On Thu, 10 Sep 2026 06:19:49 +0200, "Theo de Raadt" <[email protected]> wrote: > > We need to do something, or chrome will keep doing these coredumps. >
I vote for your way. It is way simpler whan fixing the wild world, because each fix needs someone to investigate why it crashes. > > Kirill A. Korinsky <[email protected]> wrote: > > > > > Seems that new chromium plays with TOS at UDP for HTTP/3 and our pledge > > > prevents it, and kills the process. It dumps ~100Mb core and after that it > > > fallback to HTTP/1.1. > > > > We are encountering this too many places, so I'd like everyone to consider > > this 2-step approach, becuase Linux dual-stack has utterly poisoned the > > ecosystem and noone looks at setsockopt return values accurately. > > > > 1. netinet6 accepts IPPROTO_IP/IP_TOS and converts it to > > IPPROTO_IPV6/IPV6_TCLASS > > > > 2. For programs which are pledged, allow that through > > > > Index: netinet6/ip6_output.c > > =================================================================== > > RCS file: /cvs/src/sys/netinet6/ip6_output.c,v > > diff -u -p -u -r1.308 ip6_output.c > > --- netinet6/ip6_output.c 5 Aug 2026 09:43:19 -0000 1.308 > > +++ netinet6/ip6_output.c 8 Sep 2026 23:53:46 -0000 > > @@ -1032,6 +1032,12 @@ ip6_ctloutput(int op, struct socket *so, > > privileged = (inp->inp_socket->so_state & SS_PRIV); > > uproto = (int)so->so_proto->pr_protocol; > > > > + /* Linux poisoned the ecosystem */ > > + if (level == IPPROTO_IP && optname == IP_TOS) { > > + level = IPPROTO_IPV6; > > + optname = IPV6_TCLASS; > > + } > > + > > if (level != IPPROTO_IPV6) > > return (EINVAL); > > > > > > Index: kern/kern_pledge.c > > =================================================================== > > RCS file: /cvs/src/sys/kern/kern_pledge.c,v > > diff -u -p -u -r1.365 kern_pledge.c > > --- kern/kern_pledge.c 4 Sep 2026 02:38:28 -0000 1.365 > > +++ kern/kern_pledge.c 8 Sep 2026 23:37:52 -0000 > > @@ -1451,9 +1464,17 @@ pledge_sockopt(struct proc *p, int set, > > } > > break; > > case AF_INET6: > > - if (level == IPPROTO_IPV6) { > > + switch (level) { > > + case IPPROTO_IPV6: > > switch (optname) { > > case IPV6_TCLASS: > > + return (0); > > + } > > + break; > > + /* Because Linux makes the universe stink */ > > + case IPPROTO_IP: > > + switch (optname) { > > + case IP_TOS: > > return (0); > > } > > } > > > -- wbr, Kirill
