fix(notifications): scope credentials and NAT64 resolution - #242
Conversation
|
@codex review Please review exact corrective head |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 147e37aed5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
9d74bd5 to
c89a9f5
Compare
|
@codex review Please review final corrective head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c89a9f5fb3
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
b52dd6a to
fb95278
Compare
|
@codex review Please review final W66 corrective head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: fb952781d5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
76bfbdf to
2b68a03
Compare
|
@codex review Please review final W66 corrective head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2b68a032c6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
f9dcb50 to
f2c240b
Compare
|
@codex review Please review final W66 corrective head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f2c240b707
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
6769d51 to
2d81229
Compare
|
@codex review Please review canonical exact W66 corrective head |
Refs #215 Signed-off-by: Ammar Heidari <ammar@arad-itc.org>
2d81229 to
e89a7d8
Compare
|
@codex review Please review canonical exact W66 corrective head |
|
Codex Review: Didn't find any major issues. Bravo. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Re-review exact canonical head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4a4ec6302b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (PrefixLength <= 64 && | ||
| bytes[8] != 0) |
There was a problem hiding this comment.
Validate the reserved u octet for /96 prefixes
When an operator configures a /96 prefix whose byte 8 is nonzero, this condition skips the reserved u-octet check even though RFC 6052 requires bits 64–71 to be zero for /96 network-specific prefixes as well. The constructor consequently accepts a malformed prefix and the policy can admit synthesized addresses beneath it as valid; reject such /96 prefixes during construction or apply the u-octet validation to them here.
Useful? React with 👍 / 👎.
Corrective authority
Post-merge exact-head review of W66 Slice 1 PR #240 found two P1 security gaps:
Correction
NotificationCredentialBindingId;NotificationAddressPolicywith configured RFC6052 NAT64 prefixes (/32,/40,/48,/56,/64,/96);NotificationPinnedEndpointrequires the address policy, so connection-time validation cannot be skipped;Safety
Exact head:
e89a7d8aea8ad83dffc84d2e39033e2808561db3.Refs #215 and corrects post-merge findings on #240.
Final authorization-context remediation
c27ae8dcec597bfd20f406fd50e4bbc2bc8d0193;c89a9f5fb3bf88ad47e14e9fbe2c3818077b0c36;Standard NAT64 policy closeout
c27ae8dcec597bfd20f406fd50e4bbc2bc8d0193;fb952781d5dccd0ae053ae764f602722c2752a97;NAT64 overlap closeout
2b68a032c60f620f995aced0ed104efbb43c478c;Implicit NAT64 decoding closeout
f2c240b70736ec933405edad79cb69132a183076;Canonical exact-head reconciliation
c27ae8dcec597bfd20f406fd50e4bbc2bc8d0193;2d8122900ff091298b1a60e50f676e1b103431d2;Final canonical security gate
c27ae8dcec597bfd20f406fd50e4bbc2bc8d0193;e89a7d8aea8ad83dffc84d2e39033e2808561db3;