Page MenuHomeFreeBSD

pf: take the rules read lock in pf_handle_getrule()
ClosedPublic

Authored by rcm on Wed, Sep 30, 2:04 AM.
Tags
None
Referenced Files
F174170440: D60161.diff
Thu, Oct 1, 3:03 AM
F174153238: D60161.diff
Wed, Sep 30, 11:32 PM
F174145314: D60161.id188150.diff
Wed, Sep 30, 10:06 PM
F174131210: D60161.id188150.diff
Wed, Sep 30, 7:55 PM
F174122102: D60161.diff
Wed, Sep 30, 6:46 PM
F174107219: D60161.diff
Wed, Sep 30, 4:32 PM
F174065971: D60161.id188150.diff
Wed, Sep 30, 8:39 AM
F174065750: D60161.diff
Wed, Sep 30, 8:37 AM

Details

Summary

pfctl -sr calls PFNL_CMD_GETRULE once per rule, and
pf_handle_getrule() takes the rules write lock each time, so listing a
ruleset of N rules stops packet processing N times. Only zeroing the
counters (pfctl -z) needs the write lock. Take the read lock
otherwise, as DIOCGETRULENV does.

Fixes: 777a4702c591 ("pf: implement addrule via netlink")
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable