mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 11:52:00 -04:00
FreeBSD handles subnet routes in netstack by default, but the router still installed its pf NAT rules whenever SNATSubnetRoutes was set, which is the default. Every FreeBSD node, subnet router or not, loaded and enabled pf, inserted anchor references into the host's main ruleset and loaded NAT rules that netstack never needed, since netstack dials subnet destinations from the host's own addresses. It also flipped the forwarding sysctls for any advertised route. Only do either when the kernel path is opted into with TS_DEBUG_NETSTACK_SUBNETS=false and routes are advertised. TestSubnetRouterFreeBSDManyFlows ran in netstack mode since the default changed, so it no longer exercised pf at all. Opt it into the kernel path and assert the anchor holds NAT rules, and have TestSubnetRouterFreeBSD assert the default mode leaves pf untouched. Also drop the stale claim in handleSubnetsInNetstack that the pf NAT rule never matches; that was the (self) pool bug, since fixed. Updates #21450 Change-Id: Ibf91a676a026cebb29f64e39a64fe8e75488360b Signed-off-by: Martin Minkus <martin.minkus@sonic.com>