From nobody Tue May 19 16:22:30 2026 X-Original-To: bugs@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gKg1f1sNsz6fQCh for ; Tue, 19 May 2026 16:22:30 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R13" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gKg1f0rVVz4838 for ; Tue, 19 May 2026 16:22:30 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1779207750; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OvRX6RD564V/E0NP4MCieOu+kHJ6SD5Ffr/1G0FuIqo=; b=wmFEJrRvOWPCSFrDrmVCTfbfZnLsXnxm16ThQBHTf0LVrixStFb1WinYUqp4BDfUlfo0p4 8q60UJldDconYZaeFzUmqhfLjyz/aqcfm73AdWzcvUNz4N9Ofit90Dgi0rmkSFqK9tYCfA Ap0p6VkNtjQkOobtDkgeDf4Eoa6D8ljWkmnq1xJtOed0R8Le8Uqdt0lIAAxP4jNEdopio6 gxXEmMmUkcwo0b1GDh3N3HX+A4RPemCrNrb8px7NDwDxtQ3FTqRQ/YmPQmSPr+ix+fM87y U5I+UzN9ExAFIN3Ur+jVlqemgceICwB5WtgyZS7Scer0lXrUfSfyBuEZh40Vcg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1779207750; a=rsa-sha256; cv=none; b=CJ1tfYmYPJsmLQygDig7V8WfuKKwWHoqfv03kHuPGPgAYftpmIZe8hPuQ/K8aNXCBcN6BX 8UvDtwHacmHYQMK+ByXTqD9m0Al53maUVlr18drMOHSW0K72IxYbxUYLoHvZLybUeAapAl a979nV2rr3ojGyAZu53fkCg5l2t2/XnnPVazxwHuo8nXIjosc8S2mbYzJI3KlEENJUZpAn 36DXZiN03ul+6L9jBxfOXIqZ+NIXI3ybab5AYRoywWZDKx4a7IspJZB59JJy959H4e62BM Q+9YtsVZ1yKgdHs6YU8jx99b5NSGzv4ZAih4fPQQBqaZDFvT0o+0KN1eLIvS5w== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1779207750; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=OvRX6RD564V/E0NP4MCieOu+kHJ6SD5Ffr/1G0FuIqo=; b=LL8cJ2E3NUCwQpcck1UGMqlRcwwhWUuqxUeElKFFr9ol9apDlz0WxDpKKKgNTnlVQNLeij QzTlreY7Q2Iqd2uIe8bbrNHlV3Afolx3CkRRBWGC6m2Cojjw9fwHynD+Jf7eqEa94BRLj+ H6sewKMBUZjEBIf6+yeaPTkPn1YG0fuMN1TEppl1OYvPChQBPr+D1R481dLOLT9xeb+d0n qysiDgJ9I7F8ymJciDG9FezedkkrDGeElJfeCD3W+Pbzlp6YwgHNb8nrQUKvlonIYJhApC gtaG+PrCTRIaPyytzP04bUdchbDdiAPxdvXs7LaqG9CirePfFWMO9Xl7D6qIHA== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4gKg1f0Jtdz7HQ for ; Tue, 19 May 2026 16:22:30 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 64JGMTTK040359 for ; Tue, 19 May 2026 16:22:29 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 64JGMT5f040358 for bugs@FreeBSD.org; Tue, 19 May 2026 16:22:29 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: bugs@FreeBSD.org Subject: [Bug 295415] net/if_ethersubr: Promiscuous frames are passed to upper layers with netgraph Date: Tue, 19 May 2026 16:22:30 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: new X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 16.0-CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Many People X-Bugzilla-Who: martin.mayer@m2-it-solutions.de X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: bugs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_id short_desc product version rep_platform op_sys bug_status bug_severity priority component assigned_to reporter Message-ID: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Bug reports List-Archive: https://lists.freebsd.org/archives/freebsd-bugs List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-bugs@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D295415 Bug ID: 295415 Summary: net/if_ethersubr: Promiscuous frames are passed to upper layers with netgraph Product: Base System Version: 16.0-CURRENT Hardware: Any OS: Any Status: New Severity: Affects Many People Priority: --- Component: kern Assignee: bugs@FreeBSD.org Reporter: martin.mayer@m2-it-solutions.de Overview -------- Frames ingressing the NIC which are not destined to this host are passed to upper layers if netgraph is used and promiscuous mode is enabled. This can also lead to packets being seen as duplicated/re-routed if the mac= hine has IP forwarding enabled. Steps to reproduce ------------------ Add a netgraph to NIC: ngctl mkpeer em0: tee lower left && \ ngctl name em0:lower tee1 && \ ngctl connect em0: tee1: upper right Enable promiscuous mode: ngctl msg em0: setpromisc 1 Connect host to a shared ethernet (no switched network). Packets from foreign hosts will also arrive on the machine's NIC. If you want to see FreeBSD to re-route foreign IP packets, enable IP forwarding: sysctl net.inet.ip.forwarding=3D1 If foreign hosts ping each other, you'll notice duplicates. How does this bug affect production environments ------------------------------------------------ If FreeBSD is used in a CARP setup promiscuous mode is enabled. If one want= s to use netgraph, destination checks in ether_input_internal() are skipped. Because of that, frames which are not destined to the host miss the M_PROMI= SC flag in m->m_flags when entering ether_demux() after passing netgraph. This can lead to duplicate packets until TTL is decremented to the minimum. It can be even observed in switched networks when DLFs happen or traffic ne= eds to be flooded for other reasons. Normal behavior --------------- If netgraph is not used, a packet is flagged with M_PROMISC if it is a promiscuously captured frame. ether_input_internal(): #if defined(INET) || defined(INET6) /* * Clear M_PROMISC on frame so that carp(4) will see it when the * mbuf flows up to Layer 3. * FreeBSD's implementation of carp(4) uses the inprotosw * to dispatch IPPROTO_CARP. carp(4) also allocates its own * Ethernet addresses of the form 00:00:5e:00:01:xx, which * is outside the scope of the M_PROMISC test below. * TODO: Maintain a hash table of ethernet addresses other than * ether_dhost which may be active on this ifp. */ if (ifp->if_carp && (*carp_forus_p)(ifp, eh->ether_dhost)) { m->m_flags &=3D ~M_PROMISC; } else #endif { /* * If the frame received was not for our MAC address, set t= he * M_PROMISC flag on the mbuf chain. The frame may need to * be seen by the rest of the Ethernet input path in case of * re-entry (e.g. bridge, vlan, netgraph) but should not be * seen by upper protocol layers. */ if (!ETHER_IS_MULTICAST(eh->ether_dhost) && memcmp(IF_LLADDR(ifp), eh->ether_dhost, ETHER_ADDR_LEN)= !=3D 0) m->m_flags |=3D M_PROMISC; } Afterwards it will be freed and not passed to higher layers. ether_demux(): /* * Pass promiscuously received frames to the upper layer if the user * requested this by setting IFF_PPROMISC. Otherwise, drop them. */ if ((ifp->if_flags & IFF_PPROMISC) =3D=3D 0 && (m->m_flags & M_PROM= ISC)) { m_freem(m); return; } Possible solution ----------------- A possible solution might be to move the checks at the end of ether_input_internal() to the beginning of ether_demux(). I wrote quick'n'dirty fixes which proof that this will fix the issue, but I= 'm not sure if it will break other things. External references ------------------- - https://lists.freebsd.org/archives/freebsd-net/2026-January/008272.html - https://github.com/opnsense/src/issues/279 --=20 You are receiving this mail because: You are the assignee for the bug.=