HomeFreeBSD

pf: remove incorrect fragmentation check

Description

pf: remove incorrect fragmentation check

We do not need to check PFDESC_IP_REAS while tracking TCP state.
Moreover, this check incorrectly considers no-data packets (e.g. RST) to
be in-window when this flag is not set.

Sponsored by: Rubicon Communications, LLC ("Netgate")
Approved by: so
Security: FreeBSD-SA-23:17.pf

(cherry picked from commit 6284d5f76d6bd2d97fe287c5adabf59c79688eda)

Details

Provenance
kpAuthored on Nov 29 2023, 6:06 PM
markjCommitted on Dec 5 2023, 6:25 PM
Parents
rG2e6541b943ef: rc.conf(5): add <service>_umask to run the service using this value
Branches
Unknown
Tags
Unknown