From nobody Sat Jan 28 02:35:45 2023 X-Original-To: net@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4P3dpn3rGJz3byCG for ; Sat, 28 Jan 2023 02:35:45 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4P3dpn2gsYz3wh6 for ; Sat, 28 Jan 2023 02:35:45 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1674873345; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=QntvS+/nlUx4KL4pN7GbX6nM3WeM3we6DnRKIYGcO90=; b=xUk0nhGqzj0se/zhdZhN2k1KB4vjSSOLxNCNBMGnDdDQPdP8gjluT8fgXDVl2gczFY+iTC 72wNyUEe1gXNS3CNHAFUmDj3dBC14212FnBu+ekv/o5zdExpIB8laDoPtc8Xv3n6C1t8N8 5Pe7ZHv7eor1EbOu4tsiUEyn9LLk7qe0dPzfjUfZOpTLD+7LTpV/JRF1hTXi7I06dLHwe/ JzTVPG/Tl1LbThxHT3K9rZTo+Smi8Ofn0/5W+lf4HRV8ZeZM5a7qRTXwafFzTHWPPgDy/k u6mfIlvcSD9LJn1+fkvY3MjDIhVMAzsKxXlsmVyqtrTn8a6HnwmlrO94HCY4Ew== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1674873345; a=rsa-sha256; cv=none; b=Rfm4hnKrYfZRkZT8eNO3I2vMRztSefGEc3lsxLRBMq++frkl6VhNOReu6oLDwt1emLWG09 yU6NChOFwcef8RfgJyzJb+pgpLdRJvqwkgnkntIwiU/Yh5EmkJb09tYc9Hlyo/rniIF2fd E8bw2w70aqvIPNBJ4svRH4FaOUVi8Wf6o7mKSTTKBktWHO0ATVKnbRdDoNK+vwnubxOgs5 nDAgxvuKspckDg8xPGdL/A+bYmzTW0w3EqheKPOoWhLXnA5Lx9oNWJZVIpuQPHO2/IqAqj 02Sa3vdDEVY3tsoAa5mOBuppobzjYjMhmyV/Dh99pcDDCNIpaY2sIKduMfv23w== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4P3dpn1fYGzXwY for ; Sat, 28 Jan 2023 02:35:45 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 30S2Zjfi091093 for ; Sat, 28 Jan 2023 02:35:45 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 30S2ZjQx091092 for net@FreeBSD.org; Sat, 28 Jan 2023 02:35:45 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: net@FreeBSD.org Subject: [Bug 268246] crash and panic using pfsync on 13.1-RELEASE Date: Sat, 28 Jan 2023 02:35:45 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: changed X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: 13.1-RELEASE X-Bugzilla-Keywords: crash, needs-qa X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: kp@freebsd.org X-Bugzilla-Status: Open X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: net@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: Message-ID: In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Networking and TCP/IP with FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-net List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-net@freebsd.org MIME-Version: 1.0 X-ThisMailContainsUnwantedMimeParts: N https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D268246 --- Comment #42 from Kristof Provost --- (In reply to jjasen from comment #39) Let's be a bit less subtle then: diff --git a/sys/netpfil/pf/if_pfsync.c b/sys/netpfil/pf/if_pfsync.c index 61308a35a7e1..d0bc699e4d29 100644 --- a/sys/netpfil/pf/if_pfsync.c +++ b/sys/netpfil/pf/if_pfsync.c @@ -1734,6 +1738,7 @@ pfsync_defer(struct pf_kstate *st, struct mbuf *m) struct pfsync_softc *sc =3D V_pfsyncif; struct pfsync_deferral *pd; struct pfsync_bucket *b; + struct ip *ip; if (m->m_flags & (M_BCAST|M_MCAST)) return (0); @@ -1751,6 +1756,13 @@ pfsync_defer(struct pf_kstate *st, struct mbuf *m) return (0); } + ip =3D mtod(m, struct ip *); + if (ip->ip_v =3D=3D 4) { + int len =3D ntohs(ip->ip_len); + if (m_length(m, NULL) !=3D len) + panic("Incorrect ip_len %d !=3D m_length %d", len, m_length(m, NULL)); + } + PFSYNC_BUCKET_LOCK(b); PFSYNC_UNLOCK(sc); If that panics we should have a pretty good idea of how we can end up in th= at situation. If it doesn't we have another mystery. --=20 You are receiving this mail because: You are the assignee for the bug.=