Rename blacklist to blocklist, following upstream - #517
Conversation
Upstream hash 46419aa7eea2cebc0cbc74c7b3aba8592cddc5bb. Obtained from: https://github.com/zoulasc/blocklist AI-Assisted-by: Claude Fable 5.1 Signed-off-by: Lucas Holt <luke@foolishgames.com>
Upstream renamed the project to blocklist; the replacement is imported at contrib/blocklist in the next commit. AI-Assisted-by: Claude Fable 5.1 Signed-off-by: Lucas Holt <luke@foolishgames.com>
Bring in the current upstream snapshot from the new vendor/blocklist branch (upstream 46419aa7eea2cebc0cbc74c7b3aba8592cddc5bb). Build glue and local adaptations follow in separate commits. AI-Assisted-by: Claude Fable 5.1 Signed-off-by: Lucas Holt <luke@foolishgames.com>
Apply the MidnightBSD changes (drop the Debian port, /usr/libexec paths, SA_SIZE instead of RT_ROUNDUP, packet filter man page cross-references) and record them in midnightbsd-changes.sh. Add the compatibility sources for the old blacklist names from FreeBSD so lib/libblacklist, blacklistd and blacklistctl can keep being built during the transition. Describe the import procedure in MIDNIGHTBSD-upgrade. AI-Assisted-by: Claude Fable 5.1 Signed-off-by: Lucas Holt <luke@foolishgames.com>
Build the library, daemon and control program from contrib/blocklist under their new names: libblocklist(3), blocklistd(8) and blocklistctl(8), with /etc/blocklistd.conf, the blocklistd rc script, blocklistd_enable and blocklistd_flags in rc.conf, and the blocklistd-helper script. The build knobs are MK_BLOCKLIST and MK_BLOCKLIST_SUPPORT. Consumers move to the new API: sshd (UseBlocklist, with UseBlacklist kept as an alias), ftpd and fingerd now include blocklist.h and call blocklist_*(), and their client glue is renamed from blacklist.c to blocklist.c. The old names remain available during the transition, as FreeBSD did in commit 7238317403b9: libblacklist, blacklistd, blacklistctl and blacklistd-helper are built from the compatibility sources in contrib/blocklist, the blacklistd rc script still starts the old daemon but prints a warning, and WITHOUT_BLACKLIST and WITHOUT_BLACKLIST_SUPPORT are wired to the blocklist options. The periodic pf security check looks at both anchor names. Note the rename in UPDATING. Obtained from: FreeBSD 7238317403b95a8e35cf0bc7cd66fbd78ecbe521 AI-Assisted-by: Claude Fable 5.1 Signed-off-by: Lucas Holt <luke@foolishgames.com>
There was a problem hiding this comment.
Sorry @laffer1, your pull request is larger than the review limit of 150,000 diff characters
|
Claude finished @laffer1's task in 3m 51s —— View job Claude finished reviewing this PRTodo list
SummaryThis is a well-executed, mechanical rename that mirrors FreeBSD's upstream change closely, with sensible compatibility shims. No FindingsMinor — inconsistent Both compat programs actually link against the new Things I verified as correct (no issues found)
Overall this looks solid and low-risk given the compatibility-first approach. The one Makefile nit above is cosmetic and worth a quick cleanup but doesn't block anything. As noted in the PR body, the pf integration live-test is still outstanding — I did not attempt to build or run anything in this environment (network access for |
PR #517 was squash-merged, which left the vendor/blocklist import out of master's ancestry. Record it so future blocklist updates can be merged with -X subtree=contrib/blocklist. No tree change.
Upstream renamed the blacklist project to blocklist. This follows the rename on master only, mirroring what FreeBSD did in 7238317403b9 ("blocklist: Rename blacklist to blocklist"), including the compatibility shims so existing setups keep working with a warning.
What changes
vendor/blocklist, taggedvendor/blocklist/20260409, importing upstream https://github.com/zoulasc/blocklist at 46419aa (2026-04-09).contrib/blacklistis removed andcontrib/blocklistis read in from the vendor branch, withMIDNIGHTBSD-upgradeandmidnightbsd-changes.shdescribing the procedure and the local adaptations.libblocklist(3),blocklistd(8),blocklistctl(8),/etc/blocklistd.conf,rc.d/blocklistd,blocklistd_enable/blocklistd_flags,blocklistd-helper, and theWITH[OUT]_BLOCKLIST/WITH[OUT]_BLOCKLIST_SUPPORTbuild options.UseBlocklist, withUseBlacklistkept as an alias), ftpd and fingerd. Their client glue files are renamed fromblacklist.ctoblocklist.c.libblacklist,blacklistd,blacklistctlandblacklistd-helperare built from FreeBSD's compatibility sources incontrib/blocklist; theblacklistdrc script still works but warns; the oldWITHOUT_BLACKLIST*knobs are wired to the new ones. The periodic pf check looks at both anchor names.UPDATINGentry,src.conf(5), option docs andOptionalObsoleteFiles.incupdated.Testing
Built with a private
MAKEOBJDIRPREFIXon amd64:lib/libblocklist,lib/libblacklist,usr.sbin/blocklistd,usr.sbin/blocklistctl,usr.sbin/blacklistd,usr.sbin/blacklistctl,libexec/fingerd,libexec/ftpd,secure/lib/libssh,secure/libexec/sshd-sessionandsecure/libexec/sshd-authall build cleanly under-Werror. Every consumer links againstlibblocklist.so.0.libblacklist.so.0exports the oldblacklist_*symbols plus the newblacklist_open2.blocklistd -dparses the shipped configuration. All rc and helper scripts passsh -n.Not done: a full buildworld / installworld and a live test of the daemon against pf. Please give the pf integration a run before merging.
Notes for review
contrib/blocklist/port/config.his a three line local wrapper that upstream generates with autoconf; it is documented inMIDNIGHTBSD-upgrade.old_bl.c,blacklist.c,old_internal.[ch],include/blacklist.h,include/old_bl.h,bin/blacklistd.c,bin/blacklistctl.c) and the old-name manual pages are taken from FreeBSD main unchanged.blocklistd.confis now calledduration(formerlydisable); the installed default rules are unchanged.AI-Assisted-by: Claude Fable 5.1
Obtained from: FreeBSD 7238317403b95a8e35cf0bc7cd66fbd78ecbe521
🤖 Generated with Claude Code