Netdev List
 help / color / mirror / Atom feed
From: Fernando Fernandez Mancera <fmancera@suse.de>
To: Stanislav Fomichev <sdf.kernel@gmail.com>
Cc: netdev@vger.kernel.org, horms@kernel.org, kuba@kernel.org,
	pabeni@redhat.com, edumazet@google.com, davem@davemloft.net,
	David Ahern <dsahern@kernel.org>,
	Ido Schimmel <idosch@nvidia.com>,
	Willem de Bruijn <willemb@google.com>,
	Kees Cook <kees@kernel.org>,
	Kuniyuki Iwashima <kuniyu@google.com>,
	Richard Gobert <richardbgobert@gmail.com>,
	Marc Kleine-Budde <mkl@pengutronix.de>,
	Jeff Layton <jlayton@kernel.org>, Qi Tang <tpluszz77@gmail.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH 03/13 net-next] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic
Date: Fri, 11 Sep 2026 20:41:10 +0200	[thread overview]
Message-ID: <fcb24a94-d62d-4166-b51b-4585a021500b@suse.de> (raw)
In-Reply-To: <aqMeeDnj4pcuvz7-@devvm7509.cco0.facebook.com>



On 9/10/26 11:19 PM, Stanislav Fomichev wrote:
> On 09/10, Fernando Fernandez Mancera wrote:
>> To enable compiling the INET subsystem without IPv4, shared generic
>> utilities must be relocated and IPv4 socket logic must be guarded for
>> CONFIG_IPV4.
>>
>> This patch moves the generic ip_generec_getfrag() from ip_output.c to
>> af_inet.c. It also introduces CONFIG_IPV4 guards around af_inet.c to
>> reject IPv4-specific ioctls, protocol registrations and bind requests.
>> The same guard is added to reject IPv4-mapped IPv6.
>>
>> Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
>> ---
>>   net/ipv4/af_inet.c   | 96 +++++++++++++++++++++++++++++++++++++-------
>>   net/ipv4/ip_output.c | 18 ---------
>>   net/ipv6/af_inet6.c  |  5 +++
>>   net/ipv6/datagram.c  | 12 ++++++
>>   4 files changed, 99 insertions(+), 32 deletions(-)
>>
>> diff --git a/net/ipv4/af_inet.c b/net/ipv4/af_inet.c
>> index d9421ac38d78..b0c48ba544bf 100644
>> --- a/net/ipv4/af_inet.c
>> +++ b/net/ipv4/af_inet.c
>> @@ -129,6 +129,28 @@
>>   int disable_ipv6_mod;
>>   EXPORT_SYMBOL(disable_ipv6_mod);
>>   
>> +/* Keep the function here for now as it is generic, it should be moved
>> + * to a common L3 place
>> + */
>> +int
>> +ip_generic_getfrag(void *from, char *to, int offset, int len, int odd, struct sk_buff *skb)
>> +{
>> +	struct msghdr *msg = from;
>> +
>> +	if (skb->ip_summed == CHECKSUM_PARTIAL) {
>> +		if (!copy_from_iter_full(to, len, &msg->msg_iter))
>> +			return -EFAULT;
>> +	} else {
>> +		__wsum csum = 0;
>> +
>> +		if (!csum_and_copy_from_iter_full(to, len, &csum, &msg->msg_iter))
>> +			return -EFAULT;
>> +		skb->csum = csum_block_add(skb->csum, csum, odd);
>> +	}
>> +	return 0;
>> +}
>> +EXPORT_SYMBOL(ip_generic_getfrag);
>> +
>>   /* The inetsw table contains everything that inet_create needs to
>>    * build a new socket.
>>    */
>> @@ -425,8 +447,10 @@ int inet_release(struct socket *sock)
>>   		if (!sk->sk_kern_sock)
>>   			BPF_CGROUP_RUN_PROG_INET_SOCK_RELEASE(sk);
>>   
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   		/* Applications forget to leave groups before exiting */
>>   		ip_mc_drop_socket(sk);
>> +#endif
>>   
>>   		/* If linger is set, we don't return until the close
>>   		 * is complete.  Otherwise we return immediately. The
>> @@ -478,6 +502,7 @@ EXPORT_SYMBOL(inet_bind);
>>   int __inet_bind(struct sock *sk, struct sockaddr_unsized *uaddr, int addr_len,
>>   		u32 flags)
>>   {
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   	struct sockaddr_in *addr = (struct sockaddr_in *)uaddr;
>>   	struct inet_sock *inet = inet_sk(sk);
>>   	struct net *net = sock_net(sk);
>> @@ -570,6 +595,9 @@ int __inet_bind(struct sock *sk, struct sockaddr_unsized *uaddr, int addr_len,
>>   		release_sock(sk);
>>   out:
>>   	return err;
>> +#else
>> +	return -EAFNOSUPPORT;
>> +#endif
>>   }
>>   
>>   int inet_dgram_connect(struct socket *sock, struct sockaddr_unsized *uaddr,
>> @@ -962,18 +990,24 @@ EXPORT_SYMBOL(inet_shutdown);
>>   int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
>>   {
>>   	struct sock *sk = sock->sk;
>> -	int err = 0;
>> -	struct net *net = sock_net(sk);
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   	void __user *p = (void __user *)arg;
>> -	struct ifreq ifr;
>> +	struct net *net = sock_net(sk);
>>   	struct rtentry rt;
>> +	struct ifreq ifr;
>> +#endif
>> +	int err = 0;
>>   
>>   	switch (cmd) {
>>   	case SIOCADDRT:
>>   	case SIOCDELRT:
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   		if (copy_from_user(&rt, p, sizeof(struct rtentry)))
>>   			return -EFAULT;
>>   		err = ip_rt_ioctl(net, cmd, &rt);
>> +#else
>> +		err = -EOPNOTSUPP;
>> +#endif
>>   		break;
>>   	case SIOCRTMSG:
>>   		err = -EINVAL;
>> @@ -981,18 +1015,26 @@ int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
>>   	case SIOCDARP:
>>   	case SIOCGARP:
>>   	case SIOCSARP:
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   		err = arp_ioctl(net, cmd, (void __user *)arg);
>> +#else
>> +		err = -EOPNOTSUPP;
>> +#endif
>>   		break;
>>   	case SIOCGIFADDR:
>>   	case SIOCGIFBRDADDR:
>>   	case SIOCGIFNETMASK:
>>   	case SIOCGIFDSTADDR:
>>   	case SIOCGIFPFLAGS:
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   		if (get_user_ifreq(&ifr, NULL, p))
>>   			return -EFAULT;
>>   		err = devinet_ioctl(net, cmd, &ifr);
>>   		if (!err && put_user_ifreq(&ifr, p))
>>   			err = -EFAULT;
>> +#else
>> +		err = -EOPNOTSUPP;
>> +#endif
>>   		break;
>>   
>>   	case SIOCSIFADDR:
>> @@ -1001,9 +1043,13 @@ int inet_ioctl(struct socket *sock, unsigned int cmd, unsigned long arg)
>>   	case SIOCSIFDSTADDR:
>>   	case SIOCSIFPFLAGS:
>>   	case SIOCSIFFLAGS:
>> +#if IS_ENABLED(CONFIG_IPV4)
>>   		if (get_user_ifreq(&ifr, NULL, p))
>>   			return -EFAULT;
>>   		err = devinet_ioctl(net, cmd, &ifr);
>> +#else
>> +		err = -EOPNOTSUPP;
>> +#endif
> 
> (passing by comment)
> 
> Don't we have a coding style rule to avoid ifdef conditional in C code?
> Should we add some new devinet4_ioctl/etc wrappers that we can conditionally
> compile out in the headers?

