From nobody Wed Nov 26 23:32:19 2025 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4dGwnv3Q6Dz6HmGg for ; Wed, 26 Nov 2025 23:32:19 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4dGwnv2d6rz3sqG for ; Wed, 26 Nov 2025 23:32:19 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1764199939; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=w9W3/kXSYuiWxboRhnksrd4q/eIii1Bhfp28ZxWiAdE=; b=DMem0fjKJgEkD4jTJLg1xWd3ebhEBoxa6hTgXO2o7arM+Bmt7yArzxAxNE2GOGi7P7NMAt dHGtJYRA/XXyuzYztGxX1hVZqTYsFKimrHwnXEB8vzu9jCYjZ3VilflEKrjVt94j99Mdqb g0i5nH9XcyhgKNJcvZ5qa9qkLWhh8RWb59nNFWIcDNimK57IhlvsVf12UlaiwOeWO8bMoJ lXoGRjzGM6j0+YjYzgZajsnhinVqDXKNKL9B/qiaWEZrHRoZ0U+nYjj+jP6QZxZ9vPGOol 3asbBbsi97NO734FcNvQmuZTJqIZW9G+rBX6PJFzIUz47cqJOso23gtK2FizOg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1764199939; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=w9W3/kXSYuiWxboRhnksrd4q/eIii1Bhfp28ZxWiAdE=; b=GFNS0hg1akx0HcYeEcALL+q5S4r9k4fPbJe9Im5dWRc/L23T48zS55yo17P8knCqs2HBm5 vhXghjNIMc6kWxFwB+FoLthDpxVFOJ0L3RvnJB77mMzGzX7fy1szl7dqBwdjlZnUTE9gd1 LdkXj0ed4MC8QLnbfdIK/uC2r/MXzUpXjgetil7SazuhTM/QxcZos8thHnOV6MNwStke35 0zmlgidHR0TJom/7Nt9Bcwl8muuLac6cOx8euIu2ox32vkG+NLPG3CQovQifU6hJuJGtK6 T2Y1QgRIXpHjrdabVO9Qk45VUuv9I59ZNDa8Bvb+kKMY6FFIOZtqR25M59mAVw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1764199939; a=rsa-sha256; cv=none; b=EC+iCP17tGqsLpVwLPR8Pb+LDpFeq317vqxZu8sig5jYq2TM13Amz7njWQrF8Dd2FTfyWa OR/xsUmcz+baUR9gBI+zgqyeKfWZXSuKviej8qGnMmmn6pfxVN1RULcuBNipt9DwWgkVXS q8F2qgRtDFvXf/gzvb8VbFzpxL1JI7MJF22CBdYyjtuReL1OLusXybUnmxEzKrgfiTCWU7 X6B2TYSYfP5YxUNL/jwfZHDskTpx9M6rmG/9gIY0TiLMUV/eK5x5kfJ4Ob/EEyaPvo82gS saQjdby5XiU9Q3FbiYkyh8bMufsTxGJmJ4oQ9mvtOhRm//OJcffbIeT7w/GRjw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4dGwnv2BM7z173q for ; Wed, 26 Nov 2025 23:32:19 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id a607 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Wed, 26 Nov 2025 23:32:19 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Cy Schubert Subject: git: d5d005e9bf49 - main - ipfilter: Load optionlist prior to ippool invocation List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: cy X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: d5d005e9bf4933d5680dd0bb5d42bdf440122aa4 Auto-Submitted: auto-generated Date: Wed, 26 Nov 2025 23:32:19 +0000 Message-Id: <69278e03.a607.69d46353@gitrepo.freebsd.org> The branch main has been updated by cy: URL: https://cgit.FreeBSD.org/src/commit/?id=d5d005e9bf4933d5680dd0bb5d42bdf440122aa4 commit d5d005e9bf4933d5680dd0bb5d42bdf440122aa4 Author: Cy Schubert AuthorDate: 2025-11-26 19:40:36 +0000 Commit: Cy Schubert CommitDate: 2025-11-26 22:26:38 +0000 ipfilter: Load optionlist prior to ippool invocation As a safety precaution df381bec2d2b limits ippool hash table size to 1K. This causes any legitimely large hash table to fail to load. The htable_size_max ipf tuneable adjusts this but the adjustment is made in the ipfilter rc script, invoked after the ippool script (because it depends on ippool). Let's load the ipfilter_optionlist in ippool as well. ipfilter_optionlist load will also occur in the ipfilter rc script in case the user uses ipfilter without ippool. Fixes: df381bec2d2b MFC after: 3 days --- libexec/rc/rc.d/ippool | 3 +++ 1 file changed, 3 insertions(+) diff --git a/libexec/rc/rc.d/ippool b/libexec/rc/rc.d/ippool index 0db8bbe98f61..5ef0d0522621 100755 --- a/libexec/rc/rc.d/ippool +++ b/libexec/rc/rc.d/ippool @@ -27,6 +27,9 @@ required_modules="ipl:ipfilter" ippool_start_precmd() { rc_flags="-f ${ippool_rules} ${rc_flags}" + if [ -n "${ifilter_optionlist}" ]; then + ${ipfilter_program:-/sbin/ipf} -T "${ipfilter_optionlist}" + fi } ippool_reload()