git: fecb9537a83b - main - udp: Let jail policy rewrite the dstaddr for v6 sendto()s

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Mon, 21 Sep 2026 14:23:46 UTC
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=fecb9537a83b6746bc731a7cb3bcf6a33df79562

commit fecb9537a83b6746bc731a7cb3bcf6a33df79562
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-21 14:05:01 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-21 14:05:01 +0000

    udp: Let jail policy rewrite the dstaddr for v6 sendto()s
    
    When performing an unconnected sendto() on a v6 UDP socket in a classic
    jail, we were not applying the usual policy of replacing the loopback
    addr with the jail's primary IP.  Compare with, e.g., udp6_connect() or
    the IPv4 udp_send().  Fix that.
    
    Reported by:    Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li,
                    and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai
    Reviewed by:    bz, glebius
    MFC after:      2 weeks
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D59772
---
 sys/netinet6/udp6_usrreq.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/sys/netinet6/udp6_usrreq.c b/sys/netinet6/udp6_usrreq.c
index 6ef79d2fd868..9e49d5646dbf 100644
--- a/sys/netinet6/udp6_usrreq.c
+++ b/sys/netinet6/udp6_usrreq.c
@@ -824,6 +824,10 @@ udp6_send(struct socket *so, int flags_arg, struct mbuf *m,
 		    ("%s: sin6(%p)->sin6_addr is v4mapped which we "
 		    "should have handled.", __func__, sin6));
 
+		error = prison_remote_ip6(td->td_ucred, &sin6->sin6_addr);
+		if (error != 0)
+			goto release;
+
 		/* This only requires read-locking. */
 		error = in6_selectsrc_socket(sin6, optp, inp,
 		    td->td_ucred, scope_ambiguous, &in6a, NULL);