nebula/iputil
Wade Simmons 7d3166a19d
cleanup ipv6 iputil helpers / skip reject for ICMP error packets and fragments (#1768)
* cleanup ipv6 iputil helpers

With my refactoring in this PR I accidentally had some duplicate logic,
this PR cleans it up:

- https://github.com/slackhq/nebula/pull/1766

* skip ICMP reject for ICMP error packets and fragments

Per RFC 1122, ICMP error messages must not be generated in response to
other ICMP error messages to prevent infinite error loops. This applies
to both IPv4 (types 3, 4, 5, 11, 12) and IPv6 (types 1-4).

Do not generate reject packets for IPv4 or IPv6 fragments. For IPv4,
check MF flag and fragment offset. For IPv6, add isFragment return to
ipv6FindUpperProtocol so a single traversal handles both protocol
lookup and fragment detection.

* do send rejects for the initial fragment

RFC says "non-initial fragment"s

* fix fragment checks
2026-06-16 16:51:14 -04:00
..
packet.go cleanup ipv6 iputil helpers / skip reject for ICMP error packets and fragments (#1768) 2026-06-16 16:51:14 -04:00
packet_test.go cleanup ipv6 iputil helpers / skip reject for ICMP error packets and fragments (#1768) 2026-06-16 16:51:14 -04:00