Repository navigation
Conversation
The loop in dhcp6_dadcallback() checks DECLINE_IA(ia) instead of DECLINE_IA(ia2). Only the address whose DAD finished last is checked, so with multiple addresses a duplicate found earlier is never declined.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. WalkthroughThe DHCPv6 duplicate-address check now evaluates each address in the interface’s address list when it sets ChangesDHCPv6 duplicate-address detection
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~5 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to The DHCPv6 callback now checks each listed address before deciding whether to send DECLINE, addressing the missed-duplicate case. The surrounding completion and no-match handling remain intact, with no actionable merge risk identified. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
ColinMcInnes
left a comment
There was a problem hiding this comment.
Reasonable small change, minimal fix to address the issue. I see no problem with this.
Problem
When several DHCPv6 addresses are assigned and DAD fails for one of them,
no DECLINE is sent. The client runs BOUND6 and keeps using the
duplicated address.
Cause
In
dhcp6_dadcallback()the loop over all addresses checks the callbackargument
iainstead of the loop variableia2. So only the addressthat finished DAD last is checked. With a single address both are the
same, which hides the bug.
Testing
We found this in an automated test that requests 8 DHCPv6 addresses and
injects a conflicting Neighbor Advertisement for the first one while it
is still tentative. Without the fix, no DECLINE is sent. With the fix,
the client sends a DECLINE for the duplicated address.