mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Shorten new outbound and ICMP names, fix stale comments and the log target note
Rename IcmpContext::packet_too_big to too_big, outbound::path_too_big to path_limit and Node::send_tun_packet to send_outbound. Two comments still named the removed ICMP send wrappers. The changelog note on moved log targets listed only some of the lifecycle lines, and claimed the fips::upper path still resolves, which will not hold once the transitional alias is removed.
This commit is contained in:
+6
-6
@@ -336,15 +336,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
|||||||
ICMPv6 Packet Too Big debug lines ("Sending ICMP Packet Too Big", "Rate
|
ICMPv6 Packet Too Big debug lines ("Sending ICMP Packet Too Big", "Rate
|
||||||
limiting ICMP Packet Too Big") log as `fips::ipv6tun::icmp` rather than
|
limiting ICMP Packet Too Big") log as `fips::ipv6tun::icmp` rather than
|
||||||
`fips::node::handlers::session`, so a `fips::node=debug` filter no longer
|
`fips::node::handlers::session`, so a `fips::node=debug` filter no longer
|
||||||
shows them. The TUN and DNS start and stop lines ("TUN device active",
|
shows them. All logging from TUN and DNS start and stop (for example "TUN
|
||||||
"effective MTU", "max TCP MSS", "Shutting down TUN interface", "DNS responder
|
device active", "Shutting down TUN interface" and "DNS responder started",
|
||||||
started", "DNS responder stopped" and their failure warnings) log as
|
with their failure warnings) logs as `fips::ipv6tun::lifecycle` rather than
|
||||||
`fips::ipv6tun::lifecycle` rather than `fips::node::lifecycle`, so a filter
|
`fips::node::lifecycle`, so a filter on `fips::node::lifecycle` or
|
||||||
on `fips::node::lifecycle` or `fips::node` no longer selects them. An
|
`fips::node` no longer selects it. An
|
||||||
existing `RUST_LOG` filter naming an old target still parses and simply
|
existing `RUST_LOG` filter naming an old target still parses and simply
|
||||||
stops matching, so the symptom is missing log lines rather than an error.
|
stops matching, so the symptom is missing log lines rather than an error.
|
||||||
Update `RUST_LOG` filters, journal-watch recipes and any log-scraping alert
|
Update `RUST_LOG` filters, journal-watch recipes and any log-scraping alert
|
||||||
accordingly. The library path `fips::upper` still resolves.
|
accordingly.
|
||||||
|
|
||||||
#### Packaging (Debian)
|
#### Packaging (Debian)
|
||||||
|
|
||||||
|
|||||||
+2
-2
@@ -431,7 +431,7 @@ impl<'a> IcmpContext<'a> {
|
|||||||
///
|
///
|
||||||
/// Rate-limited per source address to prevent ICMP floods from
|
/// Rate-limited per source address to prevent ICMP floods from
|
||||||
/// misconfigured applications sending repeated oversized packets.
|
/// misconfigured applications sending repeated oversized packets.
|
||||||
pub(crate) fn packet_too_big(&mut self, original_packet: &[u8], mtu: u32) {
|
pub(crate) fn too_big(&mut self, original_packet: &[u8], mtu: u32) {
|
||||||
// Extract source address for rate limiting
|
// Extract source address for rate limiting
|
||||||
if original_packet.len() < 40 {
|
if original_packet.len() < 40 {
|
||||||
return;
|
return;
|
||||||
@@ -806,7 +806,7 @@ mod tests {
|
|||||||
let remote_addr: Ipv6Addr = "fddf::2".parse().unwrap();
|
let remote_addr: Ipv6Addr = "fddf::2".parse().unwrap();
|
||||||
let original = make_ipv6_packet(local_addr, remote_addr, 6, &[0u8; 1200]); // TCP
|
let original = make_ipv6_packet(local_addr, remote_addr, 6, &[0u8; 1200]); // TCP
|
||||||
|
|
||||||
// Pass remote_addr as our_addr — this is what send_icmpv6_packet_too_big
|
// Pass remote_addr as our_addr — this is what IcmpContext::too_big
|
||||||
// does after the fix (original packet's dst = remote peer).
