Skip to content

fix(arp): preserve authorized source during neighbor discovery - #40

Merged
fslongjin merged 1 commit into
DragonOS-Community:dragonos/v0.12.0from
fslongjin:codex/fix-routed-arp-source
Oct 1, 2026
Merged

fslongjin merged 1 commit into
DragonOS-Community:dragonos/v0.12.0from
fslongjin:codex/fix-routed-arp-source

Conversation

@fslongjin

Copy link
Copy Markdown
Member

Summary

Fix ARP sender selection for already-routed IPv4 packets. Linux arp_announce=0 preserves an authorized namespace-local packet source; selecting the first interface address lost secondary-address and cross-interface source decisions.

  • Add a compatible dispatch entry with an explicit caller-authorized ARP source hint. The hint must match the actual IPv4 header source; explicit None always requests fallback.
  • Keep the original entry point available, authorizing only interface-owned addresses there. AnyIP acceptance is not address ownership.
  • Select an address in the next-hop prefix before the first-address fallback for forwarded remote sources.
  • Preserve ARP cache/rate limiting and IPv6 neighbor discovery.

The DragonOS integration classifies source addresses with namespace FIB RTN_LOCAL before taking the smoltcp lock. This addresses the existing GatewaySelectsSourceFromItsInterfacePrefix failure seen both on DragonOS master and PR #2382.

Validation

  • All 767 library tests pass, including eight new byte-level source-selection and rate-limit regressions.
  • IPv4-only and IPv6-only feature checks pass.
  • Formatting and diff whitespace checks pass.
  • Independent security/concurrency and system reviews found no unresolved actionable defects after validating explicit authorization and fallback behavior.

Add a compatible routed dispatch entry accepting a caller-authorized IPv4 source. Match the hint against the actual packet source, honor explicit fallback requests, and never treat AnyIP admission as ownership. Existing callers authorize only interface-owned sources.

Select a next-hop-prefix address before the first-address fallback for forwarded traffic. Preserve neighbor-cache rate limiting and IPv6 discovery. Add byte-level regressions for secondary/cross-interface sources, rejected hints, fallback, and rate limiting; all 767 library tests and IPv4-only/IPv6-only checks pass.

Signed-off-by: longjin <longjin@dragonos.org>
@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

@fslongjin
fslongjin merged commit 816f12d into DragonOS-Community:dragonos/v0.12.0 Oct 1, 2026
13 checks passed
fslongjin added a commit to fslongjin/DragonOS-fork that referenced this pull request Oct 1, 2026
Update smoltcp to the dragonos/v0.12.0 merge revision of DragonOS-Community/smoltcp#40. Keep the manifest and lockfile pinned to the same upstream commit.

The merged commit has an identical source tree to the previously validated PR revision. Validation: make kernel and git diff --check passed.

Signed-off-by: longjin <longjin@dragonos.org>
fslongjin added a commit to DragonOS-Community/DragonOS that referenced this pull request Oct 1, 2026
* fix(vfs): preserve sendfile offsets and transfer progress

Copy explicit offsets through protected UserBuffer access and always copy them back after the transfer, matching Linux copyout fault precedence. Validate descriptors, modes and signed ranges before bounded transfer counts.

Track local input/output cursors and commit only accepted bytes to avoid shared-description double advancement and premature termination on fully written short reads. Reuse the splice pipe writer transaction for socket inputs, pipe append flags, and readiness-before-EOF checks while preserving splice capability validation and fsnotify order.

Add 13 dunitest regressions. Linux and DragonOS pass all 13; existing splice tests pass 7/7 and inotify transfer tests 4/4. Verify default Docker published-port HTTP responses with 24 exact raw TCP responses and EOF checks. Format and build the kernel successfully.

Signed-off-by: longjin <longjin@dragonos.org>

* fix(net): preserve ARP sources and raw ingress ownership

Address the route-source failure shared by master and PR CI. Authorize IPv4 ARP announcements using namespace FIB RTN_LOCAL before taking the smoltcp lock, and pin the dependency that preserves the authorized packet source with next-hop-prefix fallback for forwarded traffic.

Keep DragonOS in control of raw receive dispatch even with an empty listener snapshot. This closes the publication window that could fall back to smoltcp's unfiltered RX queue and leak blocked ICMPv6 types. Preserve enqueue-time filtering and avoid adding generation/retry machinery.

Add three raw-filter regressions for mask edges, socket publication stress and queued-packet semantics. Validate route lifecycle 20/20, raw filters 3/3, sendfile 13/13, gVisor ICMP 17/17 and 200 repeated filter cases, existing network/transfer regressions, and 24 exact Docker HTTP responses. Format, build the pinned revision and complete three independent adversarial reviews.

Signed-off-by: longjin <longjin@dragonos.org>

* chore(deps): pin merged smoltcp ARP source fix

Update smoltcp to the dragonos/v0.12.0 merge revision of DragonOS-Community/smoltcp#40. Keep the manifest and lockfile pinned to the same upstream commit.

The merged commit has an identical source tree to the previously validated PR revision. Validation: make kernel and git diff --check passed.

Signed-off-by: longjin <longjin@dragonos.org>

---------

Signed-off-by: longjin <longjin@dragonos.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant