The branch main has been updated by kp:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=f28d5ac5c4a498883b626db163c86b5112889078

commit f28d5ac5c4a498883b626db163c86b5112889078
Author:     Kajetan Staszkiewicz <veg...@tuxpowered.net>
AuthorDate: 2024-09-26 14:48:57 +0000
Commit:     Kristof Provost <k...@freebsd.org>
CommitDate: 2024-09-26 14:50:45 +0000

    pf tests: fix max_states test
    
    Ensure our rule with '(max 3)' only matches the TCP states we're counting.
    
    Reviewed by:    kp
    Differential Revision:  https://reviews.freebsd.org/D46795
---
 tests/sys/netpfil/pf/max_states.sh | 10 +++++-----
 1 file changed, 5 insertions(+), 5 deletions(-)

diff --git a/tests/sys/netpfil/pf/max_states.sh 
b/tests/sys/netpfil/pf/max_states.sh
index 677d6f473d97..03142eeaffa6 100755
--- a/tests/sys/netpfil/pf/max_states.sh
+++ b/tests/sys/netpfil/pf/max_states.sh
@@ -39,14 +39,14 @@ max_states_body()
 
        pft_set_rules router \
                "block" \
-               "pass quick inet6 proto icmp6 icmp6-type { neighbrsol, 
neighbradv }" \
-               "pass in  on ${epair_tester}b keep state (max 3)" \
-               "pass out on ${epair_server}a keep state"
+               "pass inet6 proto icmp6 icmp6-type { neighbrsol, neighbradv }" \
+               "pass in  on ${epair_tester}b inet6 proto tcp keep state (max 
3)" \
+               "pass out on ${epair_server}a inet6 proto tcp keep state"
 
-       # The exact limit is off by 1
        ping_dummy_check_request exit:0 --ping-type=tcpsyn --send-sport=4201
        ping_dummy_check_request exit:0 --ping-type=tcpsyn --send-sport=4202
-       ping_dummy_check_request exit:1 --ping-type=tcpsyn --send-sport=4203
+       ping_dummy_check_request exit:0 --ping-type=tcpsyn --send-sport=4203
+       ping_dummy_check_request exit:1 --ping-type=tcpsyn --send-sport=4204
 }
 
 max_states_cleanup()

Reply via email to