[Bug 280701] FreeBSD-SA-24:05 fix breaks ICMP/ICMP6 states handling in pf firewall (ping, traceroute)

From: <bugzilla-noreply_at_freebsd.org>
Date: Fri, 06 Sep 2024 15:42:20 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=280701

--- Comment #80 from doktornotor <doktornotor@mailinator.com> ---
As for the technical input: here is another *downstream* issue [1] with pf
debug log (i.e., set debug misc) getting flooded (300K+/day) with

> pf: ICMP error message too short (ip6)

from ND (NS/NA) packets. That *downstream* issue also surprisingly goes away
[2] when reverting [3] *all* those *upstream* patches related to
FreeBSD-SA-24:05.

Hmmmm...

[1] https://github.com/opnsense/core/issues/7840
[2] https://forum.opnsense.org/index.php?topic=42632.msg211600#msg211600
[3] https://github.com/opnsense/src/commit/164bfe67604

-- 
You are receiving this mail because:
You are the assignee for the bug.