fix(arp): separate reply authorization from AnyIP admission - #39
Merged
fslongjin merged 1 commit intoOct 1, 2026
Conversation
Add an optional sender/target ARP reply policy to IpIngressFilter so integrations can authorize namespace-local weak-host replies without granting implicit proxy ARP to every AnyIP interface. Keep the standalone None behavior and neighbor-learning gates unchanged. Permit explicitly authorized zero-source DAD requests without learning the zero address. Pass the hook through Ethernet ingress independently of the IP admission hook. Cover foreign targets, weak-host replies, DAD, source/target arguments, and unchanged neighbor learning. Validation: 759 unit tests, 7 doctests, noalloc IPv4 and alloc IPv6-only checks, formatting, and adversarial integration review. Signed-off-by: longjin <longjin@dragonos.org>
Member
Author
|
@codex review |
fslongjin
merged commit Oct 1, 2026
a2c9cc0
into
DragonOS-Community:dragonos/v0.12.0
13 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Motivation
An AnyIP container interface could answer requests for the bridge gateway using its own MAC. Competing gateway replies poisoned peer neighbor caches and misdirected published-port HTTP responses. The integration must decide namespace ownership; the protocol library still validates and constructs ARP packets.
Validation
No optional proxy-ARP/NUD subsystem is introduced by this change.