From: Fernando Fernandez Mancera <fmancera@suse.de>
To: netdev@vger.kernel.org
Cc: horms@kernel.org, kuba@kernel.org, pabeni@redhat.com,
edumazet@kernel.org, davem@davemloft.net,
Fernando Fernandez Mancera <fmancera@suse.de>
Subject: [PATCH 00/16 net-next v3] Allow compiling an IPv6-only kernel network stack
Date: Wed, 30 Sep 2026 15:52:43 +0200 [thread overview]
Message-ID: <20260930135334.4739-1-fmancera@suse.de> (raw)
The primary goal of this patch series is to enable the compilation of an
IPv6-only kernel by decoupling the core networking infrastructure from
the IPv4 protocol.
Historically, IPv4 has been intertwined with the generic socket and
transport layers. By untangling these dependencies, this series allows
systems to be built with CONFIG_IPV4 disabled. This configuration
targets strict IPv6-only deployments, constrained environments, and
specialized appliances where removing the IPv4 subsystem reduces the
network attack surface. To provide some numbers, 0.3% (32) of the
released CVEs since 2025 were strictly related to IPv4 code. While the
number is low, it is good for users to be able to disable it if they do
not depend on it.
To achieve this, subsystems with hard dependencies on IPv4 were modified
to use conditional compilation guards. When CONFIG_IPV4 is disabled, the
affected packet manipulation routines and routing hooks evaluate to
stubs returning standard error codes. The INDIRECT_CALL_INET macros
within the transport layer were adapted to safely bypass IPv4 function
pointers without penalizing the dual-stack fast paths. In addition,
there has been several code splits for UDP, RAW, ICMP or Ping isolating
the IPv4 specific code.
Every Kconfig symbol that gained a new depends on IPV4 was audited
against the code it guards, distinguishing genuine hard link-time
dependencies from options that were only conservatively gated. Where a
symbol never depended on CONFIG_INET before, depends on IPV4 || !INET is
used instead of a bare dependency, so pre-existing CONFIG_INET=n
configurations remain buildable as before.
Finally, CONFIG_IPV4 is exposed in Kconfig as an explicit boolean,
defaulting to 'y' to preserve existing configurations.
The bloat-o-meter diff and size output for x86_64 with dualstack and
IPv6 disabled:
text data bss dec hex filename
31608053 8913174 1145484 41666711 27bc897 vmlinux.dual
28809691 8183494 1101724 38094909 245483d vmlinux.ipv6
add/remove: 53/19751 grow/shrink: 65/601 up/down: 740100/-3490467 (-2750367)
Performance testing:
Basic TCP performance validation was conducted using iperf3 on an AMD
Ryzen 9 9950X between two bridged virtual machines. These benchmarks
verify that there are no obvious performance regressions.
Kernel / Configuration Traffic Type Offloads ON Offloads OFF
-------------------------------------------------------------------------------
net-next (Dual-Stack Baseline) IPv4 20.8 Gbps 7.22 Gbps
net-next (Dual-Stack Baseline) IPv6 20.4 Gbps 7.55 Gbps
net-next (IPv4-Only Baseline) IPv4 20.9 Gbps 7.86 Gbps
Patched (Dual-Stack) IPv4 21.8 Gbps 7.77 Gbps
Patched (Dual-Stack) IPv6 21.7 Gbps 7.35 Gbps
Patched (IPv4-Only) IPv4 20.9 Gbps 7.91 Gbps
Patched (IPv6-Only) IPv6 21.1 Gbps 8.06 Gbps
Follow-up for this series:
Future work decoupled from this initial series includes expanding
Kconfig adaptations across remaining kernel subsystems to support an
IPv6-only environment. This includes patches for network bonding modes
that assume dual-stack availability and analyze Netfilter nftables
expressions and connection tracking to ensure pure IPv6 operations are
fully independent.
The main structural cost of this series is the code movement from
splitting IPv4-specific logic into new files, which will make git blame
and bisection across the affected files more cumbersome than a purely
additive change. Where possible, IPv4-only branches were expressed as
runtime IS_ENABLED() checks relying on dead-code elimination rather than
ifdef blocks, to keep the preprocessor-guard footprint as small as
possible.
