From nobody Mon Oct 02 09:33:31 2023 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4RzbNq6LYnz4vrHB; Mon, 2 Oct 2023 09:33:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4RzbNq5bKBz4SlB; Mon, 2 Oct 2023 09:33:31 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696239211; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=8Xhe6IA1r7VJwg0lyiP3xKA2kL48V48tw2LpdcvmXCE=; b=ot6/CTYCxFRHemDh8QJx8RKUTtP0bqlLvOTYCcR9Wglu0BIlH7nTGQVOyHWnqlxo87k9h6 M10QAtxZExCHEo20/S0hZsPlSWCnxLthrjNyjUGhhkVocsWQ1rkA1GTfMVRFShB63YXdbz kuSZZrZ6DTBlqUn1Z3h5/uc4lIVBrzo5UZ/sAv3k6JUFyEGwmLtT6kVjPIErKr5qnYVVH2 Ghggl0Tx02G/0Qq6PYdiwK+IGzd8kAk7as0G5OLeLqNRAvbA52R4aImzR9aFbI+lcJWFoJ 68q7fsH2c1QNzUrGuReBsvgTvXwpKjpqk/41mRODJ1Rj0aKMTYvywgkW1qqjOQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1696239211; a=rsa-sha256; cv=none; b=CrQyuVNVcu1S+xP9UrJ1qw4YIJ/MyQZuaW2dfWoZVW1KzVGuLv3UcDPfOrC5B4S4+8++BJ 4PV7v/e/ReRTt6W8NjjB5gnU7yVIpJRTVsb79tvEdOpGY07fVR7ONhpzlysl73DfU+Zjp1 Sa/1zIXYAkWDrB5vicRrt9ZYvCVpy0aIbwZqOIQVUtmqtGV7QhCesBDUJkBOnURLY04y0R oI1QkONPvaPRtknUNI5APkPiNRqA0zj1sFrQU6XXDCoQCsa5DaEhQrAX0mFIPHqnv6Vq0D 5adMTk5A86x551m2Q/lljPRIHkFvwl1uK1kGAm0aX5bI5m8ZDDVXTbmtogX87w== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1696239211; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=8Xhe6IA1r7VJwg0lyiP3xKA2kL48V48tw2LpdcvmXCE=; b=cl8sPcEQtQ/BHNPFZTtFPspuMUGBZVXeB31nkp3yXe/Gy39M1DnxCnLxd9nrdF3XJSp8H1 Hmf2Z7RjG323+tslA44dNkH1JfI2zAmnSlwbM8Unmn43jRkS/vd1gDADuWpH0UCEsxcYI9 7YT/bVkhpQ64wc1P6NPqgVBx8S6r20PXuUj6+bVxuTaLzC8ODWTlpho/Yjr6gwWr7BjgEX qOS8jIL72qB2RwgT6BLQOid4IHkylSO6wdTiK3vtevcTnzsDNpe8Z81evpuv4h53Xb6ZX0 lwY+I/dS7NLdVcoZOSDAjlPtPfUpM4fh5WNkGGrSDU2bir8jxoud9rJoRsNTYQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4RzbNq3tmjz16LT; Mon, 2 Oct 2023 09:33:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 3929XV12003559; Mon, 2 Oct 2023 09:33:31 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 3929XVXX003540; Mon, 2 Oct 2023 09:33:31 GMT (envelope-from git) Date: Mon, 2 Oct 2023 09:33:31 GMT Message-Id: <202310020933.3929XVXX003540@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Kristof Provost Subject: git: 0ca691ad1612 - stable/13 - pf: only create sctp multihome states if we pass the packet List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-all@freebsd.org X-BeenThere: dev-commits-src-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/stable/13 X-Git-Reftype: branch X-Git-Commit: 0ca691ad161253a123d9dac9e65953fe382920a5 Auto-Submitted: auto-generated The branch stable/13 has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=0ca691ad161253a123d9dac9e65953fe382920a5 commit 0ca691ad161253a123d9dac9e65953fe382920a5 Author: Kristof Provost AuthorDate: 2023-09-29 07:23:43 +0000 Commit: Kristof Provost CommitDate: 2023-10-02 08:51:44 +0000 pf: only create sctp multihome states if we pass the packet If we've decided to drop the packet we shouldn't create additional states based off it. MFC after: 3 days Sponsored by: Orange Business Services (cherry picked from commit 480f62ccd8d998e4db9dc13c354a60f8f5e32a33) --- sys/netpfil/pf/pf.c | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index 5f94379d58fa..501d9eef57cd 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -291,7 +291,7 @@ static int pf_test_state_icmp(struct pf_kstate **, int, struct pfi_kkif *, struct mbuf *, int, void *, struct pf_pdesc *, u_short *); static void pf_sctp_multihome_delayed(struct pf_pdesc *, int, - struct pfi_kkif *, struct pf_kstate *); + struct pfi_kkif *, struct pf_kstate *, int); static int pf_test_state_sctp(struct pf_kstate **, struct pfi_kkif *, struct mbuf *, int, void *, struct pf_pdesc *, u_short *); @@ -5343,10 +5343,10 @@ pf_test_state_sctp(struct pf_kstate **state, struct pfi_kkif *kif, static void pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, - struct pf_kstate *s) + struct pf_kstate *s, int action) { struct pf_sctp_multihome_job *j, *tmp; - int action;; + int ret __unused;; struct pf_kstate *sm = NULL; struct pf_krule *ra = NULL; struct pf_krule *r = &V_pf_default_rule; @@ -5355,11 +5355,14 @@ pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, PF_RULES_RLOCK_TRACKER; TAILQ_FOREACH_SAFE(j, &pd->sctp_multihome_jobs, next, tmp) { + if (s == NULL || action != PF_PASS) + goto free; + switch (j->op) { case SCTP_ADD_IP_ADDRESS: { j->pd.sctp_flags |= PFDESC_SCTP_ADD_IP; PF_RULES_RLOCK(); - action = pf_test_rule(&r, &sm, pd->dir, kif, + ret = pf_test_rule(&r, &sm, pd->dir, kif, j->m, off, &j->pd, &ra, &rs, NULL); PF_RULES_RUNLOCK(); SDT_PROBE4(pf, sctp, multihome, test, kif, r, j->m, action); @@ -5408,6 +5411,7 @@ pf_sctp_multihome_delayed(struct pf_pdesc *pd, int off, struct pfi_kkif *kif, } } +free: free(j, M_PFTEMP); } } @@ -7310,7 +7314,7 @@ done: PF_STATE_UNLOCK(s); out: - pf_sctp_multihome_delayed(&pd, off, kif, s); + pf_sctp_multihome_delayed(&pd, off, kif, s, action); return (action); } @@ -7803,7 +7807,7 @@ done: out: SDT_PROBE4(pf, ip, test6, done, action, reason, r, s); - pf_sctp_multihome_delayed(&pd, off, kif, s); + pf_sctp_multihome_delayed(&pd, off, kif, s, action); return (action); }