[Bug 280701] FreeBSD-SA-24:05 fix breaks ICMP/ICMP6 states handling in pf firewall (ping, traceroute)

[email protected]
Newsgroups gmane.os.freebsd.devel.net
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=280701

--- Comment #22 from [email protected] ---
A commit in branch stable/14 references this bug:

URL:
https://cgit.FreeBSD.org/src/commit/?id=46c4fc50d3012ca3c8756df243589add36b70830

commit 46c4fc50d3012ca3c8756df243589add36b70830
Author:     Kristof Provost <[email protected]>
AuthorDate: 2024-08-14 09:29:30 +0000
Commit:     Kristof Provost <[email protected]>
CommitDate: 2024-08-20 15:15:10 +0000

    pf: invert direction for inner icmp state lookups

    (e.g. traceroute with icmp)
    ok henning, jsing

    Also extend the test case to cover this scenario.

    PR:             280701
    Obtained from:  OpenBSD
    MFC after:      1 week
    Sponsored by:   Rubicon Communications, LLC ("Netgate")

    (cherry picked from commit 89f6723288b0d27d3f14f93e6e83f672fa2b8aca)

 sys/netpfil/pf/pf.c           | 21 +++++++++++----------
 tests/sys/netpfil/pf/icmp.sh  |  4 +++-
 tests/sys/netpfil/pf/icmp6.sh |  4 +++-
 3 files changed, 17 insertions(+), 12 deletions(-)

-- 
You are receiving this mail because:
You are the assignee for the bug.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.