Skip to content

fix(net): enforce namespace ARP reply ownership - #2381

Merged
fslongjin merged 2 commits into
DragonOS-Community:masterfrom
fslongjin:codex/fix-docker-arp-ownership
Oct 1, 2026
Merged

fslongjin merged 2 commits into
DragonOS-Community:masterfrom
fslongjin:codex/fix-docker-arp-ownership

Conversation

@fslongjin

@fslongjin fslongjin commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Authorize Ethernet ARP replies against the ingress network namespace's existing FIB, independently of AnyIP IP admission.
  • Preserve default weak-host replies across local interfaces, reject foreign targets and martian sources, and support zero-source DAD without learning the zero address.
  • Prepare an ARP route read view in both direct and NAPI polling without changing the selected IP output backend or local-input polling mode.
  • Pin the dependency hook from fix(arp): separate reply authorization from AnyIP admission smoltcp#39 at a2c9cc0da88f41baab5ecc603c33af68384d4cea and add eight packet-level dunitest regressions.

Root cause

AnyIP veth interfaces answered ARP requests for the bridge gateway with a container MAC. Packet capture showed competing gateway replies and subsequent published-port response packets forwarded to the wrong container. The bridge forwarded the incorrect destination MAC correctly; resetting caches or disabling AnyIP would not fix address ownership.

The optional dependency hook separates response permission from neighbor learning. DragonOS reuses its pre-acquired namespace route view, with no new per-packet lock, device scan, or ownership cache.

Validation

  • Before the fix: a published-port HTTP request timed out after eight seconds with zero bytes; six of seven original ARP regression cases failed on the baseline guest.
  • Linux reference: all eight final ARP tests passed.
  • DragonOS, built against the fixed git revision: ARP 8/8, Netfilter 107/107, bridge/veth 9/9, forwarding MTU 3/3, and conntrack netlink 9/9 passed.
  • Two independent snapshot cold boots with default Docker bridge/nft/OverlayFS and a second restored container: published-port HTTP first requests succeeded in 94 ms and 5.4 ms, followed by twelve successful requests each. Capture showed only the actual bridge gateway MAC answering gateway ARP.
  • Container removal/recreation and IP reuse: first HTTP response succeeded in 6 ms. Daemon normal shutdown completed.
  • make fmt, make kernel, diff checks, and three-role adversarial review passed. The reviewed martian-source boundary was fixed and covered by a Linux/guest test.
  • Dependency validation: 759 unit tests, seven doctests, noalloc IPv4 and alloc IPv6-only checks, and smoltcp PR CI passed.

Scope and remaining boundary

This fixes namespace ARP reply ownership, not every optional proxy-ARP/NUD policy. An independent pre-existing HTTP body repetition issue remains: raw TCP reads exceed Content-Length, while curl stops at the declared length. The suspected sendfile offset-update defect needs a separate syscall-level fix; HTTP 200 here validates timeout recovery, not full raw-stream correctness.

Dependency merge update

smoltcp #39 has merged into dragonos/v0.12.0. The pin now uses its merged commit. Its Git tree is identical to the previously validated dependency commit; no protocol behavior or other dependency version changes in this update.

Separate Ethernet ARP reply authorization from AnyIP admission. Container veth interfaces must not answer requests for the bridge gateway or other namespaces, while namespace-local weak-host replies remain valid across interfaces.

Use the prepared namespace FIB view in both direct and NAPI ingress; retain the existing routed-poll and output-backend decisions. Reject loopback and nonzero 0/8 senders, preserve authorized zero-source DAD, and leave neighbor-learning policy to the protocol stack.

Pin smoltcp PR DragonOS-Community#39 at a55fa7ea7a2734c7337731a9fcc11689a2a1a79b. Add eight packet-level dunitest cases for foreign targets, weak-host replies, DAD, invalid addresses, removal, gratuitous requests, and namespace moves.

Validation: make fmt and make kernel; Linux and guest ARP 8/8; guest Netfilter 107/107, bridge/veth 9/9, MTU 3/3, conntrack 9/9; two Docker cold boots, repeated published-port requests and container/IP recreation; three-role adversarial review. Raw HTTP repetition remains an independent pre-existing sendfile investigation.
Signed-off-by: longjin <longjin@dragonos.org>
@github-actions github-actions Bot added Bug fix A bug is fixed in this pull request test Unitest/User space test labels Sep 30, 2026
@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

Update smoltcp to the merged Community dragonos/v0.12.0 commit a2c9cc0da88f41baab5ecc603c33af68384d4cea from PR DragonOS-Community#39.

The merged commit has the same Git tree as the previously validated PR revision. Preserve all other locked dependencies and features. Validation: kernel build, formatting check, diff check, and independent revision-only review.

Signed-off-by: longjin <longjin@dragonos.org>
@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

@fslongjin
fslongjin merged commit c2cbd3f into DragonOS-Community:master Oct 1, 2026
15 of 16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Bug fix A bug is fixed in this pull request test Unitest/User space test

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant