From nobody Fri Sep 29 22:10:53 2023 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Ry4L539Kkz4tlNL; Fri, 29 Sep 2023 22:10:53 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Ry4L52Tnsz3Zwg; Fri, 29 Sep 2023 22:10:53 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696025453; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=+4TXnFXnhDfMKD2rts8Tt3GuXBukVL6NlReyCnRIBb0=; b=swnfoaFoDUvnBVvEH9HgqhGqaK4HEQAtaVVnUpQ2qd/uMH8v2TuJFVor1tPY7IkxphNz0i BQZad/velnhXgiy1PmiR+5EZqsICiu2+CR1/pjnapNq6PBrWBkGvF3tFJQlC4RKKrEqgXm Sv+U2jLpLuRAj1tBAwSfLDAQQbWucU1ytbcVOCH+hP5mLNnYeCl2vpdk+NnyuGhsXefnZE GGZ+DDMK26b59uGix2u3qorfk8+xHlWupkpYoFreOO1BnnfAXXmDURstmI5AJUTRSsEHJP LpTCTpDQoeyBqbwY4d3OSoJdfQvivGEnCk73LPMmMfnwh3eP1oDRU1STA5w7lQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1696025453; a=rsa-sha256; cv=none; b=pbJQybTA/9/I3JYnbLPze1CHE8/QPW5IybXviX8SjvqTxC2zlY5nCa5kIO0nRyMT3dRbnK ofA1NPrR0eI833+iVWPmFy0m/LJudHv0pnSI6+YPMC3HlU4Z3cZYpmkvWej3Xd21yBydsZ A5Yj0Iou8jogiKJZuMTg07885vpMZUkBgHxfT8jWMpDRaDeXUhPXTxiA1ELcnTPOdpQzb4 OmrzV471v15spgrmvmy6pdWQCJFXQaS5TPBGp5GMVy6aEyAE2BEUnFCleWhveaTzwBX7Hx QZ/UfExwQR0XZ+/iIDa/NEAkpxZ7/nHhqM/4g2qjJXvC4yG8Ox76Px7IFIbBtA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696025453; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=+4TXnFXnhDfMKD2rts8Tt3GuXBukVL6NlReyCnRIBb0=; b=yhxpJJUPfonmBvcaxXiwUz5UpPa8QHgPGdaL2d23grhfOQbqyriUHanW/MSbOF+0f0asvi OBmE/gISh1gkzeA/UTeMAm9Dvp4kL6Mkekt3Uzb53eeno6bfeM4TxATwnMjvjufoUDGNc6 DpHd/77U3J9f1gfK8Zizt4klx1bpvnzHnX7Ver5gVY5KEuZKmjoiGdd7crF8dCrJNYxbdZ /IGdul4kSuwlanqhWQZ4vIZjFgxQv/qbNU80u7EaV6pyrVh+tLscJdlUc5j1ZnPbxJNLyw OiOHRFqJcCX0UyB7nfQ7bCx7q0/C/sghjrbtGnSLqacXGLBVFCwY6JlqR8wOWg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Ry4L50vcbz6Pd; Fri, 29 Sep 2023 22:10:53 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 38TMArWc044945; Fri, 29 Sep 2023 22:10:53 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 38TMArqS044940; Fri, 29 Sep 2023 22:10:53 GMT (envelope-from git) Date: Fri, 29 Sep 2023 22:10:53 GMT Message-Id: <202309292210.38TMArqS044940@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: 480f62ccd8d9 - main - pf: only create sctp multihome states if we pass the packet List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 480f62ccd8d998e4db9dc13c354a60f8f5e32a33 Auto-Submitted: auto-generated The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=480f62ccd8d998e4db9dc13c354a60f8f5e32a33 commit 480f62ccd8d998e4db9dc13c354a60f8f5e32a33 Author: Kristof Provost AuthorDate: 2023-09-29 07:23:43 +0000 Commit: Kristof Provost CommitDate: 2023-09-29 22:10:32 +0000 pf: only create sctp multihome states if we pass the packet If we've decided to drop the packet we shouldn't create additional states based off it. MFC after: 3 days Sponsored by: Orange Business Services --- sys/netpfil/pf/pf.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index baa34b16f487..3e1c8d32add9 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -310,7 +310,7 @@ static int pf_test_state_icmp(struct pf_kstate **, struct pfi_kkif *, struct mbuf *, int, void *, struct pf_pdesc *, u_short *); static void pf_sctp_multihome_delayed(struct pf_pdesc *, int, - struct pfi_kkif *, struct pf_kstate *); + struct pfi_kkif *, struct pf_kstate *, int); static int pf_test_state_sctp(struct pf_kstate **, struct pfi_kkif *, struct mbuf *, int, void *, struct pf_pdesc *, u_short *); @@ -5921,10 +5921,10 @@ pf_test_state_sctp(struct pf_kstate **state, struct pfi_kkif *kif, static void pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, - struct pf_kstate *s) + struct pf_kstate *s, int action) { struct pf_sctp_multihome_job *j, *tmp; - int action __unused; + int ret __unused;; struct pf_kstate *sm = NULL; struct pf_krule *ra = NULL; struct pf_krule *r = &V_pf_default_rule; @@ -5933,11 +5933,14 @@ pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, PF_RULES_RLOCK_TRACKER; TAILQ_FOREACH_SAFE(j, &pd->sctp_multihome_jobs, next, tmp) { + if (s == NULL || action != PF_PASS) + goto free; + switch (j->op) { case SCTP_ADD_IP_ADDRESS: { j->pd.sctp_flags |= PFDESC_SCTP_ADD_IP; PF_RULES_RLOCK(); - action = pf_test_rule(&r, &sm, kif, + ret = pf_test_rule(&r, &sm, kif, j->m, off, &j->pd, &ra, &rs, NULL); PF_RULES_RUNLOCK(); SDT_PROBE4(pf, sctp, multihome, test, kif, r, j->m, action); @@ -5986,6 +5989,7 @@ pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, } } +free: free(j, M_PFTEMP); } } @@ -8154,7 +8158,7 @@ done: PF_STATE_UNLOCK(s); out: - pf_sctp_multihome_delayed(&pd, off, kif, s); + pf_sctp_multihome_delayed(&pd, off, kif, s, action); return (action); } @@ -8711,7 +8715,7 @@ done: out: SDT_PROBE4(pf, ip, test6, done, action, reason, r, s); - pf_sctp_multihome_delayed(&pd, off, kif, s); + pf_sctp_multihome_delayed(&pd, off, kif, s, action); return (action); }