git: 5c13a82de8be - main - pf: remove a source limiter from the id tree if its name is taken

From: R. Christian McDonald <rcm_at_FreeBSD.org>
Date: Thu, 01 Oct 2026 10:35:23 UTC
The branch main has been updated by rcm:

URL: https://cgit.FreeBSD.org/src/commit/?id=5c13a82de8be51c8472e922a667519d575dcb59e

commit 5c13a82de8be51c8472e922a667519d575dcb59e
Author:     R. Christian McDonald <rcm@FreeBSD.org>
AuthorDate: 2026-10-01 10:34:50 +0000
Commit:     R. Christian McDonald <rcm@FreeBSD.org>
CommitDate: 2026-10-01 10:34:50 +0000

    pf: remove a source limiter from the id tree if its name is taken
    
    When pf_sourcelim_add() finds the name of the new limiter taken, it
    undoes the insertion into the id tree with RB_REMOVE() on the name tree,
    which the limiter is not in, and then frees the limiter.  The freed
    limiter stays in the inactive id tree, and RB_REMOVE() of an element
    with no links clears the root of the name tree, which loses every other
    inactive limiter from it.  pf_statelim_add() gets this right.
    
    parse.y refuses duplicate names, so pfctl does not get here, but any
    netlink client can.
    
    Reviewed by:            kp
    Approved by:            kp (mentor)
    Fixes:                  461648121230 ("pf: introduce source and state limiters")
    Sponsored by:           Rubicon Communications, LLC ("Netgate")
    Differential Revision:  https://reviews.freebsd.org/D60189
---
 sys/netpfil/pf/pf_ioctl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sys/netpfil/pf/pf_ioctl.c b/sys/netpfil/pf/pf_ioctl.c
index 76cc6074cd8c..095d357b5ef5 100644
--- a/sys/netpfil/pf/pf_ioctl.c
+++ b/sys/netpfil/pf/pf_ioctl.c
@@ -2237,7 +2237,7 @@ pf_sourcelim_add(const struct pfioc_sourcelim *ioc)
 
 	if (RB_INSERT(pf_sourcelim_nm_tree, &V_pf_sourcelim_nm_tree_inactive,
 		pfsrlim) != NULL) {
-		RB_REMOVE(pf_sourcelim_nm_tree, &V_pf_sourcelim_nm_tree_inactive,
+		RB_REMOVE(pf_sourcelim_id_tree, &V_pf_sourcelim_id_tree_inactive,
 		    pfsrlim);
 		error = EBUSY;
 		goto unlock;