Repository navigation
Conversation
Set the IPV6_TCLASS option on probe_fd. Otherwise ip-rule is unaware of the DSCP value at connect() time and can lookup the remote address in the wrong routing table. For example: ip route add table main unreachable 2001:db8::10/124 ip route add table 100 2001:db8::10/124 dev eth0 ip -6 rule add dsfield 0x04 table 100 ping -Q 0x04 2001:db8::11 Without this patch, probe_fd fails to connect to 2001:db8::11 (No route to host) since the route lookup is done in the main table instead of table 100. Note that, to work correctly, this patch also depends on a Linux kernel bug fix (see https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e010ae08c71fda8be3d6bda256837795a0b3ea41). That kernel patch has been backported to Linux stable trees and should have already reached most distributions. Fixes: 3337034 ("Initial import of iputils") Signed-off-by: Guillaume Nault <guillaume.nault@wanadoo.fr>
The IPV6_TCLASS socket option is already set in main(). There's no need to set it again in ping6_run(). This was dead code anyway as ->opt_tclass was never set. Let's remove this field since it's not used anywhere anymore. Signed-off-by: Guillaume Nault <guillaume.nault@wanadoo.fr>
|
Thank you. LGTM, I just need time to do some testing. |
Thanks @pevik. Do you have any feedback for these patches? |
|
@gault I'm sorry to keep you waiting so long. I'll try to have look this week. |
|
@gault I'm ok to require kernel fixes, because it was merged in 2023-02-22 to even v4.14.y. And yes, following code really works with your changes: Would you mind to share other setup required for ping to be successfully get reply? Ideally using network namespaces. It could be used in the testing suite I'm planning to write. |
| error(0, 0, _("traffic class is not supported")); | ||
| #endif | ||
| } | ||
|
|
There was a problem hiding this comment.
I think it's commit ebad35f ("ping: merge ping6 command into ping"). It removed the "options |= F_TCLASS;" statement that was in ping6_main(), but didn't remove the "if (options & F_TCLASS) {" test in ping6_run().
I didn't put any Fixes: tag because that was just dead code elimination. But if we want to point to a commit, I think that should be ebad35f.
|
To both commits: |
Here's a simple, self-contained, shell script that uses two network namespaces connected by a veth (Github doesn't seem to accept shell scripts, so I've renamed the file with a .txt extension). |
Set the IPV6_TCLASS option on probe_fd. Otherwise ip-rule is unaware of the DSCP value at connect() time and can lookup the remote address in the wrong routing table. For example: ip route add table main unreachable 2001:db8::10/124 ip route add table 100 2001:db8::10/124 dev eth0 ip -6 rule add dsfield 0x04 table 100 ping -Q 0x04 2001:db8::11 Without this patch, probe_fd fails to connect to 2001:db8::11 (No route to host) since the route lookup is done in the main table instead of table 100. Note that, to work correctly, this patch also depends on a Linux kernel bug fix (see https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=e010ae08c71fda8be3d6bda256837795a0b3ea41). That kernel patch has been backported to Linux stable trees and should have already reached most distributions. Fixes: 3337034 ("Initial import of iputils") Link: #468 Reviewed-by: Petr Vorel <pvorel@suse.cz> Signed-off-by: Guillaume Nault <guillaume.nault@wanadoo.fr>
|
Thanks pevik! |
Using ping6 -Q on a system using ip-rules can fail because the probe_fd
doesn't set IPV6_TCLASS. Therefore, probe_fd might make its route
lookup in a different table than the one that will be used to really
send the packet. This is fixed by patch 1.
Patch 2 then cleans up some dead code also related to IPV6_TCLASS.