From nobody Mon Oct 02 09:33:30 2023 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RzbNp5MLWz4vrfJ; Mon, 2 Oct 2023 09:33:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RzbNp3zYvz4SsL; Mon, 2 Oct 2023 09:33:30 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696239210; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=C3GD4ZxX2R/383VXRLf0pO5gY918xFnS1A0tzZiBfGI=; b=WrvOaYLjXr6u/6UIQpD9tBQN9MetFk/zAFHlniPAz0SDaiingXXPTpxcIKAp45AajP1qVg 66YcwbtBmA2xAwqEL7K4V1VfwwiZ30DCSE8x1gcaMoe2NKkT3fK5uycsDa+8PWdjRkZIDn cB3igCmsVQUP3VH6dQgVWfhgy1nhJYygt4nWX0R6NY1VTgyFC8BhMlcQV+dOnUZYx636CF QvUWFa92J5eT7BPCHHAjmteCgueQfAUNWeEVJcfBXcxonuzd2HIOgvZhZSp59d6b5dDsSN T1+YmLzOxGiPIWxSPuAv1YXuI9CD77ELx+fE6h3FGB1UNCIitnrXAmsl66/4Nw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1696239210; a=rsa-sha256; cv=none; b=L2yniY/IzsR8+1miAsUBIasujCRyZ2qelwGJ8hqfzR9OV883Ck7M1qcw+Z/78af/QUB6MV xEBSDF9AO6E41ZpFRlAS6zobcuyufpOZaHNAzSkkbBxZGhuzpXbVRcr812e8Ok9V+sJ3DH 8UkZPkWRQNgs2aIh5OdsgyfbSetB7sSSQ7ZJ6clzhDfzo/3bEQPXIu6Qe08oqRf7XFoxJh 3Xov9Wy5mRwBI+Fy1LUaEuR8PCE/qDycMnzhNtf1uD6w4qt/IZEitpr7rES1JyNN2bnhp9 OvmB0TO7dTpLsPLiCtCmfij0NX97IUum6jfy0ZFyV7NFAIA4WMxW/ZWu8+kk2Q== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696239210; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=C3GD4ZxX2R/383VXRLf0pO5gY918xFnS1A0tzZiBfGI=; b=HD1A0IYVwrZepE9a3rHmjl2yKbiZF27HkrS81Syc2NHxpl33tPxAzech4fzW41InJgJN0C 7Mn7QeZBYR5yiGaeMm5GdLUbv79L9Uqe9SDU8CDms1wfmthj/uBInFiZxH6XEbIQ7TcElF zd1qWbbI3Afko9KV52haqTwjrpjM72aHKWqadpbklT0nLZGM32dpxAdbZisF5NYYR3A61O IzzVjn2k2jXBcCxYm7eiF3NtjkXmZc+F8YyVjRA7vGZxECRbmzmQtmRX+7eNHiKa5kmq+Y aJ6w9hICyhBo4sgV9aZfl1ik0+ywdOitPKxZm6QF2T0hFDw/x2IbD847R3NbBw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RzbNp2pCdz16CF; Mon, 2 Oct 2023 09:33:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3929XUOg003448; Mon, 2 Oct 2023 09:33:30 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3929XU9c003444; Mon, 2 Oct 2023 09:33:30 GMT (envelope-from git) Date: Mon, 2 Oct 2023 09:33:30 GMT Message-Id: <202310020933.3929XU9c003444@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Kristof Provost Subject: git: 3ab984bbe014 - stable/14 - pf: only create sctp multihome states if we pass the packet List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: 3ab984bbe0144f029d27a9ca0628b1f47a419688 Auto-Submitted: auto-generated The branch stable/14 has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=3ab984bbe0144f029d27a9ca0628b1f47a419688 commit 3ab984bbe0144f029d27a9ca0628b1f47a419688 Author: Kristof Provost AuthorDate: 2023-09-29 07:23:43 +0000 Commit: Kristof Provost CommitDate: 2023-10-02 09:32:14 +0000 pf: only create sctp multihome states if we pass the packet If we've decided to drop the packet we shouldn't create additional states based off it. MFC after: 3 days Sponsored by: Orange Business Services (cherry picked from commit 480f62ccd8d998e4db9dc13c354a60f8f5e32a33) --- sys/netpfil/pf/pf.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index 9e6cd7fae492..3e1c8d32add9 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -310,7 +310,7 @@ static int pf_test_state_icmp(struct pf_kstate **, struct pfi_kkif *, struct mbuf *, int, void *, struct pf_pdesc *, u_short *); static void pf_sctp_multihome_delayed(struct pf_pdesc *, int, - struct pfi_kkif *, struct pf_kstate *); + struct pfi_kkif *, struct pf_kstate *, int); static int pf_test_state_sctp(struct pf_kstate **, struct pfi_kkif *, struct mbuf *, int, void *, struct pf_pdesc *, u_short *); @@ -5921,10 +5921,10 @@ pf_test_state_sctp(struct pf_kstate **state, struct pfi_kkif *kif, static void pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, - struct pf_kstate *s) + struct pf_kstate *s, int action) { struct pf_sctp_multihome_job *j, *tmp; - int action;; + int ret __unused;; struct pf_kstate *sm = NULL; struct pf_krule *ra = NULL; struct pf_krule *r = &V_pf_default_rule; @@ -5933,11 +5933,14 @@ pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, PF_RULES_RLOCK_TRACKER; TAILQ_FOREACH_SAFE(j, &pd->sctp_multihome_jobs, next, tmp) { + if (s == NULL || action != PF_PASS) + goto free; + switch (j->op) { case SCTP_ADD_IP_ADDRESS: { j->pd.sctp_flags |= PFDESC_SCTP_ADD_IP; PF_RULES_RLOCK(); - action = pf_test_rule(&r, &sm, kif, + ret = pf_test_rule(&r, &sm, kif, j->m, off, &j->pd, &ra, &rs, NULL); PF_RULES_RUNLOCK(); SDT_PROBE4(pf, sctp, multihome, test, kif, r, j->m, action); @@ -5986,6 +5989,7 @@ pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, } } +free: free(j, M_PFTEMP); } } @@ -8154,7 +8158,7 @@ done: PF_STATE_UNLOCK(s); out: - pf_sctp_multihome_delayed(&pd, off, kif, s); + pf_sctp_multihome_delayed(&pd, off, kif, s, action); return (action); } @@ -8711,7 +8715,7 @@ done: out: SDT_PROBE4(pf, ip, test6, done, action, reason, r, s); - pf_sctp_multihome_delayed(&pd, off, kif, s); + pf_sctp_multihome_delayed(&pd, off, kif, s, action); return (action); }