Re: [PATCH net] ip6_gre: let collect_md ip6gretap send from the unspecified address

From: Ido Schimmel

Date: Thu Oct 08 2026 - 10:14:55 EST


On Mon, Oct 05, 2026 at 10:12:27PM +0300, Anton Danilov wrote:
> ip6gre_xmit_ipv6() drops an IPv6 packet whose source address equals the
> tunnel remote, to avoid a trivial tunneling loop. On a collect_md
> ip6gretap device t->parms.raddr is not the exit point: the outer
> destination comes from the per-packet tunnel metadata. Such devices are
> normally created without a remote, so raddr is ::, and the check never
> matches a real tunnel endpoint. It matches every frame sent from the
> unspecified address instead.
>
> On an L2 tunnel those frames are regular link traffic. Duplicate Address
> Detection sends its Neighbor Solicitations from :: (RFC 4862, section
> 5.4.2), and MLD reports are sent from :: while an interface has no
> link-local address yet (RFC 3590, section 4). Frames bridged into a
> collect_md ip6gretap device, e.g. with tc tunnel_key and mirred, are
> dropped even though they carry valid metadata, so DAD cannot detect a
> duplicate address on the other side of the tunnel.
>
> Skip the check for collect_md devices of type ARPHRD_ETHER. It stays for
> L3 ip6gre, where sending a packet with an unspecified source means
> forwarding it (RFC 4291, section 2.5.2), and for ip6gretap without
> collect_md. ip6erspan does not run this check in collect_md mode either.
>
> Fixes: 6712abc168eb ("ip6_gre: add ip6 gre and gretap collect_md mode")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Signed-off-by: Anton Danilov <littlesmilingcloud@xxxxxxxxx>

AFAICT, this isn't a regression, so for net-next:

Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>

Jakub might agree to strip the tags before applying, so don't send v2
just yet. And if v2 is required, I would also drop the comment as it
simply repeats the commit message.