Conversation
The IPv4 receive path parses a header from whichever fragment completes reassembly. Its payload_len therefore describes only that fragment, while raw sockets re-emit an IP header for the complete payload. This makes the visible total length inconsistent with the delivered bytes. Update the representation length only after successful reassembly, with an explicit IPv4 size check. Add a fragmented UDP/raw-socket regression that fails with total_len 28 for a 44-byte packet before the fix and passes afterward. This is a narrow prerequisite for complete post-defrag packet processing; it does not implement nftables hooks or preserve first-fragment header options. Signed-off-by: longjin <longjin@dragonos.org>
The dependency baseline fails its feature-matrix CI: a test uses the raw-only payload variant without socket-raw, a TIME_WAIT sequence increment has a 65537 usize literal that cannot compile on 16-bit targets, and several pre-existing Clippy warnings are denied. Gate the raw-dependent test on socket-raw, preserve wrapping TIME_WAIT ISN arithmetic across pointer widths with a boundary test, and apply semantics-preserving Clippy cleanup. The stable and MSRV test matrices, MSRV Clippy, and a 16-bit target build pass locally. Signed-off-by: longjin <longjin@dragonos.org>
Signed-off-by: longjin <longjin@dragonos.org>
Signed-off-by: longjin <longjin@dragonos.org>
Preserve the first fragment header metadata so the completed datagram uses its TTL and total-length budget instead of metadata from the fragment that happened to arrive last. Reject partial overlaps, conflicting final lengths, empty fragments, and invalid IPv4 header lengths. Propagate assembler capacity failures before copying fragment bytes; keep duplicate fragments from triggering completion, matching Linux 6.6. Cover first-header retention, duplicate and overlap classification, malformed IHL values, and raw-socket delivery. Default and DragonOS-feature library tests, no-alloc checks, and formatting pass. Full raw options/ECN preservation remains part of the later nftables packet-path work. Signed-off-by: longjin <longjin@dragonos.org>
Expose validated ingress packets and deferred IPv4/IPv6 output so DragonOS can apply firewall policy before consuming or emitting packets. Carry per-packet route, output and mark context through local delivery, fragmentation, TCP, UDP and multicast without repeating policy decisions on retries. Refresh rule generations between receive tokens and transmit sockets to prevent a committed policy from being bypassed by a stale poll snapshot. Keep multicast resource retries bounded and make policy drops non-panicking. Add routed, loopback, fragment, multicast and generation-change regression coverage. The dependent DragonOS nftables control plane and conntrack/NAT hooks are submitted separately. Signed-off-by: longjin <longjin@dragonos.org>
Member
Author
|
@codex review |
Guard the fragmentation-only assertion when that feature is disabled, while retaining the rest of the deferred output regression in every test profile. Apply equivalent Clippy cleanups for the policy-aware packet path and TCP dispatch. Validated the full Rust 1.80 feature matrix, Clippy with tests/examples and warnings denied, formatting, and the formerly failing stable feature combination. Signed-off-by: longjin <longjin@dragonos.org>
fslongjin
merged commit Sep 28, 2026
4debe65
into
DragonOS-Community:dragonos/v0.12.0
10 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification
cargo test --lib --offline --quiet: 738 passed.cargo fmt --all -- --checkandgit diff --check: passed.This PR does not claim to implement the nftables control plane by itself.