[PATCH 00/16 net-next v2] Allow compiling an IPv6-only kernel network stack
From: Fernando Fernandez Mancera <hidden>
Date: 2026-09-28 19:31:20
The primary goal of this patch series is to enable the compilation of an IPv6-only kernel by decoupling the core networking infrastructure from the IPv4 protocol. Historically, IPv4 has been intertwined with the generic socket and transport layers. By untangling these dependencies, this series allows systems to be built with CONFIG_IPV4 disabled. This configuration targets strict IPv6-only deployments, constrained environments, and specialized appliances where removing the IPv4 subsystem reduces the network attack surface. To provide some numbers, 0.3% (32) of the released CVEs since 2025 were strictly related to IPv4 code. While the number is low, it is good for users to be able to disable it if they do not depend on it. To achieve this, subsystems with hard dependencies on IPv4 were modified to use conditional compilation guards. When CONFIG_IPV4 is disabled, the affected packet manipulation routines and routing hooks evaluate to stubs returning standard error codes. The INDIRECT_CALL_INET macros within the transport layer were adapted to safely bypass IPv4 function pointers without penalizing the dual-stack fast paths. In addition, there has been several code splits for UDP, RAW, ICMP or Ping isolating the IPv4 specific code. Every Kconfig symbol that gained a new depends on IPV4 was audited against the code it guards, distinguishing genuine hard link-time dependencies from options that were only conservatively gated. Where a symbol never depended on CONFIG_INET before, depends on IPV4 || !INET is used instead of a bare dependency, so pre-existing CONFIG_INET=n configurations remain buildable as before. Finally, CONFIG_IPV4 is exposed in Kconfig as an explicit boolean, defaulting to 'y' to preserve existing configurations. The bloat-o-meter diff and size output for x86_64 with dualstack and IPv6 disabled: text data bss dec hex filename 31608053 8913174 1145484 41666711 27bc897 vmlinux.dual 28809691 8183494 1101724 38094909 245483d vmlinux.ipv6 add/remove: 53/19751 grow/shrink: 65/601 up/down: 740100/-3490467 (-2750367) Performance testing: Basic TCP performance validation was conducted using iperf3 on an AMD Ryzen 9 9950X between two bridged virtual machines. These benchmarks verify that there are no obvious performance regressions. Kernel / Configuration Traffic Type Offloads ON Offloads OFF ------------------------------------------------------------------------------- net-next (Dual-Stack Baseline) IPv4 20.8 Gbps 7.22 Gbps net-next (Dual-Stack Baseline) IPv6 20.4 Gbps 7.55 Gbps net-next (IPv4-Only Baseline) IPv4 20.9 Gbps 7.86 Gbps Patched (Dual-Stack) IPv4 21.8 Gbps 7.77 Gbps Patched (Dual-Stack) IPv6 21.7 Gbps 7.35 Gbps Patched (IPv4-Only) IPv4 20.9 Gbps 7.91 Gbps Patched (IPv6-Only) IPv6 21.1 Gbps 8.06 Gbps Follow-up for this series: Future work decoupled from this initial series includes expanding Kconfig adaptations across remaining kernel subsystems to support an IPv6-only environment. This includes patches for network bonding modes that assume dual-stack availability and analyze Netfilter nftables expressions and connection tracking to ensure pure IPv6 operations are fully independent. The main structural cost of this series is the code movement from splitting IPv4-specific logic into new files, which will make git blame and bisection across the affected files more cumbersome than a purely additive change. Where possible, IPv4-only branches were expressed as runtime IS_ENABLED() checks relying on dead-code elimination rather than ifdef blocks, to keep the preprocessor-guard footprint as small as possible. Fernando Fernandez Mancera (16): ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic tcp: move protocol agnostic TCP functions