Load MSS option via tcpopt exthdr op in clamp rule
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful

This commit is contained in:
2026-10-03 20:50:13 +10:00
parent 410109515e
commit ed3209681d
2 changed files with 20 additions and 7 deletions
+2 -2
View File
@@ -790,7 +790,7 @@ func (c *Compiler) compileMSSClamp(state *FirewallState) {
Type: 2,
Offset: 2,
Len: 2,
Op: 0,
Op: expr.ExthdrOpTcpopt,
},
&expr.Cmp{Op: expr.CmpOpGt, Register: 1, Data: mssBytes},
&expr.Immediate{Register: 1, Data: mssBytes},
@@ -799,7 +799,7 @@ func (c *Compiler) compileMSSClamp(state *FirewallState) {
Type: 2,
Offset: 2,
Len: 2,
Op: 1,
Op: expr.ExthdrOpTcpopt,
},
)
state.Rules["forward"] = append(state.Rules["forward"], ManagedRule{
+18 -5
View File
@@ -1,6 +1,7 @@
package nftables
import (
"reflect"
"testing"
"github.com/google/nftables/expr"
@@ -1197,14 +1198,26 @@ func TestCompile_MSSClamp(t *testing.T) {
t.Fatalf("Compile() error: %v", err)
}
found := false
for _, r := range state.Rules["forward"] {
var rule *ManagedRule
for i, r := range state.Rules["forward"] {
if r.Tag == "mss:eth1" {
found = true
rule = &state.Rules["forward"][i]
}
}
if !found {
t.Error("MSS clamp rule not found in forward chain")
if rule == nil {
t.Fatal("MSS clamp rule not found in forward chain")
}
mss := []byte{0x05, 0x78}
want := []expr.Any{
&expr.Exthdr{DestRegister: 1, Type: 2, Offset: 2, Len: 2, Op: expr.ExthdrOpTcpopt},
&expr.Cmp{Op: expr.CmpOpGt, Register: 1, Data: mss},
&expr.Immediate{Register: 1, Data: mss},
&expr.Exthdr{SourceRegister: 1, Type: 2, Offset: 2, Len: 2, Op: expr.ExthdrOpTcpopt},
}
got := rule.Exprs[len(rule.Exprs)-len(want):]
if !reflect.DeepEqual(got, want) {
t.Errorf("MSS clamp exprs = %#v, want %#v", got, want)
}
}