i'll give a cookie* to anyone who can fix the bug described at http://cvs.openbsd.org/cgi-bin/query-pr-wrapper?full=yes&numbers=6329.
ive stared at the pfsync code for hours trying to find it and cannot. fresh eyes might have better luck though. dlg * may not include real cookie.