Repository navigation
netstack: remove only the first matching route on RTM_DELROUTE - #15353
Merged
Merged
Conversation
copybara-service
Bot
force-pushed
the
test/cl994048898
branch
from
October 6, 2026 20:59
1d8e8ae to
d4fb937
Compare
PiperOrigin-RevId: 994684351
copybara-service
Bot
force-pushed
the
test/cl994048898
branch
from
October 6, 2026 23:09
d4fb937 to
186b5da
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
netstack: remove only the first matching route on RTM_DELROUTE
Fixes #15295
netstack.Stack.RemoveRoutepasses a match function totcpip.Stack.RemoveRoutes, which removes every route that matches. One RTM_DELROUTE request can therefore delete several routes. Linux deletes only the first matching route per request and returns ESRCH when nothing matches.This change adds a
foundflag to the match function inRemoveRoute. After the first match, the function returns false for every later route.tcpip.Stack.RemoveRoutesdoes not change.The first match is the oldest matching route in the route table. Linux sorts routes with the same prefix by metric, so its first match is the route with the lowest metric. gVisor cannot do that yet.
tcpip.Routehas no metric field andlocalRouteignores RTA_PRIORITY. Metric ordering is out of scope for this PR.Testing:
TestRemoveRouteRemovesFirstMatchOnlyinpkg/sentry/socket/netstack/stack_test.go. It adds two 10.0.0.0/24 routes on NIC 1 and NIC 2 and sends RTM_DELROUTE three times. The first request leaves only the NIC 2 route, the second leaves an empty table, and the third returns ESRCH. The test uses NICs to tell the routes apart because the routes carry no metric. Without thestack.gochange it fails withroute table after first RemoveRoute = [], want only the NIC 2 route.netstack_testtarget inBUILDgets the deps the new test needs.//pkg/sentry/socket/netstack:netstack_testand//pkg/tcpip/stack:stack_testpass locally under bazel.test/syscalls/linux/socket_netlink_route.ccgainsNetlinkRouteTest.DeleteRouteRemovesFirstMatchOnly. It adds 10.0.0.0/24 on two interfaces and deletes three times with no output interface. The route count goes from 2 to 1 to 0, and the third delete returns ESRCH.test/rtnetlink/linux/route_test.shruns the same sequence withip route del.//test/syscalls:socket_netlink_route_test_runsc_systrap_directfs(71 tests, including the new one) and//test/rtnetlink:route_test_runsc_systrap_overlay_directfspass with the fix. Both fail without thestack.gochange. The same tests also pass on native Linux. ptrace runsc variants were not run.FUTURE_COPYBARA_INTEGRATE_REVIEW=netstack: remove only the first matching route on RTM_DELROUTE #15301 from adi-IL:bot/gvisor-15295 7577af3