mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 19:18:25 +00:00
Shorten new outbound and ICMP names, fix stale comments and the log target note
Rename IcmpContext::packet_too_big to too_big, outbound::path_too_big to path_limit and Node::send_tun_packet to send_outbound. Two comments still named the removed ICMP send wrappers. The changelog note on moved log targets listed only some of the lifecycle lines, and claimed the fips::upper path still resolves, which will not hold once the transitional alias is removed.
This commit is contained in:
+6
-6
@@ -336,15 +336,15 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
ICMPv6 Packet Too Big debug lines ("Sending ICMP Packet Too Big", "Rate
|
||||
limiting ICMP Packet Too Big") log as `fips::ipv6tun::icmp` rather than
|
||||
`fips::node::handlers::session`, so a `fips::node=debug` filter no longer
|
||||
shows them. The TUN and DNS start and stop lines ("TUN device active",
|
||||
"effective MTU", "max TCP MSS", "Shutting down TUN interface", "DNS responder
|
||||
started", "DNS responder stopped" and their failure warnings) log as
|
||||
`fips::ipv6tun::lifecycle` rather than `fips::node::lifecycle`, so a filter
|
||||
on `fips::node::lifecycle` or `fips::node` no longer selects them. An
|
||||
shows them. All logging from TUN and DNS start and stop (for example "TUN
|
||||
device active", "Shutting down TUN interface" and "DNS responder started",
|
||||
with their failure warnings) logs as `fips::ipv6tun::lifecycle` rather than
|
||||
`fips::node::lifecycle`, so a filter on `fips::node::lifecycle` or
|
||||
`fips::node` no longer selects it. An
|
||||
existing `RUST_LOG` filter naming an old target still parses and simply
|
||||
stops matching, so the symptom is missing log lines rather than an error.
|
||||
Update `RUST_LOG` filters, journal-watch recipes and any log-scraping alert
|
||||
accordingly. The library path `fips::upper` still resolves.
|
||||
accordingly.
|
||||
|
||||
#### Packaging (Debian)
|
||||
|
||||
|
||||
+2
-2
@@ -431,7 +431,7 @@ impl<'a> IcmpContext<'a> {
|
||||
///
|
||||
/// Rate-limited per source address to prevent ICMP floods from
|
||||
/// misconfigured applications sending repeated oversized packets.
|
||||
pub(crate) fn packet_too_big(&mut self, original_packet: &[u8], mtu: u32) {
|
||||
pub(crate) fn too_big(&mut self, original_packet: &[u8], mtu: u32) {
|
||||
// Extract source address for rate limiting
|
||||
if original_packet.len() < 40 {
|
||||
return;
|
||||
@@ -806,7 +806,7 @@ mod tests {
|
||||
let remote_addr: Ipv6Addr = "fddf::2".parse().unwrap();
|
||||
let original = make_ipv6_packet(local_addr, remote_addr, 6, &[0u8; 1200]); // TCP
|
||||
|
||||
// Pass remote_addr as our_addr — this is what send_icmpv6_packet_too_big
|
||||
// Pass remote_addr as our_addr — this is what IcmpContext::too_big
|
||||
// does after the fix (original packet's dst = remote peer).
|
||||
let response = build_packet_too_big(&original, 1203, remote_addr);
|
||||
assert!(response.is_some());
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
//! mesh's business, reached through the [`Mesh`] trait.
|
||||
//!
|
||||
//! The decisions are the synchronous functions [`admit`] and
|
||||
//! [`path_too_big`]; [`forward`] drives them against a [`Mesh`].
|
||||
//! [`path_limit`]; [`forward`] drives them against a [`Mesh`].
|
||||
|
||||
use super::icmp::{IcmpContext, effective_ipv6_mtu};
|
||||
use std::future::Future;
|
||||
@@ -92,7 +92,7 @@ pub(crate) fn admit(packet: &[u8], ipv6_mtu: u16) -> Admit {
|
||||
///
|
||||
/// Applies only when the path is narrower than the node-wide `ipv6_mtu`,
|
||||
/// which [`admit`] has already enforced.
