Date: Fri, 10 Mar 2017 09:47:24 -0800 (PST) From: "Rodney W. Grimes" <freebsd@pdx.rh.CN85.dnsmgr.net> To: "Andrey V. Elsukov" <ae@freebsd.org> Cc: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-11@freebsd.org Subject: Re: svn commit: r314990 - stable/11/sys/netpfil/ipfw Message-ID: <201703101747.v2AHlOoO013279@pdx.rh.CN85.dnsmgr.net> In-Reply-To: <201703100544.v2A5iEWA070485@repo.freebsd.org>
next in thread | previous in thread | raw e-mail | index | archive | help
[ Charset UTF-8 unsupported, converting... ] > Author: ae > Date: Fri Mar 10 05:44:14 2017 > New Revision: 314990 > URL: https://svnweb.freebsd.org/changeset/base/314990 > > Log: > MFC r314614: > Fix matching table entry value. Use real table value instead of its index > in valuestate array. > > When opcode has size equal to ipfw_insn_u32, this means that it should > additionally match value specified in d[0] with table entry value. > ipfw_table_lookup() returns table value index, use TARG_VAL() macro to > convert it to its value. The actual 32-bit value stored in the tag field > of table_value structure, where all unspecified u32 values are kept. > > PR: 217262 > Modified: > stable/11/sys/netpfil/ipfw/ip_fw2.c > Directory Properties: > stable/11/ (props changed) Thank you for fixing this promptly, I have seen no issues running the patch in production firewalls since you provided it. -- Rod Grimes rgrimes@freebsd.org
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201703101747.v2AHlOoO013279>