Page MenuHomeFreeBSD

pf: apply a netlink table replace once all addresses have arrived
Needs ReviewPublic

Authored by rcm on Fri, Oct 9, 1:23 PM.

Details

Reviewers
kp
glebius
Summary

pfctl sends the addresses of "pfctl -T replace" in messages of 256,
and the kernel applies each message as it arrives: the first marks the
table's entries, each message adds its addresses, and the last removes
the entries that were not marked. Two replaces of one table at the
same time interleave their messages and leave the table with the
addresses of both lists. Packets also see the table half replaced
while the messages arrive, and a pfctl that is killed part way leaves
it that way.

Collect the addresses in the socket's storage and apply them once,
when the last message arrives, as DIOCRSETADDRS does. A replace that
is not completed is discarded when the socket closes, and a message
that continues no replace fails with EINVAL. A replace with more
addresses than the table-entries limit fails with ENOMEM before the
table is touched.

Add a regression test.

Fixes: 08ed87a4a276 ("pf: convert DIOCRSETADDRS to netlink")
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

Regression test included

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped