From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: passt.top; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: passt.top; dkim=pass (1024-bit key; unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=Az9OovUX; dkim-atps=neutral Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by passt.top (Postfix) with ESMTPS id 1ACD65A0272 for ; Fri, 21 Nov 2025 04:56:09 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1763697368; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=YL+pyZ//r+k6wNDPG6ft9uz6o9lDGyre6oXBEcCd1t0=; b=Az9OovUXlpemgK0iNmv+0jbUmNHGOeoQpGfOAoy7LeZ4VvtxfQaLoMhMOlXCveAAOV0fCz hZWcL9uni3iH6ZL1yQWjpo1wBI0HTd7FlsSsd0nmEcJyLPPXvP5mjuoC6nxbZMELSfxzl/ F/v2noxj7siaIhQ3cuoYPDPJ3DlZWwY= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-597-bu1SDj5POlSR1HenYS8OJA-1; Thu, 20 Nov 2025 22:56:05 -0500 X-MC-Unique: bu1SDj5POlSR1HenYS8OJA-1 X-Mimecast-MFC-AGG-ID: bu1SDj5POlSR1HenYS8OJA_1763697365 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-477964c22e0so9983605e9.0 for ; Thu, 20 Nov 2025 19:56:05 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1763697364; x=1764302164; h=content-transfer-encoding:mime-version:organization:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=YL+pyZ//r+k6wNDPG6ft9uz6o9lDGyre6oXBEcCd1t0=; b=HgoE4jJZdn/SZApBzCAihAeTEZGzVSKuPbx9OG+QoIhoOkd1bZQr5YHDnponkkT5/I wd9WBHEWyHc6tjdZObaIuuboJb9PeO3dpXBxPn7sw4C5OjL8M3/CEuGzOA5+hdnmaEXH aa2c6MZnzxl48OROcXud0lohtvDweENtM9rJhOxYtKvKqUfMaGri03fKcquyIOcwxs+C WNrvxF0PtDtCXBcjOmzlX8aydlmVM5Lmfbmc5y1nDAgoKrSaz9YULXdGRuKjJJHR7XEr EHiLQhTHAgkPAiaybGLZgcD9herZFlRkRBoWdJeyOVbZ6VClwXjsGddKkSNgpY/ve7yx NzMA== X-Gm-Message-State: AOJu0YzUiWKlIuRtbtrcmc64uH18fK7dp/rv71BeLJc4iWvLwB0ACpzX TRBNe6BBBxhnwx/Bqv2SdfpDLCZZxCMTBUzasfMdqspr27e/MXGMWG/Mzi7PbQD4rdAw/fbpiwU +2XpR3HNPqa5sp9Ilv/F+9ExAVCqRJpYyd13fZwA1gDIaXTEhEg431XWrLYBOdw== X-Gm-Gg: ASbGncu07cK6pxwdRyGVh17xY7fUeTyEzhAbPJ7LQSmYJq34LIwi6mScUmzZY5yPDgf NM8sUQfcnU6as7TbTz7MMm+M2hQIthMoaXG5Cy1eIwHGNhPBhuqRunK4xcCMQowhC38kHqQRBwD pwYq8YuYmQEctsE8GbA+a3PD2xHaQI2TFyZpysvA0TSzCQDXedLfj/59nisvJWLQSevT68OWXCG NVjFIEEQtBtGSVSRk7jn34MLnIdH43cOSpQSX6WP7ueZl1d7uptdXlB4ipJog9wHdvpVJqupbS8 p/O+bcWi1gWZyGkLXhqRFQwfj2S5uQTHC2aOu4ho0N4dZO4AJS5PawJ0sQwXl0d9PFXteZEIFB4 2Cme40JxxXJBFsI8INgr7Y0X9nkfS6LGANQiIoQ== X-Received: by 2002:a05:600c:1f85:b0:471:793:e795 with SMTP id 5b1f17b1804b1-477b9e61f7cmr43220515e9.0.1763697364166; Thu, 20 Nov 2025 19:56:04 -0800 (PST) X-Google-Smtp-Source: AGHT+IH8vHiWQ5N7Vaez9oaM8ATyfKAJ6FVTFPLoIWkhShIJxagNfIC754+g6t7XhYotEDVgrL9Esg== X-Received: by 2002:a05:600c:1f85:b0:471:793:e795 with SMTP id 5b1f17b1804b1-477b9e61f7cmr43220395e9.0.1763697363664; Thu, 20 Nov 2025 19:56:03 -0800 (PST) Received: from maya.myfinge.rs (ifcgrfdd.trafficplex.cloud. [176.103.220.4]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-477a9dfb639sm74910135e9.13.2025.11.20.19.56.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Nov 2025 19:56:03 -0800 (PST) Date: Fri, 21 Nov 2025 04:56:01 +0100 From: Stefano Brivio To: David Gibson Subject: Re: [PATCH v4 9/9] tcp, udp: Bind outbound listening sockets by interface instead of address Message-ID: <20251121045601.021b1793@elisabeth> In-Reply-To: <20251119052257.3004500-10-david@gibson.dropbear.id.au> References: <20251119052257.3004500-1-david@gibson.dropbear.id.au> <20251119052257.3004500-10-david@gibson.dropbear.id.au> Organization: Red Hat X-Mailer: Claws Mail 4.2.0 (GTK 3.24.49; x86_64-pc-linux-gnu) MIME-Version: 1.0 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: xcGsGpqOLR19q-dEZg8F1Ci5dGiynCEvH534Rw9xDAE_1763697365 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Message-ID-Hash: EGNGOJX73LDMIYFBRXG56D5IM3ASRFKB X-Message-ID-Hash: EGNGOJX73LDMIYFBRXG56D5IM3ASRFKB X-MailFrom: sbrivio@redhat.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: passt-dev@passt.top X-Mailman-Version: 3.3.8 Precedence: list List-Id: Development discussion and patches for passt Archived-At: Archived-At: List-Archive: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: The series looks good to me in general, except that: On Wed, 19 Nov 2025 16:22:57 +1100 David Gibson wrote: > Currently, outbound forwards (-T, -U) are handled by sockets bound to the > loopback address. Typically we create two sockets, one for 127.0.0.1 and > one for ::1. > > This has some disadvantages: > * The guest can't connect via 127.0.0.0/8 addresses other than 127.0.0.1 > * We can't use dual-stack sockets, we have to have separate sockets for > IPv4 and IPv6. > > The restriction exists for a reason though. If the guest has any > interfaces other than pasta (e.g. a VPN tunnel) external hosts could reach > the host via the forwards. Especially combined with -T auto / -U auto this > would make it very easy to make a mistake with nasty security implications. > > We can achieve this a different way, however. Don't bind to a specific > address, but _do_ use SO_BINDTODEVICE to restrict the sockets to the "lo" > interface. ...this means, as I pointed out on: https://archives.passt.top/passt-dev/20251022105916.53925523@elisabeth/ that we might break functionality for a number of pasta(1) users. I don't have a complete version of the SO_BINDTODEVICE fallback I sketched there, so I can't just add one on top of this series at the moment, but we need something like that before I can merge this. -- Stefano