[PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack

sashiko-bot at kernel.org sashiko-bot at kernel.org
Tue Sep 29 19:32:43 UTC 2026


Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] kconfig: core dual-stack and IPv6 features are forcibly disabled without IPv4
--

commit e9e0ffe00541dede8370017851b597f6f3e1cfa2
Author: Fernando Fernandez Mancera <fmancera at suse.de>

ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack

This commit introduces the CONFIG_IPV4 symbol to decouple the IPv4 stack,
currently defaulting it to yes. It adjusts multiple networking subsystems
across tunnels, drivers, and filesystems to depend on this new IPv4
configuration symbol.

> diff --git a/net/Kconfig b/net/Kconfig
> index 76ab44aa439a6..ca86f20540dd1 100644
> --- a/net/Kconfig
> +++ b/net/Kconfig
[ ... ]
> @@ -232,6 +235,7 @@ config BRIDGE_NETFILTER
>  	depends on BRIDGE
>  	depends on NETFILTER && INET
>  	depends on NETFILTER_ADVANCED
> +	depends on IPV4
>  	select NETFILTER_FAMILY_BRIDGE

[Severity: High]
Does adding this dependency force bridge netfilter to be unavailable on
kernels without IPv4?

Bridge netfilter handles both IPv4 and IPv6 bridged traffic. Tying it
exclusively to CONFIG_IPV4 under config BRIDGE_NETFILTER might prevent
filtering IPv6 traffic on an IPv6-only kernel.

[ ... ]
> diff --git a/net/ipv6/Kconfig b/net/ipv6/Kconfig
> index c3806c6ac96f9..f83efc1505cc4 100644
> --- a/net/ipv6/Kconfig
> +++ b/net/ipv6/Kconfig
[ ... ]
> @@ -256,7 +265,7 @@ config IPV6_SUBTREES
>  
>  config IPV6_MROUTE
>  	bool "IPv6: multicast routing"
> -	depends on IPV6
> +	depends on IPV4 && IPV6
>  	select IP_MROUTE_COMMON

[Severity: High]
Does this change break IPv6 multicast routing when CONFIG_IPV4 is disabled?

IPv6 multicast routing under config IPV6_MROUTE does not inherently require
IPv4. Adding this dependency disables purely IPv6 functionality on an
IPv6-only kernel.

[ ... ]
> diff --git a/net/xfrm/Kconfig b/net/xfrm/Kconfig
> index 4a62817a88f8f..203188b05be40 100644
> --- a/net/xfrm/Kconfig
> +++ b/net/xfrm/Kconfig
> @@ -4,7 +4,7 @@
>  #
>  config XFRM
>  	bool
> -	depends on INET
> +	depends on INET && IPV4
>  	select GRO_CELLS

[Severity: High]
Will adding this dependency disable the global IPsec subsystem for IPv6-only
kernels?

Tying config XFRM entirely to CONFIG_IPV4 restricts dual-stack infrastructure,
making it impossible to use IPsec with IPv6 if IPv4 is disabled.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928193046.6698-1-fmancera@suse.de?part=1



More information about the Linux-security-module-archive mailing list