From: Fernando Fernandez Mancera <fmancera@suse.de>
To: netdev@vger.kernel.org
Cc: horms@kernel.org, kuba@kernel.org, pabeni@redhat.com,
edumazet@kernel.org, davem@davemloft.net,
Fernando Fernandez Mancera <fmancera@suse.de>,
Eric Dumazet <edumazet@google.com>,
David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
Kees Cook <kees@kernel.org>,
Willem de Bruijn <willemb@google.com>,
Jiayuan Chen <jiayuan.chen@linux.dev>,
Christian Brauner <brauner@kernel.org>,
Qi Tang <tpluszz77@gmail.com>, Jeff Layton <jlayton@kernel.org>,
linux-kernel@vger.kernel.org
Subject: [PATCH 03/16 net-next v2] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic
Date: Mon, 28 Sep 2026 21:29:59 +0200 [thread overview]
Message-ID: <20260928193046.6698-4-fmancera@suse.de> (raw)
In-Reply-To: <20260928193046.6698-1-fmancera@suse.de>
To enable compiling the INET subsystem without IPv4, shared generic
utilities must be relocated and IPv4 socket logic must be guarded for
CONFIG_IPV4.
This patch moves the generic ip_generec_getfrag() from ip_output.c to
af_inet.c. It also introduces CONFIG_IPV4 guards around af_inet.c to
reject IPv4-specific ioctls, protocol registrations and bind requests.
The same guard is added to reject IPv4-mapped IPv6.
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
net/ipv4/af_inet.c | 69 ++++++++++++++++++++++++++++++++++++++------
net/ipv4/ip_output.c | 18 ------------
net/ipv6/af_inet6.c | 5 ++++
net/ipv6/datagram.c | 4 +--
4 files changed, 67 insertions(+), 29 deletions(-)
diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c
index d9421ac38d78..cf00386933d6 100644
--- a/net/ipv4/af_inet.c
+++ b/net/ipv4/af_inet.c
@@ -129,6 +129,28 @@
int disable_ipv6_mod;
EXPORT_SYMBOL(disable_ipv6_mod);
+/* Keep the function here for now as it is generic, it should be moved
+ * to a common L3 place
+ */
+int
+ip_generic_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
+{
+ struct msghdr *msg = from;
+
+ if (skb->ip_summed == CHECKSUM_PARTIAL) {
+ if (!copy_from_iter_full(to, len, &msg->msg_iter))
+ return -EFAULT;
+ } else {
+ __wsum csum = 0;
+
+ if (!csum_and_copy_from_iter_full(to, len, &csum, &msg->msg_iter))
+ return -EFAULT;
+ skb->csum = csum_block_add(skb->csum, csum, odd);
+ }
+ return 0;
+}
+EXPORT_SYMBOL(ip_generic_getfrag);
+
/* The inetsw table contains everything that inet_create needs to
* build a new socket.
*/
@@ -426,7 +448,8 @@ int inet_release(struct socket *sock)
BPF_CGROUP_RUN_PROG_INET_SOCK_RELEASE(sk);
/* Applications forget to leave groups before exiting */
- ip_mc_drop_socket(sk);
+ if (IS_ENABLED(CONFIG_IPV4))
+ ip_mc_drop_socket(sk);
/* If linger is set, we don't return until the close
* is complete. Otherwise we return immediately. The
@@ -486,6 +509,9 @@ int __inet_bind(struct sock *sk, struct sockaddr_unsized *uaddr, int addr_len,
u32 tb_id = RT_TABLE_LOCAL;
int err;
+ if (!IS_ENABLED(CONFIG_IPV4))
+ return -EAFNOSUPPORT;
+
if (addr->sin_family != AF_INET) {
/* Compatibility games : accept AF_UNSPEC (mapped to AF_INET)
* only if s_addr is INADDR_ANY.
@@ -968,6 +994,9 @@ int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
struct ifreq ifr;
struct rtentry rt;
+ if (!IS_ENABLED(CONFIG_IPV4))
+ return -EOPNOTSUPP;
+
switch (cmd) {
case SIOCADDRT:
case SIOCDELRT:
@@ -1023,6 +1052,9 @@ static int inet_compat_routing_ioctl(struct sock *sk, unsigned int cmd,
compat_uptr_t rtdev;
struct rtentry rt;
+ if (!IS_ENABLED(CONFIG_IPV4))
+ return -EOPNOTSUPP;
+
if (copy_from_user(&rt.rt_dst, &ur->rt_dst,
3 * sizeof(struct sockaddr)) ||
get_user(rt.rt_flags, &ur->rt_flags) ||
@@ -1153,6 +1185,7 @@ static const struct net_proto_family inet_family_ops = {
.owner = THIS_MODULE,
};
+#if IS_ENABLED(CONFIG_IPV4)
/* Upon startup we insert all the elements in inetsw_array[] into
* the linked list inetsw.
