Extend firewall rule packet modification `set tcp-mss` to accept both an
explicit MSS value and `clamp-mss-to-pmtu`.
Previously, `set tcp-mss` only accepted numeric values and rendered:
`tcp option maxseg size set <value>`.
With this change, `clamp-mss-to-pmtu` is also accepted and rendered as:
`tcp option maxseg size set rt mtu`.
Changes:
- Update CLI schema for `set tcp-mss` to allow `clamp-mss-to-pmtu`
alongside numeric range 500-1460.
- Update nftables rule rendering in firewall parser:
- numeric MSS -> `tcp option maxseg size set <value>`
- clamp-mss-to-pmtu -> `tcp option maxseg size set rt mtu`
- Add smoketest coverage for IPv4/IPv6 prerouting raw rules using
`set tcp-mss clamp-mss-to-pmtu`.
Files:
- interface-definitions/include/firewall/set-packet-modifications-tcp-mss.xml.i
- python/vyos/firewall.py
- smoketest/scripts/cli/test_firewall.py