From: Nikolay Aleksandrov <razor@blackwall.org>
To: Danielle Ratson <danieller@nvidia.com>, netdev@vger.kernel.org
Cc: dsahern@kernel.org, idosch@nvidia.com, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
horms@kernel.org, ja@ssi.bg, petrm@nvidia.com, fw@strlen.de,
kuniyu@google.com, bridge@lists.linux.dev,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH net-next 3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na()
Date: Mon, 20 Jul 2026 12:14:50 +0300 [thread overview]
Message-ID: <78f42aa0-70fe-475a-ab2b-eff062a629db@blackwall.org> (raw)
In-Reply-To: <63efa708b4b0bd9edb3a6f6a521cb5022c43aaa5.1784463131.git.danieller@nvidia.com>
On 19/07/2026 16:34, Danielle Ratson wrote:
> The bridge performs neighbor suppression by snooping NS/NA messages, but
> previously only checked the ICMPv6 type and code. This leaves it open to
> acting on malformed or spoofed packets that any RFC-compliant node should
> reject.
>
> Wire br_is_nd_neigh_msg() into the new ndisc_check_ns_na() helper, which
> enforces the full RFC 4861 section 7.1.1/7.1.2 receive validation:
> hop limit of 255, valid checksum, correct code, and type-specific rules
> (NS target not multicast; NA solicited flag clear for multicast
> destinations).
>
> MLD messages are already validated by ipv6_mc_check_mld() before the
> bridge acts on them; this brings NS/NA to the same standard.
>
> As a side effect, the skb parameter of br_is_nd_neigh_msg() changes from
> const to non-const, since ndisc_check_ns_na() may reallocate the skb head
> via pskb_may_pull() and sets the transport header. The returned pointer is
> now derived from skb_transport_header() rather than a direct cast.
>
> Reviewed-by: Petr Machata <petrm@nvidia.com>
> Signed-off-by: Danielle Ratson <danieller@nvidia.com>
> ---
> net/bridge/br_arp_nd_proxy.c | 11 ++++-------
> net/bridge/br_private.h | 2 +-
> 2 files changed, 5 insertions(+), 8 deletions(-)
>
Acked-by: Nikolay Aleksandrov <razor@blackwall.org>
next prev parent reply other threads:[~2026-07-20 9:14 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-19 13:34 [PATCH net-next 0/5] bridge: Validate and clean up IPv6 neighbour suppression Danielle Ratson
2026-07-19 13:34 ` [PATCH net-next 1/5] bridge: Use direct pointer in br_is_nd_neigh_msg() Danielle Ratson
2026-07-20 8:58 ` Nikolay Aleksandrov
2026-07-19 13:34 ` [PATCH net-next 2/5] ipv6: ndisc: Add ndisc_check_ns_na() validation helper Danielle Ratson
2026-07-20 9:13 ` Nikolay Aleksandrov
2026-07-19 13:34 ` [PATCH net-next 3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na() Danielle Ratson
2026-07-20 9:14 ` Nikolay Aleksandrov [this message]
2026-07-19 13:34 ` [PATCH net-next 4/5] bridge: Linearize skb once the ND message type is validated Danielle Ratson
2026-07-20 9:26 ` Nikolay Aleksandrov
2026-07-19 13:34 ` [PATCH net-next 5/5] bridge: Use ndisc_parse_options() to parse ND options in br_nd_send() Danielle Ratson
2026-07-20 9:27 ` Nikolay Aleksandrov
2026-07-20 9:31 ` [PATCH net-next 0/5] bridge: Validate and clean up IPv6 neighbour suppression Nikolay Aleksandrov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=78f42aa0-70fe-475a-ab2b-eff062a629db@blackwall.org \
--to=razor@blackwall.org \
--cc=bridge@lists.linux.dev \
--cc=danieller@nvidia.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=ja@ssi.bg \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=petrm@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox