From nobody Mon Sep 07 08:38:08 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hdgSk2Y05z6rh79 for ; Mon, 07 Sep 2026 08:38:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hdgSk13Dvz43g3 for ; Mon, 07 Sep 2026 08:38:14 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788770294; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=s9S01Lxs/g7yAzQc96enxf0GSH1tXypUygdlQA7TOoQ=; b=eyzirj2LgmnpKHqYcZC1XIqUwTwwc4uVd/EbqD4KuBAN9wbEz3ntyRyxc4rgdQmG32BJaN FTUC+/eTAmyaeUroeFpu8obhoSq7C0wQldpz47NsUl1Pp3FEy2HchwrjH4zniR9IO3xr4i GIKCfCDzI8XRpXUrqAsjvHo1NEr4KydLYNYl16EUhmLGwgvCs/bbxmZ2z7TqzFIwBDo6RC wCGEpAPGQ/2XM6PpSaMlDKab9WhLoFwtxSQZ9AUlWYd6BZEorB9axwV0PZKdglVirV+Xp1 TtXwg3oBxJNE0SIyWFSo235zfb0WmrytwTDKvk+S3A6H51/wFtd5ZyIBEB5x8Q== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788770294; a=rsa-sha256; cv=none; b=TnQoLtEGG+Bnpj3Y5Zyf3lw8PWNbG2nRbG+FdFWDc8hrDxEWDGtL5H+z70Pi1oc5ZL1DCL XrexIF/omVvn8mRCECLgS4Xx6zQshNqZ9lRgUPmuYN14VV1AbBSknNkx9oK7p91XgBEq+c x4p/3mit87zTWOBNdhHxvgZiSVfOt9Wf3Jw47qX8T48x0gV8irIbHnD8mFRHWhljT8f1rq G2rDTsHGru0aK7Gb1SRo/AW4CA0w/nAQ6FkoOPGc6cqzABUOQUk+hFgJv+Zy4tYfj2zVVf UT6ltkBZk2ZoUPsqtaNlPOwHjLuFmcj5lIvjiwvJqr8src1rEz49jrrySDd8rg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788770294; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=s9S01Lxs/g7yAzQc96enxf0GSH1tXypUygdlQA7TOoQ=; b=hd1aYCe6l28PfObYldBvR9Gl7SAzh5gN/oz4XzIYKK5XbHEVx+vYsiT7yUmgiXqY+u34F0 LJQcAL6PVpC2qhfdsY6g8pZ+cjca+NSLJsqFW+Px9K1OKQKZcz5GqXA+HLI+Lb1zxxQXHU EpR7w6WDztwfZVgIFO9Y+7Wj901JugcC36abmvfzdYaMk44TRJFkRFbycxOrLeVrTQK+wA cyTDb6M82rP+rdNz+t3rGhS1cEwxiC+02w6Zasurm8Lx+oT05JP9DjxG4iW+CVtw7fZKRW NFjC5n7lgGV2XGmsrLNKUgyJ8FL0nhO4Bh8Z2KQQjQdW5ptgJVNpNfJkFMq1fw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hdgSj72f6z19Hl for ; Mon, 07 Sep 2026 08:38:13 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3cd63 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 07 Sep 2026 08:38:08 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: 0a35e0afef28 - main - pf: allow unspecified addressed for certain MLD messages List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 0a35e0afef2860a0a96e30e682f6782a323a82a4 Auto-Submitted: auto-generated Date: Mon, 07 Sep 2026 08:38:08 +0000 Message-Id: <6a9e77f0.3cd63.2a94b631@gitrepo.freebsd.org> The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=0a35e0afef2860a0a96e30e682f6782a323a82a4 commit 0a35e0afef2860a0a96e30e682f6782a323a82a4 Author: Kristof Provost AuthorDate: 2026-09-02 17:03:44 +0000 Commit: Kristof Provost CommitDate: 2026-09-07 08:37:46 +0000 pf: allow unspecified addressed for certain MLD messages As per RFC 3590 MLD Report and Done messages are permitted to use the unspecified address as a source address (e.g. during duplicate address detection for the first IPv6 address). Allow this, but only this. Reported by: Alexander Leidinger Reviewed by: bms See also: OpenBSD, sashan , 60036e8507 Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D59334 --- sys/netpfil/pf/pf.c | 10 +++++++- tests/sys/netpfil/pf/mld.py | 57 +++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 66 insertions(+), 1 deletion(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index 04e919639ddb..322b10c3fce6 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -11085,9 +11085,17 @@ pf_walk_header6(struct pf_pdesc *pd, struct ip6_hdr *h, u_short *reason) * local source address. If either one is * missing then MLD message is invalid and * should be discarded. + * RFC 3590 clarifies that during initial + * duplicate address detection nodes may not + * have an address, so are permitted to use + * the unspecified address, but only for Report + * and Done messages. */ if ((h->ip6_hlim != 1) || - !IN6_IS_ADDR_LINKLOCAL(&h->ip6_src)) { + (!IN6_IS_ADDR_LINKLOCAL(&h->ip6_src) && + icmp6.icmp6_type == MLD_LISTENER_QUERY) || + (!IN6_IS_ADDR_LINKLOCAL(&h->ip6_src) && + !IN6_IS_ADDR_UNSPECIFIED(&h->ip6_src))) { DPFPRINTF(PF_DEBUG_MISC, "Invalid MLD"); REASON_SET(reason, PFRES_IPOPTIONS); return (PF_DROP); diff --git a/tests/sys/netpfil/pf/mld.py b/tests/sys/netpfil/pf/mld.py index b3ef6c21b3de..ab644d3eed4c 100644 --- a/tests/sys/netpfil/pf/mld.py +++ b/tests/sys/netpfil/pf/mld.py @@ -25,6 +25,7 @@ # SUCH DAMAGE. import pytest +import time from utils import DelayedSend from atf_python.sys.net.tools import ToolsHelper from atf_python.sys.net.vnet import VnetTestTemplate @@ -45,6 +46,11 @@ class TestMLD(VnetTestTemplate): ]) ToolsHelper.print_output("/sbin/pfctl -x loud") + while True: + cmd = self.wait_object(vnet.pipe) + result = ToolsHelper.get_output(cmd) + vnet.pipe.send(result) + def find_mld_reply(self, pkt, ifname): pkt.show() s = DelayedSend(pkt, ifname) @@ -88,3 +94,54 @@ class TestMLD(VnetTestTemplate): # Check if we logged dropping the MLD paacket dmesg = ToolsHelper.get_output("/sbin/dmesg") assert dmesg.find("Invalid MLD") != -1 + + @pytest.mark.require_user("root") + @pytest.mark.require_progs(["scapy"]) + def test_unspec(self): + """Verify that we allow MLD packets from the unspecifed address""" + pf_pipe = self.vnet_map["vnet2"].pipe + ifname = self.vnet.iface_alias_map["if1"].name + ToolsHelper.print_output("/sbin/ifconfig") + + # Import in the correct vnet, so at to not confuse Scapy + import scapy.all as sp + import scapy.contrib as sc + import scapy.contrib.igmp + self.sp = sp + self.sc = sc + + # MLD packets with an incorrect hop limit get dropped. + pkt = sp.Ether() \ + / sp.IPv6(src="::", dst="ff02::1", hlim=1) \ + / sp.IPv6ExtHdrHopByHop(options=[ \ + sp.RouterAlert(value=0) \ + ]) \ + / sp.ICMPv6MLReport() + # Send the packet, there's no reply to a report + pkt.show() + sp.sendp(pkt, iface=ifname) + + time.sleep(1) + + # We should not have logged a drop of an MLD packet + pf_pipe.send("/sbin/pfctl -sa") + out = self.wait_object(pf_pipe) + print("out %s" % out) + assert out.find("ip-option 0") != -1 + + # However, we do still drop queries from the unspecified address + pkt = sp.Ether() \ + / sp.IPv6(src="::", dst="ff02::1", hlim=1) \ + / sp.IPv6ExtHdrHopByHop(options=[ \ + sp.RouterAlert(value=0) \ + ]) \ + / sp.ICMPv6MLQuery() + # Send the packet, there's no reply to a report + sp.sendp(pkt, iface=ifname) + + time.sleep(1) + + pf_pipe.send("/sbin/pfctl -sa") + out = self.wait_object(pf_pipe) + print("out %s" % out) + assert out.find("ip-option 1") != -1