From nobody Tue Dec 2 15:28:20 2025 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4dLPmh3k5Fz6Hd49 for ; Tue, 02 Dec 2025 15:28:20 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4dLPmh2c4Gz4FR0 for ; Tue, 02 Dec 2025 15:28:20 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1764689300; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=J3+B5r3BvMoj9urHn2FaBYPWxBE8P8EDaIxaZ+d2Tcc=; b=mI/4Swb0SvuCE48cQ29YYMg6TsMC0P0kb6ChNXEymUcS6LCTe6uqjOwlekiBhZDtXVg3f4 F6z6P9n3epGKsLzLHB2OJukGmxjWq7R6kH/+6PFMTzaKf449B1h+GK7uC73istEhEhzQrK 9gQjh/DWEpHmCGRFOZNYePD+pEABjWo++gr6qDORtIJq0rVYEg0Qy4bEdIv7yzqEaxMbEd o0x6tgVhD9ghT2dCyymfsfZznt81YtiyswAcDSUQJj9uEE83DX9fZadgZlFMjFAdD6rlc0 Q1AeQjx+KTX1Ptk0wpZ885ADrehEft1RATs8KzeHsYS7kagQfl3xcUrR6u9abg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1764689300; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=J3+B5r3BvMoj9urHn2FaBYPWxBE8P8EDaIxaZ+d2Tcc=; b=T8WvOVsVc7fWwtiGtbm9KerC+O9un6e/hcRU1HTveMfRX1jCWqpK1P4mahmMikW640OMZA m7Nv7PxZmhw/HZQ/UqihSFQkV5ZnGcrqM3+KglBC3NDNju1zn5uLEHxziDJnsMV8PbXdl8 utdEg0qrdv8vdmMxjGFXWuTltzE93GrxC4vWOYCiNgRe80OcR9IzsYdT0JsEMUYFq3/JrQ Vp6Edxg9xl9+oli3P26EdbE2PfTSEGapxTqfcT4bSFI/he7fOp+5RVmgwjgmNQVuMvecOg LbY1l6rZknrds3mq4xeLm19iQojkc6vBT6Fkir3/qwqxV4HtVURo2iLTX7fcmA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1764689300; a=rsa-sha256; cv=none; b=QvGvB8Z/7erTo/Oofziqodr+Mn56yRifE1Cn6WOwz4wEY+oKEpZcbVmg+yhsvxHOQBlEW9 AwCIlRmGee3zRqHDQTXGJT9mOgliib4+5Z1SSafWYx4SPlYPPGo3BSRDG+RRlJv2Uu0mnF lErB2xMYawzmzznKJxM6zaT8txCKuy9AFk3/BisPywJQpK9q7fPdGBiRbFEtNHVvfYrpmC iIkpVkzebIFuOb0EDYbMQqZHrVyCBoZECiCZUavNQo3+12Ge1azpiYp/LXkZjD3SzNgDHV vvr7R94/ITQSkg+1eSgNi/kjyFtIErntgBdrSjU9wuWRnJMDUZJ3dukdeRzgBw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4dLPmh1fBQz1BWw for ; Tue, 02 Dec 2025 15:28:20 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 33d16 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 02 Dec 2025 15:28:20 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Cy Schubert Subject: git: d7129761f5fc - stable/15 - ipfilter: Load optionlist prior to ippool invocation List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: cy X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: d7129761f5fc8828d5701cfe14adffee58659648 Auto-Submitted: auto-generated Date: Tue, 02 Dec 2025 15:28:20 +0000 Message-Id: <692f0594.33d16.1108862@gitrepo.freebsd.org> The branch stable/15 has been updated by cy: URL: https://cgit.FreeBSD.org/src/commit/?id=d7129761f5fc8828d5701cfe14adffee58659648 commit d7129761f5fc8828d5701cfe14adffee58659648 Author: Cy Schubert AuthorDate: 2025-11-26 19:40:36 +0000 Commit: Cy Schubert CommitDate: 2025-12-02 15:28:15 +0000 ipfilter: Load optionlist prior to ippool invocation As a safety precaution df381bec2d2b limits ippool hash table size to 1K. This causes any legitimely large hash table to fail to load. The htable_size_max ipf tuneable adjusts this but the adjustment is made in the ipfilter rc script, invoked after the ippool script (because it depends on ippool). Let's load the ipfilter_optionlist in ippool as well. ipfilter_optionlist load will also occur in the ipfilter rc script in case the user uses ipfilter without ippool. Fixes: df381bec2d2b (cherry picked from commit d5d005e9bf4933d5680dd0bb5d42bdf440122aa4) --- libexec/rc/rc.d/ippool | 3 +++ 1 file changed, 3 insertions(+) diff --git a/libexec/rc/rc.d/ippool b/libexec/rc/rc.d/ippool index 0db8bbe98f61..5ef0d0522621 100755 --- a/libexec/rc/rc.d/ippool +++ b/libexec/rc/rc.d/ippool @@ -27,6 +27,9 @@ required_modules="ipl:ipfilter" ippool_start_precmd() { rc_flags="-f ${ippool_rules} ${rc_flags}" + if [ -n "${ifilter_optionlist}" ]; then + ${ipfilter_program:-/sbin/ipf} -T "${ipfilter_optionlist}" + fi } ippool_reload()