fix(acl): prevent bidirectional ping from bypassing inbound drop rules (#2570)
* fix(acl): match ICMP replies in outbound allow records Only outbound echo requests with code zero create ICMP response records. Require inbound complete packets and first fragments to be echo replies with code zero before using those records, so reverse echo requests remain subject to inbound ACL rules. Recognize ICMP fragment tails without reading their payload as an ICMP header. Allow them to use existing address and protocol records without creating new records. Walk IPv6 extension headers to locate ICMPv6 and avoid inferring an unknown tail protocol from its payload. Add IPv4 and IPv6 unit coverage for message direction, code, truncation, and fragment parsing. Add a three-node regression for bidirectional requests and ordinary and fragmented replies under inbound default-drop. Fixes #2545 * fix(acl): keep IPv6 parse failures subject to rules Retain source and destination addresses when an IPv6 extension header is truncated, exceeds the payload, or repeats a fragment header. Treat these packets as unspecified protocol instead of entering the global parse-failure allow path. Apply the same handling to truncated transport headers after an extension header. Classify non-ICMPv6 fragment tails as unspecified so their data cannot be parsed as TCP/UDP ports or create temporary response records. Keep ICMPv6 tail authorization through existing response records. Exercise the ACL entry point with malformed headers and short and long fragment tails under default-drop and default-allow policies, including port allow rules that must not match tail payload bytes.
K
KKRainbow committed
dd013e6a2aef8acf1b0f93115c2af9414690e53f
Parent: c96b6c1
Committed by GitHub <noreply@github.com>
on 9/15/2026, 2:03:15 AM