Hi David,
We used the following config:
log syslog all;
log "/var/logs/bird.log" { info, remote, warning, error, auth, fatal, bug, trace, debug };
router id 127.0.0.1;
debug protocols all; # Bug occurs only when tracing is enabled.

watchdog warning 5 s;
watchdog timeout 30 s;

protocol kernel {
   scan time 10;
   ipv4 { export all; };
}

protocol kernel {
   scan time 10;
   ipv6 { export all; };
}

protocol device {
    scan time 15;
}

protocol direct DIRECT {
    ipv4;
    ipv6;
    interface "lo*";
    interface "eth*";
}

neighbor table peers;
protocol radv {
    neighbors { table peers; };

    interface "eth*" {
        router discovery yes;
        max ra interval 4;
    };
}

protocol bgp bgp_root {
    local as 65000;
    hold time 9;
    graceful restart time 30;
    connect retry time 5;

    neighbor range fe80::/64 external;
    interface range "eth*";
    strict bind yes;

    ipv4 {
        export all;
        import all;
        extended next hop;
    };

    ipv6 {
        export all;
        import all;
    };

    neighbors {
        table peers;
        export all;
    };
}

Regards, Michal


From: David Petera via Bird-users <bird-users@network.cz>
Date: Friday, 25 September 2026 at 15:35
To: bird-users@network.cz <bird-users@network.cz>
Subject: Re: Crash on radv protocol when tracing is enabled

This Message Is From an External Sender
This message came from outside your organization.
 

Hii Michal,

thanks a lot for the report and patch! I have moved it to our internal issues, so devs can look at it and merge it.

I briefly tried to reproduce it with our RAdv test setups, but was unable to, could you also sent us the config so we can add similar case to our integration tests?

Would help us a lot.

Thanks again and happy routing,
David

David Petera (he/him) | BIRD Tech Support | CZ.NIC, z.s.p.o.
On 9/24/26 11:14, Strzadala, Michal via Bird-users wrote:
Hello, 
We've been experiencing bird crashes while using the radv protocol with enabled tracing on v2.19.2 (master branch is also affected). I've found that wrong struct is casted and forwarded into RADV_TRACE macro causing "bug("unknown network type")" and SIGABRT at the end.

Patch:

diff --git a/proto/radv/radv.c b/proto/radv/radv.c

index 7c2e8953..db2910b6 100644

--- a/proto/radv/radv.c

+++ b/proto/radv/radv.c

@@ -291,29 +291,30 @@ radv_prune_neighbors(struct radv_proto *p)

     {

       /* Only process routes from our protocol */

       if (e->src != p->p.main_source)

-       continue;

+        continue;

 

       /* Get the expiration time EA */

       eattr *expires_ea = ea_find(e->attrs->eattrs, EA_RA_LIFETIME);

       if (!expires_ea)

-       continue;

+        continue;

 

       btime expires = expires_ea->u.data S;

 

       if (expires <= now)

       {

-       /* Neighbor has expired, add to withdrawal list */

-       net_addr_nbr *nbr = (net_addr_nbr *) e->net;

+        /* Neighbor has expired, add to withdrawal list */

+        net_addr_nbr *nbr = (net_addr_nbr *) n->n.addr;

 

-       struct expired_nbr *ep = tmp_allocz(sizeof(struct expired_nbr));

-       net_copy_nbr(&ep->n, nbr);

-       ep->next = expired_list;

-       expired_list = ep;

+        struct expired_nbr *ep = tmp_allocz(sizeof(struct expired_nbr));

+        net_copy_nbr(&ep->n, nbr);

+        ep->next = expired_list;

+        expired_list = ep;

 

-       RADV_TRACE(D_EVENTS, "Router %N expired", nbr);

+        RADV_TRACE(D_EVENTS, "Router %N expired", nbr);

+      }

+      else {

+        next = MIN(next, expires);

       }

-      else

-       next = MIN(next, expires);

     }

   }

   FIB_WALK_END;


Regards, Michal