Page MenuHomeFreeBSD

pf: return errors from pf_route() and pf_route6()
ClosedPublic

Authored by kp on Jul 29 2025, 7:38 PM.
Tags
None
Referenced Files
F174775477: D51627.diff
Mon, Oct 5, 10:26 PM
F174706101: D51627.id.diff
Mon, Oct 5, 9:01 AM
Unknown Object (File)
Sat, Oct 3, 8:55 PM
Unknown Object (File)
Sat, Oct 3, 8:51 PM
Unknown Object (File)
Sat, Sep 26, 10:40 AM
Unknown Object (File)
Sat, Sep 19, 3:19 PM
Unknown Object (File)
Sat, Sep 19, 3:16 PM
Unknown Object (File)
Sat, Sep 19, 3:10 PM

Details

Summary

If we fail to route the packet in pf_route()/pf_route6() (e.g. because it
hit the TTL limit) we free the mbuf. If that packet is an SCTP packet that
establishes extra (i.e. multihome) states we have a queued job to handle that.
These jobs reference the now freed mbuf.

Pass the error from pf_route()/pf_route6() on, so that
pf_sctp_multihome_delayed() doesn't attempt to use the invalid mbuf pointer (or
establishes states for a packet we're not passing).

PR: 288274
Reported by: Robert Morris <rtm@lcs.mit.edu>
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

kp requested review of this revision.Jul 29 2025, 7:38 PM
This revision was not accepted when it landed; it landed in state Needs Review.Aug 4 2025, 8:12 AM
This revision was automatically updated to reflect the committed changes.