From owner-freebsd-current@freebsd.org Thu Nov 5 11:18:05 2015 Return-Path: Delivered-To: freebsd-current@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 132CFA26121 for ; Thu, 5 Nov 2015 11:18:05 +0000 (UTC) (envelope-from kp@vega.codepro.be) Received: from venus.codepro.be (venus.codepro.be [IPv6:2a01:4f8:162:1127::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "*.codepro.be", Issuer "Gandi Standard SSL CA 2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id CCB911E8B for ; Thu, 5 Nov 2015 11:18:04 +0000 (UTC) (envelope-from kp@vega.codepro.be) Received: from vega.codepro.be (unknown [172.16.1.3]) by venus.codepro.be (Postfix) with ESMTP id C4BAD1AA19; Thu, 5 Nov 2015 12:17:59 +0100 (CET) Received: by vega.codepro.be (Postfix, from userid 1001) id C11B54E311; Thu, 5 Nov 2015 12:17:59 +0100 (CET) Date: Thu, 5 Nov 2015 12:17:59 +0100 From: Kristof Provost To: Tom Uffner Cc: FreeBSD-Current Subject: Re: r289932 causes pf reversion - breaks rules with broadcast destination Message-ID: <20151105111759.GA2336@vega.codepro.be> References: <563AB177.6030809@uffner.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <563AB177.6030809@uffner.com> X-Checked-By-NSA: Probably User-Agent: Mutt/1.5.24 (2015-08-30) X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 05 Nov 2015 11:18:05 -0000 On 2015-11-04 20:31:35 (-0500), Tom Uffner wrote: > Commit r289932 causes pf rules with broadcast destinations (and some but not > all rules after them in pf.conf) to be silently ignored. This is bad. > Thanks for the report. What version did you test exactly? There was an issue with r289932 that was fixed in r289940, so if you're in between those two can you test with something after r289940? Thanks, Kristof