An af-to pf rule must have an address family naf to use after
authorbluhm <bluhm@openbsd.org>
Mon, 24 Jan 2022 22:49:48 +0000 (22:49 +0000)
committerbluhm <bluhm@openbsd.org>
Mon, 24 Jan 2022 22:49:48 +0000 (22:49 +0000)
commit035d4f5430cb74df720b029db6206161d62be3c7
tree3e2e2994b25276a5d38a7ef36f4d93d58ac213e1
parent0e162ba39fbe078f8a51baba585cc84873fce843
An af-to pf rule must have an address family naf to use after
translation.  Make stricter sanity checks in pf ioctl to avoid later
crashes during packet processing.
Reported-by: syzbot+0ef9190e7d0195496d0d@syzkaller.appspotmail.com
OK sashan@
sys/net/pf_ioctl.c