From nobody Thu Aug 6 16:28:06 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hGCPx3ZHTz6nJVx for ; Thu, 06 Aug 2026 16:28:21 +0000 (UTC) (envelope-from freebsd@oldach.net) Received: from mp80.oldach.net (hmo.in-vpn.de [IPv6:2001:67c:1407:60::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature ECDSA (prime256v1) client-digest SHA256) (Client CN "mp80.oldach.net", Issuer "YE1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hGCPv3pfDz3TJs for ; Thu, 06 Aug 2026 16:28:19 +0000 (UTC) (envelope-from freebsd@oldach.net) Authentication-Results: mx1.freebsd.org; dkim=none; dmarc=pass (policy=none) header.from=oldach.net; spf=pass (mx1.freebsd.org: domain of freebsd@oldach.net designates 2001:67c:1407:60::1 as permitted sender) smtp.mailfrom=freebsd@oldach.net Received: from mp80.oldach.net (localhost [127.0.0.1]) by mp80.oldach.net (8.18.2/8.18.2) with ESMTPS id 676GS6fY091708 (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384 bits=256 verify=NO); Thu, 6 Aug 2026 18:28:08 +0200 (CEST) (envelope-from freebsd@oldach.net) Received: (from hmo@localhost) by mp80.oldach.net (8.18.2/8.18.2/Submit) id 676GS6mx091706; Thu, 6 Aug 2026 18:28:06 +0200 (CEST) (envelope-from freebsd@oldach.net) Message-Id: <202608061628.676GS6mx091706@mp80.oldach.net> X-Authentication-Warning: mp80.oldach.net: hmo set sender to freebsd@oldach.net using -f Subject: Re: git: 978b9026b018 - stable/15 - bind(2): Lookup local address in current FIB if '*.bind_all_fibs' is active In-Reply-To: <6a74a791.18343.42b24743@gitrepo.freebsd.org> from =?us-ascii?Q?Bojan_Novk=3D=3Fiso=2D8859=2D15=3Fb=3Fb3ZpPw=3D=3D?= =?us-ascii?Q?=3F=3D?= at "6 Aug 2026 15:26:09" To: bnovkov@FreeBSD.org (Bojan =?us-ascii?Q?Novk=3D=3Fiso=2D8859=2D15=3Fb=3Fb3ZpPw=3D=3D=3F=3D?=) Date: Thu, 6 Aug 2026 18:28:06 +0200 (CEST) Cc: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: freebsd@oldach.net (Helge Oldach) X-No-Archive: Yes List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable X-Greylist: inspected by milter-greylist-4.6.4 (mp80.oldach.net [0.0.0.0]); Thu, 06 Aug 2026 18:28:08 +0200 (CEST) for IP:127.0.0.1 DOMAIN:localhost HELO:mp80.oldach.net FROM:freebsd@oldach.net RCPT: X-Spamd-Result: default: False [-2.60 / 15.00]; TO_EXCESS_QP(1.20)[]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_SHORT(-1.00)[-1.000]; DMARC_POLICY_ALLOW(-0.50)[oldach.net,none]; R_SPF_ALLOW(-0.20)[+mx]; MIME_GOOD(-0.10)[text/plain]; MISSING_XM_UA(0.00)[]; FROM_NO_DN(0.00)[]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; ASN(0.00)[asn:29670, ipnet:2001:67c:1400::/45, country:DE]; MLMMJ_DEST(0.00)[dev-commits-src-branches@FreeBSD.org]; MID_RHS_MATCH_FROMTLD(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; HAS_XAW(0.00)[]; R_DKIM_NA(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_SOME(0.00)[]; TO_DN_NONE(0.00)[]; RCVD_TLS_LAST(0.00)[]; RCPT_COUNT_THREE(0.00)[4] X-Rspamd-Queue-Id: 4hGCPv3pfDz3TJs X-Spamd-Bar: -- Bojan Novk=3D?iso-8859-15?b?b3ZpPw=3D=3D?=3D wrote on Thu, 06 Aug 2026 17:2= 6:09 +0200 (CEST): > The branch stable/15 has been updated by bnovkov: >=20 > URL: https://cgit.FreeBSD.org/src/commit/?id=3D978b9026b01852bc78289fd2c8= c747c78441b5f1 >=20 > commit 978b9026b01852bc78289fd2c8c747c78441b5f1 > Author: Bojan Novkovi > AuthorDate: 2026-07-15 13:47:01 +0000 > Commit: Bojan Novkovi > CommitDate: 2026-08-06 15:25:24 +0000 >=20 > bind(2): Lookup local address in current FIB if '*.bind_all_fibs' is = active > =20 > When a protocol-specific 'bind_all_fibs' tunable is set to 0, a > listening socket will only receive traffic originating from the FIB > it was bound to. However, there are no checks to determine whether > an address exists in the target FIB when binding the socket, which can > lead to a situation where a socket and the address it was bound to > belong to different FIBs. > =20 > Prevent this footgun by looking up the requested address in the curre= nt > FIB if 'bind_all_fibs' is active and returning an error if the address > does not exist. > =20 > Sponsored by: Stormshield > Sponsored by: Klara, Inc. > Differential Revision: https://reviews.freebsd.org/D58281 > Reviewed by: glebius, pouria, markj > MFC after: 2 weeks > =20 > (cherry picked from commit 948ad32ae1e0811f45e1d38f26636fefed5051f0) > --- > sys/netinet/in_pcb.c | 2 +- > sys/netinet/raw_ip.c | 7 ++- > sys/netinet6/in6_pcb.c | 2 +- > sys/netinet6/raw_ip6.c | 7 ++- > tests/sys/netinet/Makefile | 1 + > tests/sys/netinet/fib_bind.py | 100 ++++++++++++++++++++++++++++++++++++= ++++++ > 6 files changed, 113 insertions(+), 6 deletions(-) cc -target x86_64-unknown-freebsd15.1 --sysroot=3D/usr/obj/usr/src/amd64.am= d64/tmp -B/usr/obj/usr/src/amd64.amd64/tmp/usr/bin -c -O2 -pipe -fno-stric= t-aliasing -g -nostdinc -I. -I/usr/src/sys -I/usr/src/sys/contrib/ck/incl= ude -I/usr/src/sys/contrib/libf= dt -D_KERNEL -DHAVE_KERNEL_OPTION_HEADERS -include opt_global.h -fno-common= -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -MD -MF.depend.in_= pcb.o -MTin_pcb.o -ffile-prefix-map=3D/usr/src/sys=3D/usr/src/sys -ffile-pr= efix-map=3D/usr/obj/usr/src/amd64.a= md64/sys/GENERIC=3D/usr/obj/usr/src/amd64.amd64/sys/GENERIC -ffile-prefix-m= ap=3D/usr/obj/usr/src/amd64.amd64/tmp=3D/sysroot -fdebug-prefix-map=3D./mac= hine=3D/usr/src/sys/amd64/include -fdebug-prefix-map=3D./x86=3D/usr/src/sys= /x86/include -fdebug-prefix-map=3D./i386=3D/usr= /src/sys/i386/include -mcmodel=3Dkernel -mno-red-zone -mno-mmx -mno-sse -ms= oft-float -fno-asynchronous-unwind-tables -ffreestanding -fwrapv -fstack-p= rotector-strong -gdwarf-4 -Wall -Wstrict-prototypes -Wmissing-prototypes -= Wpointer-arith -Wcast-qual -Wun= def -Wno-pointer-sign -D__printf__=3D__freebsd_kprintf__ -Wmissing-include-= dirs -fdiagnostics-show-option -Wno-unknown-pragmas -Wswitch -Wno-error=3Dt= autological-compare -Wno-error=3Dempty-body -Wno-error=3Dparentheses-equali= ty -Wno-error=3Dunused-function -Wno-er= ror=3Dpointer-sign -Wno-error=3Dshift-negative-value -Wno-address-of-packed= -member -Wno-format-zero-length -mno-aes -mno-avx -std=3Dgnu17 -Werror /= usr/src/sys/netinet/in_pcb.c /usr/src/sys/netinet/in_pcb.c:954:7: error: call to undeclared function 'ifa_ifwithaddr_fib_check'; ISO C99 and later do not support implicit function declarations [-Werror,-Wimplicit-function-declaration] 954 | ifa_ifwithaddr_fib_check((const struct sockaddr= *)&s... | ^ /usr/src/sys/netinet/in_pcb.c:954:7: note: did you mean 'ifa_ifwithaddr_che= ck'? /usr/src/sys/net/if_var.h:551:6: note: 'ifa_ifwithaddr_check' declared here 551 | int ifa_ifwithaddr_check(const struct sockaddr *); | ^ 1 error generated. *** Error code 1 Stop. make[2]: stopped making "all" in /usr/obj/usr/src/amd64.amd64/sys/GENERIC 429.20 real 410.50 user 18.43 sys *** Error code 1 Stop. make[1]: stopped making "buildkernel" in /usr/src *** Error code 1 Stop. make: stopped making "buildkernel" in /usr/src