Page MenuHomeFreeBSD

pf: remove a source limiter from the id tree if its name is taken
ClosedPublic

Authored by rcm on Thu, Oct 1, 12:06 AM.
Tags
None
Referenced Files
F174982903: D60189.id188282.diff
Wed, Oct 7, 9:16 AM
F174979222: D60189.id188282.diff
Wed, Oct 7, 8:25 AM
F174976201: D60189.id188306.diff
Wed, Oct 7, 7:56 AM
F174926299: D60189.id.diff
Wed, Oct 7, 12:41 AM
F174920271: D60189.id188306.diff
Tue, Oct 6, 11:46 PM
F174913774: D60189.id188282.diff
Tue, Oct 6, 10:45 PM
F174899481: D60189.id188282.diff
Tue, Oct 6, 8:41 PM
F174891655: D60189.id188306.diff
Tue, Oct 6, 7:29 PM

Details

Summary

When pf_sourcelim_add() finds the name of the new limiter taken, it
undoes the insertion into the id tree with RB_REMOVE() on the name tree,
which the limiter is not in, and then frees the limiter. The freed
limiter stays in the inactive id tree, and RB_REMOVE() of an element
with no links clears the root of the name tree, which loses every other
inactive limiter from it. pf_statelim_add() gets this right.

parse.y refuses duplicate names, so pfctl does not get here, but any
netlink client can.

Fixes: 461648121230 ("pf: introduce source and state limiters")
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped