From: Omar Ramadan <omar@blockcast.net>
To: Taehee Yoo <ap420073@gmail.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
"David S . Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@kernel.org>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Shuah Khan <shuah@kernel.org>
Cc: Simon Horman <horms@kernel.org>,
netdev@vger.kernel.org, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH net-next 09/13] amt: receive the AMT gateway control plane over IPv6
Date: Fri, 9 Oct 2026 12:24:22 +0000 [thread overview]
Message-ID: <20261009122426.551178-10-omar@blockcast.net> (raw)
In-Reply-To: <20261009122426.551178-1-omar@blockcast.net>
An IPv6 gateway now sends its Discovery, Request and Updates over IPv6,
but it cannot take the replies. amt_rcv() checks the outer source of an
Advertisement against the discovery address, and that of Multicast Data
and a Membership Query against the learned relay address, by reading
ip_hdr(skb)->saddr, which on an IPv6 outer header is bytes 4-7 of the
source address, so only 32 bits of it are compared.
amt_advertisement_handler() parses only the IPv4 form, so the gateway
never learns an IPv6 relay address.
amt_rcv() now takes the outer source with amt_outer_saddr() before
amt_parse_type() pulls, and checks it in the device's family through
amt_from_relay(). On an IPv6 gateway amt_advertisement_handler() pulls
the 24-byte IPv6 form, whose header and nonce are laid out as in the
IPv4 one, and refuses an unspecified, loopback, multicast or
IPv4-mapped relay address, the IPv6 counterparts of the checks on the
IPv4 address; the V6ONLY socket could not reach an IPv4-mapped relay.
amt_set_remote_ipv6() publishes the learned address under
remote_ipv6_lock. amt_clear_remote() forgets the relay in both families
and replaces the IPv4-only reset in amt_event_send_request(),
amt_dev_open() and amt_dev_stop(), so a gateway taken down and up again
neither accepts traffic from its previous relay's IPv6 address nor
keeps reporting it.
IPv6 input delivers a packet from ::. On a gateway that has lost its
relay it would match the cleared relay address and, with a zero nonce,
could inject a Membership Query, and a relay would create a tunnel for
it. amt_rcv() drops a :: source, and amt_from_relay() matches nothing
against a relay address that is not known, in either family: IPv4
input delivers a 0.0.0.0 source too, when the packet is sent to
255.255.255.255.
RFC 7450 s5.2.3.3 says a gateway that processes Multicast Data itself,
as amt_rcv() does, must not discard it for a zero UDP checksum, which
s5.1.6 lets a relay send, the RFC 6936 exception to RFC 8200 s8.1. An
IPv6 gateway's socket therefore accepts a zero checksum and still
verifies a non-zero one. amt_rcv() drops a zero checksum on every other
message a gateway receives, as RFC 6936 s5 asks, and a relay's socket
keeps requiring the checksum.
The Membership Query and Multicast Data handlers work on the payload
behind the outer header and need no change.
Assisted-by: LLM
Signed-off-by: Omar Ramadan <omar@blockcast.net>
---
drivers/net/amt.c | 116 +++++++++++++++++++++++++++++++++++++---------
1 file changed, 94 insertions(+), 22 deletions(-)
diff --git a/drivers/net/amt.c b/drivers/net/amt.c
index 148d1fb..86f168c 100644
--- a/drivers/net/amt.c
+++ b/drivers/net/amt.c
@@ -116,6 +116,16 @@ static void amt_outer_saddr(const struct amt_dev *amt,
addr->ip4 = ip_hdr(skb)->saddr;
}
+/* An IPv6 address no relay or gateway can use: the counterparts of the
+ * IPv4 zeronet, loopback and multicast checks, and IPv4-mapped, which the
+ * V6ONLY socket cannot reach.