*/
@@ -1193,6 +1226,7 @@ static struct inet_protosw inetsw_array[] =
};
#define INETSW_ARRAY_LEN ARRAY_SIZE(inetsw_array)
+#endif
void inet_register_protosw(struct inet_protosw *p)
{
@@ -1267,6 +1301,9 @@ static int inet_sk_reselect_saddr(struct sock *sk)
struct ip_options_rcu *inet_opt;
int err;
+ if (!IS_ENABLED(CONFIG_IPV4))
+ return -EAFNOSUPPORT;
+
inet_opt = rcu_dereference_protected(inet->inet_opt,
lockdep_sock_is_held(sk));
if (inet_opt && inet_opt->opt.srr)
@@ -1371,6 +1408,9 @@ struct sk_buff *inet_gso_segment(struct sk_buff *skb,
int ihl;
int id;
+ if (!IS_ENABLED(CONFIG_IPV4))
+ return ERR_PTR(-EPROTONOSUPPORT);
+
skb_reset_network_header(skb);
nhoff = skb_network_header(skb) - skb_mac_header(skb);
if (unlikely(!pskb_may_pull(skb, sizeof(*iph))))
@@ -1774,6 +1814,10 @@ static int __init init_ipv4_mibs(void)
return register_pernet_subsys(&ipv4_mib_ops);
}
+#if IS_ENABLED(CONFIG_IPV4)
+static int ipv4_proc_init(void);
+#endif
+
static __net_init int inet_init_net(struct net *net)
{
/*
@@ -1824,8 +1868,6 @@ static int __init init_inet_pernet_ops(void)
return register_pernet_subsys(&af_inet_ops);
}
-static int ipv4_proc_init(void);
-
/*
* IP protocol layer initialiser
*/
@@ -1870,20 +1912,25 @@ static int __init ipv4_offload_init(void)
fs_initcall(ipv4_offload_init);
+#if IS_ENABLED(CONFIG_IPV4)
static struct packet_type ip_packet_type __read_mostly = {
.type = cpu_to_be16(ETH_P_IP),
.func = ip_rcv,
.list_func = ip_list_rcv,
};
+#endif
static int __init inet_init(void)
{
+#if IS_ENABLED(CONFIG_IPV4)
struct inet_protosw *q;
struct list_head *r;
int rc;
+#endif
sock_skb_cb_check_size(sizeof(struct inet_skb_parm));
+#if IS_ENABLED(CONFIG_IPV4)
raw_hashinfo_init(&raw_v4_hashinfo);
rc = proto_register(&tcp_prot, 1);
@@ -1958,7 +2005,7 @@ static int __init inet_init(void)
*/
ip_init();
-
+#endif /* CONFIG_IPV4 */
/* Initialise per-cpu ipv4 mibs */
if (init_ipv4_mibs())
panic("%s: Cannot init ipv4 mibs\n", __func__);
@@ -1980,6 +2027,9 @@ static int __init inet_init(void)
if (icmp_init() < 0)
panic("Failed to create the ICMP control socket.\n");
+ if (init_inet_pernet_ops())
+ pr_crit("%s: Cannot init ipv4 inet pernet ops\n", __func__);
+#if IS_ENABLED(CONFIG_IPV4)
/*
* Initialise the multicast router
*/
@@ -1987,19 +2037,17 @@ static int __init inet_init(void)
if (ip_mr_init())
pr_crit("%s: Cannot init ipv4 mroute\n", __func__);
#endif
-
- if (init_inet_pernet_ops())
- pr_crit("%s: Cannot init ipv4 inet pernet ops\n", __func__);
-
ipv4_proc_init();
ipfrag_init();
dev_add_pack(&ip_packet_type);
+#endif /* CONFIG_IPV4 */
ip_tunnel_core_init();
- rc = 0;
+ return 0;
+#if IS_ENABLED(CONFIG_IPV4)
out:
return rc;
out_unregister_raw_proto:
@@ -2009,12 +2057,14 @@ static int __init inet_init(void)
out_unregister_tcp_proto:
proto_unregister(&tcp_prot);
goto out;
+#endif
}
fs_initcall(inet_init);
/* ------------------------------------------------------------------------ */
+#if IS_ENABLED(CONFIG_IPV4)
#ifdef CONFIG_PROC_FS
static int __init ipv4_proc_init(void)
{
@@ -2051,3 +2101,4 @@ static int __init ipv4_proc_init(void)
return 0;
}
#endif /* CONFIG_PROC_FS */
+#endif
diff --git a/net/ipv4/ip_output.c b/net/ipv4/ip_output.c
index a24cc8ee11d3..4c6b34e70990 100644
--- a/net/ipv4/ip_output.c
+++ b/net/ipv4/ip_output.c
@@ -932,24 +932,6 @@ int ip_do_fragment(struct net *net, struct sock *sk, struct sk_buff *skb,
}
EXPORT_SYMBOL(ip_do_fragment);
-int
-ip_generic_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
-{
- struct msghdr *msg = from;
-
- if (skb->ip_summed == CHECKSUM_PARTIAL) {
- if (!copy_from_iter_full(to, len, &msg->msg_iter))
- return -EFAULT;
- } else {
- __wsum csum = 0;
- if (!csum_and_copy_from_iter_full(to, len, &csum, &msg->msg_iter))
- return -EFAULT;
- skb->csum = csum_block_add(skb->csum, csum, odd);
- }
- return 0;
-}
-EXPORT_SYMBOL(ip_generic_getfrag);
-
static int __ip_append_data(struct sock *sk,
struct flowi4 *fl4,
struct sk_buff_head *queue,
diff --git a/net/ipv6/af_inet6.c b/net/ipv6/af_inet6.c
index f0efdc13baf4..f220eaab085b 100644
--- a/net/ipv6/af_inet6.c
+++ b/net/ipv6/af_inet6.c
@@ -302,6 +302,11 @@ int __inet6_bind(struct sock *sk, struct sockaddr_unsized *uaddr, int addr_len,
struct net_device *dev = NULL;
int chk_addr_ret;
+ if (!IS_ENABLED(CONFIG_IPV4)) {
+ err = -EADDRNOTAVAIL;
+ goto out;
+ }
+
/* Binding to v4-mapped address on a v6-only socket
* makes no sense
*/
diff --git a/net/ipv6/datagram.c b/net/ipv6/datagram.c
index 191c9733ff9f..079d1951405b 100644
--- a/net/ipv6/datagram.c
+++ b/net/ipv6/datagram.c
@@ -153,7 +153,7 @@ int __ip6_datagram_connect(struct sock *sk, struct sockaddr_unsized *uaddr,
int err;
if (usin->sin6_family == AF_INET) {
- if (ipv6_only_sock(sk))
+ if (!IS_ENABLED(CONFIG_IPV4) || ipv6_only_sock(sk))
return -EAFNOSUPPORT;
err = __ip4_datagram_connect(sk, uaddr, addr_len);
goto ipv4_connected;
@@ -186,7 +186,7 @@ int __ip6_datagram_connect(struct sock *sk, struct sockaddr_unsized *uaddr,
if (addr_type & IPV6_ADDR_MAPPED) {
struct sockaddr_in sin;
- if (ipv6_only_sock(sk)) {
+ if (!IS_ENABLED(CONFIG_IPV4) || ipv6_only_sock(sk)) {
err = -ENETUNREACH;
goto out;
}
--
2.55.0
next prev parent reply other threads:[~2026-09-28 19:31 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260928193046.6698-1-fmancera@suse.de>
2026-09-28 19:29 ` [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-09-28 19:29 ` [PATCH 02/16 net-next v2] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-28 19:29 ` Fernando Fernandez Mancera [this message]
2026-09-28 19:30 ` [PATCH 04/16 net-next v2] tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 05/16 net-next v2] ipv4: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 06/16 net-next v2] ipv4: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 07/16 net-next v2] ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 08/16 net-next v2] ipv4: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 09/16 net-next v2] ipv4: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 10/16 net-next v2] tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 11/16 net-next v2] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-29 7:14 ` Joel Granados
2026-09-29 8:20 ` Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 13/16 net-next v2] net: bridge: guard ARP/RARP proxy and suppression " Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 14/16 net-next v2] wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 16/16 net-next v2] ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928193046.6698-4-fmancera@suse.de \
--to=fmancera@suse.de \
--cc=brauner@kernel.org \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=jiayuan.chen@linux.dev \
--cc=jlayton@kernel.org \
--cc=kees@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=tpluszz77@gmail.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®