Bug #17084
closedIPv6 packets with options are not correctly matched with source address '[::]'
0%
Description
Rules for IPv6 packets with options (router alert) no longer match correctly with a source address of '[::]'.
[NB: Rule examples shown below are pulled from /tmp/rules.debug for clarity.]
This rule should match a packet with a source address of '[::]' and a destination of '[ff02::/16]' but does not:
pass in quick on $LAN inet6 from any to ff02::/16 ridentifier 1788968224 allow-opts keep state label "id=1788968224" label "tags=user_rule" label "descr=IPv6 Option Test Rule"
Even changing to a destination of 'any' does not match:
pass in quick on $LAN inet6 from any to any ridentifier 1788968224 allow-opts keep state label "id=1788968224" label "tags=user_rule" label "descr=IPv6 Option Test Rule"
Even as the first rule in the floating list the rule still does not match:
pass quick on { ix0 } inet6 from any to any ridentifier 1788983463 allow-opts keep state label "id=1788983463" label "tags=user_rule" label "descr=IPv6 Option Test Rule"
The filter log entries all identify the blocking rule as 4294967295 (-1):
<134>1 2026-09-09T12:41:19.763865-07:00 fw.mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,76,::,ff02::16,HBH,PADN,RTALERT,0x0000, <134>1 2026-09-09T12:41:19.763905-07:00 fw.mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,36,::,ff02::16,HBH,PADN,RTALERT,0x0000, <134>1 2026-09-09T12:41:19.763923-07:00 fw.mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,76,::,ff02::16,HBH,PADN,RTALERT,0x0000, <134>1 2026-09-09T12:41:19.763939-07:00 fw.mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,56,::,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T12:41:20.764206-07:00 fw.mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,56,::,ff02::16,HBH,RTALERT,0x0000,PADN,
The problem appears to be very specific to a source address of '[::]'.
The following rule does match source addresses of '[fe80::/10]', but does not match source address '[::]':
pass in log quick on $LAN inet6 from any to ff02::/16 ridentifier 1788984935 allow-opts keep state label "id=1788984935" label "tags=user_rule" label "descr=IPv6 Test Rule"
Example filter log entries with that rule in place:
<134>1 2026-09-09T14:03:03.250607-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,36,fe80::c884:8c19:8530,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:03.250624-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,56,fe80::6662:66ff:fe22:86b5,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:05.286217-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,96,fe80::cb69:4971:b1f6:3514,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:05.286254-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,76,fe80::211:32ff:feec:7c33,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:06.291869-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,176,fe80::85:3561:de4a:1091,ff02::16,HBH,PADN,RTALERT,0x0000, <134>1 2026-09-09T14:03:34.540217-07:00 fw..mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,56,::,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:35.539503-07:00 fw..mydomain filterlog 73070 - - 4294967295,,,0,ix0,ip-option,block,in,6,0x00,0x00000,1,Options,0,56,::,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:36.570369-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,56,fe80::2e8d:48ff:fe4b:bcfe,ff02::16,HBH,RTALERT,0x0000,PADN, <134>1 2026-09-09T14:03:40.584722-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,36,fe80::18f6:c02e:dc08:a5bb,ff02::16,HBH,PADN,RTALERT,0x0000, <134>1 2026-09-09T14:04:16.914517-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,36,fe80::1828:db78:7107:7fef,ff02::16,HBH,PADN,RTALERT,0x0000, <134>1 2026-09-09T14:04:53.376373-07:00 fw..mydomain filterlog 73070 - - 1,176,,1788984935,ix0,match,pass,in,6,0x00,0x00000,1,Options,0,36,fe80::c27:755:ebc:aaf7,ff02::16,HBH,PADN,RTALERT,0x0000,
FWIW, I believe this is new to 26.07, but I have not loaded an old version to test. Also, I have not tested with CE but assume the bug is likely present there as well.