|
||||
pub(crate) fn path_too_big(len: usize, path_mtu: u16, ipv6_mtu: u16) -> Option<u32> {
|
||||
pub(crate) fn path_limit(len: usize, path_mtu: u16, ipv6_mtu: u16) -> Option<u32> {
|
||||
let path_ipv6_mtu = effective_ipv6_mtu(path_mtu) as usize;
|
||||
if path_ipv6_mtu < ipv6_mtu as usize && len > path_ipv6_mtu {
|
||||
Some(path_ipv6_mtu as u32)
|
||||
@@ -112,7 +112,7 @@ pub(crate) async fn forward<M: Mesh>(mesh: &mut M, packet: Vec<u8>) {
|
||||
let prefix = match admit(&packet, ipv6_mtu) {
|
||||
Admit::Drop => return,
|
||||
Admit::TooBig(mtu) => {
|
||||
mesh.icmp().packet_too_big(&packet, mtu);
|
||||
mesh.icmp().too_big(&packet, mtu);
|
||||
return;
|
||||
}
|
||||
Admit::Forward(prefix) => prefix,
|
||||
@@ -129,9 +129,9 @@ pub(crate) async fn forward<M: Mesh>(mesh: &mut M, packet: Vec<u8>) {
|
||||
// generate ICMPv6 Packet Too Big back to the application.
|
||||
if let Some(mtu) = route
|
||||
.path_mtu
|
||||
.and_then(|path_mtu| path_too_big(packet.len(), path_mtu, ipv6_mtu))
|
||||
.and_then(|path_mtu| path_limit(packet.len(), path_mtu, ipv6_mtu))
|
||||
{
|
||||
mesh.icmp().packet_too_big(&packet, mtu);
|
||||
mesh.icmp().too_big(&packet, mtu);
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -254,16 +254,16 @@ mod tests {
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn path_too_big_applies_only_below_the_node_mtu() {
|
||||
fn path_limit_applies_only_below_the_node_mtu() {
|
||||
let node = 1280;
|
||||
let narrow = effective_ipv6_mtu(1000);
|
||||
assert_eq!(
|
||||
path_too_big(narrow as usize + 1, 1000, node),
|
||||
path_limit(narrow as usize + 1, 1000, node),
|
||||
Some(narrow as u32)
|
||||
);
|
||||
assert_eq!(path_too_big(narrow as usize, 1000, node), None);
|
||||
assert_eq!(path_limit(narrow as usize, 1000, node), None);
|
||||
// A path at least as wide as the node MTU never answers.
|
||||
assert_eq!(path_too_big(1280, 1280 + 77, node), None);
|
||||
assert_eq!(path_limit(1280, 1280 + 77, node), None);
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
|
||||
@@ -3084,7 +3084,7 @@ impl Node {
|
||||
/// for the initiation it starts discovery and still queues. Refuses the
|
||||
/// packet, handing it back, when a new session would exceed the session
|
||||
/// table.
|
||||
async fn send_tun_packet(
|
||||
async fn send_outbound(
|
||||
&mut self,
|
||||
dest_addr: NodeAddr,
|
||||
dest_pubkey: PublicKey,
|
||||
@@ -3230,7 +3230,7 @@ impl Mesh for Node {
|
||||
|
||||
fn send(&mut self, dest: Self::Dest, packet: Vec<u8>) -> impl Future<Output = Outcome> + Send {
|
||||
let (dest_addr, dest_pubkey) = dest;
|
||||
self.send_tun_packet(dest_addr, dest_pubkey, packet)
|
||||
self.send_outbound(dest_addr, dest_pubkey, packet)
|
||||
}
|
||||
|
||||
fn icmp(&mut self) -> IcmpContext<'_> {
|
||||
|
||||
@@ -1855,7 +1855,7 @@ async fn test_check_pending_lookups_default_sequence_unreachable() {
|
||||
"test pins the [1,2,4,8] default; update the test if the default changes"
|
||||
);
|
||||
|
||||
// Inject a TUN sender so `send_icmpv6_dest_unreachable` is observable.
|
||||
// Inject a TUN sender so the no-route Destination Unreachable is observable.
|
||||
let (tun_tx, tun_rx) = mpsc::channel::<Vec<u8>>();
|
||||
node.install_tun(tun_tx);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user