lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-Id: <b9182b02829b158d55acc53a0bcec1ed667b2668.1680000784.git.stefan@agner.ch> Date: Tue, 28 Mar 2023 17:38:50 +0200 From: Stefan Agner <stefan@...er.ch> To: davem@...emloft.net, dsahern@...nel.org Cc: edumazet@...gle.com, kuba@...nel.org, pabeni@...hat.com, netdev@...r.kernel.org, stefan@...er.ch, john.carr@...outed.co.uk, linux-kernel@...r.kernel.org Subject: [RFC PATCH] ipv6: add option to explicitly enable reachability test Systems which act as host as well as router might prefer the host behavior. Currently the kernel does not allow to use IPv6 forwarding globally and at the same time use route reachability probing. Add a compile time flag to enable route reachability probe in any case. Signed-off-by: Stefan Agner <stefan@...er.ch> --- My use case is a OpenThread device which at the same time can also act as a client communicating with Thread devices. Thread Border routers use the Route Information mechanism to publish routes with a lifetime of up to 1800s. If one of the Thread Border router goes offline, the lack of reachability probing currenlty leads to outages of up to 30 minutes. Not sure if the chosen method is acceptable. Maybe a runtime flag is preferred? -- Stefan net/ipv6/Kconfig | 9 +++++++++ net/ipv6/route.c | 3 ++- 2 files changed, 11 insertions(+), 1 deletion(-) diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig index 658bfed1df8b..5147fd4c93ff 100644 --- a/net/ipv6/Kconfig +++ b/net/ipv6/Kconfig @@ -48,6 +48,15 @@ config IPV6_OPTIMISTIC_DAD If unsure, say N. +config IPV6_REACHABILITY_PROBE + bool "IPv6: Always use reachability probing (RFC 4191)" + help + By default reachability probing is disabled on router devices (when + IPv6 forwarding is enabled). This option explicitly enables + reachability probing always. + + If unsure, say N. + config INET6_AH tristate "IPv6: AH transformation" select XFRM_AH diff --git a/net/ipv6/route.c b/net/ipv6/route.c index 0fdb03df2287..5e1e1f02f400 100644 --- a/net/ipv6/route.c +++ b/net/ipv6/route.c @@ -2210,7 +2210,8 @@ struct rt6_info *ip6_pol_route(struct net *net, struct fib6_table *table, strict |= flags & RT6_LOOKUP_F_IFACE; strict |= flags & RT6_LOOKUP_F_IGNORE_LINKSTATE; - if (net->ipv6.devconf_all->forwarding == 0) + if (net->ipv6.devconf_all->forwarding == 0 || + IS_ENABLED(IPV6_REACHABILITY_PROBE)) strict |= RT6_LOOKUP_F_REACHABLE; rcu_read_lock(); -- 2.40.0
Powered by blists - more mailing lists