David Leadbeater <[email protected]> wrote:
> On Tue, Sep 08, 2026 at 05:55:31PM -0600, Theo de Raadt wrote:
> [...]
> > We are encountering this too many places, so I'd like everyone to consider
> > this 2-step approach, becuase Linux dual-stack has utterly poisoned the
> > ecosystem and noone looks at setsockopt return values accurately.
> >
> > 1. netinet6 accepts IPPROTO_IP/IP_TOS and converts it to
> > IPPROTO_IPV6/IPV6_TCLASS
>
> That doesn't match the Linux behaviour, it appears to store two values
> for a socket, the IP_TOS and the IPV6_TCLASS.
What?
None is interested in turning OpenBSD into a Linux clone, and their dual
stack behaviour is insecure and we simply won't do it
I don't understand your perspective on telling me what Linux does.
Noone cares, and that is not the goal.
The smaller goal is to allow software we find in the wild to still work
even when they make such stupid mistakes.
> > 2. For programs which are pledged, allow that through
>
> ...therefore I don't think the translation is needed, only this allowing
> setting IP_TOS for AF_INET6 (i.e. just the kern_pledge.c change
> in the diff).
What??
"allow setting?' Apply the diff and read the next lines.
if (level != IPPROTO_IPV6)
return (EINVAL);
Then read the chrome code to see what it does.
You have failed to grasp the variety and potential chain of failures
we are seeing in various pieces of software.
See, setsockopt does not set a single opt. It is a PAIRING, level + opt.
The level is rejected. Then the opt is rejected.
The code we are seeing trying to do IPPROTO_IP / IP_TOS on an AF_INET6
socket, and there is no way a non-dual-stack system can behave like a
Linux dual-stack system, because these out-of-spec setsockopt behaviours
are not defined in ANY STANDARD.