out of tcp_ipv4.c ipv4: raw: split IPv4 specific logic into raw_ipv4.c ipv4: udp: split IPv4 specific logic into udp_ipv4.c ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c ipv4: ping: split IPv4 specific logic into ping_ipv4.c ipv4: fib: split common nexthop logic to fib_core.c tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 net: bridge: guard ARP/RARP proxy and suppression with CONFIG_IPV4 wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency ipv4: make CONFIG_IPV4 boolean drivers/infiniband/Kconfig | 2 +- drivers/infiniband/sw/rxe/Kconfig | 2 +- drivers/net/Kconfig | 23 +- drivers/net/ethernet/chelsio/Kconfig | 2 +- drivers/net/ethernet/intel/Kconfig | 2 + drivers/net/ethernet/marvell/prestera/Kconfig | 1 + .../net/ethernet/mellanox/mlx5/core/Kconfig | 3 +- drivers/net/ethernet/mellanox/mlxsw/Kconfig | 1 + drivers/net/ethernet/qlogic/Kconfig | 2 + drivers/net/ethernet/rocker/Kconfig | 1 + drivers/net/ethernet/sfc/Kconfig | 1 + drivers/net/ethernet/stmicro/stmmac/Kconfig | 1 + drivers/net/ethernet/via/Kconfig | 1 + drivers/net/ppp/Kconfig | 1 + .../broadcom/brcm80211/brcmfmac/Kconfig | 1 + drivers/net/wireless/intel/iwlwifi/Kconfig | 1 + drivers/nvme/host/Kconfig | 2 +- drivers/nvme/target/Kconfig | 2 +- drivers/scsi/cxgbi/cxgb3i/Kconfig | 2 +- drivers/scsi/cxgbi/cxgb4i/Kconfig | 2 +- drivers/target/iscsi/Kconfig | 2 +- drivers/target/iscsi/cxgbit/Kconfig | 2 +- fs/Kconfig | 1 + fs/afs/Kconfig | 2 +- fs/nfs/Kconfig | 2 +- fs/nfsd/Kconfig | 2 +- include/linux/indirect_call_wrapper.h | 8 +- include/net/cipso_ipv4.h | 18 +- include/net/icmp.h | 1 + include/net/ip.h | 111 +- include/net/ip_fib.h | 27 +- include/net/route.h | 14 + include/net/tcp.h | 16 +- include/net/udp.h | 11 + net/Kconfig | 9 +- net/batman-adv/Kconfig | 6 +- net/bridge/Kconfig | 2 +- net/bridge/br_arp_nd_proxy.c | 2 +- net/bridge/br_device.c | 2 +- net/bridge/br_input.c | 2 +- net/bridge/netfilter/Kconfig | 3 +- net/core/Makefile | 2 +- net/core/dev_ioctl.c | 3 + net/core/fib_core.c | 307 +++ net/core/filter.c | 20 +- net/core/neighbour.c | 4 + net/ipv4/Kconfig | 29 +- net/ipv4/Makefile | 24 +- net/ipv4/af_inet.c | 126 +- net/ipv4/fib_frontend.c | 96 - net/ipv4/fib_semantics.c | 205 -- net/ipv4/icmp.c | 1418 +------------ net/ipv4/icmp_ipv4.c | 1448 +++++++++++++ net/ipv4/inet_connection_sock.c | 2 +- net/ipv4/inet_hashtables.c | 3 + net/ipv4/ip_output.c | 18 - net/ipv4/ip_tunnel_core.c | 11 + net/ipv4/netfilter.c | 3 + net/ipv4/netfilter/Kconfig | 2 +- net/ipv4/nexthop.c | 5 +- net/ipv4/ping.c | 210 +- net/ipv4/ping_ipv4.c | 228 +++ net/ipv4/proc.c | 45 +- net/ipv4/raw.c | 853 -------- net/ipv4/raw_diag.c | 3 +- net/ipv4/raw_ipv4.c | 883 ++++++++ net/ipv4/sysctl_net_ipv4.c | 413 ++-- net/ipv4/tcp.c | 1300 +++++++++++- net/ipv4/tcp_bpf.c | 3 +- net/ipv4/tcp_ipv4.c | 1307 +----------- net/ipv4/udp.c | 1817 +---------------- net/ipv4/udp_bpf.c | 5 +- net/ipv4/udp_ipv4.c | 1790 ++++++++++++++++ net/ipv4/udp_offload.c | 3 + net/ipv6/Kconfig | 17 +- net/ipv6/af_inet6.c | 5 + net/ipv6/datagram.c | 4 +- net/ipv6/netfilter/Kconfig | 2 +- net/ipv6/tcp_ipv6.c | 23 +- net/ipv6/udp.c | 11 +- net/l2tp/Kconfig | 2 +- net/mac80211/main.c | 10 +- net/mptcp/Kconfig | 2 +- net/netfilter/Kconfig | 2 +- net/netfilter/ipset/Kconfig | 2 +- net/netfilter/ipvs/Kconfig | 2 +- net/netlabel/Kconfig | 4 + net/netlabel/Makefile | 2 +- net/netlabel/netlabel_cipso_v4.h | 7 + net/netlabel/netlabel_kapi.c | 3 + net/rds/Kconfig | 1 + net/rxrpc/Kconfig | 2 +- net/sched/Kconfig | 2 +- net/sctp/Kconfig | 2 +- net/sunrpc/Kconfig | 2 +- net/tipc/Kconfig | 1 + net/xfrm/Kconfig | 10 +- 97 files changed, 6738 insertions(+), 6262 deletions(-) create mode 100644 net/core/fib_core.c create mode 100644 net/ipv4/icmp_ipv4.c create mode 100644 net/ipv4/ping_ipv4.c create mode 100644 net/ipv4/raw_ipv4.c create mode 100644 net/ipv4/udp_ipv4.c -- 2.55.0