Fix MSS clamp loading the option as an IPv6 exthdr #19
Reference in New Issue
Block a user
Delete Branch "benvin/mss-clamp-tcpopt"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The MSS clamp rule loads the MSS option with exthdr op 0 (IPv6), so the kernel lists it as
unknown-exthdr ... [invalid type]and the size comparison never matches TCP options; the clamp is ineffective.ExthdrOpTcpoptfor both the MSS load and write, rendering astcp option maxseg size > N tcp option maxseg size set NTestCompile_MSSClampNo findings.