> Network denial events now report the port from their one authoritative
> validated address through one signed field.  Verify this value directly
> without inferring a source or destination role.
> 
> Exercise a nonzero IPv4 TCP bind, an explicit-zero IPv4 UDP bind, a
> synthetic-zero IPv6 UDP autobind, and a family-only AF_UNSPEC UDP send.
> Require exactly one event with the exact policy blocker for each shape.
> The value -1 distinguishes a family-only address with no validated port
> from the two valid port-zero cases.
> 
> Cc: Günther Noack <[email protected]>
> Cc: Steven Rostedt <[email protected]>
> Signed-off-by: Mickaël Salaün <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · 
https://sashiko.dev/#/patchset/[email protected]?part=8


Reply via email to