From nobody Tue Sep 29 00:14:23 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4htzFC60Ybz6t3Sl for ; Tue, 29 Sep 2026 00:14:23 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4htzFC5P0Hz4Sj5 for ; Tue, 29 Sep 2026 00:14:23 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790640863; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Y63hggaafP4NgyioGfvqRQxAeEVa/veqAmeuD+tJnkk=; b=op6KM8F6jolkk8sVHeZnHqlWEHqmn3ZHf72EH4d3FGXx+fsrBmE9udGz/0snAgqgpQgD76 1g1uwqc4MFYfJ7HOL+dMn8wVJDQBqJXD1uyhdB7HD5LB3S9pV/Wm00Vr7hHz1xLmSxICqT ZjXgg23AQc2Sxua2uYp51iIwnALDnbmqOh02cMrjPXKX/vBa5bjuBSp1kmXY1IMXAdnEiw +3x4WmxoEKHKAqJGr/o79sQzLMzFsGTYeHQjzQnmuiD+2CTiHT8eiZG3jO1OCY9fI/z3GG kW+9/+c2ltY9cuGnWgZjfnupaRxJxnBF6E9LzoWK3hJDuW36cERvkgCBtMNNGg== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790640863; b=iv6wQbjQNFCRoRjH3XlbWC/isGYfn/HH0yy5+w1/v9JtDAtVfAUM9sqHUh+M2pwPxZRw78 kPoGz0c/K11Ovr/bqNcVkFOYaCbVVIxTqMcHoUpKwHViOikTNoZJz+mVmxRS40oBJtGLvi Mgw0TMmVuiImpKL3Uu1GYfoppPgXUqSt44Zi6T8fhu98iNevCy2eawZDdjVqFCZaDVS20U S5OmNNWDENzBHv4w3uLqccgMjyxnb0YgzNG3VZl1dlTkUkUaougaTCSMVhKQtg5TpEC9Ze ypWqaQCXb3mi0hXTMbqW3s1B7kZz3clt07O4lcGtFmacK9HjCD+fh2ZJ2Oc9+Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790640863; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=Y63hggaafP4NgyioGfvqRQxAeEVa/veqAmeuD+tJnkk=; b=c95CLD5BEH/1KtOHKn1yupNtd1z3TeAOE1b+nVdqm2hfPQsL+SANXcSTu1PT2r+odYutvK M5OXnn5VZey23nz7ETLL7eo2xb3EI2HaZmdlzduj4fj/DkqCDQQp7rokGjb4QNQUHTkA65 +CeiLKwn7rM8ALgM3W3cmAuIydOxY2epyQozqctX2pw6riRsBHLkG80RZuqM6XnDMW2nWL zGe9bxMyhoIW+ylZZHKZINDtS9o+GhMqqC4AWofYYIV4/UQykypLx1bjGqlBlu5hDfM87e 7m9JqHbWxEONknNNB8c+MWhbhWMwogBbJ24rTzS+4SU5YwyLM/FsNvLZTGVnfg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4htzFC4NYwzr87 for ; Tue, 29 Sep 2026 00:14:23 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3a9e8 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 29 Sep 2026 00:14:23 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: R. Christian McDonald Subject: git: ee05a360b02e - main - pf: do not loop on an address that is cleared twice in pfr_clr_astats() List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: rcm X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: ee05a360b02e4615d50eae7cababd2ab2d05d488 Auto-Submitted: auto-generated Date: Tue, 29 Sep 2026 00:14:23 +0000 Message-Id: <6abb02df.3a9e8.1775a6ca@gitrepo.freebsd.org> The branch main has been updated by rcm: URL: https://cgit.FreeBSD.org/src/commit/?id=ee05a360b02e4615d50eae7cababd2ab2d05d488 commit ee05a360b02e4615d50eae7cababd2ab2d05d488 Author: R. Christian McDonald AuthorDate: 2026-09-29 00:07:22 +0000 Commit: R. Christian McDonald CommitDate: 2026-09-29 00:11:00 +0000 pf: do not loop on an address that is cleared twice in pfr_clr_astats() pfr_clr_astats() looks up each address it is given and inserts the entry it finds at the head of a work queue. If the same address is given more than once, the entry is inserted twice and the second insertion makes it its own successor. pfr_clstats_kentries() then walks the queue forever, with the rules lock held for writing, so packet processing and every other pf operation in that vnet stop as well. To reproduce: pfctl -e pfctl -t foo -T add 192.0.2.1 pfctl -t foo -T zero 192.0.2.1 192.0.2.1 Do as pfr_del_addrs() does: clear pfrke_mark on the entries named, then queue an entry only the first time it is seen. An address given more than once is cleared, and counted, once. Validate all addresses before any entry is touched. Add a regression test. Reviewed by: kp Approved by: kp (mentor) MFC after: 1 week Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D60103 --- sys/netpfil/pf/pf_table.c | 11 +++++++++-- tests/sys/netpfil/pf/table.sh | 34 ++++++++++++++++++++++++++++++++++ 2 files changed, 43 insertions(+), 2 deletions(-) diff --git a/sys/netpfil/pf/pf_table.c b/sys/netpfil/pf/pf_table.c index d11401b6f5a7..7fc3b0a6380b 100644 --- a/sys/netpfil/pf/pf_table.c +++ b/sys/netpfil/pf/pf_table.c @@ -651,16 +651,23 @@ pfr_clr_astats(struct pfr_table *tbl, struct pfr_addr *addr, int size, kt = pfr_lookup_table(tbl); if (kt == NULL || !(kt->pfrkt_flags & PFR_TFLAG_ACTIVE)) return (ESRCH); - SLIST_INIT(&workq); for (i = 0, ad = addr; i < size; i++, ad++) { if (pfr_validate_addr(ad)) senderr(EINVAL); p = pfr_lookup_addr(kt, ad, 1); + if (p != NULL) + p->pfrke_mark = 0; + } + SLIST_INIT(&workq); + for (i = 0, ad = addr; i < size; i++, ad++) { + p = pfr_lookup_addr(kt, ad, 1); if (flags & PFR_FLAG_FEEDBACK) { ad->pfra_fback = (p != NULL) ? PFR_FB_CLEARED : PFR_FB_NONE; } - if (p != NULL) { + /* An address given more than once is cleared once. */ + if (p != NULL && !p->pfrke_mark) { + p->pfrke_mark = 1; SLIST_INSERT_HEAD(&workq, p, pfrke_workq); xzero++; } diff --git a/tests/sys/netpfil/pf/table.sh b/tests/sys/netpfil/pf/table.sh index c5c9c45c9d3d..7c8cb084b48a 100644 --- a/tests/sys/netpfil/pf/table.sh +++ b/tests/sys/netpfil/pf/table.sh @@ -294,6 +294,39 @@ zero_all_cleanup() pft_cleanup } +atf_test_case "zero_twice" "cleanup" +zero_twice_head() +{ + atf_set descr 'Test zeroing an address that is given twice' + atf_set require.user root + atf_set timeout 30 +} + +zero_twice_body() +{ + pft_init + + vnet_mkjail alcatraz + jexec alcatraz pfctl -e + + pft_set_rules alcatraz \ + "table counters { 192.0.2.1, 192.0.2.3 }" \ + "pass in from to any" + + # This used to hang the kernel with the rules lock held: + # pfr_clr_astats() put the entry on its work queue twice. + atf_check -s exit:0 -e "match:1/2 addresses cleared." \ + jexec alcatraz pfctl -t foo -T zero 192.0.2.1 192.0.2.1 + atf_check -s exit:0 -e "match:2/4 addresses cleared." \ + jexec alcatraz pfctl -t foo -T zero 192.0.2.3 192.0.2.1 \ + 192.0.2.3 192.0.2.5 +} + +zero_twice_cleanup() +{ + pft_cleanup +} + atf_test_case "reset_nonzero" "cleanup" reset_nonzero_head() { @@ -923,6 +956,7 @@ atf_init_test_cases() atf_add_test_case "match_counters" atf_add_test_case "zero_one" atf_add_test_case "zero_all" + atf_add_test_case "zero_twice" atf_add_test_case "reset_nonzero" atf_add_test_case "pr251414" atf_add_test_case "automatic"