mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: netdev-bot+sashiko@kernel.org
To: omar@blockcast.net
Cc: ap420073@gmail.com, andrew+netdev@lunn.ch, davem@davemloft.net,
	edumazet@kernel.org, kuba@kernel.org, pabeni@redhat.com,
	netdev@vger.kernel.org, linux-kernel@vger.kernel.org,
	horms@kernel.org
Subject: Re: [PATCH net v2 2/3] amt: make pre-query report drops visible
Date: Sat, 10 Oct 2026 21:08:53 +0000	[thread overview]
Message-ID: <179166653324.434549.3763843215808008320@kernel.org> (raw)
In-Reply-To: <20261009201455.1904698-3-omar@blockcast.net>

Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.

Low priority / nit picks for your consideration:

- [Low] The commit message's protocol explanation is wrong.

--

amt: make pre-query report drops visible

In gateway mode, amt_dev_xmit() drops an IGMP or MLD report when no
Membership Query has arrived yet for that family. This commit adds a
family-specific netdev_dbg() message before that drop. The drop path
itself is unchanged and still increments tx_dropped.

> A gateway cannot forward an IGMP or MLD report until it has received the
> relay's Membership Query for that family. The query supplies the nonce and
> interval echoed by the Membership Update, so dropping an early report is
> required, but doing so silently leaves operators with a dark multicast path
> and no indication why the join never happened.

[Severity: Low]
Is "The query supplies the nonce and interval echoed by the Membership
Update" accurate? The code doesn't seem to match it.

The gateway generates the nonce itself in amt_event_send_request():

drivers/net/amt.c:amt_event_send_request() {
    ...
		get_random_bytes(&amt->nonce, sizeof(__be32));
    ...
}

amt_membership_query_handler() only checks the nonce against that value.
>From the Query it stores the response MAC and the query interval:

drivers/net/amt.c:amt_membership_query_handler() {
    ...
	if (amtmq->nonce != amt->nonce)
		return true;

	response_mac = amtmq->response_mac;
    ...
		WRITE_ONCE(amt->ready4, true);
		amt->mac = response_mac;
		amt->req_cnt = 0;
		amt->qi = ihv3->qqic;
    ...
}

amt_send_membership_update() echoes only the nonce and the response MAC.
amt->qi is not part of the Update:

drivers/net/amt.c:amt_send_membership_update() {
    ...
	amtmu->nonce		= amt->nonce;
	amtmu->response_mac	= amt->mac;
    ...
}

So the state the Update needs from the relay's Query is the response
MAC, not the nonce or the interval. Could the commit message say that
instead?

-- 
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20261009201455.1904698-1-omar%40blockcast.net

  reply	other threads:[~2026-10-10 21:08 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09 20:14 [PATCH net v2 0/3] amt: fix relay tunnel keying and unauthenticated-Request DoS Omar Ramadan
2026-10-09 20:14 ` [PATCH net v2 1/3] amt: key relay tunnel state on the (address, port) endpoint, not the address Omar Ramadan
2026-10-10 21:08   ` netdev-bot+sashiko
2026-10-09 20:14 ` [PATCH net v2 2/3] amt: make pre-query report drops visible Omar Ramadan
2026-10-10 21:08   ` netdev-bot+sashiko [this message]
2026-10-09 20:14 ` [PATCH net v2 3/3] amt: do not create tunnel state for unauthenticated Requests Omar Ramadan
2026-10-10 21:08   ` netdev-bot+sashiko
2026-10-09 20:19 ` [PATCH net v2 0/3] amt: fix relay tunnel keying and unauthenticated-Request DoS netdev-bot+sinfo
2026-10-09 21:37 ` Omar Ramadan
2026-10-10 15:20   ` Taehee Yoo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=179166653324.434549.3763843215808008320@kernel.org \
    --to=netdev-bot+sashiko@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=ap420073@gmail.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@kernel.org \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=omar@blockcast.net \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®