Skip to content

netstack: remove only the first matching route on RTM_DELROUTE - #15353

Merged
copybara-service[bot] merged 2 commits into
masterfrom
test/cl994048898
Oct 6, 2026
Merged

copybara-service[bot] merged 2 commits into
masterfrom
test/cl994048898

Conversation

@copybara-service

Copy link
Copy Markdown

netstack: remove only the first matching route on RTM_DELROUTE

Fixes #15295

netstack.Stack.RemoveRoute passes a match function to tcpip.Stack.RemoveRoutes, which removes every route that matches. One RTM_DELROUTE request can therefore delete several routes. Linux deletes only the first matching route per request and returns ESRCH when nothing matches.

This change adds a found flag to the match function in RemoveRoute. After the first match, the function returns false for every later route. tcpip.Stack.RemoveRoutes does not change.

The first match is the oldest matching route in the route table. Linux sorts routes with the same prefix by metric, so its first match is the route with the lowest metric. gVisor cannot do that yet. tcpip.Route has no metric field and localRoute ignores RTA_PRIORITY. Metric ordering is out of scope for this PR.

Testing:

  • New TestRemoveRouteRemovesFirstMatchOnly in pkg/sentry/socket/netstack/stack_test.go. It adds two 10.0.0.0/24 routes on NIC 1 and NIC 2 and sends RTM_DELROUTE three times. The first request leaves only the NIC 2 route, the second leaves an empty table, and the third returns ESRCH. The test uses NICs to tell the routes apart because the routes carry no metric. Without the stack.go change it fails with route table after first RemoveRoute = [], want only the NIC 2 route.
  • The netstack_test target in BUILD gets the deps the new test needs.
  • //pkg/sentry/socket/netstack:netstack_test and //pkg/tcpip/stack:stack_test pass locally under bazel.
  • test/syscalls/linux/socket_netlink_route.cc gains NetlinkRouteTest.DeleteRouteRemovesFirstMatchOnly. It adds 10.0.0.0/24 on two interfaces and deletes three times with no output interface. The route count goes from 2 to 1 to 0, and the third delete returns ESRCH.
  • test/rtnetlink/linux/route_test.sh runs the same sequence with ip route del.
  • Local bazel runs of //test/syscalls:socket_netlink_route_test_runsc_systrap_directfs (71 tests, including the new one) and //test/rtnetlink:route_test_runsc_systrap_overlay_directfs pass with the fix. Both fail without the stack.go change. The same tests also pass on native Linux. ptrace runsc variants were not run.
    FUTURE_COPYBARA_INTEGRATE_REVIEW=netstack: remove only the first matching route on RTM_DELROUTE #15301 from adi-IL:bot/gvisor-15295 7577af3

@copybara-service copybara-service Bot added the exported Issue was exported automatically label Oct 6, 2026
@copybara-service
copybara-service Bot merged commit 186b5da into master Oct 6, 2026
7 of 10 checks passed
@copybara-service
copybara-service Bot deleted the test/cl994048898 branch October 6, 2026 23:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

exported Issue was exported automatically

Projects

None yet

Development

Successfully merging this pull request may close these issues.

RTM_DELROUTE deletes all matching routes

2 participants