envoyproxy/envoy

UDP proxying should track and decrement TTL

オープン

#20,379 opened on 2022/03/16

 (0 件のコメント) (0 件のリアクション) (0 人の担当者)C++ (5,373 件のフォーク)batch import
area/udphelp wanted

Repository metrics

Stars
 (27,997 個のスター)
PR merge metrics
 (PR metrics pending)

説明

When UDP proxying from A-B it's really unfortunate when bad or misconfigured hardware ends up routing your packets in a loop. Decrementing TTL means you don't end up with that loop being infinite and destroying your CPU.

useful kernel options:

setsockopt(fd, IPPROTO_IP, IP_RECVTTL, &get_ttl, sizeof(get_ttl));

setsockopt(fd, IPPROTO_IPV6, IPV6_RECVHOPLIMIT, &get_ttl, sizeof(get_ttl));

kMinCmsgSpaceForRead += CMSG_SPACE(sizeof(int)) // TTL

if ((cmsg->cmsg_level == IPPROTO_IP && cmsg->cmsg_type == IP_TTL) || (cmsg->cmsg_level == IPPROTO_IPV6 && cmsg->cmsg_type == IPV6_HOPLIMIT)) { ttl = reinterpret_cast<int*>(CMSG_DATA(cmsg)))); }

コントリビューターガイド