Red Bear OS f67802967d netstack: fix P001 IPv6 ext header firewall bypass
CRITICAL from NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §3.1:
netstack/src/router/mod.rs:528-545 used a fixed 40-byte offset for IPv6
transport-layer payload extraction. Any IPv6 packet with extension
headers (Hop-by-Hop, Routing, Fragment, Destination, ESP, AH) caused
parse_ports() to read the wrong bytes and return None,None. A
firewall rule with a port predicate (--sport/--dport) would silently
fail to match on such packets — a firewall bypass.

Fix: add ipv6_transport_offset(packet, initial_next_header) that walks
the extension header chain (RFC 8200 §4) and returns the byte offset
of the transport-layer header. The walker handles:
- Hop-by-Hop (0), Routing (43), Destination (60), AH (51): 8-byte
  aligned headers with length-in-units field
- Fragment (44): fixed 8-byte header, no length field
- ESP (50): returns None (payload is encrypted, port extraction
  impossible)
- No Next Header (59): chain ends, transport offset unknown
- Unknown header types: returns None to avoid unbounded walk

The walker is bounded by packet.len() to prevent DoS via a chain
that loops on itself. The transport-layer protocols (TCP=6, UDP=17,
ICMPv6=58, SCTP=132) terminate the chain and return the current
offset.
2026-07-27 16:37:04 +09:00
2025-11-29 19:04:06 +01:00
2025-11-29 19:04:06 +01:00

Base

Repository containing various system daemons, that are considered fundamental for the OS.

You can see what each component does in the following list:

  • audiod : Daemon used to process the sound drivers audio
  • bootstrap : First code that the kernel executes, responsible for spawning the init daemon
  • daemon : Redox daemon library
  • drivers
  • init : Daemon used to start most system components and programs
  • initfs : Filesystem with the necessary system components to run RedoxFS
  • ipcd : Daemon used for inter-process communication
  • logd : Daemon used to log system components and daemons
  • netstack : Daemon used for networking
  • ptyd : Daemon used for pseudo-terminal
  • ramfs : RAM filesystem
  • randd : Daemon used for random number generation
  • zerod : Daemon used to discard all writes and fill read buffers with zero

How To Contribute

To learn how to contribute you need to read the following document:

If you want to contribute to drivers read its README

Development

To learn how to do development with these system components inside the Redox build system you need to read the Build System and Coding and Building pages.

How To Build

It is recommended to build this system component via the Redox build system, you can learn how to do it on the Building Redox page.

To build and test outside the build system, install redoxer then use check.sh script to build or test:

  • ./check.sh - Check build for x86_64
  • ./check.sh --arch=ARCH - Check build for specific ARCH (aarch64, i586, riscv64gc)
  • ./check.sh --all - Check build for all ARCH
  • ./check.sh --test - Check the base system boots up on x86_64

You can also use make install to inspect the content on ./sysroot, or make test-gui to test booting with orbital interactively.

S
Description
RedBear Operating System, based on RedoxOS. Licenced under MIT license.
https://redbearos.org
Readme MIT 18 GiB
Languages
C 37.5%
C++ 37.2%
JavaScript 6.7%
QML 3.4%
HTML 3.2%
Other 11.4%