Linux Security Modules development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Fernando Fernandez Mancera" <fmancera@suse.de>
Cc: antonio@mandelbit.com, sw@simonwunderlich.de,
	linux-scsi@vger.kernel.org, "Jeff Layton" <jlayton@kernel.org>,
	sven@narfation.org, linux-security-module@vger.kernel.org,
	"Anna Schumaker" <anna@kernel.org>,
	"Chuck Lever" <cel@kernel.org>,
	marek.lindner@mailbox.org, mptcp@lists.linux.dev,
	linux-rdma@vger.kernel.org
Subject: Re: [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack
Date: Tue, 29 Sep 2026 19:32:43 +0000	[thread overview]
Message-ID: <20260929193243.90FF01F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928193046.6698-2-fmancera@suse.de>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] kconfig: core dual-stack and IPv6 features are forcibly disabled without IPv4
--

commit e9e0ffe00541dede8370017851b597f6f3e1cfa2
Author: Fernando Fernandez Mancera <fmancera@suse.de>

ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack

This commit introduces the CONFIG_IPV4 symbol to decouple the IPv4 stack,
currently defaulting it to yes. It adjusts multiple networking subsystems
across tunnels, drivers, and filesystems to depend on this new IPv4
configuration symbol.

> diff --git a/net/Kconfig b/net/Kconfig
> index 76ab44aa439a6..ca86f20540dd1 100644
> --- a/net/Kconfig
> +++ b/net/Kconfig
[ ... ]
> @@ -232,6 +235,7 @@ config BRIDGE_NETFILTER
>  	depends on BRIDGE
>  	depends on NETFILTER && INET
>  	depends on NETFILTER_ADVANCED
> +	depends on IPV4
>  	select NETFILTER_FAMILY_BRIDGE

[Severity: High]
Does adding this dependency force bridge netfilter to be unavailable on
kernels without IPv4?

Bridge netfilter handles both IPv4 and IPv6 bridged traffic. Tying it
exclusively to CONFIG_IPV4 under config BRIDGE_NETFILTER might prevent
filtering IPv6 traffic on an IPv6-only kernel.

[ ... ]
> diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
> index c3806c6ac96f9..f83efc1505cc4 100644
> --- a/net/ipv6/Kconfig
> +++ b/net/ipv6/Kconfig
[ ... ]
> @@ -256,7 +265,7 @@ config IPV6_SUBTREES
>  
>  config IPV6_MROUTE
>  	bool "IPv6: multicast routing"
> -	depends on IPV6
> +	depends on IPV4 && IPV6
>  	select IP_MROUTE_COMMON

[Severity: High]
Does this change break IPv6 multicast routing when CONFIG_IPV4 is disabled?

IPv6 multicast routing under config IPV6_MROUTE does not inherently require
IPv4. Adding this dependency disables purely IPv6 functionality on an
IPv6-only kernel.

[ ... ]
> diff --git a/net/xfrm/Kconfig b/net/xfrm/Kconfig
> index 4a62817a88f8f..203188b05be40 100644
> --- a/net/xfrm/Kconfig
> +++ b/net/xfrm/Kconfig
> @@ -4,7 +4,7 @@
>  #
>  config XFRM
>  	bool
> -	depends on INET
> +	depends on INET && IPV4
>  	select GRO_CELLS

[Severity: High]
Will adding this dependency disable the global IPsec subsystem for IPv6-only
kernels?

Tying config XFRM entirely to CONFIG_IPV4 restricts dual-stack infrastructure,
making it impossible to use IPsec with IPv6 if IPv4 is disabled.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928193046.6698-1-fmancera@suse.de?part=1

  reply	other threads:[~2026-09-29 19:32 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20260928193046.6698-1-fmancera@suse.de>
2026-09-28 19:29 ` [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-09-29 19:32   ` sashiko-bot [this message]
2026-09-28 19:30 ` [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency Fernando Fernandez Mancera
2026-09-29 19:32   ` sashiko-bot
2026-09-30  1:37   ` Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929193243.90FF01F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=anna@kernel.org \
    --cc=antonio@mandelbit.com \
    --cc=cel@kernel.org \
    --cc=fmancera@suse.de \
    --cc=jlayton@kernel.org \
    --cc=linux-rdma@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=marek.lindner@mailbox.org \
    --cc=mptcp@lists.linux.dev \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=sven@narfation.org \
    --cc=sw@simonwunderlich.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox