On Tue, Sep 08, 2026 at 05:55:31PM -0600, Theo de Raadt wrote:
[...]
> We are encountering this too many places, so I'd like everyone to consider
> this 2-step approach, becuase Linux dual-stack has utterly poisoned the
> ecosystem and noone looks at setsockopt return values accurately.
>
> 1. netinet6 accepts IPPROTO_IP/IP_TOS and converts it to
> IPPROTO_IPV6/IPV6_TCLASS
That doesn't match the Linux behaviour, it appears to store two values
for a socket, the IP_TOS and the IPV6_TCLASS.
> 2. For programs which are pledged, allow that through
...therefore I don't think the translation is needed, only this allowing
setting IP_TOS for AF_INET6 (i.e. just the kern_pledge.c change
in the diff).
> Index: kern/kern_pledge.c
> ===================================================================
> RCS file: /cvs/src/sys/kern/kern_pledge.c,v
> diff -u -p -u -r1.365 kern_pledge.c
> --- kern/kern_pledge.c 4 Sep 2026 02:38:28 -0000 1.365
> +++ kern/kern_pledge.c 8 Sep 2026 23:37:52 -0000
> @@ -1451,9 +1464,17 @@ pledge_sockopt(struct proc *p, int set,
> }
> break;
> case AF_INET6:
> - if (level == IPPROTO_IPV6) {
> + switch (level) {
> + case IPPROTO_IPV6:
> switch (optname) {
> case IPV6_TCLASS:
> + return (0);
> + }
> + break;
> + /* Because Linux makes the universe stink */
> + case IPPROTO_IP:
> + switch (optname) {
> + case IP_TOS:
> return (0);
> }
> }
>