Conversation
…etection The custom req_pattern parser only followed 0x8100 tags, so frames with an 802.1ad (0x88a8) or 0x9100/0x9200 outer tag never reached the IP layer, were judged PKT_DIR_UNKNOWN and dropped by every output. Skip the whole tag stack in a loop, as parse_packet and output_zmq already do, and drop the per-tag recursion, whose depth was bounded only by caplen. Add is_vlan_ethertype() to vlan.h and use it in output_zmq.c as well. Fixes #270
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
With a custom
req_pattern,req_pattern_judge_pkt_direction()parses the IP/port of each frame. The parser followed only0x8100tags. A frame whose tag stack contains an 802.1ad (0x88a8) or0x9100/0x9200tag never reached the IP layer, was judgedPKT_DIR_UNKNOWN, and every output dropped it as a direction drop. With a custom pattern, all QinQ traffic on the interface was lost.parse_packet(packet_split.c) andoutput_zmq.calready accept all four TPIDs.Changes
vlan.h: addis_vlan_ethertype()for the four tag TPIDs.req_pattern.c:extract_ipport_from_ether_layerskips the whole tag stack in a loop, bounded bycaplen, then dispatches to IPv4/IPv6.extract_ipport_from_vlan_layeris removed: it recursed once per tag, so its depth was bounded only bycaplen.output_zmq.c: useis_vlan_ethertype()in the existing tag walk (no behaviour change).packet_split.ckeeps its own four-way check for now.Tests
New
tests/unit/req_pattern.c(14 tests). Before the fix, the 7 QinQ cases failed and the controls passed.caplen→ unknown; a frame made only of tags → unknownUnit tests 9/9 and the integration suite pass (Ubuntu 24.04).
Fixes #270