Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 24 Apr 2024 07:54:17 +0200
From:      Gerrit =?UTF-8?B?S8O8aG4=?= <gerrit.kuehn@aei.mpg.de>
To:        Matthew Grooms <mgrooms@shrew.net>
Cc:        stable@freebsd.org
Subject:   Re: possible regression handling packet fragmentation in 14.0 with tftp/pxe
Message-ID:  <20240424075417.6640e97f@arc.aei.uni-hannover.de>
In-Reply-To: <922446cd-4511-4132-8e8f-9c9144a7f9b1@shrew.net>
References:  <20240419153951.5a23ce5f@arc.aei.uni-hannover.de> <86y1999wwe.fsf@ltc.des.dev> <20240422075948.5bb856ac@arc.aei.uni-hannover.de> <86o7a18ppl.fsf@ltc.des.dev> <20240423071923.52b90652@arc.aei.uni-hannover.de> <922446cd-4511-4132-8e8f-9c9144a7f9b1@shrew.net>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
Am Tue, 23 Apr 2024 09:50:33 -0500
schrieb Matthew Grooms <mgrooms@shrew.net>:

> Sorry. I didn't missed some of the previous details here, but I see you 
> mention pf below. Did you happen to see this?
> 
> https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=276856

Ah, great. No, I hadn't seen that before, thanks.
This certainly looks like it might be the cause of the issue I see,
although I'm not sure I fully understand the situation. What I get so far
is that

* 14.0 does not reassemble packets by default anymore when using scrub
  while 13.x did

* 14.0 silently drops fragmented packets by default where 13.x didn't

Is that correct? That would probably explain why tftp couldn't pass my vpn
tunnel anymore.

What I am using in my pf.conf is a simple
---
scrub in all
---

From the bug report I get that either using
---
scrub fragment reassemble
---

or

---
set reassemble yes
---

should be able to fix this and get the old behaviour back?


I remember playing with the "scrub fragment" option last week, but maybe I
didn't try to explicitely turn it on as that was described as default in
the manpage.
Anyway, I'll look into this again, thank you very much for the pointer.



One more question:
Looking at the linked reviews:
https://reviews.freebsd.org/D42355
https://reviews.freebsd.org/D42270

These appear to address the issue. I can get to the actual commit from the
review:
https://reviews.freebsd.org/rGede5d4ff5b39ccbc193c30fb6c093c7c4de9a464

Is there an easy way to find out where this commit ends up, i.e., whether
it is merged into 14.0, 14.1 or so?


cu
  Gerrit

[-- Attachment #2 --]
0	*H
010
	`He0	*H
0200
	*H
0{10	UGB10UGreater Manchester10USalford10U
Comodo CA Limited1!0UAAA Certificate Services0
040101000000Z
281231235959Z0{10	UGB10UGreater Manchester10USalford10U
Comodo CA Limited1!0UAAA Certificate Services0"0
	*H
0
@nvMEDFȃ*]P1p"I-Tc̶nhFSL$rNT
z3`ډU"XOhF'v5,^deHav PfxbV18'2Xok+c_s8x6Qx:B/I-߬tMG)b&{>%ݝ5h Ä
^/00U
#>)00U0U00{Ut0r08642http://crl.comodoca.com/AAACertificateServices.crl06420http://crl.comodo.net/AAACertificateServices.crl0
	*H
V{DOX̦Ihv]`֍PO&N氥tTAOZ``J¿Ĺt-}kF/j4,}Z
/\:l7U	S@lXen<ZƞYH0!el!s7Χ,,&"`^tԢShnlhV+8:	k׾-?cb,jAP96n00i9rD:"Ql150
	*H
0{10	UGB10UGreater Manchester10USalford10U
Comodo CA Limited1!0UAAA Certificate Services0
190312000000Z
281231235959Z010	UUS10U
New Jersey10UJersey City10U
The USERTRUST Network1.0,U%USERTrust RSA Certification Authority0"0
	*H
0
e6ЬW
v'LPa M	-d	Ή=ӱ{7(+G9Ƽ:_}cBv;+o 	>tbdj"<{QgFQˆT?3~lQ5frg!fԛxP:ܼL5WZ=,T:ML\ ="4~;hfDNFS3`S7sC2S۪tNik`2̓;Qxg=Vi%&k3mnGsC~f)|2cU
T0}7]:l5\AکI؀	bf%̈́?9L|k^̸g[L[s#;-5Ut	IIX6Q&}MC&пA_@DDWPWT>tc/Pe	XB.CL%GY&FJP޾xgWcb_U.\(%9+L?
R/00U#0
#>)00USyZ+JT؛f0U0U00U 
00U 0CU<0:08642http://crl.comodoca.com/AAACertificateServices.crl04+(0&0$+0http://ocsp.comodoca.com0
	*H
Qt!='3.^"our-J~or<C;?\Ʈ{C6|?޸Cd~}}B+XfvN΢M2q[A
"͒7;:E&u?{w;=\9?{
E͓/]YO?QE?Jat#
Ps'DG]*k1jLjxϸvrב_00Π1p5$VI0
	*H
010	UUS10U
New Jersey10UJersey City10U
The USERTRUST Network1.0,U%USERTrust RSA Certification Authority0
200218000000Z
330501235959Z0F10	UNL10U
GEANT Vereniging10UGEANT Personal CA 40"0
	*H
0
J"^'[[52 1@PDʯJa-b3j-Bʖ<p=hxn<0d[Iep^¾r{D$8Uӡ};'Q܌=320ѬgGx& 5ꄪi7tbLdjK2@v7*!즃ɽZD3'6Q_*YR4o>DAt|ز?ui+􉮺Pglwi3PeV"JD"<"KښoKv+1u#8!͋G1ߛf"Qi>g%NY.^rax1ym"x~Ti/
]rnYHϴ,,q5;}&~Wmf*r|:ؖ8ŧjraC3jf|kXo+V)25nE!u;-/
%l>v&L3(;pogS`Ӹ>/00U#0SyZ+JT؛f0Ui!X 
ݧQ0U0U00U%0++08U 10/0-U 0%0#+https://sectigo.com/CPS0PUI0G0ECA?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v+j0h0?+03http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%+0http://ocsp.usertrust.com0
	*H

N{
9obx?G]tC@`JϐDW#kz9QҞ,=1t3?S
< 7D5(/Mn7j\y|؀A̵/k>5	C1C1XEO	4sjq#(61YmA<K_~4J5Pf7VGli/+5O7f|Pk޳D!Uk4Odyep@Wo[+0k/5֬HM{ْY6G`43d
ԦnV0[<URO\^<ɵ((ow"*u51]+m0	3ĂVMbFNb@ڱɛ{~␘&jYzptYB
-:Ej#dDݧ/cBtFԼ3=\];62hPj)l/T#6"8$2x]si0K03&V)vQZ0
	*H
0F10	UNL10U
GEANT Vereniging10UGEANT Personal CA 40
230815000000Z
260814235959Z010U805391G0EU
>Max-Planck-Gesellschaft zur Förderung der Wissenschaften e.V.10U	Hofgartenstraße 810
UBayern10	UDE10UGerrit Kuehn1&0$	*H
	gerrit.kuehn@aei.mpg.de0"0
	*H
0
~D-!!&t/ʍDp~Οr}Vkry{{%E]iZU+;UH88>6iBW(R?cHhc{}'4V>56T~x@eঊRԪo+"ktuK@0&OI%mgl2b60~Y0;cI;s.
~i7RUPQRC}>BkȻN(Il9@pbNX^Eld~ ~¦^tQ
ھV/p&-t)o,l~(5zK 9r%dzeGvGsV+>n8uY`@=eNK]Qx-S~o	=eMU	R5yѩvS	(a{
Qغ`:m}ROgtWVd<O%!V
rL|#_g{g\/REce+00U#0i!X 
ݧQ0Up̴%c?0U0U00U%0++0?U 80604+1O0%0#+https://sectigo.com/CPS0BU;0907531http://GEANT.crl.sectigo.com/GEANTPersonalCA4.crl0x+l0j0=+01http://GEANT.crt.sectigo.com/GEANTPersonalCA4.crt0)+0http://GEANT.ocsp.sectigo.com0"U0gerrit.kuehn@aei.mpg.de0
	*H
m@{kg/{:gl
JO[X[:F9F&OFM:;_9IhuȘXsJ!饈$C5UbW8SF7hA=e<0ALhƺOT(]9ˌ,釻]BU1\Fl4m>P1c
o/VEl9YF`xIQjũ%;3,#Ӊ*xŵ~RLEADUYụƗ|󋴶(J/yzP%%LBh4f*~
$T1=]Dnϧ~ѱZ"YU*q*`_@Gֽo
1&X|c?V*36ؖ7=j
lY.|8$7ZEϪY|@9D6iIFR/N2n"lȭ9,RFi؄/ySݷa-Ds п1,0(0[0F10	UNL10U
GEANT Vereniging10UGEANT Personal CA 4&V)vQZ0
	`He0	*H
	1	*H
0	*H
	1
240424055417Z0(	*H
	100	`He0
*H
0?	*H
	120@wY`m$a0]f$=<}^"Gk!U0
	*H
i?{OsC|BUD"oFAm'D3bX	E;ƞd%[tHo cjX=IjW2r`qm;e{+
Ё}С@"5A9,չ@oW)גPB##ܳe@CXsy+vzo@iRT\ZiyQ`^e}\l^wa/~dYd	ћ|bXc}S`Y
܆s c@q-ү
28P$,Oqp#jЃfzůʙ:3=bH>E:WVbF%P$BO֑xE~#g^L6$R06U4G=I:&/oc3`E]>D4yng0*pgDǢfe3cźp	j7e=:v#`Yf$X"yKBf,{hkL`
home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20240424075417.6640e97f>