From: netdev-bot+sashiko@kernel.org
To: fmancera@suse.de
Cc: netdev@vger.kernel.org, horms@kernel.org, kuba@kernel.org,
pabeni@redhat.com, edumazet@kernel.org, davem@davemloft.net,
edumazet@google.com, ebiggers@kernel.org, ardb@kernel.org,
krzk@kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH 11/16 net-next v2] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n
Date: Fri, 02 Oct 2026 10:32:26 +0000 [thread overview]
Message-ID: <179093714642.434549.8365340209471178412@kernel.org> (raw)
In-Reply-To: <20260928193046.6698-12-fmancera@suse.de>
Thank you for your contribution! Sashiko AI review found 1 potential
issue(s) to consider.
Critical: 0 · High: 0 · Medium: 1 · Low: 0
If you believe none of the issues are legitimate, please reply to each
issue of Medium severity or higher and explain why the AI is wrong.
If any of them are legitimate and you plan to respin, please let patchwork
know by including "pw-bot: cr" as a separate line at the end of your reply
(one such reply per series is enough).
- [Medium] The patch moves the `fib_multipath_hash_seed` entry of
`ipv4_net_table` (net/ipv4/sysctl_net_ipv4.c:1644-1650) into the new…
--
ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n
This commit moves the IPv4-only entries of ipv4_net_table into a new
IS_ENABLED(CONFIG_IPV4) block, so they are not registered when IPv4
support is compiled out. The handlers and limit variables that are now
only used conditionally are marked __maybe_unused.
> diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c
> index 0e7fef5973db6..6096e9e4d82d8 100644
> --- a/net/ipv4/sysctl_net_ipv4.c
> +++ b/net/ipv4/sysctl_net_ipv4.c
[ ... ]
> @@ -492,9 +493,9 @@ static void proc_fib_multipath_hash_set_seed(struct net *net, u32 user_seed)
> WRITE_ONCE(net->ipv4.sysctl_fib_multipath_hash_seed.mp_seed, new.mp_seed);
> }
>
> -static int proc_fib_multipath_hash_seed(const struct ctl_table *table, int write,
> - void *buffer, size_t *lenp,
> - loff_t *ppos)
> +static int __maybe_unused
> +proc_fib_multipath_hash_seed(const struct ctl_table *table, int write,
> + void *buffer, size_t *lenp, loff_t *ppos)
> {
> struct sysctl_fib_multipath_hash_seed *mphs;
> struct net *net = table->data;
[ ... ]
> @@ -1656,6 +1469,196 @@ static const struct ctl_table ipv4_net_table[] = {
> .extra1 = SYSCTL_ONE_THOUSAND,
> .extra2 = &tcp_rto_max_max,
> },
> +#if IS_ENABLED(CONFIG_IPV4)
> + {
> + .procname = "icmp_echo_ignore_all",
[ ... ]
> +#ifdef CONFIG_IP_ROUTE_MULTIPATH
> + {
> + .procname = "fib_multipath_use_neigh",
[ ... ]
> + {
> + .procname = "fib_multipath_hash_seed",
> + .data = &init_net,
> + .maxlen = sizeof(u32),
> + .mode = 0644,
> + .proc_handler = proc_fib_multipath_hash_seed,
> + },
> +#endif
[Severity: Medium]
Is fib_multipath_hash_seed really an IPv4-only sysctl?
The seed is read by the shared helper fib_multipath_hash_from_keys(),
which is gated only by CONFIG_IP_ROUTE_MULTIPATH:
include/net/ip_fib.h:fib_multipath_hash_from_keys() {
...
mp_seed = READ_ONCE(net->ipv4.sysctl_fib_multipath_hash_seed.mp_seed);
fib_multipath_hash_construct_key(&hash_key, mp_seed);
...
}
The IPv6 datapath calls this helper for every multipath hash, through
rt6_multipath_hash() in net/ipv6/route.c.
net/ipv6/sysctl_net_ipv6.c has its own fib_multipath_hash_policy and
fib_multipath_hash_fields, but it has no seed knob. That makes this entry
the only way to set the seed for either family.
Documentation/networking/ip-sysctl.rst describes it the same way:
The seed value used when calculating hash for multipath routes. Applies
to both IPv4 and IPv6 datapath. Only present for kernels built with
CONFIG_IP_ROUTE_MULTIPATH enabled.
CONFIG_IP_ROUTE_MULTIPATH depends only on IP_ADVANCED_ROUTER, not on
IPV4. After "ipv4: make CONFIG_IPV4 boolean" later in the series,
CONFIG_IPV4 can be disabled when IPV6 is enabled. At the end of the
series this entry is still inside the CONFIG_IPV4 block.
Take a kernel built with CONFIG_IPV4=n, CONFIG_IPV6=y and
CONFIG_IP_ROUTE_MULTIPATH=y. ipv4_sysctl_init_net() still calls
proc_fib_multipath_hash_set_seed(net, 0), so IPv6 ECMP keeps hashing with
the random seed picked at boot. However,
/proc/sys/net/ipv4/fib_multipath_hash_seed no longer exists, so the seed
cannot be set to a fixed value. mlxsw programs its hardware ECMP seed from
user_seed, so it would also always see 0.
Could the fib_multipath_hash_seed entry and proc_fib_multipath_hash_seed()
stay outside the CONFIG_IPV4 block, under CONFIG_IP_ROUTE_MULTIPATH? That
would match how icmp_echo_enable_probe, icmp_msgs_per_sec and
ip_early_demux were left in place. fib_multipath_use_neigh,
fib_multipath_hash_policy and fib_multipath_hash_fields do look IPv4-only
and could stay inside the block.
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260928193046.6698-1-fmancera%40suse.de
next prev parent reply other threads:[~2026-10-02 10:32 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 19:29 [PATCH 00/16 net-next v2] Allow compiling an IPv6-only kernel network stack Fernando Fernandez Mancera
2026-09-28 19:29 ` [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:29 ` [PATCH 02/16 net-next v2] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:29 ` [PATCH 03/16 net-next v2] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 04/16 net-next v2] tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 05/16 net-next v2] ipv4: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 06/16 net-next v2] ipv4: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 07/16 net-next v2] ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 08/16 net-next v2] ipv4: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 09/16 net-next v2] ipv4: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 10/16 net-next v2] tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 11/16 net-next v2] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-29 7:14 ` Joel Granados
2026-09-29 8:20 ` Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko [this message]
2026-09-28 19:30 ` [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 13/16 net-next v2] net: bridge: guard ARP/RARP proxy and suppression " Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 14/16 net-next v2] wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency Fernando Fernandez Mancera
2026-09-30 1:37 ` Paul Moore
2026-10-02 10:32 ` netdev-bot+sashiko
2026-09-28 19:30 ` [PATCH 16/16 net-next v2] ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
2026-10-02 10:32 ` netdev-bot+sashiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=179093714642.434549.8365340209471178412@kernel.org \
--to=netdev-bot+sashiko@kernel.org \
--cc=ardb@kernel.org \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=edumazet@google.com \
--cc=edumazet@kernel.org \
--cc=fmancera@suse.de \
--cc=horms@kernel.org \
--cc=krzk@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox