The branch main has been updated by kp:

URL: 
https://cgit.FreeBSD.org/src/commit/?id=04f25ef716f74d6bb7941750091c6cb4b51d0b4d

commit 04f25ef716f74d6bb7941750091c6cb4b51d0b4d
Author:     Kristof Provost <[email protected]>
AuthorDate: 2026-07-21 13:10:16 +0000
Commit:     Kristof Provost <[email protected]>
CommitDate: 2026-07-22 09:29:14 +0000

    authpf(8) read_config() should chop off trailing white space
    
    if administrator mistakenly types into configuration file
    
    anchor=authpf_test
    
    where 'authpf_test' is followed by white space, the authpf(8)
    is going to use anchor 'authpf_test ' instead of the 'authpf_test'
    which is defined in pf.conf(5) as 'anchor authpf_test/*'
    
    issue kindly reported and patch submitted by
    
    Avinash Duduskar <avinash.duduskar (_at_) gmail (_dot_) com>
    
    OK sashan@
    
    PR:             296958
    MFC after:      1 week
    Obtained from:  OpenBSD, sashan <[email protected]>, 2d12a8e44d
    Sponsored by:   Rubicon Communications, LLC ("Netgate")
---
 contrib/pf/authpf/authpf.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/contrib/pf/authpf/authpf.c b/contrib/pf/authpf/authpf.c
index 14d3d41b6e21..b835737c5ee2 100644
--- a/contrib/pf/authpf/authpf.c
+++ b/contrib/pf/authpf/authpf.c
@@ -404,8 +404,8 @@ read_config(FILE *f)
                if (ap != &pair[2])
                        goto parse_error;
 
-               tp = pair[1] + strlen(pair[1]);
-               while ((*tp == ' ' || *tp == '\t') && tp >= pair[1])
+               tp = pair[1] + strlen(pair[1]) - 1;
+               while (tp >= pair[1] && (*tp == ' ' || *tp == '\t'))
                        *tp-- = '\0';
 
                if (strcasecmp(pair[0], "anchor") == 0) {

Reply via email to