From nobody Tue Aug 5 22:28:09 2025 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4bxSk20xpzz63nW5; Tue, 05 Aug 2025 22:28:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R10" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4bxSk132fnz4LVB; Tue, 05 Aug 2025 22:28:09 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1754432889; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gXuEYM6RKRod6tRh/k6UX3DmSG05DNWZpxq0vR12zjU=; b=isN8qex3GyuhzEmDjs9ReF4UqyPcL7dNoDUYq6sYPTGL41i7P9YouseJAE5Qod4aomvXvv amOSWvWMhk7ybzi7VmWl4WWbGDqOiVy9yGRinV1zXmyBYEv1NeIYcnA3RbX6My7ELOaw8b TaTJuluVwSoDZhcpGYzkdiihCWC0gptVcSOV1kOyvw5elN2HScHHR/GIEKJVgEgVP4OmD5 uYgEkk7ZSB1g+TUb+jwcFa/8z3EQ3sbH8d66OiGdBJWl3GVqn8G/9NUWy6pgihrUl4R7pJ 1cBngOvfocefWEbaPjZ0YZXJJ1Ra/AA2lKDfaGpR6tuGksH+asT/jS7ZzNqxYg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1754432889; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gXuEYM6RKRod6tRh/k6UX3DmSG05DNWZpxq0vR12zjU=; b=H+gf252C5XvzQzm3vZzlgDYilA5Y00JWHtym/cRizMFydRCmlnrfoA3OALt+CvzFaSEjRG FjB54/0UkP7JQjkrPbyBS/Kxy0FeQ/Y+eBAxhKtuKWguw8hO/Ed8eoLA5wnFuGfjlrAwIt iCfmhsoAas3v5UX7TzlYIIC/kmcdIIVRYIPLAMFBkpipxJIPy3wP+zUBWo2BHzH0fI+foe piv8JM2KgDUzvYMa8g9nr5xikENQjecnab60RV+Dp4uBmw8B7EBl86LlKt5O+pyFsdsViV v64z1OSrUH3nAO9ZrnibCbGKcfYmc5a6l7GGgzAaLXUhrmrmpgZFlQXxn+Uukw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1754432889; a=rsa-sha256; cv=none; b=TMYOkg2u9nO3kHg8Qh4LoDsot6KarK66a6kaOHfS/UmCaow++eBMSCdwLUzT9tbLIbliis D7PVYtpcWi4D623Kpi7cFzJ/n5r1qbNY34+VW2Yj2jKx1VvTBg17xBeIlc8+1tvS2Ee5FA 3EoGWD3F9Hn1xvWoA1XBmV8U18O3bHuNJUcN/hQMYS65iGmkaK+276qp66+nZ5VYgZoTnM Q/jvQ00UeenHVD61aG1ATct3oMrLIu8UXYFwOpWu9BrZMVBUCkE3EbS2IKqcNDFNuXHWts 2llt2cbnLZx8e6b0Mc0JZBPS3HLRjdp+a040/JN2rMkzQjlYTdwwCfezIBu9zw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4bxSk12bBZztbt; Tue, 05 Aug 2025 22:28:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 575MS9jQ014360; Tue, 5 Aug 2025 22:28:09 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 575MS93i014357; Tue, 5 Aug 2025 22:28:09 GMT (envelope-from git) Date: Tue, 5 Aug 2025 22:28:09 GMT Message-Id: <202508052228.575MS93i014357@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: 17ac89e1dfc3 - main - pf.conf.5: rework the text on mtu and mss List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 17ac89e1dfc3b34658b5430ae860e88085876896 Auto-Submitted: auto-generated The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=17ac89e1dfc3b34658b5430ae860e88085876896 commit 17ac89e1dfc3b34658b5430ae860e88085876896 Author: Kristof Provost AuthorDate: 2025-07-18 16:58:51 +0000 Commit: Kristof Provost CommitDate: 2025-08-05 22:27:15 +0000 pf.conf.5: rework the text on mtu and mss According to some notes from sthen; ok sthen Obtained from: OpenBSD, jmc , 7f29e7e980 Sponsored by: Rubicon Communications, LLC ("Netgate") --- share/man/man5/pf.conf.5 | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/share/man/man5/pf.conf.5 b/share/man/man5/pf.conf.5 index 8954e872c231..1c40765f908a 100644 --- a/share/man/man5/pf.conf.5 +++ b/share/man/man5/pf.conf.5 @@ -27,7 +27,7 @@ .\" ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE .\" POSSIBILITY OF SUCH DAMAGE. .\" -.Dd July 9, 2025 +.Dd July 18, 2025 .Dt PF.CONF 5 .Os .Sh NAME @@ -855,7 +855,15 @@ modifier to ensure unique IP identifiers. .It Ar min-ttl Aq Ar number Enforces a minimum TTL for matching IP packets. .It Ar max-mss Aq Ar number -Enforces a maximum MSS for matching TCP packets. +Reduces the maximum segment size (MSS) +on TCP SYN packets to be no greater than +.Ar number . +This is sometimes required in scenarios where the two endpoints +of a TCP connection are not able to carry similar sized packets +and the resulting mismatch can lead to packet fragmentation or loss. +Note that setting the MSS this way can have undesirable effects, +such as interfering with the OS detection features of +.Xr pf 4 . .It Xo Ar set-tos Aq Ar string .No \*(Ba Aq Ar number .Xc