From: netdev-bot+sashiko@kernel.org
To: fmancera@suse.de
Cc: netdev@vger.kernel.org, horms@kernel.org, kuba@kernel.org,
pabeni@redhat.com, edumazet@kernel.org, davem@davemloft.net,
edumazet@google.com, ebiggers@kernel.org, ardb@kernel.org,
krzk@kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4
Date: Fri, 02 Oct 2026 10:32:27 +0000 [thread overview]
Message-ID: <179093714759.434549.2698814184548027577@kernel.org> (raw)
In-Reply-To: <20260928193046.6698-13-fmancera@suse.de>
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] In ip_route_me_harder() (net/ipv4/netfilter.c), the new `if
(!IS_ENABLED(CONFIG_IPV4)) return -EPROTONOSUPPORT;` check (lines…
--
netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4
This commit adds an IS_ENABLED(CONFIG_IPV4) check to ip_route_me_harder()
in net/ipv4/netfilter.c. When IPv4 is disabled, the function returns
-EPROTONOSUPPORT and skips the IPv4 rerouting logic. The goal is to let
the network stack build without IPv4.
> diff --git a/net/ipv4/netfilter.c b/net/ipv4/netfilter.c
> index ce9e1bfa4259f..f2d9e0110b779 100644
> --- a/net/ipv4/netfilter.c
> +++ b/net/ipv4/netfilter.c
> @@ -30,6 +30,9 @@ int ip_route_me_harder(struct net *net, struct sock *sk, struct sk_buff *skb, un
> struct flow_keys flkeys;
> unsigned int hh_len;
>
> + if (!IS_ENABLED(CONFIG_IPV4))
> + return -EPROTONOSUPPORT;
> +
[Severity: Low]
This isn't a bug, but would it be clearer to do this check before the
declaration initializers in ip_route_me_harder()?
As placed, the initializers above the check still load from the dst and
from the IPv4 header when CONFIG_IPV4=n:
net/ipv4/netfilter.c:ip_route_me_harder() {
struct net_device *dev = skb_dst_dev(skb);
const struct iphdr *iph = ip_hdr(skb);
...
__be32 saddr = iph->saddr;
...
}
This doesn't look reachable in practice. With the rest of the series
applied, every in-tree caller sits behind a Kconfig option that depends
on IPV4. For example, the core netfilter menu in net/netfilter/Kconfig
now has:
depends on INET && IPV4 && NETFILTER
The callers also always pass an skb that has a dst set.
Moving the IS_ENABLED(CONFIG_IPV4) check above the initializers, or
deferring those assignments until after it, would make it clearer that
nothing IPv4-specific runs when IPv4 is disabled.
> sk = sk_to_full_sk(sk);
> flags = sk ? inet_sk_flowi_flags(sk) : 0;
>
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260928193046.6698-1-fmancera%40suse.de
next prev parent reply other threads:[~2026-10-02 10:32 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260928193046.6698-1-fmancera@suse.de>
2026-09-28 19:29 ` [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:29 ` [PATCH 02/16 net-next v2] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:29 ` [PATCH 03/16 net-next v2] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 04/16 net-next v2] tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 05/16 net-next v2] ipv4: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 06/16 net-next v2] ipv4: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 07/16 net-next v2] ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 08/16 net-next v2] ipv4: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 09/16 net-next v2] ipv4: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 10/16 net-next v2] tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 11/16 net-next v2] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-29 7:14 ` Joel Granados
2026-09-29 8:20 ` Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko [this message]
2026-09-28 19:30 ` [PATCH 13/16 net-next v2] net: bridge: guard ARP/RARP proxy and suppression " Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 14/16 net-next v2] wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency Fernando Fernandez Mancera
2026-09-30 1:37 ` Paul Moore
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 16/16 net-next v2] ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179093714759.434549.2698814184548027577@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=ardb@kernel.org \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=edumazet@google.com \
--cc=edumazet@kernel.org \
--cc=fmancera@suse.de \
--cc=horms@kernel.org \
--cc=krzk@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®