From nobody Sat Oct 16 23:12:07 2021 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 7FBD918101B3 for ; Sat, 16 Oct 2021 23:12:08 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-qt1-x830.google.com (mail-qt1-x830.google.com [IPv6:2607:f8b0:4864:20::830]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4HWzRr2vzzz4XRL for ; Sat, 16 Oct 2021 23:12:08 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-qt1-x830.google.com with SMTP id i1so12178695qtr.6 for ; Sat, 16 Oct 2021 16:12:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd.org; s=google; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=OLKXWc6Efue4NFwZ5fortKde2wOnatTl1dte/wexwOE=; b=a7PbvDxb+pI2VaOlZF4fzg8Rsf1NC3EnmeOrCFoeMkIz3/lxlUSaBK7iNhNPnJb00Y IfD+54rw6MtUBswVJhx47TUfPEzMbrPaiy5ju6GslyK4cWN8ofLGdtKr6LeSmI2J7JOr Nhzjj60nyEvKJvrxCVaHm9wsCnNw3XhImHBWkgFiVdHbHLNlZ5C7SLFxCiw6zFobAbe5 v6EV1s1qN2MVxrOXIHU+Tj7LLckLcD0gIopxgdt2ObAUpBjBYhcAgnTY1bb+FeEDtvop lZZTGbMwSn933KbsRW+qC4Kb8U+KgEAgQY/mGfl0su9XxVfNS3YLcth1JQ8WDetO2Gq8 7izw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=OLKXWc6Efue4NFwZ5fortKde2wOnatTl1dte/wexwOE=; b=ELD8kHwXwHTIXceNVuXVt2rdabyjzKRcVeYINTc7RvsnJrMTGwHgpBF2q14eiv6Dac m2HCLps6bEJejg8R/UhSLxeh5JwZ1dG1lHMfo7RRb8ZYr6W0C1ljd9SDDt3NSBhqecBA p/5T+ftx7T+RoaSGQwsz2cFuyFMSfAqUBCUx8SXXOiH32nG8R0ALc22Q2beDBo77i0H9 MSuFKjXfgqt0jtfoQaRk5Dp0VVICF7t4A8S0HzkcfyluzM3DDYgMLtnfw2fFrCrBIuHG UQ15wumqv8HtK6bcfAp4bpUU4x/7/sqSCgq9XaA/q8OozPBadQcKLMLYC9KSPKaauJt+ f14Q== X-Gm-Message-State: AOAM530Jv+7CLu778Z+875/xfUKlGUVvGxf8IEfit7ZcOjM8Ql/bHShm 620h42Bzxkb1gX2w99a1deeQtQvYInkA8MXk X-Google-Smtp-Source: ABdhPJw22gskl28caa5UiaztdGDMXS4I+ljIC7GI3rR9CNb7BmFAmqTZWljEjgWuAFEE8mCYtXPzNA== X-Received: by 2002:ac8:7c52:: with SMTP id o18mr22236067qtv.139.1634425928005; Sat, 16 Oct 2021 16:12:08 -0700 (PDT) Received: from mutt-hbsd (pool-100-16-224-136.bltmmd.fios.verizon.net. [100.16.224.136]) by smtp.gmail.com with ESMTPSA id h20sm2255632qtx.10.2021.10.16.16.12.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 16 Oct 2021 16:12:07 -0700 (PDT) Date: Sat, 16 Oct 2021 19:12:07 -0400 From: Shawn Webb To: Kristof Provost Cc: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org Subject: Re: git: 076b3a50fd71 - main - pf: don't drop packets when redirection information comes from a state Message-ID: <20211016231207.s6rw6ndjrsshya2r@mutt-hbsd> X-Operating-System: FreeBSD mutt-hbsd 14.0-CURRENT-HBSD FreeBSD 14.0-CURRENT-HBSD X-PGP-Key: https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/blob/master/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc References: <202110162306.19GN6MLj036119@gitrepo.freebsd.org> List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-main@freebsd.org X-BeenThere: dev-commits-src-main@freebsd.org MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="pxsb6acv6liysvfb" Content-Disposition: inline In-Reply-To: <202110162306.19GN6MLj036119@gitrepo.freebsd.org> X-Rspamd-Queue-Id: 4HWzRr2vzzz4XRL X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; none X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[] X-ThisMailContainsUnwantedMimeParts: N --pxsb6acv6liysvfb Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Oct 16, 2021 at 11:06:22PM +0000, Kristof Provost wrote: > The branch main has been updated by kp: >=20 > URL: https://cgit.FreeBSD.org/src/commit/?id=3D076b3a50fd71d84f47bca71758= e7fff3c02582e9 >=20 > commit 076b3a50fd71d84f47bca71758e7fff3c02582e9 > Author: Kristof Provost > AuthorDate: 2021-10-16 16:53:39 +0000 > Commit: Kristof Provost > CommitDate: 2021-10-16 21:02:26 +0000 >=20 > pf: don't drop packets when redirection information comes from a state > =20 > For some traffic there might be no matching rule in the current rules= et, > for example when a state was imported via pfsync from a sytem with a > different ruleset checksum. In this case pf_route uses s->rt_addr for > routing target instead of r->rpool.cur but r->rpool is checked anyway, > resulting in dropped packets. > =20 > PR: 259183 > Submitted by: Kajetan Staszkiewicz > Sponsored by: InnoGames GmbH Hey Kristof, Any plans to MFC? Thanks, --=20 Shawn Webb Cofounder / Security Engineer HardenedBSD https://git.hardenedbsd.org/hardenedbsd/pubkeys/-/raw/master/Shawn_Webb/03A= 4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc --pxsb6acv6liysvfb Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEA6TL67gupaZ9nzhT/y5nonf44foFAmFrXEQACgkQ/y5nonf4 4frwDBAAi/OG1vgbYiKMFkm+vYLZqxakAj7629ezWtbrNHZgsl6Eh6JuG3tdrV3A O+cI9b/pR9VN6uLV6HNzaJigAuvudOs4M3nG3oxNOx/w0d0zBuFL0YQ9/L+MHwLO WpJXnq4mwiuzBY4L3MYgMX6/Tyb/JVsmcTKMvdInJYfLIICL5JuCDCaUVnp9md3b FD92W/eHx0AKxi+AhBbrGoJRkXSFA61Nt3v3pmLSpS0H/VHAH/Z77NvDuaecorrL gQvXuqEbwQWn6TSReGI34MOBhMdjAhn7I/1kvrIOSm+w5Iy/Vtdeyt0OYNmln25/ jSE6t8VJBPkyioBLvF+h1ufuCIT+GejcFHm8Xu9aWCGIjiBzZEwPCeoTmtIRo9co ynRKkp+fkHuzwOeASo8Tv9lgHG4DG0rpPIDjT+gttoej1jnktr1yS4uRwa5siPkk 1lwLvbNds4Ux4H1LecNjgkTEjKtHvhi6ye5wG/O9oa6HqbJiBzZk/DrHdLthTbeF uVRwk2OladTkqrJZf5w0bXjXQ7u314JJNPVsc3DngNGuAmkjYigoYtfxhgsDjQ4G vbeCYXxzQTYgE0ttwHLpzmqI+7XuHqwC/7h8q5XQWtj5Ha90PZXN4EgiiwTaSzlm jfa48mNMvwTkUFH9M2Sn0uNfKQWPj0W3GQiwH+TNuz9cDCeQbXw= =ge0J -----END PGP SIGNATURE----- --pxsb6acv6liysvfb--