summaryrefslogtreecommitdiffstats
path: root/sys/netpfil/pf
diff options
context:
space:
mode:
authorglebius <glebius@FreeBSD.org>2012-12-13 12:48:57 +0000
committerglebius <glebius@FreeBSD.org>2012-12-13 12:48:57 +0000
commitd370f96d4ccd311d5725056967234b35a54039d2 (patch)
treea68e4e2888507229eb262d8b6655e2a59fce4825 /sys/netpfil/pf
parent8137816adb03dc4adf599f4790b2f2cecbe5f5b4 (diff)
downloadFreeBSD-src-d370f96d4ccd311d5725056967234b35a54039d2.zip
FreeBSD-src-d370f96d4ccd311d5725056967234b35a54039d2.tar.gz
Initialize state id prior to attaching state to key hash. Otherwise a
race can happen, when pf_find_state() finds state via key hash, and locks id hash slot 0 instead of appropriate to state id slot.
Diffstat (limited to 'sys/netpfil/pf')
-rw-r--r--sys/netpfil/pf/pf.c6
1 files changed, 3 insertions, 3 deletions
diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c
index 5816320..d629aea 100644
--- a/sys/netpfil/pf/pf.c
+++ b/sys/netpfil/pf/pf.c
@@ -1080,9 +1080,6 @@ pf_state_insert(struct pfi_kif *kif, struct pf_state_key *skw,
s->kif = kif;
- if (pf_state_key_attach(skw, sks, s))
- return (-1);
-
if (s->id == 0 && s->creatorid == 0) {
/* XXX: should be atomic, but probability of collision low */
if ((s->id = V_pf_stateid[curcpu]++) == PFID_MAXID)
@@ -1092,6 +1089,9 @@ pf_state_insert(struct pfi_kif *kif, struct pf_state_key *skw,
s->creatorid = V_pf_status.hostid;
}
+ if (pf_state_key_attach(skw, sks, s))
+ return (-1);
+
ih = &V_pf_idhash[PF_IDHASH(s)];
PF_HASHROW_LOCK(ih);
LIST_FOREACH(cur, &ih->states, entry)
OpenPOWER on IntegriCloud