Changes:
v3:
Patch 1: Mark SMC as depends on IPV4 too
Patch 3: Make sure inetsw isn't accessible from other modules when
IPV4=n by using runtime checks
Patch 5: Included missing <linux/compat.h>
Patch 6: Fixed wrong removal of udp_get_len() due to a wrong rebase.
Patch 13: Fixed building with INET=n
v2: https://lore.kernel.org/netdev/20260928193046.6698-1-fmancera@suse.de/
Fernando Fernandez Mancera (16):
ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack
net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n
net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic
tcp: move protocol agnostic TCP functions out of tcp_ipv4.c
ipv4: raw: split IPv4 specific logic into raw_ipv4.c
ipv4: udp: split IPv4 specific logic into udp_ipv4.c
ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c
ipv4: ping: split IPv4 specific logic into ping_ipv4.c
ipv4: fib: split common nexthop logic to fib_core.c
tunnels: guard IPv4 tunnel functions with CONFIG_IPV4
ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n
netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4
net: bridge: guard ARP/RARP proxy and suppression with CONFIG_IPV4
wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards
netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
ipv4: make CONFIG_IPV4 boolean
drivers/infiniband/Kconfig | 2 +-
drivers/infiniband/sw/rxe/Kconfig | 2 +-
drivers/net/Kconfig | 23 +-
drivers/net/ethernet/chelsio/Kconfig | 2 +-
drivers/net/ethernet/intel/Kconfig | 2 +
drivers/net/ethernet/marvell/prestera/Kconfig | 1 +
.../net/ethernet/mellanox/mlx5/core/Kconfig | 3 +-
drivers/net/ethernet/mellanox/mlxsw/Kconfig | 1 +
drivers/net/ethernet/qlogic/Kconfig | 2 +
drivers/net/ethernet/rocker/Kconfig | 1 +
drivers/net/ethernet/sfc/Kconfig | 1 +
drivers/net/ethernet/stmicro/stmmac/Kconfig | 1 +
drivers/net/ethernet/via/Kconfig | 1 +
drivers/net/ppp/Kconfig | 1 +
.../broadcom/brcm80211/brcmfmac/Kconfig | 1 +
drivers/net/wireless/intel/iwlwifi/Kconfig | 1 +
drivers/nvme/host/Kconfig | 2 +-
drivers/nvme/target/Kconfig | 2 +-
drivers/scsi/cxgbi/cxgb3i/Kconfig | 2 +-
drivers/scsi/cxgbi/cxgb4i/Kconfig | 2 +-
drivers/target/iscsi/Kconfig | 2 +-
drivers/target/iscsi/cxgbit/Kconfig | 2 +-
fs/Kconfig | 1 +
fs/afs/Kconfig | 2 +-
fs/nfs/Kconfig | 2 +-
fs/nfsd/Kconfig | 2 +-
include/linux/indirect_call_wrapper.h | 8 +-
include/net/cipso_ipv4.h | 18 +-
include/net/icmp.h | 1 +
include/net/ip.h | 111 +-
include/net/ip_fib.h | 27 +-
include/net/route.h | 14 +
include/net/tcp.h | 16 +-
include/net/udp.h | 11 +
net/Kconfig | 9 +-
net/batman-adv/Kconfig | 6 +-
net/bridge/Kconfig | 2 +-
net/bridge/br_arp_nd_proxy.c | 2 +
net/bridge/br_device.c | 2 +-
net/bridge/br_input.c | 2 +-
net/bridge/netfilter/Kconfig | 3 +-
net/core/Makefile | 2 +-
net/core/dev_ioctl.c | 3 +
net/core/fib_core.c | 307 +++
net/core/filter.c | 20 +-
net/core/neighbour.c | 4 +
net/ipv4/Kconfig | 29 +-
net/ipv4/Makefile | 24 +-
net/ipv4/af_inet.c | 132 +-
net/ipv4/fib_frontend.c | 96 -
net/ipv4/fib_semantics.c | 205 --
net/ipv4/icmp.c | 1418 +------------
net/ipv4/icmp_ipv4.c | 1448 +++++++++++++
net/ipv4/inet_connection_sock.c | 2 +-
net/ipv4/inet_hashtables.c | 3 +
net/ipv4/ip_output.c | 18 -
net/ipv4/ip_tunnel_core.c | 11 +
net/ipv4/netfilter.c | 3 +
net/ipv4/netfilter/Kconfig | 2 +-
net/ipv4/nexthop.c | 5 +-
net/ipv4/ping.c | 210 +-
net/ipv4/ping_ipv4.c | 228 +++
net/ipv4/proc.c | 45 +-
net/ipv4/raw.c | 853 --------
net/ipv4/raw_diag.c | 3 +-
net/ipv4/raw_ipv4.c | 884 ++++++++
net/ipv4/sysctl_net_ipv4.c | 413 ++--
net/ipv4/tcp.c | 1300 +++++++++++-
net/ipv4/tcp_bpf.c | 3 +-
net/ipv4/tcp_ipv4.c | 1307 +-----------
net/ipv4/udp.c | 1817 +----------------
net/ipv4/udp_bpf.c | 5 +-
net/ipv4/udp_ipv4.c | 1790 ++++++++++++++++
net/ipv4/udp_offload.c | 3 +
net/ipv6/Kconfig | 17 +-
net/ipv6/af_inet6.c | 5 +
net/ipv6/datagram.c | 4 +-
net/ipv6/netfilter/Kconfig | 2 +-
net/ipv6/tcp_ipv6.c | 23 +-
net/ipv6/udp.c | 11 +-
net/l2tp/Kconfig | 2 +-
net/mac80211/main.c | 10 +-
net/mptcp/Kconfig | 2 +-
net/netfilter/Kconfig | 2 +-
net/netfilter/ipset/Kconfig | 2 +-
net/netfilter/ipvs/Kconfig | 2 +-
net/netlabel/Kconfig | 4 +
net/netlabel/Makefile | 2 +-
net/netlabel/netlabel_cipso_v4.h | 7 +
net/netlabel/netlabel_kapi.c | 3 +
net/rds/Kconfig | 1 +
net/rxrpc/Kconfig | 2 +-
net/sched/Kconfig | 2 +-
net/sctp/Kconfig | 2 +-
net/smc/Kconfig | 2 +-
net/sunrpc/Kconfig | 2 +-
net/tipc/Kconfig | 1 +
net/xfrm/Kconfig | 10 +-
98 files changed, 6747 insertions(+), 6262 deletions(-)
create mode 100644 net/core/fib_core.c
create mode 100644 net/ipv4/icmp_ipv4.c
create mode 100644 net/ipv4/ping_ipv4.c
create mode 100644 net/ipv4/raw_ipv4.c
create mode 100644 net/ipv4/udp_ipv4.c
--
2.55.0
next reply other threads:[~2026-09-30 13:53 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 13:52 Fernando Fernandez Mancera [this message]
2026-09-30 13:52 ` [PATCH 01/16 net-next v3] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-10-01 14:05 ` sashiko-bot
2026-09-30 13:52 ` [PATCH 02/16 net-next v3] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 03/16 net-next v3] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 04/16 net-next v3] tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 05/16 net-next v3] ipv4: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 06/16 net-next v3] ipv4: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-10-06 9:12 ` Fernando Fernandez Mancera
2026-09-30 13:52 ` [PATCH 07/16 net-next v3] ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 08/16 net-next v3] ipv4: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-30 13:52 ` [PATCH 09/16 net-next v3] ipv4: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-10-01 14:05 ` sashiko-bot
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 10/16 net-next v3] tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-30 13:52 ` [PATCH 11/16 net-next v3] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 12/16 net-next v3] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-30 13:52 ` [PATCH 13/16 net-next v3] net: bridge: guard ARP/RARP proxy and suppression " Fernando Fernandez Mancera
2026-09-30 13:52 ` [PATCH 14/16 net-next v3] wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards Fernando Fernandez Mancera
2026-09-30 13:52 ` [PATCH 15/16 net-next v3] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency Fernando Fernandez Mancera
2026-10-01 14:05 ` sashiko-bot
2026-10-04 17:22 ` netdev-bot+sashiko
2026-09-30 13:52 ` [PATCH 16/16 net-next v3] ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
2026-10-04 17:22 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930135334.4739-1-fmancera@suse.de \
--to=fmancera@suse.de \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.