Page MenuHomeFreeBSD

icmp6: rate limit our echo replies
ClosedPublic

Authored by glebius on Mar 22 2024, 9:49 PM.
Tags
None
Referenced Files
F95374167: D44480.id136164.diff
Fri, Sep 20, 12:58 PM
Unknown Object (File)
Mon, Sep 16, 10:18 PM
Unknown Object (File)
Mon, Sep 16, 3:25 PM
Unknown Object (File)
Sun, Sep 8, 7:59 PM
Unknown Object (File)
Fri, Sep 6, 3:50 AM
Unknown Object (File)
Sun, Sep 1, 4:16 AM
Unknown Object (File)
Sat, Aug 31, 9:58 PM
Unknown Object (File)
Mon, Aug 26, 7:48 PM

Details

Summary

The generation of ICMP6_ECHO_REPLY bypasses icmp6_error(), thus rate
limit was not applied.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 56751
Build 53639: arc lint + arc unit

Event Timeline

This revision is now accepted and ready to land.Mar 23 2024, 2:21 PM
zlei added a subscriber: zlei.

Generally looks good to me.

sys/netinet6/icmp6.c
549

And do not forget to update statistic icp6s_toofreq if D44479 is abandoned.

This revision was automatically updated to reflect the committed changes.