git: 782c6ea08603 - main - pf: do not leak a source hash row lock in the netlink dump

From: R. Christian McDonald <rcm_at_FreeBSD.org>
Date: Fri, 02 Oct 2026 17:13:05 UTC
The branch main has been updated by rcm:

URL: https://cgit.FreeBSD.org/src/commit/?id=782c6ea08603a4839c2c099842df92b6159b799f

commit 782c6ea08603a4839c2c099842df92b6159b799f
Author:     R. Christian McDonald <rcm@FreeBSD.org>
AuthorDate: 2026-10-02 17:10:56 +0000
Commit:     R. Christian McDonald <rcm@FreeBSD.org>
CommitDate: 2026-10-02 17:11:33 +0000

    pf: do not leak a source hash row lock in the netlink dump
    
    pf_handle_get_srcnodes() returns with the lock of a source hash row
    held when it cannot start the message for a source node.  Unlock the
    row there, as the other error exit of the loop does.
    
    Reviewed by:            kp
    Approved by:            kp (mentor)
    Fixes:                  9c125336727b ("pf: convert DIOCGETSRCNODES to netlink")
    MFC after:              1 week
    Sponsored by:           Rubicon Communications, LLC ("Netgate")
    Differential Revision:  https://reviews.freebsd.org/D60251
---
 sys/netpfil/pf/pf_nl.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sys/netpfil/pf/pf_nl.c b/sys/netpfil/pf/pf_nl.c
index 80d12c3abae3..3ddd2308a318 100644
--- a/sys/netpfil/pf/pf_nl.c
+++ b/sys/netpfil/pf/pf_nl.c
@@ -1824,6 +1824,7 @@ pf_handle_get_srcnodes(struct nlmsghdr *hdr, struct nl_pstate *npt)
 
 		LIST_FOREACH(n, &sh->nodes, entry) {
 			if (!nlmsg_reply(nw, hdr, sizeof(struct genlmsghdr))) {
+				PF_HASHROW_UNLOCK(sh);
 				nlmsg_abort(nw);
 				return (ENOMEM);
 			}