Page MenuHomeFreeBSD

pf: remove a source limiter from the id tree if its name is taken
Needs ReviewPublic

Authored by rcm on Thu, Oct 1, 12:06 AM.

Details

Reviewers
kp
Summary

When pf_sourcelim_add() finds the name of the new limiter taken, it
undoes the insertion into the id tree with RB_REMOVE() on the name tree,
which the limiter is not in, and then frees the limiter. The freed
limiter stays in the inactive id tree, and RB_REMOVE() of an element
with no links clears the root of the name tree, which loses every other
inactive limiter from it. pf_statelim_add() gets this right.

parse.y refuses duplicate names, so pfctl does not get here, but any
netlink client can.

Fixes: 461648121230 ("pf: introduce source and state limiters")
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped