diff options
| author | R. Christian McDonald <rcm@FreeBSD.org> | 2026-09-29 00:07:22 +0000 |
|---|---|---|
| committer | R. Christian McDonald <rcm@FreeBSD.org> | 2026-09-29 00:11:00 +0000 |
| commit | ee05a360b02e4615d50eae7cababd2ab2d05d488 (patch) | |
| tree | 227ae08be6464044eb5aeae3449e0e8308226edc /stand/kshim/kshim.mk | |
| parent | f084f28a52c5fb4557ff0b56e98ca36af3d8eec0 (diff) | |
pfr_clr_astats() looks up each address it is given and inserts the entry
it finds at the head of a work queue. If the same address is given more
than once, the entry is inserted twice and the second insertion makes it
its own successor. pfr_clstats_kentries() then walks the queue forever,
with the rules lock held for writing, so packet processing and every
other pf operation in that vnet stop as well. To reproduce:
pfctl -e
pfctl -t foo -T add 192.0.2.1
pfctl -t foo -T zero 192.0.2.1 192.0.2.1
Do as pfr_del_addrs() does: clear pfrke_mark on the entries named, then
queue an entry only the first time it is seen. An address given more
than once is cleared, and counted, once. Validate all addresses before
any entry is touched.
Add a regression test.
Reviewed by: kp
Approved by: kp (mentor)
MFC after: 1 week
Sponsored by: Rubicon Communications, LLC ("Netgate")
Differential Revision: https://reviews.freebsd.org/D60103
Diffstat (limited to 'stand/kshim/kshim.mk')
0 files changed, 0 insertions, 0 deletions
