mirror of
https://github.com/netbirdio/gvisor.git
synced 2026-05-22 17:12:49 -07:00
Discard invalid Neighbor Solicitations
...per RFC 4861 s7.1.1. PiperOrigin-RevId: 335742851
This commit is contained in:
committed by
gVisor bot
parent
99bf022c2a
commit
95cac27d0d
@@ -309,14 +309,21 @@ func IsV6UnicastAddress(addr tcpip.Address) bool {
|
||||
return addr[0] != 0xff
|
||||
}
|
||||
|
||||
const solicitedNodeMulticastPrefix = "\xff\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\xff"
|
||||
|
||||
// SolicitedNodeAddr computes the solicited-node multicast address. This is
|
||||
// used for NDP. Described in RFC 4291. The argument must be a full-length IPv6
|
||||
// address.
|
||||
func SolicitedNodeAddr(addr tcpip.Address) tcpip.Address {
|
||||
const solicitedNodeMulticastPrefix = "\xff\x02\x00\x00\x00\x00\x00\x00\x00\x00\x00\x01\xff"
|
||||
return solicitedNodeMulticastPrefix + addr[len(addr)-3:]
|
||||
}
|
||||
|
||||
// IsSolicitedNodeAddr determines whether the address is a solicited-node
|
||||
// multicast address.
|
||||
func IsSolicitedNodeAddr(addr tcpip.Address) bool {
|
||||
return solicitedNodeMulticastPrefix == addr[:len(addr)-3]
|
||||
}
|
||||
|
||||
// EthernetAdddressToModifiedEUI64IntoBuf populates buf with a modified EUI-64
|
||||
// from a 48-bit Ethernet/MAC address, as per RFC 4291 section 2.5.1.
|
||||
//
|
||||
|
||||
@@ -286,6 +286,17 @@ func (e *endpoint) handleICMP(r *stack.Route, pkt *stack.PacketBuffer, hasFragme
|
||||
e.linkAddrCache.AddLinkAddress(e.nic.ID(), r.RemoteAddress, sourceLinkAddr)
|
||||
}
|
||||
|
||||
// As per RFC 4861 section 7.1.1:
|
||||
// A node MUST silently discard any received Neighbor Solicitation
|
||||
// messages that do not satisfy all of the following validity checks:
|
||||
// ...
|
||||
// - If the IP source address is the unspecified address, the IP
|
||||
// destination address is a solicited-node multicast address.
|
||||
if unspecifiedSource && !header.IsSolicitedNodeAddr(r.LocalAddress) {
|
||||
received.Invalid.Increment()
|
||||
return
|
||||
}
|
||||
|
||||
// ICMPv6 Neighbor Solicit messages are always sent to
|
||||
// specially crafted IPv6 multicast addresses. As a result, the
|
||||
// route we end up with here has as its LocalAddress such a
|
||||
|
||||
@@ -410,7 +410,7 @@ func TestNeighorSolicitationResponse(t *testing.T) {
|
||||
naDst tcpip.Address
|
||||
}{
|
||||
{
|
||||
name: "Unspecified source to multicast destination",
|
||||
name: "Unspecified source to solicited-node multicast destination",
|
||||
nsOpts: nil,
|
||||
nsSrcLinkAddr: remoteLinkAddr0,
|
||||
nsSrc: header.IPv6Any,
|
||||
@@ -437,11 +437,7 @@ func TestNeighorSolicitationResponse(t *testing.T) {
|
||||
nsSrcLinkAddr: remoteLinkAddr0,
|
||||
nsSrc: header.IPv6Any,
|
||||
nsDst: nicAddr,
|
||||
nsInvalid: false,
|
||||
naDstLinkAddr: remoteLinkAddr0,
|
||||
naSolicited: false,
|
||||
naSrc: nicAddr,
|
||||
naDst: header.IPv6AllNodesMulticastAddress,
|
||||
nsInvalid: true,
|
||||
},
|
||||
{
|
||||
name: "Unspecified source with source ll option to unicast destination",
|
||||
|
||||
Reference in New Issue
Block a user