aboutgitcodebugslistschat
diff options
context:
space:
mode:
authorDavid Gibson <david@gibson.dropbear.id.au>2026-07-10 15:38:42 +1000
committerDavid Gibson <david@gibson.dropbear.id.au>2026-07-13 14:48:54 +1000
commit94578a40cadc1a13f6b3943b799036966a1f14dd (patch)
tree71d6d439b760b3e76bfb39d1a315a12fff27acb3
parent0b31c0be7efb588c7da0eb89f54dc62a167fa8c9 (diff)
downloadpasst-bug209.tar
passt-bug209.tar.gz
passt-bug209.tar.bz2
passt-bug209.tar.lz
passt-bug209.tar.xz
passt-bug209.tar.zst
passt-bug209.zip
fwd: Don't rewrite inbound multicast destinationsbug209
fwd_nat_from_host() (nearly) always rewrites the destination address for inbound flows to the observed guest address. Usually, that makes sense: regardless of the host address to which the new flow arrived, we want to direct it to the guest. However, that clearly does not make sense for multicast - it should still appear as a multicast transmission to the guest. In particular this can work very badly for multicast protocols which use the same source and destination ports by convention (e.g. mDNS). In this case, we will attempt to forword multicast packets to our own socket, causing a forwarding loop (see bug 209 for more details). While it's certainly not enough to make us handle multicast correctly in all circumstances, not translating multicast destinations is closer to correct, and prevents bug 209 at least. Link: https://bugs.passt.top/show_bug.cgi?id=209 Signed-off-by: David Gibson <david@gibson.dropbear.id.au>
-rw-r--r--fwd.c3
1 files changed, 2 insertions, 1 deletions
diff --git a/fwd.c b/fwd.c
index 1369bae..7152169 100644
--- a/fwd.c
+++ b/fwd.c
@@ -1042,7 +1042,8 @@ uint8_t fwd_nat_from_host(const struct ctx *c,
tgt->eport = rule->to + (ini->oport - rule->first);
if (!inany_is_unspecified(&rule->taddr))
tgt->eaddr = rule->taddr;
- else if (c->host_lo_to_ns_lo && inany_is_loopback(&ini->oaddr))
+ else if (inany_is_multicast(&ini->oaddr) ||
+ (c->host_lo_to_ns_lo && inany_is_loopback(&ini->oaddr)))
tgt->eaddr = ini->oaddr;
/* TODO: Allow splicing with specified target address */