Repository navigation
feat(net): implement IPv4 and IPv6 endpoint PMTU discovery - #2398
Conversation
Complete the ICMP-driven endpoint path for raw, UDP and TCP: validate quoted packets and socket association, maintain bounded per-network-namespace route exceptions, invalidate transport hints on expiry and topology changes, and apply discovery policies at the actual post-NAT output route. Share bounded extended-error queue and PMTU policy code across inet sockets. Preserve protocol-specific error gates, SO_ERROR single consumption, error payload/offender/truncation semantics, and raw blocking-send wakeups. Keep synchronous LOCAL EMSGSIZE out of pending socket errors. Integrate validated TCP feedback and non-congestion resegmentation using smoltcp PR DragonOS-Community#41 at d4b0ece81366fd72dd635973dcb1e9cce344a38f. Retain transport ownership in smoltcp and route/NAT ownership in DragonOS. Bound direct receive polling so deferred control work executes after interface and FIB locks are released. Separate socket output policy and IPv6 multicast cloning from the common output admission pipeline. Add 22 isolated endpoint regression cases and isolate raw ICMP filter iterations to avoid legitimate in-flight packets from previous sockets contaminating assertions. Validation: make kernel and make fmt; guest endpoint suite 66/66 plus fixed-Git-revision 22/22; forwarding MTU 3/3, bridge/veth semantics 9/9, UDP IPv6 25/25, TCP handshake 5/5, TCP close/error and multicast regressions; raw filter 15/15. Default Docker small-MTU ping changes from 0/3 to 2/3 with exit 0; ordinary container run and published HTTP succeed. Three-role adversarial review findings were fixed and re-reviewed. Scope is ICMP-driven PMTU, not PLPMTUD or unrelated Docker capability gaps. Signed-off-by: longjin <longjin@dragonos.org>
|
@codex review |
Pin smoltcp to 6eba35e02e1da1bbe2ab56eb6ac6c2b7650e8346 from dependency PR DragonOS-Community#41. This preserves Rust 1.80 compatibility, corrects single-family PMTU regression coverage, and provides a typed PMTU policy validation error without changing packet dispatch behavior. Validation: make kernel completed successfully against the pinned Git revision. The dependency passed all 19 MSRV and stable feature matrices, MSRV checks, examples, strict Clippy and formatting checks. Signed-off-by: longjin <longjin@dragonos.org>
|
Updated the pinned smoltcp revision and lockfile to 6eba35e02e1da1bbe2ab56eb6ac6c2b7650e8346 (dependency PR #41 CI fixes). The dependency preserves Rust 1.80 support, corrects IPv6-only PMTU test assumptions, and uses a typed policy validation error. DragonOS make kernel compiled and linked successfully against this Git revision. No guest tests were rerun for this dependency-only update. |
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Update the dependency and lockfile to d3f1aa2e6975729598221639b991fbd996dcc8f8, the merge commit of smoltcp PR DragonOS-Community#41 on dragonos/v0.12.0. Confirmed the merged tree is identical to the previously validated PR head. Validation: make kernel completed successfully, including final kernel linking. No packet-processing behavior changes are introduced by this revision update. Signed-off-by: longjin <longjin@dragonos.org>
|
Pinned smoltcp to the merged Community dragonos/v0.12.0 commit d3f1aa2e6975729598221639b991fbd996dcc8f8 from PR #41, updating Cargo.toml and Cargo.lock together. Verified the merged tree is identical to the validated dependency PR head. make kernel compiled and linked successfully against the merged revision. |
|
@codex review |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
The route-aware TCP PMTU callback returned loopback MTU 65536 without applying the transport Device limit of 65535. Large IPv4 segments then exceeded the encodable packet length and were rejected before admission, leaving concurrent self-connect send and receive waiting indefinitely. Bound the path hint at the TCP device boundary without changing the interface MTU, PMTU cache or protocol timers. Restore Linux EOPNOTSUPP for IPv4 TCP getsockopt at the IPv6 level. The PMTU dispatcher previously masked the V6ONLY getter errno with ENOPROTOOPT. Keep the distinct setter errno and extend the regression to V6ONLY, MTU_DISCOVER and MTU queries. Validation: pre-fix guest reproduced the stalled self-connect test; temporary atomic snapshots showed Established, full TX, empty RX and both IO waiters. All diagnostic code was removed. Post-fix snapshot guest passed dual-stack 11/11, self-connect 18/18 and endpoint PMTU 22/22, plus three repeated dual-stack large-transfer rounds (6/6). Original 64 x 1 MiB load retained. make kernel, format checks, Clippy and git diff --check completed. Independent adversarial review found no candidate defects. Signed-off-by: longjin <longjin@dragonos.org>
|
Fixed both Dunitest failures from run 37876852354 in f9225aa.
Pre-fix guest reproduction and low-disturbance GDB/atomic snapshots were captured; all diagnostic code was removed. The final snapshot guest passed the full dual-stack suite (11/11), self-connect suite (18/18), endpoint PMTU suite (22/22), and three additional dual-stack 64 x 1 MiB stress rounds (6/6). make kernel and format/Clippy checks completed. Independent adversarial review found no defects in the candidate. The full CI suite will validate the pushed commit; focused local results do not imply all CI checks have completed. |
|
@codex review |
|
Codex Review: Something went wrong. Try again later by commenting “@codex review”. ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
Complete ICMP-driven endpoint PMTU discovery for IPv4/IPv6 raw, UDP and TCP (DKC-057). Router feedback already works; this change closes the missing endpoint learning, output-policy, error-reporting and TCP resegmentation loop.
Architecture
Dependency
Depends on DragonOS-Community/smoltcp#41. Cargo.toml and Cargo.lock pin d4b0ece81366fd72dd635973dcb1e9cce344a38f; the Community Git URL was fetched and the fixed-revision kernel built and boot-tested. Please merge the dependency first.
Regression fixes found during adversarial review
Validation
Boundaries
This is ICMP-driven PMTU, not PLPMTUD, IPsec or tunnels. Packet tests cover concrete dual-family feedback/error and TCP paths; not every extension-header, multicast/NAT rule combination, allocation-failure injection or long-running expiry scenario is exhaustively tested. Existing unrelated Docker wait, memory-growth, quota and optional XFRM issues remain separate. Public-registry throughput and crash recovery are not claimed by this PR.