lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <1623974988948.39187@alliedtelesis.co.nz>
Date:   Fri, 18 Jun 2021 00:09:48 +0000
From:   Callum Sinclair <Callum.Sinclair@...iedtelesis.co.nz>
To:     Andrew Lunn <andrew@...n.ch>
CC:     "dsahern@...nel.org" <dsahern@...nel.org>,
        "nikolay@...dia.com" <nikolay@...dia.com>,
        "netdev@...r.kernel.org" <netdev@...r.kernel.org>,
        "linux-kernel@...r.kernel.org" <linux-kernel@...r.kernel.org>,
        "linus.luessing@...3.blue" <linus.luessing@...3.blue>
Subject: Re: [PATCH 1/1] net: Allow all multicast packets to be received on a
 interface.

Hi Andrew

> What is the big picture here? Are you trying to move the snooping
> algorithm into user space? User space will then add/remove Multicast
> FIB entries to the bridge to control where mulitcast frames are sent?

Yes I want to run a IGMP, MLD and PIM implementation in userspace and
just use the kernel to send multicast frames to addresses that have been
installed into the multicast forwarding cache.

> In the past i have written a multicast routing daemon. It is a similar
> problem. You need access to all the join/leaves. But the stack does
> provide them, if you bind to the multicast routing socket. Why not use
> that mechanism? Look in the mrouted sources for an example.

Ah I can see that I get the IGMP and MLD packets now. I was just creating
the socket as a IP socket without multicast routing. Thanks for your help.

Cheers
Callum
________________________________________
From: Andrew Lunn <andrew@...n.ch>
Sent: Friday, June 18, 2021 2:18 AM
To: Callum Sinclair
Cc: dsahern@...nel.org; nikolay@...dia.com; netdev@...r.kernel.org; linux-kernel@...r.kernel.org; linus.luessing@...3.blue
Subject: Re: [PATCH 1/1] net: Allow all multicast packets to be received on a interface.

On Thu, Jun 17, 2021 at 09:50:20PM +1200, Callum Sinclair wrote:
> To receive IGMP or MLD packets on a IP socket on any interface the
> multicast group needs to be explicitly joined. This works well for when
> the multicast group the user is interested in is known, but does not
> provide an easy way to snoop all packets in the http://scanmail.trustwave.com/?c=20988&d=wNnL4EU-bOXOuxnfu9BLng8ncWxDIw3ACrur9S2N4w&u=http%3a%2f%2f224%2e0%2e0%2e0%2f8 or the
> FF00::/8 range.
>
> Define a new sysctl to allow a given interface to become a IGMP or MLD
> snooper. When set the interface will allow any IGMP or MLD packet to be
> received on sockets bound to these devices.

Hi Callum

What is the big picture here? Are you trying to move the snooping
algorithm into user space? User space will then add/remove Multicast
FIB entries to the bridge to control where mulitcast frames are sent?

In the past i have written a multicast routing daemon. It is a similar
problem. You need access to all the join/leaves. But the stack does
provide them, if you bind to the multicast routing socket. Why not use
that mechanism? Look in the mrouted sources for an example.

     Andrew

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