mirror of
https://github.com/tailscale/tailscale.git
synced 2025-02-18 10:58:39 +00:00
wgengine/filter: drop multicast packets out, don't log about them
Eventually we'll probably support multicast. For now it's just log spam. Fixes #629
This commit is contained in:
parent
bbb56f2303
commit
5f807c389e
@ -367,6 +367,11 @@ func (f *Filter) pre(q *packet.ParsedPacket, rf RunFlags, dir direction) Respons
|
|||||||
f.logRateLimit(rf, q, dir, Drop, "ipv6")
|
f.logRateLimit(rf, q, dir, Drop, "ipv6")
|
||||||
return Drop
|
return Drop
|
||||||
}
|
}
|
||||||
|
if q.DstIP.IsMulticast() {
|
||||||
|
f.logRateLimit(rf, q, dir, Drop, "multicast")
|
||||||
|
return Drop
|
||||||
|
}
|
||||||
|
|
||||||
switch q.IPProto {
|
switch q.IPProto {
|
||||||
case packet.Unknown:
|
case packet.Unknown:
|
||||||
// Unknown packets are dangerous; always drop them.
|
// Unknown packets are dangerous; always drop them.
|
||||||
@ -409,6 +414,9 @@ func omitDropLogging(p *packet.ParsedPacket, dir direction) bool {
|
|||||||
if ipProto == packet.IGMP {
|
if ipProto == packet.IGMP {
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
if p.DstIP.IsMulticast() {
|
||||||
|
return true
|
||||||
|
}
|
||||||
case 6:
|
case 6:
|
||||||
if len(b) < 40 {
|
if len(b) < 40 {
|
||||||
return false
|
return false
|
||||||
|
@ -379,6 +379,18 @@ func TestOmitDropLogging(t *testing.T) {
|
|||||||
dir: out,
|
dir: out,
|
||||||
want: true,
|
want: true,
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "v6_multicast_out_low",
|
||||||
|
pkt: &packet.ParsedPacket{IPVersion: 4, DstIP: packet.NewIP(net.ParseIP("224.0.0.0"))},
|
||||||
|
dir: out,
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "v6_multicast_out_high",
|
||||||
|
pkt: &packet.ParsedPacket{IPVersion: 4, DstIP: packet.NewIP(net.ParseIP("239.255.255.255"))},
|
||||||
|
dir: out,
|
||||||
|
want: true,
|
||||||
|
},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
|
@ -39,6 +39,10 @@ func (ip IP) String() string {
|
|||||||
return fmt.Sprintf("%d.%d.%d.%d", byte(ip>>24), byte(ip>>16), byte(ip>>8), byte(ip))
|
return fmt.Sprintf("%d.%d.%d.%d", byte(ip>>24), byte(ip>>16), byte(ip>>8), byte(ip))
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (ip IP) IsMulticast() bool {
|
||||||
|
return byte(ip>>24)&0xf0 == 0xe0
|
||||||
|
}
|
||||||
|
|
||||||
// IPProto is either a real IP protocol (ITCP, UDP, ...) or an special value like Unknown.
|
// IPProto is either a real IP protocol (ITCP, UDP, ...) or an special value like Unknown.
|
||||||
// If it is a real IP protocol, its value corresponds to its IP protocol number.
|
// If it is a real IP protocol, its value corresponds to its IP protocol number.
|
||||||
type IPProto uint8
|
type IPProto uint8
|
||||||
|
Loading…
x
Reference in New Issue
Block a user