git: 2fa4ef491608 - main - pf: free the packet rate counter of a rule

From: R. Christian McDonald <rcm_at_FreeBSD.org>
Date: Thu, 01 Oct 2026 10:33:17 UTC
The branch main has been updated by rcm:

URL: https://cgit.FreeBSD.org/src/commit/?id=2fa4ef491608aad827f8ceef3eb389d8c07451fb

commit 2fa4ef491608aad827f8ceef3eb389d8c07451fb
Author:     R. Christian McDonald <rcm@FreeBSD.org>
AuthorDate: 2026-10-01 10:32:32 +0000
Commit:     R. Christian McDonald <rcm@FreeBSD.org>
CommitDate: 2026-10-01 10:32:32 +0000

    pf: free the packet rate counter of a rule
    
    pf_ioctl_addrule() allocates a counter_rate for every rule, whether it
    has a max-pkt-rate or not, and pf_krule_free() never frees it.
    
    Free it with the rest of the rule.
    
    Reviewed by:            kp
    Approved by:            kp (mentor)
    Fixes:                  ff11f1c8c76c ("pf: add a generic packet rate matching filter")
    MFC after:              1 week
    Sponsored by:           Rubicon Communications, LLC ("Netgate")
    Differential Revision:  https://reviews.freebsd.org/D60190
---
 sys/netpfil/pf/pf_ioctl.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sys/netpfil/pf/pf_ioctl.c b/sys/netpfil/pf/pf_ioctl.c
index ab2140a60ce7..76cc6074cd8c 100644
--- a/sys/netpfil/pf/pf_ioctl.c
+++ b/sys/netpfil/pf/pf_ioctl.c
@@ -2758,6 +2758,7 @@ pf_krule_free(struct pf_krule *rule)
 	counter_u64_free(rule->states_tot);
 	for (pf_sn_types_t sn_type=0; sn_type<PF_SN_MAX; sn_type++)
 		counter_u64_free(rule->src_nodes[sn_type]);
+	counter_rate_free(rule->pktrate.cr);
 	uma_zfree_pcpu(pf_timestamp_pcpu_zone, rule->timestamp);
 
 	mtx_destroy(&rule->nat.mtx);