On Wed, 09 Sep 2026 01:55:31 +0200,
"Theo de Raadt" <[email protected]> wrote:
> 
> Kirill A. Korinsky <[email protected]> wrote:
> 
> > Seems that new chromium plays with TOS at UDP for HTTP/3 and our pledge
> > prevents it, and kills the process. It dumps ~100Mb core and after that it
> > fallback to HTTP/1.1.
> 
> We are encountering this too many places, so I'd like everyone to consider
> this 2-step approach, becuase Linux dual-stack has utterly poisoned the
> ecosystem and noone looks at setsockopt return values accurately.
> 
> 1. netinet6 accepts IPPROTO_IP/IP_TOS and converts it to 
> IPPROTO_IPV6/IPV6_TCLASS
> 
> 2. For programs which are pledged, allow that through
>

I think this is the correct solutio which allows to avoid patching open set
of software.

Chromium runs well here with this diff without my patch.

> Index: netinet6/ip6_output.c
> ===================================================================
> RCS file: /cvs/src/sys/netinet6/ip6_output.c,v
> diff -u -p -u -r1.308 ip6_output.c
> --- netinet6/ip6_output.c     5 Aug 2026 09:43:19 -0000       1.308
> +++ netinet6/ip6_output.c     8 Sep 2026 23:53:46 -0000
> @@ -1032,6 +1032,12 @@ ip6_ctloutput(int op, struct socket *so,
>       privileged = (inp->inp_socket->so_state & SS_PRIV);
>       uproto = (int)so->so_proto->pr_protocol;
>  
> +     /* Linux poisoned the ecosystem */
> +     if (level == IPPROTO_IP && optname == IP_TOS) {
> +             level = IPPROTO_IPV6;
> +             optname = IPV6_TCLASS;
> +     }
> +
>       if (level != IPPROTO_IPV6)
>               return (EINVAL);
>  
> 
> Index: kern/kern_pledge.c
> ===================================================================
> RCS file: /cvs/src/sys/kern/kern_pledge.c,v
> diff -u -p -u -r1.365 kern_pledge.c
> --- kern/kern_pledge.c        4 Sep 2026 02:38:28 -0000       1.365
> +++ kern/kern_pledge.c        8 Sep 2026 23:37:52 -0000
> @@ -1451,9 +1464,17 @@ pledge_sockopt(struct proc *p, int set, 
>               }
>               break;
>       case AF_INET6:
> -             if (level == IPPROTO_IPV6) {
> +             switch (level) {
> +             case IPPROTO_IPV6:
>                       switch (optname) {
>                       case IPV6_TCLASS:
> +                             return (0);
> +                     }
> +                     break;
> +             /* Because Linux makes the universe stink */
> +             case IPPROTO_IP:
> +                     switch (optname) {
> +                     case IP_TOS:
>                               return (0);
>                       }
>               }
> 

-- 
wbr, Kirill

Reply via email to