Skip to content

igmp: fix IGMPv3()/IGMPv3mr() compatibility - #5223

Open
Jafaral wants to merge 1 commit into
secdev:masterfrom
Jafaral:igmpv3-fix
Open

Jafaral wants to merge 1 commit into
secdev:masterfrom
Jafaral:igmpv3-fix

Conversation

@Jafaral

@Jafaral Jafaral commented Oct 6, 2026 •

Copy link
Copy Markdown

Scapy 2.8 broke existing applications that still use the old API, IGMPv3() / IGMPv3mr(...).

The compatibility aliases are wrong. IGMPv3mr points at IGMPv3_MR, which already includes the IGMP header, and a bare IGMPv3() is built as an IGMPv1/v2 Membership Query. That stack sends an invalid report: a query with a second report glued on. On 2.7 the same call was one Membership Report (type 0x22).

FRR pimd reads the first IGMP type, treats the packet as a query, and installs no group. That broke FRR's IGMPv3 fragmentation topotest: FRRouting/frr#23533

A bare IGMPv3 stacked with a complete v3 message now keeps that message, so the old API builds one report again. IGMPv3_MQ and IGMPv3_MR are unchanged. Covered in test/scapy/layers/igmp.uts.

Scapy 2.8 aliases contrib IGMPv3mr to IGMPv3_MR, which already includes
the IGMP header, and IGMPv3() with no bytes was built as an IGMPv1/v2
query. The old stack therefore sends an invalid report: a Membership
Query with a second report glued on. Receivers such as FRR pimd treat
the packet as a query and install no group.

Drop the bare header when it is stacked with a complete v3 message.

This broke FRR's IGMPv3 fragmentation topotest:
FRRouting/frr#23533

Signed-off-by: Jafar Al-Gharaibeh <jafar@atcorp.com>
@Jafaral Jafaral changed the title igmp: keep IGMPv3()/IGMPv3mr() a single membership report igmp: fix IGMPv3()/IGMPv3mr() compatibility Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant