Re: pf.conf bug

2023-02-06 Thread Theo de Raadt
> This creates an ABI change. People have to recompile their pfctl. > I think we never guarantee this level of compatibility. Correct. It is a binary suppled with the kernel. We pay attention if it is inconvenient. That means if you need a new binary before a new kernel. But this is in the re

Re: pf.conf bug

2023-02-06 Thread Alexander Bluhm
On Mon, Feb 06, 2023 at 09:37:47PM +0100, Alexandr Nedvedicky wrote: > if we want to allow firewall administrator to specify a match > on icmptype 255 then extending type from uint8_t to uint16_t > is the right change. > > another option is to change logic here to allow matching ic

Re: pf.conf bug

2023-02-06 Thread Alexandr Nedvedicky
Hello, [ cc'ing also tech@ ] On Mon, Feb 06, 2023 at 06:44:38PM +0300, r...@bh0.amt.ru wrote: > >Synopsis: pf.conf bug > >Category:system > >Environment: > System : OpenBSD 7.2 > Details : OpenBSD 7.2 (GENERIC.MP) #6:

pf.conf bug

2023-02-06 Thread root
>Synopsis: pf.conf bug >Category: system >Environment: System : OpenBSD 7.2 Details : OpenBSD 7.2 (GENERIC.MP) #6: Sat Jan 21 01:03:04 MST 2023 r...@syspatch-72-amd64.openbsd.org:/usr/src/sys/arch/amd64/compile/G