|
// does after the fix (original packet's dst = remote peer).
|
||||||
let response = build_packet_too_big(&original, 1203, remote_addr);
|
let response = build_packet_too_big(&original, 1203, remote_addr);
|
||||||
assert!(response.is_some());
|
assert!(response.is_some());
|
||||||
|
|||||||
@@ -7,7 +7,7 @@
|
|||||||
//! mesh's business, reached through the [`Mesh`] trait.
|
//! mesh's business, reached through the [`Mesh`] trait.
|
||||||
//!
|
//!
|
||||||
//! The decisions are the synchronous functions [`admit`] and
|
//! The decisions are the synchronous functions [`admit`] and
|
||||||
//! [`path_too_big`]; [`forward`] drives them against a [`Mesh`].
|
//! [`path_limit`]; [`forward`] drives them against a [`Mesh`].
|
||||||
|
|
||||||
use super::icmp::{IcmpContext, effective_ipv6_mtu};
|
use super::icmp::{IcmpContext, effective_ipv6_mtu};
|
||||||
use std::future::Future;
|
use std::future::Future;
|
||||||
@@ -92,7 +92,7 @@ pub(crate) fn admit(packet: &[u8], ipv6_mtu: u16) -> Admit {
|
|||||||
///
|
///
|
||||||
/// Applies only when the path is narrower than the node-wide `ipv6_mtu`,
|
/// Applies only when the path is narrower than the node-wide `ipv6_mtu`,
|
||||||
/// which [`admit`] has already enforced.
|
/// which [`admit`] has already enforced.
|
||||||
pub(crate) fn path_too_big(len: usize, path_mtu: u16, ipv6_mtu: u16) -> Option<u32> {
|
pub(crate) fn path_limit(len: usize, path_mtu: u16, ipv6_mtu: u16) -> Option<u32> {
|
||||||
let path_ipv6_mtu = effective_ipv6_mtu(path_mtu) as usize;
|
let path_ipv6_mtu = effective_ipv6_mtu(path_mtu) as usize;
|
||||||
if path_ipv6_mtu < ipv6_mtu as usize && len > path_ipv6_mtu {
|
if path_ipv6_mtu < ipv6_mtu as usize && len > path_ipv6_mtu {
|
||||||
Some(path_ipv6_mtu as u32)
|
Some(path_ipv6_mtu as u32)
|
||||||
@@ -112,7 +112,7 @@ pub(crate) async fn forward<M: Mesh>(mesh: &mut M, packet: Vec<u8>) {
|
|||||||
let prefix = match admit(&packet, ipv6_mtu) {
|
let prefix = match admit(&packet, ipv6_mtu) {
|
||||||
Admit::Drop => return,
|
Admit::Drop => return,
|
||||||
Admit::TooBig(mtu) => {
|
Admit::TooBig(mtu) => {
|
||||||
mesh.icmp().packet_too_big(&packet, mtu);
|
mesh.icmp().too_big(&packet, mtu);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
Admit::Forward(prefix) => prefix,
|
Admit::Forward(prefix) => prefix,
|
||||||
@@ -129,9 +129,9 @@ pub(crate) async fn forward<M: Mesh>(mesh: &mut M, packet: Vec<u8>) {
|
|||||||
// generate ICMPv6 Packet Too Big back to the application.
|
// generate ICMPv6 Packet Too Big back to the application.
|
||||||
if let Some(mtu) = route
|
if let Some(mtu) = route
|
||||||
.path_mtu
|
.path_mtu
|
||||||
.and_then(|path_mtu| path_too_big(packet.len(), path_mtu, ipv6_mtu))
|
.and_then(|path_mtu| path_limit(packet.len(), path_mtu, ipv6_mtu))
|
||||||
{
|
{
|
||||||
mesh.icmp().packet_too_big(&packet, mtu);
|
mesh.icmp().too_big(&packet, mtu);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -254,16 +254,16 @@ mod tests {
|
|||||||
}
|
}
|
||||||
|
|
||||||
#[test]
|
#[test]
|
||||||
fn path_too_big_applies_only_below_the_node_mtu() {
|
fn path_limit_applies_only_below_the_node_mtu() {
|
||||||
let node = 1280;
|
let node = 1280;
|
||||||
let narrow = effective_ipv6_mtu(1000);
|
let narrow = effective_ipv6_mtu(1000);
|
||||||
assert_eq!(
|
assert_eq!(
|
||||||
path_too_big(narrow as usize + 1, 1000, node),
|
path_limit(narrow as usize + 1, 1000, node),
|
||||||
Some(narrow as u32)
|
Some(narrow as u32)
|
||||||
);
|
);
|
||||||
assert_eq!(path_too_big(narrow as usize, 1000, node), None);
|
assert_eq!(path_limit(narrow as usize, 1000, node), None);
|
||||||
// A path at least as wide as the node MTU never answers.
|
// A path at least as wide as the node MTU never answers.
|
||||||
assert_eq!(path_too_big(1280, 1280 + 77, node), None);
|
assert_eq!(path_limit(1280, 1280 + 77, node), None);
|
||||||
}
|
}
|
||||||
|
|
||||||
#[tokio::test]
|
#[tokio::test]
|
||||||
|
|||||||
@@ -3084,7 +3084,7 @@ impl Node {
|
|||||||
/// for the initiation it starts discovery and still queues. Refuses the
|
/// for the initiation it starts discovery and still queues. Refuses the
|
||||||
/// packet, handing it back, when a new session would exceed the session
|
/// packet, handing it back, when a new session would exceed the session
|
||||||
/// table.
|
/// table.
|
||||||
async fn send_tun_packet(
|
async fn send_outbound(
|
||||||
&mut self,
|
&mut self,
|
||||||
dest_addr: NodeAddr,
|
dest_addr: NodeAddr,
|
||||||
dest_pubkey: PublicKey,
|
dest_pubkey: PublicKey,
|
||||||
@@ -3230,7 +3230,7 @@ impl Mesh for Node {
|
|||||||
|
|
||||||
fn send(&mut self, dest: Self::Dest, packet: Vec<u8>) -> impl Future<Output = Outcome> + Send {
|
fn send(&mut self, dest: Self::Dest, packet: Vec<u8>) -> impl Future<Output = Outcome> + Send {
|
||||||
let (dest_addr, dest_pubkey) = dest;
|
let (dest_addr, dest_pubkey) = dest;
|
||||||
self.send_tun_packet(dest_addr, dest_pubkey, packet)
|
self.send_outbound(dest_addr, dest_pubkey, packet)
|
||||||
}
|
}
|
||||||
|
|
||||||
fn icmp(&mut self) -> IcmpContext<'_> {
|
fn icmp(&mut self) -> IcmpContext<'_> {
|
||||||
|
|||||||
@@ -1855,7 +1855,7 @@ async fn test_check_pending_lookups_default_sequence_unreachable() {
|
|||||||
"test pins the [1,2,4,8] default; update the test if the default changes"
|
"test pins the [1,2,4,8] default; update the test if the default changes"
|
||||||
);
|
);
|
||||||
|
|
||||||
// Inject a TUN sender so `send_icmpv6_dest_unreachable` is observable.
|
// Inject a TUN sender so the no-route Destination Unreachable is observable.
|
||||||
let (tun_tx, tun_rx) = mpsc::channel::<Vec<u8>>();
|
let (tun_tx, tun_rx) = mpsc::channel::<Vec<u8>>();
|
||||||
node.install_tun(tun_tx);
|
node.install_tun(tun_tx);
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user