Skip to content

IPv6 ACL: match protocol-number rules with meta l4proto - #14360

Open
bhouse-nexthop wants to merge 4 commits into
apache:4.22from
bhouse-nexthop:fix-ip6-acl-l4proto
Open

bhouse-nexthop wants to merge 4 commits into
apache:4.22from
bhouse-nexthop:fix-ip6-acl-l4proto

Conversation

@bhouse-nexthop

@bhouse-nexthop bhouse-nexthop commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Description

IPv6 network ACL rules given by protocol number are now matched with meta l4proto, the expression nft itself uses for tcp, udp and icmpv6 rules. Every IPv6 ACL rule then identifies the protocol the same way. A rule given by the number of an IPv6 extension header (0, 43, 44, 60, 135) is matched as that extension header (exthdr <name> exists).

Types of changes

  • Breaking change (fix or feature that would cause existing functionality to change)
  • New feature (non-breaking change which adds functionality)
  • Bug fix (non-breaking change which fixes an issue)
  • Enhancement (improves an existing feature and functionality)
  • Cleanup (Code refactoring and cleanup, that may add test cases)
  • Build/CI
  • Test (unit or integration test code)

Feature/Enhancement Scale or Bug Severity

Bug Severity

  • BLOCKER
  • Critical
  • Major
  • Minor
  • Trivial

How Has This Been Tested?

  • New systemvm/test/TestCsAclIpv6.py checks the rendered ingress and egress rules, including extension header numbers.
  • The generated rules were loaded into nft through CsNetfilters.apply_ip6_rules() and checked against traffic.
  • meta l4proto and exthdr ... exists were checked to load on nft 1.0.6, the version in the Debian 12 systemvm template.
  • pycodestyle and pylint (as in systemvm/test/runtests.sh) report nothing new.

Match IPv6 ACL rules given by protocol number with "meta l4proto", the
expression nft itself uses for tcp, udp and icmpv6 rules, so that every
IPv6 ACL rule identifies the protocol the same way.

Signed-off-by: Brad House <bhouse@nexthop.ai>
@codecov

codecov Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 18.01%. Comparing base (2974af8) to head (b1e0fd6).
⚠️ Report is 1 commits behind head on 4.22.

Additional details and impacted files
@@             Coverage Diff              @@
##               4.22   #14360      +/-   ##
============================================
- Coverage     18.02%   18.01%   -0.01%     
+ Complexity    16250    16245       -5     
============================================
  Files          5936     5936              
  Lines        535823   535823              
  Branches      65612    65612              
============================================
- Hits          96582    96546      -36     
- Misses       428242   428281      +39     
+ Partials      10999    10996       -3     
Flag Coverage Δ
uitests 4.04% <ø> (ø)
unittests 19.09% <ø> (-0.01%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

An ACL rule given by the protocol number of an IPv6 extension header
(0, 43, 44, 60, 135) is rendered as nft's "exthdr <name> exists" for
that header, rather than as an upper-layer protocol.

Signed-off-by: Brad House <bhouse@nexthop.ai>
Comment thread systemvm/debian/opt/cloud/bin/configure.py
Signed-off-by: Brad House <bhouse@nexthop.ai>
Comment thread systemvm/debian/opt/cloud/bin/configure.py
@bhouse-nexthop

Copy link
Copy Markdown
Collaborator Author

@vladimirpetrov @sureshanaparti could you take a look at this one? We'd like this fix to make it into the upcoming 4.22.2 release.

Signed-off-by: Brad House <bhouse@nexthop.ai>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants