From: Fernando Fernandez Mancera <fmancera@suse.de>
To: Stanislav Fomichev <sdf.kernel@gmail.com>
Cc: netdev@vger.kernel.org, horms@kernel.org, kuba@kernel.org,
pabeni@redhat.com, edumazet@google.com, davem@davemloft.net,
David Ahern <dsahern@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
Willem de Bruijn <willemb@google.com>,
Kees Cook <kees@kernel.org>,
Kuniyuki Iwashima <kuniyu@google.com>,
Richard Gobert <richardbgobert@gmail.com>,
Marc Kleine-Budde <mkl@pengutronix.de>,
Jeff Layton <jlayton@kernel.org>, Qi Tang <tpluszz77@gmail.com>,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 03/13 net-next] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic
Date: Fri, 11 Sep 2026 20:41:10 +0200 [thread overview]
Message-ID: <fcb24a94-d62d-4166-b51b-4585a021500b@suse.de> (raw)
In-Reply-To: <aqMeeDnj4pcuvz7-@devvm7509.cco0.facebook.com>
On 9/10/26 11:19 PM, Stanislav Fomichev wrote:
> On 09/10, Fernando Fernandez Mancera wrote:
>> To enable compiling the INET subsystem without IPv4, shared generic
>> utilities must be relocated and IPv4 socket logic must be guarded for
>> CONFIG_IPV4.
>>
>> This patch moves the generic ip_generec_getfrag() from ip_output.c to
>> af_inet.c. It also introduces CONFIG_IPV4 guards around af_inet.c to
>> reject IPv4-specific ioctls, protocol registrations and bind requests.
>> The same guard is added to reject IPv4-mapped IPv6.
>>
>> Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
>> ---
>> net/ipv4/af_inet.c | 96 +++++++++++++++++++++++++++++++++++++-------
>> net/ipv4/ip_output.c | 18 ---------
>> net/ipv6/af_inet6.c | 5 +++
>> net/ipv6/datagram.c | 12 ++++++
>> 4 files changed, 99 insertions(+), 32 deletions(-)
>>
>> diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c
>> index d9421ac38d78..b0c48ba544bf 100644
>> --- a/net/ipv4/af_inet.c
>> +++ b/net/ipv4/af_inet.c
>> @@ -129,6 +129,28 @@
>> int disable_ipv6_mod;
>> EXPORT_SYMBOL(disable_ipv6_mod);
>>
>> +/* Keep the function here for now as it is generic, it should be moved
>> + * to a common L3 place
>> + */
>> +int
>> +ip_generic_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
>> +{
>> + struct msghdr *msg = from;
>> +
>> + if (skb->ip_summed == CHECKSUM_PARTIAL) {
>> + if (!copy_from_iter_full(to, len, &msg->msg_iter))
>> + return -EFAULT;
>> + } else {
>> + __wsum csum = 0;
>> +
>> + if (!csum_and_copy_from_iter_full(to, len, &csum, &msg->msg_iter))
>> + return -EFAULT;
>> + skb->csum = csum_block_add(skb->csum, csum, odd);
>> + }
>> + return 0;
>> +}
>> +EXPORT_SYMBOL(ip_generic_getfrag);
>> +
>> /* The inetsw table contains everything that inet_create needs to
>> * build a new socket.
>> */
>> @@ -425,8 +447,10 @@ int inet_release(struct socket *sock)
>> if (!sk->sk_kern_sock)
>> BPF_CGROUP_RUN_PROG_INET_SOCK_RELEASE(sk);
>>
>> +#if IS_ENABLED(CONFIG_IPV4)
>> /* Applications forget to leave groups before exiting */
>> ip_mc_drop_socket(sk);
>> +#endif
>>
>> /* If linger is set, we don't return until the close
>> * is complete. Otherwise we return immediately. The
>> @@ -478,6 +502,7 @@ EXPORT_SYMBOL(inet_bind);
>> int __inet_bind(struct sock *sk, struct sockaddr_unsized *uaddr, int addr_len,
>> u32 flags)
>> {
>> +#if IS_ENABLED(CONFIG_IPV4)
>> struct sockaddr_in *addr = (struct sockaddr_in *)uaddr;
>> struct inet_sock *inet = inet_sk(sk);
>> struct net *net = sock_net(sk);
>> @@ -570,6 +595,9 @@ int __inet_bind(struct sock *sk, struct sockaddr_unsized *uaddr, int addr_len,
>> release_sock(sk);
>> out:
>> return err;
>> +#else
>> + return -EAFNOSUPPORT;
>> +#endif
>> }
>>
>> int inet_dgram_connect(struct socket *sock, struct sockaddr_unsized *uaddr,
>> @@ -962,18 +990,24 @@ EXPORT_SYMBOL(inet_shutdown);
>> int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
>> {
>> struct sock *sk = sock->sk;
>> - int err = 0;
>> - struct net *net = sock_net(sk);
>> +#if IS_ENABLED(CONFIG_IPV4)
>> void __user *p = (void __user *)arg;
>> - struct ifreq ifr;
>> + struct net *net = sock_net(sk);
>> struct rtentry rt;
>> + struct ifreq ifr;
>> +#endif
>> + int err = 0;
>>
>> switch (cmd) {
>> case SIOCADDRT:
>> case SIOCDELRT:
>> +#if IS_ENABLED(CONFIG_IPV4)
>> if (copy_from_user(&rt, p, sizeof(struct rtentry)))
>> return -EFAULT;
>> err = ip_rt_ioctl(net, cmd, &rt);
>> +#else
>> + err = -EOPNOTSUPP;
>> +#endif
>> break;
>> case SIOCRTMSG:
>> err = -EINVAL;
>> @@ -981,18 +1015,26 @@ int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
>> case SIOCDARP:
>> case SIOCGARP:
>> case SIOCSARP:
>> +#if IS_ENABLED(CONFIG_IPV4)
>> err = arp_ioctl(net, cmd, (void __user *)arg);
>> +#else
>> + err = -EOPNOTSUPP;
>> +#endif
>> break;
>> case SIOCGIFADDR:
>> case SIOCGIFBRDADDR:
>> case SIOCGIFNETMASK:
>> case SIOCGIFDSTADDR:
>> case SIOCGIFPFLAGS:
>> +#if IS_ENABLED(CONFIG_IPV4)
>> if (get_user_ifreq(&ifr, NULL, p))
>> return -EFAULT;
>> err = devinet_ioctl(net, cmd, &ifr);
>> if (!err && put_user_ifreq(&ifr, p))
>> err = -EFAULT;
>> +#else
>> + err = -EOPNOTSUPP;
>> +#endif
>> break;
>>
>> case SIOCSIFADDR:
>> @@ -1001,9 +1043,13 @@ int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
>> case SIOCSIFDSTADDR:
>> case SIOCSIFPFLAGS:
>> case SIOCSIFFLAGS:
>> +#if IS_ENABLED(CONFIG_IPV4)
>> if (get_user_ifreq(&ifr, NULL, p))
>> return -EFAULT;
>> err = devinet_ioctl(net, cmd, &ifr);
>> +#else
>> + err = -EOPNOTSUPP;
>> +#endif
>
> (passing by comment)
>
> Don't we have a coding style rule to avoid ifdef conditional in C code?
> Should we add some new devinet4_ioctl/etc wrappers that we can conditionally
> compile out in the headers?
I think yes but when it makes sense. Of course, that is something a bit
hard to judge IMHO. I tried to use it when it makes sense, like for
stubs or for functions that are protocol agnostic but contains a small
part related to IPv4/IPV6. I was willing to avoid code duplication as
much as possible.
next prev parent reply other threads:[~2026-09-11 18:41 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 14:48 [PATCH 00/13 net-next] Allow compiling an IPv6-only kernel network stack Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 01/13 net-next] net: ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-09-10 15:11 ` Nicolai Buchwitz
2026-09-10 15:32 ` Fernando Fernandez Mancera
2026-09-10 15:36 ` Arnd Bergmann
2026-09-10 16:22 ` Fernando Fernandez Mancera
2026-09-10 16:30 ` Fernando Fernandez Mancera
2026-09-10 16:56 ` Sven Eckelmann
2026-09-11 18:39 ` Fernando Fernandez Mancera
2026-09-10 18:55 ` Chuck Lever
2026-09-11 15:15 ` sashiko-bot
2026-09-11 17:46 ` Casey Schaufler
2026-09-11 18:31 ` Fernando Fernandez Mancera
2026-09-11 18:59 ` Casey Schaufler
2026-09-10 14:48 ` [PATCH 02/13 net-next] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 03/13 net-next] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-09-10 21:19 ` Stanislav Fomichev
2026-09-11 18:41 ` Fernando Fernandez Mancera [this message]
2026-09-28 13:29 ` Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 04/13 net-next] net: tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 05/13 net-next] net: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 06/13 net-next] net: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-09-11 15:15 ` sashiko-bot
2026-09-10 14:48 ` [PATCH 07/13 net-next] net: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 08/13 net-next] net: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 09/13 net-next] net: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-09-11 15:15 ` sashiko-bot
2026-09-10 14:48 ` [PATCH 10/13 net-next] net: tunnel: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 11/13 net-next] netfilter: ipv4: guard ip_route_me_harder() " Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 12/13 net-next] net: ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-15 12:16 ` Joel Granados
2026-09-10 14:48 ` [PATCH 13/13 net-next] net: ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
2026-09-15 0:24 ` [PATCH 00/13 net-next] Allow compiling an IPv6-only kernel network stack Jakub Kicinski
2026-09-28 13:37 ` Fernando Fernandez Mancera
2026-09-28 17:08 ` Willem de Bruijn
2026-09-28 19:15 ` Fernando Fernandez Mancera
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=fcb24a94-d62d-4166-b51b-4585a021500b@suse.de \
--to=fmancera@suse.de \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=jlayton@kernel.org \
--cc=kees@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mkl@pengutronix.de \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=richardbgobert@gmail.com \
--cc=sdf.kernel@gmail.com \
--cc=tpluszz77@gmail.com \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.