java-topology/docs/tickets/dragonflybsd-0002.md

1.3 KiB

dragonflybsd-0002 — CWE-407: if_delallmulti_serialized — O(N²) redundant list scan

Severity: MEDIUM File: sys/net/if.c Function: if_delallmulti_serialized CWE: CWE-407 Algorithmic Complexity

Defect

Marker-walk (outer, N multicast entries) calls if_delmulti_serialized() for each, which re-scans the same list to find the entry by address comparison. O(N²) — the pointer is already in hand from the outer walk.

/* outer walk — marker iteration over if_multiaddrs */
while ((ifma = ...next marker...)) {
    if_delmulti_serialized(ifp, ifma->ifma_addr);  // O(N) scan inside
}

/* inside if_delmulti_serialized — scans from head to find by addr */
TAILQ_FOREACH(ifma, &ifp->if_multiaddrs, ifma_link) {
    if (sa_equal(ifma->ifma_addr, sa))  // re-find what caller already has
        break;
}

Complexity: O(N²) where N = number of multicast entries on the interface.

Scale

An interface with 200 multicast subscriptions (common on a multicast router) incurs 40,000 comparisons on if_delallmulti_serialized — triggered at interface teardown or ip_msfilter bulk clear.

Fix

Add if_delmulti_ifma() accepting a direct ifmultiaddr* pointer; skip the scan entirely. The outer marker-walk already holds the pointer — pass it directly and avoid the O(N) re-scan.