Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #88175 > unrolled thread

Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped

Started byAiden Yang <ling@moedove.com>
First post2025-06-28 15:00 +0200
Last post2025-07-22 21:20 +0200
Articles 6 — 3 participants

Back to article view | Back to linux.debian.kernel


Contents

  Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped Aiden Yang <ling@moedove.com> - 2025-06-28 15:00 +0200
    Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped Salvatore Bonaccorso <carnil@debian.org> - 2025-06-28 21:20 +0200
      Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped Aiden Yang <ling@moedove.com> - 2025-07-12 16:20 +0200
    Processed: Re: Bug#1108430: Kernel Regression between 6.1.0-35  and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently  dropped "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-06-28 21:20 +0200
    Bug#1108430: Acknowledgement (Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped) Aiden Yang <ling@moedove.com> - 2025-07-12 16:20 +0200
    Bug#1108430: marked as done (Kernel Regression between 6.1.0-35  and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently  dropped) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2025-07-22 21:20 +0200

#88175 — Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped

FromAiden Yang <ling@moedove.com>
Date2025-06-28 15:00 +0200
SubjectBug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped
Message-ID<L2DjX-dM27-1@gated-at.bofh.it>
PACKAGE: linux SUBJECT: Kernel Regression between 6.1.0-35 and
6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently
dropped SEVERITY: normal

===================================================================

Summary:
This report details a regression in the Linux kernel that prevents
IPv6 link-local all-nodes multicast packets (ff02::1) from being
transmitted over a GRE tunnel. The issue is confirmed to have been
introduced between kernel versions 6.1.0-35-cloud-amd64 (working) and
6.1.0-37-cloud-amd64 (failing) on Debian 12 (Bookworm).
On affected kernels, the ping utility reports 100% packet loss, and a
tcpdump on the underlying physical interface confirms that the kernel
is silently dropping the encapsulated GRE packets instead of sending
them. The sendto() system call does not return an error to the
userspace application in the default namespace.

===================================================================

Regression Point:
Last Known Good Version: 6.1.0-35-cloud-amd64
First Failing Version: 6.1.0-37-cloud-amd64
The regression is also present in later kernels tested, including
6.12.33 and 6.15.x on Debian 13 (Trixie).

===================================================================

Steps to Reproduce:
Use a Debian system with an affected kernel (e.g., >= 6.1.0-37).
Establish a GRE tunnel. Replace [PEER_IP] and [LOCAL_IP] with actual
endpoint addresses.
ip tunnel add tun_gre mode gre remote [PEER_IP] local [LOCAL_IP] ttl
255 ip link set tun_gre up
In one terminal, start a tcpdump on the physical interface that
provides the local IP, to monitor for outgoing GRE packets (GRE is IP
protocol 47).
tcpdump -i [PHYSICAL_IFACE] -n 'proto gre'
In a second terminal, attempt to ping the link-local all-nodes
multicast address via the GRE tunnel interface.
ping ff02::1%tun_gre -c 4

===================================================================

Observed Behavior (The Bug):
The ping command runs and reports "4 packets transmitted, 0 received,
100% packet loss".
The tcpdump window on the physical interface shows NO outgoing GRE
packets. This proves the kernel is silently dropping the packets.

===================================================================

Expected Behavior (as observed on kernel 6.1.0-35):
The ping command runs.
The tcpdump window shows outgoing GRE packets being sent from
[LOCAL_IP] to [PEER_IP] for each ICMPv6 echo request. (Receiving a
reply is dependent on the peer configuration, but the packets should
be transmitted).

===================================================================

Additional Diagnostic Information:
VRF Context: When the failing GRE interface (tun_gre) is placed within
a VRF, the failure mode changes. The ping or sendto() system call
fails immediately with an ENETUNREACH (Network is unreachable) error.
This is likely because the VRF routing table does not have a route to
the tunnel's physical peer address, and the kernel correctly
identifies this dependency issue.
veth Control Test: The issue is specific to the gre tunnel interface
type. A control test using a veth pair inside a VRF works perfectly
for link-local multicast, proving the core VRF and multicast logic is
sound.
This detailed bracketing of the regression should provide a strong
starting point for identifying the specific commit that introduced
this behavior.

-- 

WARNING: *This email (including its attachments) may contain confidential 
information protected by confidentiality agreements or other rights, and is 
intended only for the designated recipient or individuals who need to know 
it for the stated purpose. The recipient is prohibited from disclosing this 
information to unauthorized parties without prior permission from MoeDove 
LLC. If you have received this email in error, please notify the sender 
immediately and delete this email and its attachments from your system. Any 
use, dissemination, transmission, or copying of this email by someone other 
than the intended recipient is prohibited and may be unlawful.*

[toc] | [next] | [standalone]


#88179

FromSalvatore Bonaccorso <carnil@debian.org>
Date2025-06-28 21:20 +0200
Message-ID<L2JfH-dPSu-1@gated-at.bofh.it>
In reply to#88175
Control: tags -1 + moreinfo

On Sat, Jun 28, 2025 at 08:49:17PM +0800, Aiden Yang wrote:
> PACKAGE: linux SUBJECT: Kernel Regression between 6.1.0-35 and
> 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently
> dropped SEVERITY: normal
> 
> ===================================================================
> 
> Summary:
> This report details a regression in the Linux kernel that prevents
> IPv6 link-local all-nodes multicast packets (ff02::1) from being
> transmitted over a GRE tunnel. The issue is confirmed to have been
> introduced between kernel versions 6.1.0-35-cloud-amd64 (working) and
> 6.1.0-37-cloud-amd64 (failing) on Debian 12 (Bookworm).
> On affected kernels, the ping utility reports 100% packet loss, and a
> tcpdump on the underlying physical interface confirms that the kernel
> is silently dropping the encapsulated GRE packets instead of sending
> them. The sendto() system call does not return an error to the
> userspace application in the default namespace.
> 
> ===================================================================
> 
> Regression Point:
> Last Known Good Version: 6.1.0-35-cloud-amd64
> First Failing Version: 6.1.0-37-cloud-amd64
> The regression is also present in later kernels tested, including
> 6.12.33 and 6.15.x on Debian 13 (Trixie).
> 
> ===================================================================
> 
> Steps to Reproduce:
> Use a Debian system with an affected kernel (e.g., >= 6.1.0-37).
> Establish a GRE tunnel. Replace [PEER_IP] and [LOCAL_IP] with actual
> endpoint addresses.
> ip tunnel add tun_gre mode gre remote [PEER_IP] local [LOCAL_IP] ttl
> 255 ip link set tun_gre up
> In one terminal, start a tcpdump on the physical interface that
> provides the local IP, to monitor for outgoing GRE packets (GRE is IP
> protocol 47).
> tcpdump -i [PHYSICAL_IFACE] -n 'proto gre'
> In a second terminal, attempt to ping the link-local all-nodes
> multicast address via the GRE tunnel interface.
> ping ff02::1%tun_gre -c 4
> 
> ===================================================================
> 
> Observed Behavior (The Bug):
> The ping command runs and reports "4 packets transmitted, 0 received,
> 100% packet loss".
> The tcpdump window on the physical interface shows NO outgoing GRE
> packets. This proves the kernel is silently dropping the packets.
> 
> ===================================================================
> 
> Expected Behavior (as observed on kernel 6.1.0-35):
> The ping command runs.
> The tcpdump window shows outgoing GRE packets being sent from
> [LOCAL_IP] to [PEER_IP] for each ICMPv6 echo request. (Receiving a
> reply is dependent on the peer configuration, but the packets should
> be transmitted).
> 
> ===================================================================
> 
> Additional Diagnostic Information:
> VRF Context: When the failing GRE interface (tun_gre) is placed within
> a VRF, the failure mode changes. The ping or sendto() system call
> fails immediately with an ENETUNREACH (Network is unreachable) error.
> This is likely because the VRF routing table does not have a route to
> the tunnel's physical peer address, and the kernel correctly
> identifies this dependency issue.
> veth Control Test: The issue is specific to the gre tunnel interface
> type. A control test using a veth pair inside a VRF works perfectly
> for link-local multicast, proving the core VRF and multicast logic is
> sound.
> This detailed bracketing of the regression should provide a strong
> starting point for identifying the specific commit that introduced
> this behavior.

since you can reproduce the regression on all newer upstream versions
as well, can you please report in to upstream and report back here the
upstream report so we can follow its status.

Thanks already.

Regards,
Salvatore

> WARNING: *This email (including its attachments) may contain confidential 
> information protected by confidentiality agreements or other rights, and is 
> intended only for the designated recipient or individuals who need to know 
> it for the stated purpose. The recipient is prohibited from disclosing this 
> information to unauthorized parties without prior permission from MoeDove 
> LLC. If you have received this email in error, please notify the sender 
> immediately and delete this email and its attachments from your system. Any 
> use, dissemination, transmission, or copying of this email by someone other 
> than the intended recipient is prohibited and may be unlawful.*

Drop this when you send public bugreports, thanks.

[toc] | [prev] | [next] | [standalone]


#88372

FromAiden Yang <ling@moedove.com>
Date2025-07-12 16:20 +0200
Message-ID<L7Jf4-h62B-1@gated-at.bofh.it>
In reply to#88179
Hello,
Just a follow-up to report that the upstream kernel developers have
now merged a fix for this issue into the 'net' tree.
The official commit is:
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=4e914ef063de40397e25a025c70d9737a9e45a8c
The patch submission cover letter on the mailing list can be found
here, providing additional context:
https://lore.kernel.org/netdev/cover.1752070620.git.gnault@redhat.com/T/
I will be looking forward to seeing this fix in a future Debian kernel update.
Best regards,
Aiden Yang

Salvatore Bonaccorso <carnil@debian.org> 于2025年6月29日周日 03:17写道:
>
> Control: tags -1 + moreinfo
>
> On Sat, Jun 28, 2025 at 08:49:17PM +0800, Aiden Yang wrote:
> > PACKAGE: linux SUBJECT: Kernel Regression between 6.1.0-35 and
> > 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently
> > dropped SEVERITY: normal
> >
> > ===================================================================
> >
> > Summary:
> > This report details a regression in the Linux kernel that prevents
> > IPv6 link-local all-nodes multicast packets (ff02::1) from being
> > transmitted over a GRE tunnel. The issue is confirmed to have been
> > introduced between kernel versions 6.1.0-35-cloud-amd64 (working) and
> > 6.1.0-37-cloud-amd64 (failing) on Debian 12 (Bookworm).
> > On affected kernels, the ping utility reports 100% packet loss, and a
> > tcpdump on the underlying physical interface confirms that the kernel
> > is silently dropping the encapsulated GRE packets instead of sending
> > them. The sendto() system call does not return an error to the
> > userspace application in the default namespace.
> >
> > ===================================================================
> >
> > Regression Point:
> > Last Known Good Version: 6.1.0-35-cloud-amd64
> > First Failing Version: 6.1.0-37-cloud-amd64
> > The regression is also present in later kernels tested, including
> > 6.12.33 and 6.15.x on Debian 13 (Trixie).
> >
> > ===================================================================
> >
> > Steps to Reproduce:
> > Use a Debian system with an affected kernel (e.g., >= 6.1.0-37).
> > Establish a GRE tunnel. Replace [PEER_IP] and [LOCAL_IP] with actual
> > endpoint addresses.
> > ip tunnel add tun_gre mode gre remote [PEER_IP] local [LOCAL_IP] ttl
> > 255 ip link set tun_gre up
> > In one terminal, start a tcpdump on the physical interface that
> > provides the local IP, to monitor for outgoing GRE packets (GRE is IP
> > protocol 47).
> > tcpdump -i [PHYSICAL_IFACE] -n 'proto gre'
> > In a second terminal, attempt to ping the link-local all-nodes
> > multicast address via the GRE tunnel interface.
> > ping ff02::1%tun_gre -c 4
> >
> > ===================================================================
> >
> > Observed Behavior (The Bug):
> > The ping command runs and reports "4 packets transmitted, 0 received,
> > 100% packet loss".
> > The tcpdump window on the physical interface shows NO outgoing GRE
> > packets. This proves the kernel is silently dropping the packets.
> >
> > ===================================================================
> >
> > Expected Behavior (as observed on kernel 6.1.0-35):
> > The ping command runs.
> > The tcpdump window shows outgoing GRE packets being sent from
> > [LOCAL_IP] to [PEER_IP] for each ICMPv6 echo request. (Receiving a
> > reply is dependent on the peer configuration, but the packets should
> > be transmitted).
> >
> > ===================================================================
> >
> > Additional Diagnostic Information:
> > VRF Context: When the failing GRE interface (tun_gre) is placed within
> > a VRF, the failure mode changes. The ping or sendto() system call
> > fails immediately with an ENETUNREACH (Network is unreachable) error.
> > This is likely because the VRF routing table does not have a route to
> > the tunnel's physical peer address, and the kernel correctly
> > identifies this dependency issue.
> > veth Control Test: The issue is specific to the gre tunnel interface
> > type. A control test using a veth pair inside a VRF works perfectly
> > for link-local multicast, proving the core VRF and multicast logic is
> > sound.
> > This detailed bracketing of the regression should provide a strong
> > starting point for identifying the specific commit that introduced
> > this behavior.
>
> since you can reproduce the regression on all newer upstream versions
> as well, can you please report in to upstream and report back here the
> upstream report so we can follow its status.
>
> Thanks already.
>
> Regards,
> Salvatore
>
> > WARNING: *This email (including its attachments) may contain confidential
> > information protected by confidentiality agreements or other rights, and is
> > intended only for the designated recipient or individuals who need to know
> > it for the stated purpose. The recipient is prohibited from disclosing this
> > information to unauthorized parties without prior permission from MoeDove
> > LLC. If you have received this email in error, please notify the sender
> > immediately and delete this email and its attachments from your system. Any
> > use, dissemination, transmission, or copying of this email by someone other
> > than the intended recipient is prohibited and may be unlawful.*
>
> Drop this when you send public bugreports, thanks.

-- 

WARNING: *This email (including its attachments) may contain confidential 
information protected by confidentiality agreements or other rights, and is 
intended only for the designated recipient or individuals who need to know 
it for the stated purpose. The recipient is prohibited from disclosing this 
information to unauthorized parties without prior permission from MoeDove 
LLC. If you have received this email in error, please notify the sender 
immediately and delete this email and its attachments from your system. Any 
use, dissemination, transmission, or copying of this email by someone other 
than the intended recipient is prohibited and may be unlawful.*

[toc] | [prev] | [next] | [standalone]


#88180 — Processed: Re: Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-06-28 21:20 +0200
SubjectProcessed: Re: Bug#1108430: Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped
Message-ID<L2JfH-dPSu-7@gated-at.bofh.it>
In reply to#88175
Processing control commands:

> tags -1 + moreinfo
Bug #1108430 [src:linux] Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped
Added tag(s) moreinfo.

-- 
1108430: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108430
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [next] | [standalone]


#88373 — Bug#1108430: Acknowledgement (Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped)

FromAiden Yang <ling@moedove.com>
Date2025-07-12 16:20 +0200
SubjectBug#1108430: Acknowledgement (Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped)
Message-ID<L7Jf4-h62B-3@gated-at.bofh.it>
In reply to#88175
Hello,
Just a follow-up to report that the upstream kernel developers have
now merged a fix for this issue into the 'net' tree.
The official commit is:
https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=4e914ef063de40397e25a025c70d9737a9e45a8c
The patch submission cover letter on the mailing list can be found
here, providing additional context:
https://lore.kernel.org/netdev/cover.1752070620.git.gnault@redhat.com/T/
I will be looking forward to seeing this fix in a future Debian kernel update.
Best regards,
Aiden Yang

Debian Bug Tracking System <owner@bugs.debian.org> 于2025年6月28日周六 20:51写道:
>
> Thank you for filing a new Bug report with Debian.
>
> You can follow progress on this Bug here: 1108430: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108430.
>
> This is an automatically generated reply to let you know your message
> has been received.
>
> Your message is being forwarded to the package maintainers and other
> interested parties for their attention; they will reply in due course.
>
> Your message has been sent to the package maintainer(s):
>  Debian Kernel Team <debian-kernel@lists.debian.org>
>  unknown-package@qa.debian.org
>
> If you wish to submit further information on this problem, please
> send it to 1108430@bugs.debian.org.
>
> Please do not send mail to owner@bugs.debian.org unless you wish
> to report a problem with the Bug-tracking system.
>
> --
> 1108430: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108430
> Debian Bug Tracking System
> Contact owner@bugs.debian.org with problems

-- 

WARNING: *This email (including its attachments) may contain confidential 
information protected by confidentiality agreements or other rights, and is 
intended only for the designated recipient or individuals who need to know 
it for the stated purpose. The recipient is prohibited from disclosing this 
information to unauthorized parties without prior permission from MoeDove 
LLC. If you have received this email in error, please notify the sender 
immediately and delete this email and its attachments from your system. Any 
use, dissemination, transmission, or copying of this email by someone other 
than the intended recipient is prohibited and may be unlawful.*

[toc] | [prev] | [next] | [standalone]


#88492 — Bug#1108430: marked as done (Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped)

From"Debian Bug Tracking System" <owner@bugs.debian.org>
Date2025-07-22 21:20 +0200
SubjectBug#1108430: marked as done (Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped)
Message-ID<LbqGR-1Tf1-11@gated-at.bofh.it>
In reply to#88175

[Multipart message — attachments visible in raw view] — view raw

Your message dated Tue, 22 Jul 2025 18:00:11 +0000
with message-id <E1ueHHf-00Bhjh-08@fasolo.debian.org>
and subject line Bug#1108430: fixed in linux 6.16~rc7-1~exp1
has caused the Debian Bug report #1108430,
regarding Kernel Regression between 6.1.0-35 and 6.1.0-37: IPv6 link-local multicast over GRE tunnel is silently dropped
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1108430: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1108430
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web