Page MenuHomeFreeBSD

pf: Handle if_groups with the same name as interfaces

Authored by kp on Aug 19 2015, 9:23 PM.


Group Reviewers

pf allows network interfaces and groups to be used interchangeably. They don't
share a namespace so it's possible for an interface and a group to have the same

If that happens we recurse infinitely in pfi_kif_update() because the pfi_kif is
both an interface and a group. That means that the kif is a member of itself.

Simply checking that we're not calling pfi_kif_update() on the current pfi_kif
fixes the panic.

PR: 127042, 202178

Diff Detail

rS FreeBSD src repository
Lint Skipped
Unit Tests Skipped

Event Timeline

kp updated this revision to Diff 8072.Aug 19 2015, 9:23 PM
kp retitled this revision from to pf: Handle if_groups with the same name as interfaces.
kp updated this object.
kp edited the test plan for this revision. (Show Details)
kp set the repository for this revision to rS FreeBSD src repository.
op added a subscriber: op.Aug 19 2015, 10:04 PM
kp added a reviewer: network.Aug 25 2015, 1:19 PM
eri added a reviewer: eri.Aug 25 2015, 5:14 PM
eri requested changes to this revision.Aug 25 2015, 5:26 PM
eri edited edge metadata.

I do not think this is the root cause for this, it just hides another issue.
I think that the result of RB_INSERT should be checked when a group/iface is created should be tested.
If that returns NULL the result should be null.

To me it is not good to have this weirdness in the configuration and nevertheless allow that.

This revision now requires changes to proceed.Aug 25 2015, 5:26 PM
kp abandoned this revision.Aug 16 2016, 9:55 AM

I'll post a patch with an alternative approach: change the network stack to put ifgroup and interface names in the same namespace.