From c2d29dd197cbff6c143a570576c81bee20fc06eb Mon Sep 17 00:00:00 2001 From: "Ondrej Zajicek (work)" Date: Tue, 18 Dec 2018 19:16:23 +0100 Subject: IO: Workaround for broken FreeBSD behavior FreeBSD silently changes TTL to 1 when MSG_DONTROUTE is used, even when it is explicitly set to another value. That breaks TTL security sockets, including BFD which always uses TTL 255. Bad FreeBSD! --- sysdep/unix/io.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/sysdep/unix/io.c b/sysdep/unix/io.c index 8c9052a3..a511e88e 100644 --- a/sysdep/unix/io.c +++ b/sysdep/unix/io.c @@ -1566,7 +1566,9 @@ sk_sendmsg(sock *s) }; #ifdef CONFIG_DONTROUTE_UNICAST - if (ipa_is_ip4(s->daddr) && ip4_is_unicast(ipa_to_ip4(s->daddr))) + /* FreeBSD silently changes TTL to 1 when MSG_DONTROUTE is used, therefore we + cannot use it for other cases (e.g. when TTL security is used). */ + if (ipa_is_ip4(s->daddr) && ip4_is_unicast(ipa_to_ip4(s->daddr)) && (s->ttl == 1)) flags = MSG_DONTROUTE; #endif -- cgit v1.2.3