From nobody Wed Sep 15 07:43:54 2021 X-Original-To: freebsd-pf@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 220CA17D1639 for ; Wed, 15 Sep 2021 07:44:12 +0000 (UTC) (envelope-from ozkan.kirik@gmail.com) Received: from mail-ua1-x92e.google.com (mail-ua1-x92e.google.com [IPv6:2607:f8b0:4864:20::92e]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4H8XKR2RC9z4g7D for ; Wed, 15 Sep 2021 07:44:11 +0000 (UTC) (envelope-from ozkan.kirik@gmail.com) Received: by mail-ua1-x92e.google.com with SMTP id 88so149733uae.10 for ; Wed, 15 Sep 2021 00:44:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:from:date:message-id:subject:to; bh=AFUaapEinB9S5PY+U6BGu0ntDsaaXzvCxBcA1aNbuMg=; b=bgjP3y4bWijg1Hu3jZZcf/p+wjOO0inmqQkCf62Aw084OxwPEb4+v3s95hX0ZV5aB5 5ZMDII+IfZ5ucSL0yUfB8ju1WsCB4/PsSaXf0Pyn0i6zD24vAo0loyO9f/zZRhV/xeko F7bVCpFYhI2OijZk5AdRns4Koe7Z7ncyc+krnh+Hk96J+srLpGInnpwMBiaDo/Dmhobl 2fHi4TWcazQn3dIWX0txxMvFbuK/KZNqWeyhmJVFZtduvlt+hkYbKpQphj0Zdcg6AVod xDe/DE86jaqyn2z6vT4mZyAkw2gFXjjEHOOTITw2s/ZqqFaH0ZzfWqQxB/fyfazgGJF+ qjlw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=AFUaapEinB9S5PY+U6BGu0ntDsaaXzvCxBcA1aNbuMg=; b=xxJWOmReXu3bk8HGAhnJ03sLe7mVqso1w0bY+W/BuFxRRr8pypj4aJFGwJoWGEZokj UIqx3JU8dE7357UKd+t/U567Cj+jYv+SUyDRZ8vq6XmC7cNieUwZmgZ2f7XdTjdnnOLW Ls8DJlrEluHZdXAi0z4urLK7rddtN035WHHo8JNmsUKTGKYfKmDt2qckDYc9CJ1DMhUZ OdDdYUNN9K5j07wQYtkX91PGL/uqumNXt8VoA+ysaLFMeoQFy7mzXhmKbLT1OZqbTvYS nSgWtvvktlHo/Yg7PFc+p9JEPq5KxHBX5pA4LkCnoQGxyfe0lPGp9JbtIr6D7gHDMUh7 Mxkg== X-Gm-Message-State: AOAM5322VF0hoCneGeYMyPx2p96y200fgVdybn9estAAfAlrup8A21Wf BL/Lyopv1k8qy8YwYeCZ5+ZtksiEkYRoTh+5+VgLJuMfWpc= X-Google-Smtp-Source: ABdhPJz7d6lDC0eyKaw+87ApPNYvlbJQn+OYs9TQUGIyfvi7k1yE6VKOe6SPiElBmvKsSb0yek1/MOpBwkZC9lwZ9Og= X-Received: by 2002:ab0:60d8:: with SMTP id g24mr7570922uam.110.1631691845206; Wed, 15 Sep 2021 00:44:05 -0700 (PDT) List-Id: Technical discussion and general questions about packet filter (pf) List-Archive: https://lists.freebsd.org/archives/freebsd-pf List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-pf@freebsd.org X-BeenThere: freebsd-pf@freebsd.org MIME-Version: 1.0 From: =?UTF-8?B?w5Z6a2FuIEtJUklL?= Date: Wed, 15 Sep 2021 10:43:54 +0300 Message-ID: Subject: pf label $nr macro expand reproducable bug To: freebsd-pf@freebsd.org Content-Type: text/plain; charset="UTF-8" X-Rspamd-Queue-Id: 4H8XKR2RC9z4g7D X-Spamd-Bar: -- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20210112 header.b=bgjP3y4b; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of ozkankirik@gmail.com designates 2607:f8b0:4864:20::92e as permitted sender) smtp.mailfrom=ozkankirik@gmail.com X-Spamd-Result: default: False [-3.00 / 15.00]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36:c]; FREEMAIL_FROM(0.00)[gmail.com]; SUBJECT_HAS_CURRENCY(1.00)[]; TO_DN_NONE(0.00)[]; MID_RHS_MATCH_FROMTLD(0.00)[]; DKIM_TRACE(0.00)[gmail.com:+]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; NEURAL_HAM_SHORT(-1.00)[-0.999]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; FREEMAIL_ENVFROM(0.00)[gmail.com]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; TAGGED_FROM(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20210112]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_GOOD(-0.10)[text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-pf@freebsd.org]; RCPT_COUNT_ONE(0.00)[1]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::92e:from]; RCVD_COUNT_TWO(0.00)[2]; RCVD_TLS_ALL(0.00)[] X-ThisMailContainsUnwantedMimeParts: N Hi, I'm using FreeBSD stable/12. I've tested this situation on stable/12 both 0f97f2a1857a (Jul 26 2021) and ebb3327d09ce (Sep 14) build. label $nr macro is works as expected for most of rules. But with the example below $nr macro was expanded incorrectly. Outputs are below. If you need, I can open a PR. # ifconfig -g lo lo0 Experiment #1: The right output should be "ruleNo:2", but system expands as "ruleNo:257". # cat pf.conf pass quick on lo from lo:network to lo:network block quick all label "ruleNo:$nr" # pfctl -f pf.conf # pfctl -sr -vvv @0 pass quick on lo inet6 from ::1 to ::1 flags S/SA keep state [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] [ Inserted: uid 0 pid 17691 State Creations: 0 ] @1 pass quick on lo inet from 127.0.0.0/8 to 127.0.0.0/8 flags S/SA keep state [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] [ Inserted: uid 0 pid 17691 State Creations: 0 ] @2 block drop quick all label "ruleNo:257" [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] [ Inserted: uid 0 pid 17691 State Creations: 0 ] Experiment #2: The right output should be "ruleNo:2", but system expands as "ruleNo:17". # cat pf.conf pass quick on lo from lo:network block quick all label "ruleNo:$nr" # pfctl -f pf.conf # pfctl -sr -vvv @0 pass quick on lo inet6 from ::1 to any flags S/SA keep state [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] [ Inserted: uid 0 pid 8726 State Creations: 0 ] @1 pass quick on lo inet from 127.0.0.0/8 to any flags S/SA keep state [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] [ Inserted: uid 0 pid 8726 State Creations: 0 ] @2 block drop quick all label "ruleNo:17" [ Evaluations: 0 Packets: 0 Bytes: 0 States: 0 ] [ Inserted: uid 0 pid 8726 State Creations: 0 ] Regards Ozkan