sep 2026 23:31:21 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hwBBd2Wmwz4KVh for ; Wed, 30 Sep 2026 23:31:21 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790811081; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OcvQ+/bXoSDVnls2xGIzmkqkxK3+Ur1/bbQOhDzn13E=; b=Zg4xfjpTqjoMbU3oSE9InIZeEiiPu3ZqA1euz5sz8FvO4ueNobOp6grLF0SCg+tF3M3TXz 3nJIDxGcxQmnpEiq1pXnPRVZ3wI6xfSAQkcBHMvPLAEsZ/mQH/W6eB36/QNKhlZTUa5KcX h4r7I14mL+zeTZ43Tf0wV3iiyoKjnwDZY/I7cdUDT9PfYHIBYq2bOScMmO14tqWRaQpgy3 lItO16844Ox4oxfU7dPGKXNxMJAkTksuodxrMSiwqwSTRkB85G9s4RTsS2G2kWyT8YJP2f pZ7yDnzSQf0UZDTWJ3oqEzYhz4AW/1FlcDDR1QBEP5en5WRW+oaC3OCOWSXaEQ== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790811081; b=XtQFh0ZZ1smtA7o4zIsx5N2QHNxS/uRFhkjKNFdfY3xueDI7VUb86c68xERITVQAUa4dGj U7WggW+QIRReJGxzCg3AV9NRjWKsqJZuOzudsj57FoZQTl4pYTxRtE6wO0i0LDrawH1JVw tU5cIzixq1OhDSj0JEQMKHWqpMQFbtvJ3/ngT0ZHfRC0oLp2E0kDiPTZRJ5NINlUWbr+r/ ukOSVx7IMxGoY8vd7/DeenxRmZHn+1smV/2urFuw+VIyzvGG3Cj29LzQsPHRGtRa4Wvv7s lIdUhe7r8lYm4Wb0d9QKUWogU3BonbMX93LI2a/PAnOunRpom5T0VGPqGO9q2Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790811081; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OcvQ+/bXoSDVnls2xGIzmkqkxK3+Ur1/bbQOhDzn13E=; b=s4E/9AtThZCA8M38RO/l489kEd1DcSC2hpvc+kpSUnlSdHNwOpzymzuQe9p5wkTxDaF4av Rg+JJ8WNBbqeBe5MikAda0RdCamxdjjrALR8eA0ZiXbR1q0bkz4jy20cnUiDlwuVyirVIq sqPegENnVZn1H8rgsl5qbESrMkWAIpCJ2zu9+JUXWAiUCvhyaMY+ZRb3POxbBNdC5mHYpB zdPtVC2i7GeP7HaESE+7Ifi0qEj9ryLLa0sObBnqrYaiczm3kDxtvXMZ/zSpWNc8yG14yE NB+K6Rh6vzSPPRaNxFgPzVzj3T6hTauZ5USsNLYa7MaA+qA+xhIBWyB8bnxMcw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hwBBd1bw4z15ZB for ; Wed, 30 Sep 2026 23:31:21 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 44c39 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Wed, 30 Sep 2026 23:31:21 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: R. Christian McDonald Subject: git: 55a69b9be886 - main - libpfctl: zero the counters before summing per-chunk results List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rcm X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 55a69b9be886731087894ab0b3851215ff791ef9 Auto-Submitted: auto-generated Date: Wed, 30 Sep 2026 23:31:21 +0000 Message-Id: <6abd9bc9.44c39.21f4ed90@gitrepo.freebsd.org> The branch main has been updated by rcm: URL: https://cgit.FreeBSD.org/src/commit/?id=55a69b9be886731087894ab0b3851215ff791ef9 commit 55a69b9be886731087894ab0b3851215ff791ef9 Author: R. Christian McDonald AuthorDate: 2026-09-30 23:23:21 +0000 Commit: R. Christian McDonald CommitDate: 2026-09-30 23:23:21 +0000 libpfctl: zero the counters before summing per-chunk results The chunked table address functions (set, add, del, clr_astats) add each chunk's result to the caller's counter without initialising it. pfctl reuses nadd for the number of tables created, so a replace that also creates the table is off by one: pfctl -t foo -T replace 192.0.2.1 reports "2 addresses added". Zero the counters first, as pfctl_test_addrs() already does. Remove the workaround for the add case from pfctl (da64f6e047b5), which is no longer needed. Add a regression test. Reviewed by: kp Approved by: kp (mentor) Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink") MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D60174 --- lib/libpfctl/libpfctl.c | 16 ++++++++++++++++ sbin/pfctl/pfctl_radix.c | 3 --- tests/sys/netpfil/pf/table.sh | 38 ++++++++++++++++++++++++++++++++++++++ 3 files changed, 54 insertions(+), 3 deletions(-) diff --git a/lib/libpfctl/libpfctl.c b/lib/libpfctl/libpfctl.c index a7dbc0a412aa..aa3f4ec30f74 100644 --- a/lib/libpfctl/libpfctl.c +++ b/lib/libpfctl/libpfctl.c @@ -2517,6 +2517,9 @@ pfctl_table_add_addrs_h(struct pfctl_handle *h, struct pfr_table *tbl, struct pf int partial_added; int chunk_size; + if (nadd) + *nadd = 0; + do { chunk_size = MIN(size - off, 256); ret = _pfctl_table_add_addrs_h(h, tbl, &addr[off], chunk_size, &partial_added, flags); @@ -2609,6 +2612,9 @@ pfctl_table_del_addrs_h(struct pfctl_handle *h, struct pfr_table *tbl, struct pf int partial_deleted; int chunk_size; + if (ndel) + *ndel = 0; + do { chunk_size = MIN(size - off, 256); ret = _pfctl_table_del_addrs_h(h, tbl, &addr[off], chunk_size, @@ -2694,6 +2700,13 @@ pfctl_table_set_addrs_h(struct pfctl_handle *h, struct pfr_table *tbl, int partial_add, partial_del, partial_change; int chunk_size; + if (nadd) + *nadd = 0; + if (ndel) + *ndel = 0; + if (nchange) + *nchange = 0; + do { flags &= ~(PFR_FLAG_START | PFR_FLAG_DONE); if (off == 0) @@ -3984,6 +3997,9 @@ pfctl_clr_astats(struct pfctl_handle *h, const struct pfr_table *tbl, int partial_zeroed; int chunk_size; + if (nzero) + *nzero = 0; + do { chunk_size = MIN(size - off, 256); ret = _pfctl_clr_astats(h, tbl, &addrs[off], chunk_size, diff --git a/sbin/pfctl/pfctl_radix.c b/sbin/pfctl/pfctl_radix.c index d99923e4fb67..088c41e0583e 100644 --- a/sbin/pfctl/pfctl_radix.c +++ b/sbin/pfctl/pfctl_radix.c @@ -136,9 +136,6 @@ pfr_add_addrs(struct pfr_table *tbl, struct pfr_addr *addr, int size, { int ret; - if (*nadd) - *nadd = 0; - ret = pfctl_table_add_addrs_h(pfh, tbl, addr, size, nadd, flags); if (ret) { errno = ret; diff --git a/tests/sys/netpfil/pf/table.sh b/tests/sys/netpfil/pf/table.sh index 24201588ddbf..9c93df781852 100644 --- a/tests/sys/netpfil/pf/table.sh +++ b/tests/sys/netpfil/pf/table.sh @@ -878,6 +878,43 @@ replace_verbose_cleanup() pft_cleanup } +atf_test_case "replace_create" "cleanup" +replace_create_head() +{ + atf_set descr 'Test the counts of a replace that creates the table' + atf_set require.user root +} + +replace_create_body() +{ + pft_init + pwd=$(pwd) + + vnet_mkjail alcatraz + jexec alcatraz pfctl -e + + # libpfctl used to add the number of addresses to whatever the + # caller's counter held, which here is the number of tables created. + atf_check -s exit:0 -e "match:^1 table created\.$" \ + -e "match:^1 addresses added\.$" \ + jexec alcatraz pfctl -t foo -T replace 192.0.2.1 + + # More than one chunk of addresses. + for i in `seq 1 2`; do + for j in `seq 1 150`; do + echo "1.${i}.${j}.1" >> ${pwd}/bar.lst + done + done + atf_check -s exit:0 -e "match:^1 table created\.$" \ + -e "match:^300 addresses added\.$" \ + jexec alcatraz pfctl -t bar -T replace -f ${pwd}/bar.lst +} + +replace_create_cleanup() +{ + pft_cleanup +} + atf_test_case "load" "cleanup" load_head() { @@ -1002,6 +1039,7 @@ atf_init_test_cases() atf_add_test_case "in_anchor" atf_add_test_case "replace" atf_add_test_case "replace_verbose" + atf_add_test_case "replace_create" atf_add_test_case "load" atf_add_test_case "test" atf_add_test_case "show_no_counters"