From nobody Mon Sep 07 08:38:08 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hdgSd0cCCz6rhSH for ; Mon, 07 Sep 2026 08:38:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hdgSd020Pz43Yh for ; Mon, 07 Sep 2026 08:38:09 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788770289; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=s9S01Lxs/g7yAzQc96enxf0GSH1tXypUygdlQA7TOoQ=; b=Ganuv7Bm6GirofsqmFPas6z9RKPraW1g7QEOh3V3KaSdi7UA9OG/WXJqYsGyA0IheqeA6i q7l8RuNGmzbZH/S8LALek94YVM3ezmy0DCSvioSYD4UCrVb+nQpNyUfnCXIXs/wLa1EuXm fbyvHQPK2FooQIzXPmPdefxj1mwBwUyJXBaGqtuxdzV31iWkpX5fsYk/CcJU93fppiDAa4 X++UsIQsgL7lu9DwI3aCveYp6IOVwnNuYV4kYp3tmM9x+UsOvelgFKybs9hA3j81elF+MA h5qxL24dKSR4bvwaPfFrx9iydXkDsSzudNz9BsCsCfz0tdAIqKZWKc0ZE6rUmA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788770289; a=rsa-sha256; cv=none; b=jgDGR1GVlLwNlazXF6bO+ucjetZxmfxWAcOHJPy63E254p+CGrTt3QG6qFds5iJGfcnOr6 Z4AliGplr2pgKKQT6VjHYXpIQu3UoTmwuFPceVxBEqIwPp+C0Xn+1cXJlNl6p2XWqckmnP Vyj0WYr3ljIgPFzxQdncE1ogtoTt9O6sfcmfXnH4CJQPSUH+r54+PDSo+ad2TkygJyqhhV 6+8O6I6JjN51a5RaazSlVL3dQZRW+xHDUGDukbpKZRWUBV/zQ0zK+iszOLvEFu7Oopoak5 ykTlq2fiDL7y92Onyw04rZd//t/fP6M++NMaL9ft+Hn5HlcMEB3kNBhRpzByHw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788770289; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=s9S01Lxs/g7yAzQc96enxf0GSH1tXypUygdlQA7TOoQ=; b=CCMvqTFOThHjkK0yOpVK1zstrB2iXv42WaEQmdombU6Ts/LOohpzuiAKhs2uDmwKihXnnU XJCDcIWoYLkpz5eA996wTXQuCmHtYEdxhtb3h9rlOMhQU4xnyJPyCH2A7efWfpuoeup9RJ jI0xllR/sbsnKIvFDRSQu6OPKBKRTlqozw2Ox/FMWEgCa+lOmIoAhBJRgzk14JNw+cNs52 EzuA3U9S4ZSsuU+aYkIwKJ823E77UKFDxhl5D6gxrfXaq9CiMoWnTctUb33c/wzO3qbmiN o55mBhlRpKNMcqzxOqurjClz6BUPv7fpDfJsiyfC7xGLcATEoZxkrnOTzpfEpg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hdgSc5s0pz18Wm for ; Mon, 07 Sep 2026 08:38:08 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3cd63 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 07 Sep 2026 08:38:08 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: 0a35e0afef28 - main - pf: allow unspecified addressed for certain MLD messages List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 0a35e0afef2860a0a96e30e682f6782a323a82a4 Auto-Submitted: auto-generated Date: Mon, 07 Sep 2026 08:38:08 +0000 Message-Id: <6a9e77f0.3cd63.2a94b631@gitrepo.freebsd.org> The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=0a35e0afef2860a0a96e30e682f6782a323a82a4 commit 0a35e0afef2860a0a96e30e682f6782a323a82a4 Author: Kristof Provost AuthorDate: 2026-09-02 17:03:44 +0000 Commit: Kristof Provost CommitDate: 2026-09-07 08:37:46 +0000 pf: allow unspecified addressed for certain MLD messages As per RFC 3590 MLD Report and Done messages are permitted to use the unspecified address as a source address (e.g. during duplicate address detection for the first IPv6 address). Allow this, but only this. Reported by: Alexander Leidinger Reviewed by: bms See also: OpenBSD, sashan , 60036e8507 Sponsored by: Rubicon Communications, LLC ("Netgate") Differential Revision: https://reviews.freebsd.org/D59334 --- sys/netpfil/pf/pf.c | 10 +++++++- tests/sys/netpfil/pf/mld.py | 57 +++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 66 insertions(+), 1 