Re: [PATCH] ipv6: addrconf: drop "BUG: " prefix from pr_warn()
From: Ido Schimmel
Date: Mon Sep 28 2026 - 12:42:43 EST
On Sun, Sep 27, 2026 at 01:51:34PM -0400, AnishMulay wrote:
> On Wed, Sep 09, 2026 at 02:56:55PM +0300, Ido Schimmel wrote:
> > Does your reproducer rely on both keep_addr_on_down being set on the
> > loopback device and its MTU going below 1280?
> >
> > The loopback device retains global addresses when this happens, unlike
> > any other device [...]
> >
> > So, given that this state is quite broken and unlikely to be used by
> > anyone other than fuzzers, I would like to simply align the loopback
> > behavior with other devices and avoid keeping its addresses when the MTU
> > goes below the minimum:
> >
> > [...]
> > - if (!unregister && !idev->cnf.disable_ipv6) {
> > + if (!unregister && !idev->cnf.disable_ipv6 &&
> > + dev->mtu >= IPV6_MIN_MTU) {
> >
> > Regenerating the route in this case is more complexity for a case that
> > nobody is hitting other than fuzzers.
>
> No, mine does not touch MTU at all. dev->mtu stays above 1280 the whole
> time. My trigger is a second addrconf_ifdown() racing the pending
> addrconf_dad_work from an earlier up, both inside a single "ip link set
> lo up" call (that fires both NETDEV_UP and NETDEV_CHANGE through
> addrconf_notify()). The route gets deleted, the notifier gets skipped,
> and the async work later runs with ifp->rt NULL.
Please share your reproducer. Earlier in the thread you said you're
working on [1]. I asked Claude to translate the syz reproducer to bash
and it came up with [2]. It does set an MTU below the minimum on the
loopback device. I verified that the issue is reproduced without my
patch and doesn't reproduce with my patch.
syzbot was not able to test my patch because of some issue on its end.
[1] https://syzkaller.appspot.com/bug?extid=57f410c9a4f8d7a441d6
[2]
#!/bin/bash
# syzbot 57f410c9a4f8d7a441d6 as iproute2. Run in a fresh netns so the
# group-wide MTU change only reaches lo.
ip netns add syz
ns="ip netns exec syz"
$ns ip link set dev lo up
# 1st sendmsg: RTM_NEWLINK, no ifindex, IFLA_GROUP=0, IFLA_MTU=68
# Walks group 0 in registration order; lo is first, so it is already
# at 68 when a later fallback tunnel (sit0, min_mtu 1280) makes the
# whole request return -EINVAL. syzkaller ignores that, so do we.
# -> rtnl_group_changelink() -> do_setlink() on every group-0 device
$ns ip link set group 0 mtu 68 2>/dev/null
$ns ip -d link show dev lo | grep -ow "mtu [0-9]*"
# write(.../conf/all/keep_addr_on_down, "1")
$ns sysctl -wq net.ipv6.conf.all.keep_addr_on_down=1
# "repeat":true — the whole program loops; the warning is a race between
# the DAD work queued by fixup_permanent_addr() and the tail
# addrconf_ifdown() in the same NETDEV_UP, so it needs a few iterations.
for i in $(seq 1 20); do
# 2nd sendmsg: RTM_NEWADDR 2001::fb/64 dev lo, no NLM_F_EXCL
$ns ip -6 address replace 2001::fb/64 dev lo
# SIOCSIFFLAGS lo 0x1, then SIOCSIFFLAGS lo 0x0
$ns ip link set dev lo up
$ns ip link set dev lo down
done
echo "warnings: $(dmesg | grep -c 'missing its host route')"
$ns ip -6 address show dev lo
$ns ip -6 route show table local
ip netns del syz