Page MenuHomeFreeBSD

netinet: re-read IP length after PFIL hook
ClosedPublic

Authored by kp on Jun 2 2023, 7:27 PM.
Tags
None
Referenced Files
F107194723: D40395.diff
Sat, Jan 11, 11:54 AM
Unknown Object (File)
Nov 19 2024, 5:51 AM
Unknown Object (File)
Nov 19 2024, 1:32 AM
Unknown Object (File)
Nov 11 2024, 12:09 AM
Unknown Object (File)
Oct 17 2024, 8:42 AM
Unknown Object (File)
Oct 1 2024, 7:48 AM
Unknown Object (File)
Oct 1 2024, 7:46 AM
Unknown Object (File)
Oct 1 2024, 5:00 AM

Details

Summary

The pfil hook may modify the packet, so before we check its length (to
decide if it needs to be fragmented or not) we should re-read that
length.

This is most likely to happen when pf is reassembling packets. In that
scenario we'd receive the last fragment, which is likely to be a short
packet, pf would reassemble it (likely exceeding the interface MTU) and
then we'd transmit it without fragmenting, because we're comparing the
MTU to the length of the last fragment, not the fully reassembled
packet.

See also: https://redmine.pfsense.org/issues/14396
MFC after: 3 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 51866
Build 48757: arc lint + arc unit

Event Timeline

kp requested review of this revision.Jun 2 2023, 7:27 PM

so the reload is only needed if hooks are present to begin with? as in it should get hoisted up

what about other fields:

ip = mtod(m, struct ip *);
ip_len = ntohs(ip->ip_len);
ip_off = ntohs(ip->ip_off);

ip is is already getting reloaded

  • move re-read of ip_len to only be done when we run pfil hooks.
cy added a subscriber: cy.

LGTM

This revision is now accepted and ready to land.Jun 5 2023, 3:20 PM
This revision was automatically updated to reflect the committed changes.