[Bug 296838] pf: cannot reload ruleset in securelevel 2

From: <bugzilla-noreply_at_freebsd.org>
Date: Thu, 16 Jul 2026 11:53:08 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=296838

            Bug ID: 296838
           Summary: pf: cannot reload ruleset in securelevel 2
           Product: Base System
           Version: 15.1-RELEASE
          Hardware: Any
                OS: Any
            Status: New
          Severity: Affects Many People
          Priority: ---
         Component: kern
          Assignee: bugs@FreeBSD.org
          Reporter: rob2g2-freebsd@bitbert.com

I have a x86 system running in securelevel 2. Reloading the ruleset was no
problem in 15.0-RELEASE, however, with 15.1-RELEASE with "pfctl -ef
/etc/pf.conf" I get "pfctl: DIOCADDRULE: Operation not permitted". Trying to
add an ip address to a table was also no problem with 15.0, however, with 15.1
a "pfctl -t dns_servers -T add 1.1.1.1" results in "pfctl: Operation not
supported by device"

-- 
You are receiving this mail because:
You are the assignee for the bug.