deletion(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index 04e919639ddb..322b10c3fce6 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -11085,9 +11085,17 @@ pf_walk_header6(struct pf_pdesc *pd, struct ip6_hdr *h, u_short *reason) * local source address. If either one is * missing then MLD message is invalid and * should be discarded. + * RFC 3590 clarifies that during initial + * duplicate address detection nodes may not + * have an address, so are permitted to use + * the unspecified address, but only for Report + * and Done messages. */ if ((h->ip6_hlim != 1) || - !IN6_IS_ADDR_LINKLOCAL(&h->ip6_src)) { + (!IN6_IS_ADDR_LINKLOCAL(&h->ip6_src) && + icmp6.icmp6_type == MLD_LISTENER_QUERY) || + (!IN6_IS_ADDR_LINKLOCAL(&h->ip6_src) && + !IN6_IS_ADDR_UNSPECIFIED(&h->ip6_src))) { DPFPRINTF(PF_DEBUG_MISC, "Invalid MLD"); REASON_SET(reason, PFRES_IPOPTIONS); return (PF_DROP); diff --git a/tests/sys/netpfil/pf/mld.py b/tests/sys/netpfil/pf/mld.py index b3ef6c21b3de..ab644d3eed4c 100644 --- a/tests/sys/netpfil/pf/mld.py +++ b/tests/sys/netpfil/pf/mld.py @@ -25,6 +25,7 @@ # SUCH DAMAGE. import pytest +import time from utils import DelayedSend from atf_python.sys.net.tools import ToolsHelper from atf_python.sys.net.vnet import VnetTestTemplate @@ -45,6 +46,11 @@ class TestMLD(VnetTestTemplate): ]) ToolsHelper.print_output("/sbin/pfctl -x loud") + while True: + cmd = self.wait_object(vnet.pipe) + result = ToolsHelper.get_output(cmd) + vnet.pipe.send(result) + def find_mld_reply(self, pkt, ifname): pkt.show() s = DelayedSend(pkt, ifname) @@ -88,3 +94,54 @@ class TestMLD(VnetTestTemplate): # Check if we logged dropping the MLD paacket dmesg = ToolsHelper.get_output("/sbin/dmesg") assert dmesg.find("Invalid MLD") != -1 + + @pytest.mark.require_user("root") + @pytest.mark.require_progs(["scapy"]) + def test_unspec(self): + """Verify that we allow MLD packets from the unspecifed address""" + pf_pipe = self.vnet_map["vnet2"].pipe + ifname = self.vnet.iface_alias_map["if1"].name + ToolsHelper.print_output("/sbin/ifconfig") + + # Import in the correct vnet, so at to not confuse Scapy + import scapy.all as sp + import scapy.contrib as sc + import scapy.contrib.igmp + self.sp = sp + self.sc = sc + + # MLD packets with an incorrect hop limit get dropped. + pkt = sp.Ether() \ + / sp.IPv6(src="::", dst="ff02::1", hlim=1) \ + / sp.IPv6ExtHdrHopByHop(options=[ \ + sp.RouterAlert(value=0) \ + ]) \ + / sp.ICMPv6MLReport() + # Send the packet, there's no reply to a report + pkt.show() + sp.sendp(pkt, iface=ifname) + + time.sleep(1) + + # We should not have logged a drop of an MLD packet + pf_pipe.send("/sbin/pfctl -sa") + out = self.wait_object(pf_pipe) + print("out %s" % out) + assert out.find("ip-option 0") != -1 + + # However, we do still drop queries from the unspecified address + pkt = sp.Ether() \ + / sp.IPv6(src="::", dst="ff02::1", hlim=1) \ + / sp.IPv6ExtHdrHopByHop(options=[ \ + sp.RouterAlert(value=0) \ + ]) \ + / sp.ICMPv6MLQuery() + # Send the packet, there's no reply to a report + sp.sendp(pkt, iface=ifname) + + time.sleep(1) + + pf_pipe.send("/sbin/pfctl -sa") + out = self.wait_object(pf_pipe) + print("out %s" % out) + assert out.find("ip-option 1") != -1