]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
pf: skip urpf check for sctp multihomed states
authorKristof Provost <kp@FreeBSD.org>
Thu, 16 Nov 2023 19:55:02 +0000 (20:55 +0100)
committerKristof Provost <kp@FreeBSD.org>
Fri, 17 Nov 2023 22:33:44 +0000 (23:33 +0100)
commita8dbbeb1c71b6f302818b8e041a2b50486b90180
treed39d5b3719159a0d48d66aaad8aecba5f2ff2109
parent0fe663b2a815dcb41431543940ec51408f418392
pf: skip urpf check for sctp multihomed states

When we create a new state for multihomed sctp connections (i.e.
based on INIT/INIT_ACK or ASCONF parameters) we cannot know what
interfaces we'll be seeing that traffic on. These states are floating
states, i.e. on "all" interfaces. We cannot do reverse path filtering
for these states, so do not do so.

MFC after: 1 week
Sponsored by: Orange Business Services
sys/netpfil/pf/pf.c