Re: [PATCH] net: ipv6: fix dif and sdif mismatch in raw6_icmp_error

From: Joe Damato

Date: Mon Jul 20 2026 - 09:12:38 EST


On Fri, Jul 17, 2026 at 10:32:30PM +0800, lirongqing wrote:
> From: Li RongQing <lirongqing@xxxxxxxxx>
>
> In raw6_icmp_error(), raw_v6_match() is called with inet6_iif(skb) passed
> to both the 'dif' and 'sdif' arguments. This is a copy-paste or typo error,
> as the last argument should represent the secondary interface index (sdif).
>
> This mismatch breaks ICMPv6 error handling for IPv6 raw sockets in VRF
> (Virtual Routing and Forwarding) environments. When a raw socket is bound
> to a VRF master device, raw_v6_match() fails to find a match because it is
> not given the correct sdif value, causing the socket to miss relevant
> ICMPv6 error notifications.
>
> Fix this by properly passing inet6_sdif(skb) as the last argument to
> raw_v6_match().
>
> Fixes: 5108ab4bf446fa ("net: ipv6: add second dif to raw socket lookups")
> Signed-off-by: Li RongQing <lirongqing@xxxxxxxxx>
> ---
> net/ipv6/raw.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/net/ipv6/raw.c b/net/ipv6/raw.c
> index 3cc5869..b88d364 100644
> --- a/net/ipv6/raw.c
> +++ b/net/ipv6/raw.c
> @@ -349,7 +349,7 @@ void raw6_icmp_error(struct sk_buff *skb, int nexthdr,
> const struct ipv6hdr *ip6h = (const struct ipv6hdr *)skb->data;
>
> if (!raw_v6_match(net, sk, nexthdr, &ip6h->saddr, &ip6h->daddr,
> - inet6_iif(skb), inet6_iif(skb)))
> + inet6_iif(skb), inet6_sdif(skb)))

Looking at the commit under fixes, this does look like a copy/paste bug to me.

I wonder if a future contribution would be a test to exercise this path?

Reviewed-by: Joe Damato <joe@xxxxxxx>