Re: [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4
From: netdev-bot+sashiko
Date: Fri Oct 02 2026 - 06:40:41 EST
Thank you for your contribution! Sashiko AI review found more severe
issue(s) in other patches of this series. This mail is only an FYI, in case
you want to address the nit picks below when you respin.
Low priority / nit picks for your consideration:
- [Low] In ip_route_me_harder() (net/ipv4/netfilter.c), the new `if
(!IS_ENABLED(CONFIG_IPV4)) return -EPROTONOSUPPORT;` check (lines…
--
netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4
This commit adds an IS_ENABLED(CONFIG_IPV4) check to ip_route_me_harder()
in net/ipv4/netfilter.c. When IPv4 is disabled, the function returns
-EPROTONOSUPPORT and skips the IPv4 rerouting logic. The goal is to let
the network stack build without IPv4.
> diff --git a/net/ipv4/netfilter.c b/net/ipv4/netfilter.c
> index ce9e1bfa4259f..f2d9e0110b779 100644
> --- a/net/ipv4/netfilter.c
> +++ b/net/ipv4/netfilter.c
> @@ -30,6 +30,9 @@ int ip_route_me_harder(struct net *net, struct sock *sk, struct sk_buff *skb, un
> struct flow_keys flkeys;
> unsigned int hh_len;
>
> + if (!IS_ENABLED(CONFIG_IPV4))
> + return -EPROTONOSUPPORT;
> +
[Severity: Low]
This isn't a bug, but would it be clearer to do this check before the
declaration initializers in ip_route_me_harder()?
As placed, the initializers above the check still load from the dst and
from the IPv4 header when CONFIG_IPV4=n:
net/ipv4/netfilter.c:ip_route_me_harder() {
struct net_device *dev = skb_dst_dev(skb);
const struct iphdr *iph = ip_hdr(skb);
...
__be32 saddr = iph->saddr;
...
}
This doesn't look reachable in practice. With the rest of the series
applied, every in-tree caller sits behind a Kconfig option that depends
on IPV4. For example, the core netfilter menu in net/netfilter/Kconfig
now has:
depends on INET && IPV4 && NETFILTER
The callers also always pass an skb that has a dst set.
Moving the IS_ENABLED(CONFIG_IPV4) check above the initializers, or
deferring those assignments until after it, would make it clearer that
nothing IPv4-specific runs when IPv4 is disabled.
> sk = sk_to_full_sk(sk);
> flags = sk ? inet_sk_flowi_flags(sk) : 0;
>
--
Sashiko AI review · https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260928193046.6698-1-fmancera%40suse.de