I think yes but when it makes sense. Of course, that is something a bit 
hard to judge IMHO. I tried to use it when it makes sense, like for 
stubs or for functions that are protocol agnostic but contains a small 
part related to IPv4/IPV6. I was willing to avoid code duplication as 
much as possible.


  reply	other threads:[~2026-09-11 18:41 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-10 14:48 [PATCH 00/13 net-next] Allow compiling an IPv6-only kernel network stack Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 01/13 net-next] net: ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-09-10 15:11   ` Nicolai Buchwitz
2026-09-10 15:32     ` Fernando Fernandez Mancera
2026-09-10 15:36     ` Arnd Bergmann
2026-09-10 16:22   ` Fernando Fernandez Mancera
2026-09-10 16:30     ` Fernando Fernandez Mancera
2026-09-10 16:56   ` Sven Eckelmann
2026-09-11 18:39     ` Fernando Fernandez Mancera
2026-09-10 18:55   ` Chuck Lever
2026-09-11 17:46   ` Casey Schaufler
2026-09-11 18:31     ` Fernando Fernandez Mancera
2026-09-11 18:59       ` Casey Schaufler
2026-09-10 14:48 ` [PATCH 02/13 net-next] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 03/13 net-next] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-09-10 21:19   ` Stanislav Fomichev
2026-09-11 18:41     ` Fernando Fernandez Mancera [this message]
2026-09-10 14:48 ` [PATCH 04/13 net-next] net: tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 05/13 net-next] net: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 06/13 net-next] net: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 07/13 net-next] net: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 08/13 net-next] net: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 09/13 net-next] net: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 10/13 net-next] net: tunnel: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 11/13 net-next] netfilter: ipv4: guard ip_route_me_harder() " Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 12/13 net-next] net: ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-10 14:48 ` [PATCH 13/13 net-next] net: ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=fcb24a94-d62d-4166-b51b-4585a021500b@suse.de \
    --to=fmancera@suse.de \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=jlayton@kernel.org \
    --cc=kees@kernel.org \
    --cc=kuba@kernel.org \
    --cc=kuniyu@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mkl@pengutronix.de \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=richardbgobert@gmail.com \
    --cc=sdf.kernel@gmail.com \
    --cc=tpluszz77@gmail.com \
    --cc=willemb@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox