git: 5c13a82de8be - main - pf: remove a source limiter from the id tree if its name is taken
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 01 Oct 2026 10:35:23 UTC
The branch main has been updated by rcm:
URL: https://cgit.FreeBSD.org/src/commit/?id=5c13a82de8be51c8472e922a667519d575dcb59e
commit 5c13a82de8be51c8472e922a667519d575dcb59e
Author: R. Christian McDonald <rcm@FreeBSD.org>
AuthorDate: 2026-10-01 10:34:50 +0000
Commit: R. Christian McDonald <rcm@FreeBSD.org>
CommitDate: 2026-10-01 10:34:50 +0000
pf: remove a source limiter from the id tree if its name is taken
When pf_sourcelim_add() finds the name of the new limiter taken, it
undoes the insertion into the id tree with RB_REMOVE() on the name tree,
which the limiter is not in, and then frees the limiter. The freed
limiter stays in the inactive id tree, and RB_REMOVE() of an element
with no links clears the root of the name tree, which loses every other
inactive limiter from it. pf_statelim_add() gets this right.
parse.y refuses duplicate names, so pfctl does not get here, but any
netlink client can.
Reviewed by: kp
Approved by: kp (mentor)
Fixes: 461648121230 ("pf: introduce source and state limiters")
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60189
---
sys/netpfil/pf/pf_ioctl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/sys/netpfil/pf/pf_ioctl.c b/sys/netpfil/pf/pf_ioctl.c
index 76cc6074cd8c..095d357b5ef5 100644
--- a/sys/netpfil/pf/pf_ioctl.c
+++ b/sys/netpfil/pf/pf_ioctl.c
@@ -2237,7 +2237,7 @@ pf_sourcelim_add(const struct pfioc_sourcelim *ioc)
if (RB_INSERT(pf_sourcelim_nm_tree, &V_pf_sourcelim_nm_tree_inactive,
pfsrlim) != NULL) {
- RB_REMOVE(pf_sourcelim_nm_tree, &V_pf_sourcelim_nm_tree_inactive,
+ RB_REMOVE(pf_sourcelim_id_tree, &V_pf_sourcelim_id_tree_inactive,
pfsrlim);
error = EBUSY;
goto unlock;