+ */
+static bool amt_ip6_unusable(const struct in6_addr *addr)
+{
+ return ipv6_addr_any(addr) || ipv6_addr_loopback(addr) ||
+ ipv6_addr_is_multicast(addr) || ipv6_addr_v4mapped(addr);
+}
+
static void __amt_source_gc_work(void)
{
struct amt_source_node *snode;
@@ -731,6 +741,21 @@ static struct in6_addr amt_get_remote_ipv6(const struct amt_dev *amt)
return addr;
}
+static void amt_set_remote_ipv6(struct amt_dev *amt,
+ const struct in6_addr *addr)
+{
+ write_seqlock_bh(&amt->remote_ipv6_lock);
+ amt->remote_ipv6 = *addr;
+ write_sequnlock_bh(&amt->remote_ipv6_lock);
+}
+
+/* Forget the relay a gateway learned, in both outer families. */
+static void amt_clear_remote(struct amt_dev *amt)
+{
+ WRITE_ONCE(amt->remote_ip, 0);
+ amt_set_remote_ipv6(amt, &in6addr_any);
+}
+
/* IPv6-outer variant of amt_send_discovery(). */
static void amt_send_discovery_v6(struct amt_dev *amt)
{
@@ -1134,7 +1159,7 @@ static void amt_event_send_request(struct amt_dev *amt)
amt->qi = AMT_INIT_REQ_TIMEOUT;
WRITE_ONCE(amt->ready4, false);
WRITE_ONCE(amt->ready6, false);
- WRITE_ONCE(amt->remote_ip, 0);
+ amt_clear_remote(amt);
amt_update_gw_status(amt, AMT_STATUS_INIT, false);
amt->req_cnt = 0;
amt->nonce = 0;
@@ -2476,27 +2501,39 @@ static bool amt_advertisement_handler(struct amt_dev *amt, struct sk_buff *skb)
struct amt_header_advertisement *amta;
int hdr_size;
- hdr_size = sizeof(*amta) + sizeof(struct udphdr);
+ /* Both forms start with the same header and nonce. */
+ hdr_size = sizeof(struct udphdr) +
+ (amt_v6(amt) ? sizeof(struct amt_header_advertisement_v6) :
+ sizeof(*amta));
if (!pskb_may_pull(skb, hdr_size))
return true;
amta = (struct amt_header_advertisement *)(udp_hdr(skb) + 1);
- if (!amta->ip4)
- return true;
-
if (amta->reserved || amta->version)
return true;
- if (ipv4_is_loopback(amta->ip4) || ipv4_is_multicast(amta->ip4) ||
- ipv4_is_zeronet(amta->ip4))
- return true;
-
if (amt->status != AMT_STATUS_SENT_DISCOVERY ||
amt->nonce != amta->nonce)
return true;
- WRITE_ONCE(amt->remote_ip, amta->ip4);
- netdev_dbg(amt->dev, "advertised remote ip = %pI4\n", &amta->ip4);
+ if (amt_v6(amt)) {
+ const struct in6_addr *ip6;
+
+ ip6 = &((struct amt_header_advertisement_v6 *)amta)->ip6;
+ if (amt_ip6_unusable(ip6))
+ return true;
+
+ amt_set_remote_ipv6(amt, ip6);
+ netdev_dbg(amt->dev, "advertised remote ipv6 = %pI6c\n", ip6);
+ } else {
+ if (!amta->ip4 || ipv4_is_loopback(amta->ip4) ||
+ ipv4_is_multicast(amta->ip4) || ipv4_is_zeronet(amta->ip4))
+ return true;
+
+ WRITE_ONCE(amt->remote_ip, amta->ip4);
+ netdev_dbg(amt->dev, "advertised remote ip = %pI4\n",
+ &amta->ip4);
+ }
mod_delayed_work(amt_wq, &amt->req_wq, 0);
amt_update_gw_status(amt, AMT_STATUS_RECEIVED_ADVERTISEMENT, true);
@@ -3075,11 +3112,32 @@ drop:
}
}
+/* Whether a message a gateway received came from its relay: the discovery
+ * address for an Advertisement, the learned relay address otherwise. A
+ * relay address that is not known matches nothing, not even a 0.0.0.0
+ * source, which IPv4 input delivers in a packet sent to 255.255.255.255.
+ */
+static bool amt_from_relay(const struct amt_dev *amt,
+ const union amt_addr *saddr, bool discovery)
+{
+ __be32 relay4;
+
+ if (amt_v6(amt)) {
+ struct in6_addr relay;
+
+ relay = discovery ? amt->discovery_ipv6 :
+ amt_get_remote_ipv6(amt);
+ return !ipv6_addr_any(&relay) &&
+ ipv6_addr_equal(&saddr->ip6, &relay);
+ }
+ relay4 = discovery ? amt->discovery_ip : READ_ONCE(amt->remote_ip);
+ return relay4 && saddr->ip4 == relay4;
+}
+
static int amt_rcv(struct sock *sk, struct sk_buff *skb)
{
+ union amt_addr saddr;
struct amt_dev *amt;
- __be32 remote_ip;
- __be32 saddr;
int type;
bool err;
@@ -3090,10 +3148,14 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
kfree_skb(skb);
goto out;
}
- remote_ip = READ_ONCE(amt->remote_ip);
skb->dev = amt->dev;
- saddr = ip_hdr(skb)->saddr;
+ amt_outer_saddr(amt, skb, &saddr);
+ /* No relay or gateway sends from ::, but IPv6 input delivers it. */
+ if (amt_v6(amt) && ipv6_addr_any(&saddr.ip6)) {
+ err = true;
+ goto drop;
+ }
type = amt_parse_type(skb);
if (type == -1) {
err = true;
@@ -3101,9 +3163,17 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
}
if (amt->mode == AMT_MODE_GATEWAY) {
+ /* RFC 6936 s5: accept the zero checksum only on the message
+ * that needs it.
+ */
+ if (amt_v6(amt) && !udp_hdr(skb)->check &&
+ type != AMT_MSG_MULTICAST_DATA) {
+ err = true;
+ goto drop;
+ }
switch (type) {
case AMT_MSG_ADVERTISEMENT:
- if (saddr != amt->discovery_ip) {
+ if (!amt_from_relay(amt, &saddr, true)) {
netdev_dbg(amt->dev, "Invalid Relay IP\n");
err = true;
goto drop;
@@ -3115,7 +3185,7 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
}
goto out;
case AMT_MSG_MULTICAST_DATA:
- if (saddr != remote_ip) {
+ if (!amt_from_relay(amt, &saddr, false)) {
netdev_dbg(amt->dev, "Invalid Relay IP\n");
err = true;
goto drop;
@@ -3126,7 +3196,7 @@ static int amt_rcv(struct sock *sk, struct sk_buff *skb)
else
goto out;
case AMT_MSG_MEMBERSHIP_QUERY:
- if (saddr != remote_ip) {
+ if (!amt_from_relay(amt, &saddr, false)) {
netdev_dbg(amt->dev, "Invalid Relay IP\n");
err = true;
goto drop;
@@ -3264,12 +3334,14 @@ static struct sock *amt_create_sock(const struct amt_dev *amt)
* that IPv6 route lookups are strict about the output
* interface, as IPv4 ones are, and a link-local peer is
* unique. V6ONLY leaves the IPv4 wildcard port to an IPv4
- * amt device.
+ * amt device. A gateway accepts a zero UDP checksum, which
+ * RFC 7450 s5.2.3.3 requires for Multicast Data; amt_rcv()
+ * drops it on the other messages.
*/
udp_conf.family = AF_INET6;
udp_conf.bind_ifindex = amt->stream_dev->ifindex;
udp_conf.use_udp6_tx_checksums = true;
- udp_conf.use_udp6_rx_checksums = true;
+ udp_conf.use_udp6_rx_checksums = amt->mode == AMT_MODE_RELAY;
udp_conf.ipv6_v6only = true;
} else {
udp_conf.family = AF_INET;
@@ -3328,7 +3400,7 @@ static int amt_dev_open(struct net_device *dev)
}
amt->req_cnt = 0;
- WRITE_ONCE(amt->remote_ip, 0);
+ amt_clear_remote(amt);
amt->nonce = 0;
get_random_bytes(&amt->key, sizeof(siphash_key_t));
@@ -3373,7 +3445,7 @@ static int amt_dev_stop(struct net_device *dev)
amt->ready4 = false;
amt->ready6 = false;
amt->req_cnt = 0;
- WRITE_ONCE(amt->remote_ip, 0);
+ amt_clear_remote(amt);
list_for_each_entry_safe(tunnel, tmp, &amt->tunnel_list, list) {
list_del_rcu(&tunnel->list);
--
2.43.0
next prev parent reply other threads:[~2026-10-09 12:24 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 12:24 [PATCH net-next 00/13] amt: add an IPv6 outer transport Omar Ramadan
2026-10-09 12:24 ` [PATCH net-next 01/13] amt: create an AF_INET6 encapsulation socket for an IPv6 outer address Omar Ramadan
2026-10-09 12:24 ` [PATCH net-next 02/13] amt: send the Relay Advertisement over IPv6 Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 03/13] amt: key relay tunnels on a union amt_addr endpoint Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 04/13] amt: send the Membership Query over IPv6 Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 05/13] amt: match the Membership Update tunnel by outer family Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 06/13] amt: forward multicast data over IPv6 Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 07/13] amt: size the encapsulation headroom by the outer IP version Omar Ramadan
2026-10-09 12:24 ` [PATCH net-next 08/13] amt: send the AMT gateway control plane over IPv6 Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` Omar Ramadan [this message]
2026-10-10 12:41 ` [PATCH net-next 09/13] amt: receive " netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 10/13] amt: add netlink attributes for an IPv6 outer transport Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 11/13] MAINTAINERS: amt: cover the amt headers and selftests Omar Ramadan
2026-10-09 12:24 ` [PATCH net-next 12/13] selftests: net: add amt_v6.sh for an IPv6 outer transport Omar Ramadan
2026-10-10 12:41 ` netdev-bot+sashiko
2026-10-09 12:24 ` [PATCH net-next 13/13] selftests: net: add amt_gw_v6.sh for the IPv6 netlink attributes Omar Ramadan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009122426.551178-10-omar@blockcast.net \
--to=omar@blockcast.net \
--cc=andrew+netdev@lunn.ch \
--cc=ap420073@gmail.com \
--cc=davem@davemloft.net \
--cc=edumazet@kernel.org \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=shuah@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox