From nobody Thu Oct 30 10:08:14 2025 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4cy0DZ5NqDz6FQRY; Thu, 30 Oct 2025 10:08:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4cy0DZ4wFvz3w9q; Thu, 30 Oct 2025 10:08:14 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1761818894; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=aARI1ODqlpihZuT+BQp/n612UA7lzNAiGvdMQ57rXvQ=; b=b2ns7dhZO33BMedsqj0lBcaIII0pZAwCSJgfY0CkSp9XyS9sHPVohZckcBHBkyaREY0sBk h0X5EAlEOaer4O+8ZMSQ7TOWr2r2khWO/KzMZpI221Id0MXrbrQrtDLN3AoUIuagBF6jCq rFLuZ5k7SRqMvaGqIsR6KTUAWDUDCzwmLIdtDNPWoCMdDoH7+eDuDM82bMJYjjo/0Az3M8 QNDni+K2LV+PaGd1m6IWyhjeGRaYre4Y1gfdEBR7h7fLZQn79XiGAsK6mtMDiDEJZO/hnv SqrZEs9HdVs5Em2O+WZtGhYXG0lZzIjhTciHZ/0yVhvvzFzNmVuB6JtHZHqVMA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1761818894; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=aARI1ODqlpihZuT+BQp/n612UA7lzNAiGvdMQ57rXvQ=; b=hdMfBudWKhwp3Yv7U9AqPPB/CWtqJfYVvUz2J7dGbv/atheTlrv6YYSyGzCbNHVAc8j9BB FXw9BXznAh0oJWWSn6veISSioJwE+UFyWcU78bPqcayX/Q6j9cTKMmZPZoM15z5Zon+l9F DQ6DDlnu2y7SJOzMz9uj6II0GA62CFZ8U6TuJj+DM4UAfBH7tpumeWkLk1tny7jcae7HNI qgQLSitf+HGnJsi3XyIo0cEOC17AA3icZ0ZZR3boODwislHyy/gCH27VMaX7lzXYeGNIJB UB9dNJm1//529rkLr6++TrPuKkQRqfsgt74ypHtXi3EdocaokWsSiVSSnbdMTg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1761818894; a=rsa-sha256; cv=none; b=vtfUOAeCBZyi+6utMpt1cnRkOy9joBeiMT4ilpUh0kcw8n64g0qwSZIySAWcMnpDtKu8pX UVxRAKQlZ/FLN+4iglIGaUaPCEtEA3k5g3gCa5VjQHXAm+AdQIAFEkjlQgLGKsyu8VLI81 Wp0eL7vaunclS4lqUCILVtEl4Cw7qUdfZjLFDh8fiUk3LXcnyqItEWzOyWUSJij/wri/wL rGbTjRtxLG2homXgEI4fVuas7plb30rjtY58iwrH1Jgz3RBATrCRIU/mb03HqRomyZvCyd Rhz5aRNsRn5i7roqIU6Cr4G5IKW1wdMySicncJcBHTC1uNBhEObH6pUdtOimaw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4cy0DZ4Lpmz363; Thu, 30 Oct 2025 10:08:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 59UA8E0X026019; Thu, 30 Oct 2025 10:08:14 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 59UA8Eg9026016; Thu, 30 Oct 2025 10:08:14 GMT (envelope-from git) Date: Thu, 30 Oct 2025 10:08:14 GMT Message-Id: <202510301008.59UA8Eg9026016@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: faacc0d96881 - main - pf: improve add state validation List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: faacc0d968816cf8714c974b6d8df6191cfb0e0d Auto-Submitted: auto-generated The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=faacc0d968816cf8714c974b6d8df6191cfb0e0d commit faacc0d968816cf8714c974b6d8df6191cfb0e0d Author: Kristof Provost AuthorDate: 2025-10-29 10:40:52 +0000 Commit: Kristof Provost CommitDate: 2025-10-30 08:42:27 +0000 pf: improve add state validation Both for the DIOCADDSTATE ioctl and for states imported through pfsync packets. Add a test case to exercise this code path. Reported by: Ilja Van Sprundel MFC after: 3 days Sponsored by: Rubicon Communications, LLC ("Netgate") --- sys/netpfil/pf/if_pfsync.c | 3 +++ tests/sys/netpfil/pf/ioctl/validation.c | 25 +++++++++++++++++++++++++ 2 files changed, 28 insertions(+) diff --git a/sys/netpfil/pf/if_pfsync.c b/sys/netpfil/pf/if_pfsync.c index 66bc99df2afa..de69ecbb0985 100644 --- a/sys/netpfil/pf/if_pfsync.c +++ b/sys/netpfil/pf/if_pfsync.c @@ -546,6 +546,9 @@ pfsync_state_import(union pfsync_state_union *sp, int flags, int msg_version) PF_RULES_RASSERT(); + if (strnlen(sp->pfs_1301.ifname, IFNAMSIZ) == IFNAMSIZ) + return (EINVAL); + if (sp->pfs_1301.creatorid == 0) { if (V_pf_status.debug >= PF_DEBUG_MISC) printf("%s: invalid creator id: %08x\n", __func__, diff --git a/tests/sys/netpfil/pf/ioctl/validation.c b/tests/sys/netpfil/pf/ioctl/validation.c index a619cfdff2ea..bb060e22f3a0 100644 --- a/tests/sys/netpfil/pf/ioctl/validation.c +++ b/tests/sys/netpfil/pf/ioctl/validation.c @@ -981,6 +981,30 @@ ATF_TC_CLEANUP(natlook, tc) COMMON_CLEANUP(); } +ATF_TC_WITH_CLEANUP(addstate); +ATF_TC_HEAD(addstate, tc) +{ + atf_tc_set_md_var(tc, "require.user", "root"); + atf_tc_set_md_var(tc, "require.kmods", "pfsync"); +} + +ATF_TC_BODY(addstate, tc) +{ + struct pfioc_state st; + + COMMON_HEAD(); + + memset(&st, 'a', sizeof(st)); + st.state.timeout = PFTM_TCP_FIRST_PACKET; + + ATF_CHECK_ERRNO(EINVAL, ioctl(dev, DIOCADDSTATE, &st) == -1); +} + +ATF_TC_CLEANUP(addstate, tc) +{ + COMMON_CLEANUP(); +} + ATF_TP_ADD_TCS(tp) { ATF_TP_ADD_TC(tp, addtables); @@ -1007,6 +1031,7 @@ ATF_TP_ADD_TCS(tp) ATF_TP_ADD_TC(tp, rpool_mtx); ATF_TP_ADD_TC(tp, rpool_mtx2); ATF_TP_ADD_TC(tp, natlook); + ATF_TP_ADD_TC(tp, addstate); return (atf_no_error()); }