Skip to content

feat(net): implement IPv4 and IPv6 endpoint PMTU discovery - #2398

Merged
fslongjin merged 4 commits into
DragonOS-Community:masterfrom
fslongjin:codex/dkc057-endpoint-pmtu
Oct 9, 2026
Merged

fslongjin merged 4 commits into
DragonOS-Community:masterfrom
fslongjin:codex/dkc057-endpoint-pmtu

Conversation

@fslongjin

Copy link
Copy Markdown
Member

Summary

Complete ICMP-driven endpoint PMTU discovery for IPv4/IPv6 raw, UDP and TCP (DKC-057). Router feedback already works; this change closes the missing endpoint learning, output-policy, error-reporting and TCP resegmentation loop.

Architecture

  • Bounded per-network-namespace route exceptions with monotonic expiry, route/MTU invalidation and transport-hint generations.
  • One validated ICMP quote parser and bounded deferred control work, executed after interface/FIB locks drop. TCP additionally validates admitted sequence ranges and device binding.
  • Shared inet PMTU policy and bounded extended-error queue; protocol-specific learning/error gates remain in each transport.
  • Final MTU enforcement follows the actual OUTPUT/DNAT/POST_ROUTING route. Conntrack path lookup is read-only and does not refresh flow state. TCP retries resegment without congestion-loss backoff.
  • Socket PMTU output policy and IPv6 multicast cloning are separate modules over the existing output admission pipeline.
  • Direct receive polling is bounded so sustained traffic cannot indefinitely postpone deferred feedback.

Dependency

Depends on DragonOS-Community/smoltcp#41. Cargo.toml and Cargo.lock pin d4b0ece81366fd72dd635973dcb1e9cce344a38f; the Community Git URL was fetched and the fixed-revision kernel built and boot-tested. Please merge the dependency first.

Regression fixes found during adversarial review

  • Wake raw blocking send/sendto/sendmsg on pending PMTU errors, not only available send budget.
  • Do not turn synchronous LOCAL EMSGSIZE queue entries into a second pending socket error; preserve Linux dequeue semantics.
  • Respect MTU retry backoff for TCP Closed/RST output.
  • Isolate raw ICMP filter test iterations rather than treating legitimate packets still in flight from previous sockets as duplicates.

Validation

  • make kernel; make fmt; git diff --check.
  • Guest endpoint suite: 22 cases x 3 rounds = 66 passed, no skips. Rebuilt fixed Git dependency: another 22 passed.
  • Same endpoint suite on Linux: 22 passed, no skips.
  • Guest forwarding MTU: 3 passed; bridge/veth lifecycle: 9 passed; UDP IPv6: 25 passed; TCP handshake with its standard fixture: 5 passed.
  • TCP close/pending-error and rtnetlink multicast suites pass; isolated raw ICMP filter: 15 passed over 5 rounds.
  • Production route-cache algorithm harness: 5 passed.
  • smoltcp: 776 default library tests and 787 Reno/Cubic/IPv6-fragmentation configuration tests pass.
  • Default Docker bridge/NAT: MTU576 large ping now gets 2/3 replies and exits 0, matching Linux discovery behavior; baseline gets 0/3 and exits 1. Ordinary run --rm and published HTTP responses succeed.
  • Three-role adversarial design/code review, issue adjudication, fixes and final re-review completed.

Boundaries

This is ICMP-driven PMTU, not PLPMTUD, IPsec or tunnels. Packet tests cover concrete dual-family feedback/error and TCP paths; not every extension-header, multicast/NAT rule combination, allocation-failure injection or long-running expiry scenario is exhaustively tested. Existing unrelated Docker wait, memory-growth, quota and optional XFRM issues remain separate. Public-registry throughput and crash recovery are not claimed by this PR.

Complete the ICMP-driven endpoint path for raw, UDP and TCP: validate quoted packets and socket association, maintain bounded per-network-namespace route exceptions, invalidate transport hints on expiry and topology changes, and apply discovery policies at the actual post-NAT output route.

Share bounded extended-error queue and PMTU policy code across inet sockets. Preserve protocol-specific error gates, SO_ERROR single consumption, error payload/offender/truncation semantics, and raw blocking-send wakeups. Keep synchronous LOCAL EMSGSIZE out of pending socket errors.

Integrate validated TCP feedback and non-congestion resegmentation using smoltcp PR DragonOS-Community#41 at d4b0ece81366fd72dd635973dcb1e9cce344a38f. Retain transport ownership in smoltcp and route/NAT ownership in DragonOS. Bound direct receive polling so deferred control work executes after interface and FIB locks are released.

Separate socket output policy and IPv6 multicast cloning from the common output admission pipeline. Add 22 isolated endpoint regression cases and isolate raw ICMP filter iterations to avoid legitimate in-flight packets from previous sockets contaminating assertions.

Validation: make kernel and make fmt; guest endpoint suite 66/66 plus fixed-Git-revision 22/22; forwarding MTU 3/3, bridge/veth semantics 9/9, UDP IPv6 25/25, TCP handshake 5/5, TCP close/error and multicast regressions; raw filter 15/15. Default Docker small-MTU ping changes from 0/3 to 2/3 with exit 0; ordinary container run and published HTTP succeed. Three-role adversarial review findings were fixed and re-reviewed. Scope is ICMP-driven PMTU, not PLPMTUD or unrelated Docker capability gaps.
Signed-off-by: longjin <longjin@dragonos.org>
@github-actions github-actions Bot added the enhancement New feature or request label Oct 8, 2026
@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

Pin smoltcp to 6eba35e02e1da1bbe2ab56eb6ac6c2b7650e8346 from dependency PR DragonOS-Community#41. This preserves Rust 1.80 compatibility, corrects single-family PMTU regression coverage, and provides a typed PMTU policy validation error without changing packet dispatch behavior.

Validation: make kernel completed successfully against the pinned Git revision. The dependency passed all 19 MSRV and stable feature matrices, MSRV checks, examples, strict Clippy and formatting checks.
Signed-off-by: longjin <longjin@dragonos.org>
@fslongjin

Copy link
Copy Markdown
Member Author

Updated the pinned smoltcp revision and lockfile to 6eba35e02e1da1bbe2ab56eb6ac6c2b7650e8346 (dependency PR #41 CI fixes). The dependency preserves Rust 1.80 support, corrects IPv6-only PMTU test assumptions, and uses a typed policy validation error. DragonOS make kernel compiled and linked successfully against this Git revision. No guest tests were rerun for this dependency-only update.

@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ⚠️ Failed 2026-10-09T03:54:36.769612Z f9225aa Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Update the dependency and lockfile to d3f1aa2e6975729598221639b991fbd996dcc8f8, the merge commit of smoltcp PR DragonOS-Community#41 on dragonos/v0.12.0. Confirmed the merged tree is identical to the previously validated PR head.

Validation: make kernel completed successfully, including final kernel linking. No packet-processing behavior changes are introduced by this revision update.
Signed-off-by: longjin <longjin@dragonos.org>
@fslongjin

Copy link
Copy Markdown
Member Author

Pinned smoltcp to the merged Community dragonos/v0.12.0 commit d3f1aa2e6975729598221639b991fbd996dcc8f8 from PR #41, updating Cargo.toml and Cargo.lock together. Verified the merged tree is identical to the validated dependency PR head. make kernel compiled and linked successfully against the merged revision.

@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Failed to sample tokens
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

The route-aware TCP PMTU callback returned loopback MTU 65536 without applying the transport Device limit of 65535. Large IPv4 segments then exceeded the encodable packet length and were rejected before admission, leaving concurrent self-connect send and receive waiting indefinitely. Bound the path hint at the TCP device boundary without changing the interface MTU, PMTU cache or protocol timers.

Restore Linux EOPNOTSUPP for IPv4 TCP getsockopt at the IPv6 level. The PMTU dispatcher previously masked the V6ONLY getter errno with ENOPROTOOPT. Keep the distinct setter errno and extend the regression to V6ONLY, MTU_DISCOVER and MTU queries.

Validation: pre-fix guest reproduced the stalled self-connect test; temporary atomic snapshots showed Established, full TX, empty RX and both IO waiters. All diagnostic code was removed. Post-fix snapshot guest passed dual-stack 11/11, self-connect 18/18 and endpoint PMTU 22/22, plus three repeated dual-stack large-transfer rounds (6/6). Original 64 x 1 MiB load retained. make kernel, format checks, Clippy and git diff --check completed. Independent adversarial review found no candidate defects.
Signed-off-by: longjin <longjin@dragonos.org>
@fslongjin

Copy link
Copy Markdown
Member Author

Fixed both Dunitest failures from run 37876852354 in f9225aa.

  1. IPv4 TCP getsockopt at IPPROTO_IPV6 must return EOPNOTSUPP (95), while setsockopt retains ENOPROTOOPT (92). The new PMTU dispatcher masked the existing V6ONLY getter error. Restored the family-level getter check and expanded coverage to V6ONLY, MTU_DISCOVER and MTU.
  2. The route-aware TCP PMTU callback bypassed the transport Device packet-size limit: loopback supplied MTU 65536, but the transport supports 65535. Large IPv4 packets were rejected by smoltcp before admission. This left the original self-connect stress test with full TX, empty RX and both IO waiters. The callback now bounds the route hint by device capabilities; interface MTU and test load remain unchanged.

Pre-fix guest reproduction and low-disturbance GDB/atomic snapshots were captured; all diagnostic code was removed. The final snapshot guest passed the full dual-stack suite (11/11), self-connect suite (18/18), endpoint PMTU suite (22/22), and three additional dual-stack 64 x 1 MiB stress rounds (6/6). make kernel and format/Clippy checks completed. Independent adversarial review found no defects in the candidate. The full CI suite will validate the pushed commit; focused local results do not imply all CI checks have completed.

@fslongjin

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Something went wrong. Try again later by commenting “@codex review”.

Failed to sample tokens
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@fslongjin
fslongjin merged commit 67cf7be into DragonOS-Community:master Oct 9, 2026
18 of 19 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant