Red Bear OS 76e01f06ff netstack: fix IPv6 firewall bypass - return final protocol + offset
Fixes the P001 review finding. The previous ipv6_transport_offset
walker returned only the offset, but the caller passed the INITIAL
next_header (which is usually a Hop-by-Hop / Routing / Destination /
Fragment number, not a transport protocol) to parse_ports() and to
PacketContext.protocol. Any IPv6 packet with extension headers
silently failed firewall port rules.

Two changes:
1. ipv6_transport_offset now returns (final_protocol, offset) tuple.
   Continues to return None for malformed/encrypted/too-deep chains
   so we never fall through to wrong-offset parse.
2. The IPv6 dispatch in infer_context() uses the returned final
   protocol: parse_ports() gets the right IpProtocol (TCP/UDP/ICMPv6)
   and PacketContext.protocol is set to the discovered final protocol.

Also corrects the AH header length formula: RFC 8200 §4 says AH
length is in 4-octet units over the 8-octet fixed part, so total
= (len+2)*8, not the generic (len+1)*8 used for Hop-by-Hop /
Routing / Destination.
2026-07-27 20:26:48 +09:00
2025-11-29 19:04:06 +01:00
2025-11-29 19:04:06 +01:00

Base

Repository containing various system daemons, that are considered fundamental for the OS.

You can see what each component does in the following list:

  • audiod : Daemon used to process the sound drivers audio
  • bootstrap : First code that the kernel executes, responsible for spawning the init daemon
  • daemon : Redox daemon library
  • drivers
  • init : Daemon used to start most system components and programs
  • initfs : Filesystem with the necessary system components to run RedoxFS
  • ipcd : Daemon used for inter-process communication
  • logd : Daemon used to log system components and daemons
  • netstack : Daemon used for networking
  • ptyd : Daemon used for pseudo-terminal
  • ramfs : RAM filesystem
  • randd : Daemon used for random number generation
  • zerod : Daemon used to discard all writes and fill read buffers with zero

How To Contribute

To learn how to contribute you need to read the following document:

If you want to contribute to drivers read its README

Development

To learn how to do development with these system components inside the Redox build system you need to read the Build System and Coding and Building pages.

How To Build

It is recommended to build this system component via the Redox build system, you can learn how to do it on the Building Redox page.

To build and test outside the build system, install redoxer then use check.sh script to build or test:

  • ./check.sh - Check build for x86_64
  • ./check.sh --arch=ARCH - Check build for specific ARCH (aarch64, i586, riscv64gc)
  • ./check.sh --all - Check build for all ARCH
  • ./check.sh --test - Check the base system boots up on x86_64

You can also use make install to inspect the content on ./sysroot, or make test-gui to test booting with orbital interactively.

S
Description
RedBear Operating System, based on RedoxOS. Licenced under MIT license.
https://redbearos.org
Readme MIT 18 GiB
Languages
C 37.5%
C++ 37.2%
JavaScript 6.7%
QML 3.4%
HTML 3.2%
Other 11.4%