From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=DN3ZfWB6; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by passt.top (Postfix) with ESMTPS id 456CE5A0271 for ; Tue, 22 Apr 2025 14:46:35 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1745325993; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C+r/lSwuflLQLjCLQ1slfo+9lrIl4KB5TAqELiZPqd0=; b=DN3ZfWB6o5kGGEPPEJ7/AcTBKbq40FEMIL+g6NvtiORvYHl69NiUkg2EZT09e8gs4fdC98 b/wnuHRu/18h6gsIkL1/sbFERrXXiNnCp31Rj8pwpSMMNkHC90wVJGoOsHGh+u2g3xOUqv pphjT5Bf0sbYumTMiASHQevRWg/JrFc= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-362-fobicnEdNKuORSEPWCofKA-1; Tue, 22 Apr 2025 08:46:32 -0400 X-MC-Unique: fobicnEdNKuORSEPWCofKA-1 X-Mimecast-MFC-AGG-ID: fobicnEdNKuORSEPWCofKA_1745325991 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-440667e7f92so23094775e9.3 for ; Tue, 22 Apr 2025 05:46:32 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1745325991; x=1745930791; h=content-transfer-encoding:mime-version:organization:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=C+r/lSwuflLQLjCLQ1slfo+9lrIl4KB5TAqELiZPqd0=; b=unq8r9+0tKhjf6BQKkkIAYiAXSOEass+X7m7By2IjRqZikvV+t69en+3qn+35sTN1G BYPS7u3IOvHvKT4H/iPDA+StOfdbJU8aB8+7aCKpCiPA9SimapK7SGFSkMbhuVL5RE/c T048dPcgzJXHLis2UXPsZsh9QPto/PusKisI0ewRXclMxnqJ/c5FeAMlVcyNUznDsaCS /brMeDBn0wgbu9sHjH/FGZb0BIMzjyyGz9fKentxsRUWihhC/L5oU6g53leGIpK+Y2DO AQb2fP7jbOSgkx4DxCAfvis6W0Iq0vL054dPyw8h4Uq6Bs6q5ngC6q8BC/o9P2kT0dn9 bqVg== X-Gm-Message-State: AOJu0YztDpjcnyR6Yyav5izkDTLrEbVa40mXdH0ui/vSPj9ibW0r0OwL WC/okim5H+rDrjCLRWDF7VHZJnFi5PXWurycfxoXUP5LWdTOan0uOqyEE241kF1vsb42f81sYOk E+gq3HI1kDXe9phNFGbkRxFobK2dkMIgnEAJPI5C0GafoajCMnA== X-Gm-Gg: ASbGnctn4/wtBMgZ64YKvgKGloaAofC23Fgrxj6dFAKvWqovcsydoeKLHDqHBJUY7Rh 5+dMPZb35a4kz+M/IzYd/SM145lKzvebfO0UEq68Eh02BHtEBa2JYRO9eKEvJQU9Nw6tJn5qzqF Ww+dUOp/oACqeiy1QFM9RDV1XgTTed9t0B9Zg7gqk7y1bT959atQ3gvr3ixqoaQo4O9VTPXmtxc 22y9GNyP3SSVJkwjApGB6t5/W5pXxWAJ1gnP0GiKXK/daKQX5eGSq89J7dCOX0vhDH2h5DK8tXf H4N+CZRoA3D36w2Ptzj8Rww= X-Received: by 2002:a05:600c:1e1b:b0:43d:22d9:4b8e with SMTP id 5b1f17b1804b1-4406ab93fb0mr176713475e9.10.1745325991186; Tue, 22 Apr 2025 05:46:31 -0700 (PDT) X-Google-Smtp-Source: AGHT+IHvTM1C6sCBLJ8mZPke9FXynEidcnr77Egshl7FiRbpVF33HV6urIOS2zE+z0wU2fgMxK1DCw== X-Received: by 2002:a05:600c:1e1b:b0:43d:22d9:4b8e with SMTP id 5b1f17b1804b1-4406ab93fb0mr176713255e9.10.1745325990811; Tue, 22 Apr 2025 05:46:30 -0700 (PDT) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [2a10:fc81:a806:d6a9::1]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4406d5a9ed9sm176823865e9.3.2025.04.22.05.46.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 22 Apr 2025 05:46:30 -0700 (PDT) Date: Tue, 22 Apr 2025 14:46:29 +0200 From: Stefano Brivio To: David Gibson Subject: Re: [PATCH v2 0/4] Translate source addresses for ICMP errors Message-ID: <20250422144629.2cab660f@elisabeth> In-Reply-To: <20250417015543.457310-1-david@gibson.dropbear.id.au> References: <20250417015543.457310-1-david@gibson.dropbear.id.au> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: _mIZqqB5nm9IPWIuT_gJzWZpR4dzj-UwgW_Gzq5ePbE_1745325991 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: HQVWGDIM7GNQE23I2CZXDI64PQXBCEJZ X-Message-ID-Hash: HQVWGDIM7GNQE23I2CZXDI64PQXBCEJZ X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top, Jon Maloy X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: On Thu, 17 Apr 2025 11:55:39 +1000 David Gibson wrote: > We now propagate ICMP errors on UDP flows back into ICMP packets on > the tap interface. However, we don't always get the source address > right for the synthesized message. Because ICMPs can be generated by > intermediate routers, that source address might not be one of the > endpoints, so the address translation we already have isn't > sufficient. > > Implement properly translating ICMP addresses when we need to. This > ended up a bit messier than I hoped, but it seems to work. A simple > case to test this is: > > pasta --config-net --map-host-loopback=172.16.1.1 -- \ > sh -c "echo hello | socat STDIO UDP4:172.16.1.1:10001" > > where 10001 is a port where nothing is listening on the host. > > Without this series, this will just time out. pasta sends an ICMP > Port Unreachable message, but it's sent with source address 127.0.0.1 > and so discarded by the guest. With this series, the address is > properly translated and we correctly get the error from socat: > > 2025/04/16 19:02:37 socat[3] E read(5, 0x555c3dbf2000, 8192): Connection refused > > v2: > * Fix a (bogus) coverity warning > * Minor cosmetic changes based on Stefano's review Applied. -- Stefano