Bug 190038 - [ipf] ipf -Fa -6 clears v6 and v6 lists
Summary: [ipf] ipf -Fa -6 clears v6 and v6 lists
Status: Closed FIXED
Alias: None
Product: Base System
Classification: Unclassified
Component: kern (show other bugs)
Version: Unspecified
Hardware: Any Any
: Normal Affects Only Me
Assignee: Cy Schubert
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-05-20 22:20 UTC by heas
Modified: 2015-02-26 20:18 UTC (History)
1 user (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description heas 2014-05-20 22:20:00 UTC
ipf -I -6 -Fa clears both v4 and v6 lists.  I and /etc/rc.d/ipfilter
reload expect it to only clear v6 lists. I happen not to have a v6 list
installed, but that does not seem to matter.

How-To-Repeat: load an ipfilter v4 list from /etc/ipf.conf, run /etc/rc.d/ipfilter
reload, notice that the active v4 list is empty.
Comment 1 Mark Linimon freebsd_committer freebsd_triage 2014-05-21 20:18:10 UTC
Responsible Changed
From-To: freebsd-bugs->freebsd-net

Over to maintainer(s).
Comment 2 Cy Schubert freebsd_committer freebsd_triage 2014-09-20 03:59:15 UTC
This is by design. As of IP Filter 5, IPv4 and IPv6 rules are stored in the sane table internally.
Comment 3 heas 2015-02-26 14:32:14 UTC
If it is by design, /etc/rc.d/ipfilter on 10.1-REL needs updating
Comment 4 Cy Schubert freebsd_committer freebsd_triage 2015-02-26 20:18:27 UTC
Fix MFCed.