netdev-bot+sashiko@ wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> 
> Critical: 0 · High: 1 · Medium: 0 · Low: 0
> 
> - [High] Incomplete fix: the patch adds source-address/source-port
>   filtering only to the PF_PACKET verification path…
> 
> 
> Would it make sense to also connect() the receive UDP socket to
> cfg_saddr:cfg_port_src, or use recvfrom() and drop datagrams whose peer does
> not match, with the same cfg_zero_sum exception used above since the source
> port is computed at send time in that mode?

That's a great suggestion. I'll add recvfrom() src verification in v2.

Reply via email to