Page MenuHomeFreeBSD

ipfw: add additional check for orphaned states
ClosedPublic

Authored by ae on Jul 22 2025, 8:14 AM.
Tags
None
Referenced Files
Unknown Object (File)
Tue, Nov 25, 3:07 PM
Unknown Object (File)
Tue, Nov 25, 4:21 AM
Unknown Object (File)
Sun, Nov 23, 4:19 PM
Unknown Object (File)
Sun, Nov 23, 6:08 AM
Unknown Object (File)
Nov 9 2025, 7:39 AM
Unknown Object (File)
Nov 9 2025, 5:23 AM
Unknown Object (File)
Oct 31 2025, 4:23 PM
Unknown Object (File)
Oct 19 2025, 3:02 AM

Details

Summary

When parent rule of dynamic state is deleted and net.inet.ip.fw.dyn_keep_states is enabled, such states are called ORPHANED.
Orphaned states still keep pointer to original parent rule. In case when rule action is skipto this can lead to unpredictable consequences.
To avoid this problem add special handling for skipto action when we have found ORPHANED state.
Check that new rule has the same opcode and skipto number for O_SKIPTO rule action.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

ae held this revision as a draft.
ae published this revision for review.Jul 22 2025, 8:14 AM
This revision was not accepted when it landed; it landed in state Needs Review.Aug 3 2025, 9:59 AM
This revision was automatically updated to reflect the committed changes.