[roll] Roll fuchsia [netstack3] Don't short circuit on strict filter parsing errors

When parsing a TCP header in the packet filtering logic, if either the
TCP options or the TCP control flags are malformed, the parser would
previously fail and return None. This caused the firewall to lose port
information, leading to a potential bypass of port-based DROP rules
while the IP layer still forwarded the packet.

Normally skipping the filter rule for these malformed packets is not big
problem, because we expect the final destination to drop it eventually.
However, it is possible that the intended host may have a more lax
parsing rule than netstack3, causing it to deliver those packets
successfully.

Original-Original-Fixed: 518696592
Test: netstack3-filter-test

Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1634276
Original-Original-Revision: 7d2f6444eb77d372338a7a4e43d5e153071d9832
GitOrigin-RevId: 4307bdee10a9aa03ff83f0bb9662018cfd151523
Change-Id: I835ad401ae1ce8acece3f9b6e74d630a6a76a182
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1640900
Cr-Commit-Position: refs/heads/main@{#194268}
1 file changed
tree: 0ad597e183927e1a3bd3e14a746ef3b4bbfc4a1d
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.