aboutsummaryrefslogtreecommitdiff
path: root/sys/netinet6/ip6_fastfwd.c
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2025-01-16 15:46:37 +0000
committerMark Johnston <markj@FreeBSD.org>2025-01-16 16:45:16 +0000
commit40faf87894ff67ffdf8126fce9bb438ddf61a26f (patch)
tree961bfc9bc4fb4ea51ec9412b2817d01abccd068a /sys/netinet6/ip6_fastfwd.c
parent886396f1b1a727c642071965612e2c2c9dd11d6c (diff)
ip: Defer checks for an unspecified dstaddr until after pfil hooks
To comply with Common Criteria certification requirements, it may be necessary to ensure that packets to 0.0.0.0/::0 are dropped and logged by the system firewall. Currently, such packets are dropped by ip_input() and ip6_input() before reaching pfil hooks; let's defer the checks slightly to give firewalls a chance to drop the packets themselves, as this gives better observability. Add some regression tests for this with pf+pflog. Note that prior to commit 713264f6b8b, v4 packets to the unspecified address were not dropped by the IP stack at all. Note that ip_forward() and ip6_forward() ensure that such packets are not forwarded; they are passed back unmodified. Add a regression test which ensures that such packets are visible to pflog. Reviewed by: glebius MFC after: 3 weeks Sponsored by: Klara, Inc. Sponsored by: OPNsense Differential Revision: https://reviews.freebsd.org/D48163
Diffstat (limited to 'sys/netinet6/ip6_fastfwd.c')
-rw-r--r--sys/netinet6/ip6_fastfwd.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/sys/netinet6/ip6_fastfwd.c b/sys/netinet6/ip6_fastfwd.c
index 08531cee05bf..0ed313bd49a5 100644
--- a/sys/netinet6/ip6_fastfwd.c
+++ b/sys/netinet6/ip6_fastfwd.c
@@ -107,6 +107,7 @@ ip6_tryforward(struct mbuf *m)
IN6_IS_ADDR_MULTICAST(&ip6->ip6_dst) ||
IN6_IS_ADDR_LINKLOCAL(&ip6->ip6_dst) ||
IN6_IS_ADDR_LINKLOCAL(&ip6->ip6_src) ||
+ IN6_IS_ADDR_UNSPECIFIED(&ip6->ip6_dst) ||
IN6_IS_ADDR_UNSPECIFIED(&ip6->ip6_src) ||
in6_localip(&ip6->ip6_dst))
return (m);