> Network denial events now report the port from their one authoritative > validated address through one signed field. Verify this value directly > without inferring a source or destination role. > > Exercise a nonzero IPv4 TCP bind, an explicit-zero IPv4 UDP bind, a > synthetic-zero IPv6 UDP autobind, and a family-only AF_UNSPEC UDP send. > Require exactly one event with the exact policy blocker for each shape. > The value -1 distinguishes a family-only address with no validated port > from the two valid port-zero cases. > > Cc: Günther Noack <[email protected]> > Cc: Steven Rostedt <[email protected]> > Signed-off-by: Mickaël Salaün <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=8
