Page MenuHomeFreeBSD

pf: do not loop on an address that is cleared twice in pfr_clr_astats()
ClosedPublic

Authored by rcm on Mon, Sep 28, 6:28 PM.

Details

Summary

pfr_clr_astats() looks up each address it is given and inserts the entry
it finds at the head of a work queue. If the same address is given more
than once, the entry is inserted twice and the second insertion makes it
its own successor. pfr_clstats_kentries() then walks the queue forever,
with the rules lock held for writing, so packet processing and every
other pf operation in that vnet stop as well. To reproduce:

pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -t foo -T zero 192.0.2.1 192.0.2.1

Do as pfr_del_addrs() does: clear pfrke_mark on the entries named, then
queue an entry only the first time it is seen. An address given more
than once is cleared, and counted, once. Validate all addresses before
any entry is touched.

Add a regression test.

MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

rcm requested review of this revision.Mon, Sep 28, 6:28 PM
This revision was not accepted when it landed; it landed in state Needs Review.Tue, Sep 29, 12:14 AM
This revision was automatically updated to reflect the committed changes.