Page MenuHomeFreeBSD

pf: free an unparsed rule with pf_krule_free() in pf_handle_addrule()
Needs ReviewPublic

Authored by rcm on Mon, Sep 28, 7:00 PM.
Tags
None
Referenced Files
F174091674: D60104.diff
Wed, Sep 30, 1:47 PM
F174076683: D60104.id188147.diff
Wed, Sep 30, 10:52 AM
F174062156: D60104.diff
Wed, Sep 30, 7:49 AM
F174055860: D60104.id188147.diff
Wed, Sep 30, 6:34 AM
F174054012: D60104.id187917.diff
Wed, Sep 30, 6:12 AM
F174031039: D60104.diff
Wed, Sep 30, 2:38 AM

Details

Reviewers
kp
Summary

When the PFNL_CMD_ADDRULE message fails to parse, pf_handle_addrule()
frees the rule with pf_free_rule(), which asserts the rules and config
locks (neither is held) and releases references that
pf_ioctl_addrule() has not taken yet. With INVARIANTS this panics on
any parse error; without, a rule address parsed as PF_ADDR_TABLE makes
pfr_detach_table() dereference NULL.

Use pf_krule_free(), as the ioctl paths do.

Fixes: e249f5daa41f ("pf: fix memory leak on rule add parse failure")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

rcm requested review of this revision.Mon, Sep 28, 7:00 PM
rcm created this revision.
rcm created this object with visibility "rcm (R. Christian McDonald)".
rcm created this object with edit policy "rcm (R. Christian McDonald)".
rcm edited the summary of this revision. (Show Details)
rcm edited the test plan for this revision. (Show Details)
rcm added a reviewer: kp.
rcm changed the visibility from "rcm (R. Christian McDonald)" to "Public (No Login Required)".
rcm changed the edit policy from "rcm (R. Christian McDonald)" to "All Users".