Repository navigation
IPv6 ACL: match protocol-number rules with meta l4proto - #14360
Open
bhouse-nexthop wants to merge 4 commits into
Open
bhouse-nexthop wants to merge 4 commits into
bhouse-nexthop wants to merge 4 commits into
Conversation
Match IPv6 ACL rules given by protocol number with "meta l4proto", the expression nft itself uses for tcp, udp and icmpv6 rules, so that every IPv6 ACL rule identifies the protocol the same way. Signed-off-by: Brad House <bhouse@nexthop.ai>
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## 4.22 #14360 +/- ##
============================================
- Coverage 18.02% 18.01% -0.01%
+ Complexity 16250 16245 -5
============================================
Files 5936 5936
Lines 535823 535823
Branches 65612 65612
============================================
- Hits 96582 96546 -36
- Misses 428242 428281 +39
+ Partials 10999 10996 -3
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
An ACL rule given by the protocol number of an IPv6 extension header (0, 43, 44, 60, 135) is rendered as nft's "exthdr <name> exists" for that header, rather than as an upper-layer protocol. Signed-off-by: Brad House <bhouse@nexthop.ai>
bhouse-nexthop
force-pushed
the
fix-ip6-acl-l4proto
branch
from
October 8, 2026 11:01
fd021d6 to
6ff859e
Compare
Signed-off-by: Brad House <bhouse@nexthop.ai>
Damans227
reviewed
Oct 8, 2026
3 of 12 tasks
bhouse-nexthop
requested review from
DaanHoogland,
sureshanaparti,
vladimirpetrov and
weizhouapache
and removed request for
mohithvardhan002
October 8, 2026 12:43
Collaborator
Author
|
@vladimirpetrov @sureshanaparti could you take a look at this one? We'd like this fix to make it into the upcoming 4.22.2 release. |
Signed-off-by: Brad House <bhouse@nexthop.ai>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
IPv6 network ACL rules given by protocol number are now matched with
meta l4proto, the expression nft itself uses fortcp,udpandicmpv6rules. Every IPv6 ACL rule then identifies the protocol the same way. A rule given by the number of an IPv6 extension header (0, 43, 44, 60, 135) is matched as that extension header (exthdr <name> exists).Types of changes
Feature/Enhancement Scale or Bug Severity
Bug Severity
How Has This Been Tested?
systemvm/test/TestCsAclIpv6.pychecks the rendered ingress and egress rules, including extension header numbers.CsNetfilters.apply_ip6_rules()and checked against traffic.meta l4protoandexthdr ... existswere checked to load on nft 1.0.6, the version in the Debian 12 systemvm template.pycodestyleandpylint(as insystemvm/test/runtests.sh) report nothing new.