netdev-bot+sashiko@ wrote: > Thank you for your contribution! Sashiko AI review found 1 potential > issue(s) to consider: > > Critical: 0 · High: 1 · Medium: 0 · Low: 0 > > - [High] Incomplete fix: the patch adds source-address/source-port > filtering only to the PF_PACKET verification path… > > > Would it make sense to also connect() the receive UDP socket to > cfg_saddr:cfg_port_src, or use recvfrom() and drop datagrams whose peer does > not match, with the same cfg_zero_sum exception used above since the source > port is computed at send time in that mode?
That's a great suggestion. I'll add recvfrom() src verification in v2.
