On Thu, 10 Sep 2026 06:19:49 +0200,
"Theo de Raadt" <[email protected]> wrote:
> 
> We need to do something, or chrome will keep doing these coredumps.
>

I vote for your way. It is way simpler whan fixing the wild world, because
each fix needs someone to investigate why it crashes.

> > Kirill A. Korinsky <[email protected]> wrote:
> > 
> > > Seems that new chromium plays with TOS at UDP for HTTP/3 and our pledge
> > > prevents it, and kills the process. It dumps ~100Mb core and after that it
> > > fallback to HTTP/1.1.
> > 
> > We are encountering this too many places, so I'd like everyone to consider
> > this 2-step approach, becuase Linux dual-stack has utterly poisoned the
> > ecosystem and noone looks at setsockopt return values accurately.
> > 
> > 1. netinet6 accepts IPPROTO_IP/IP_TOS and converts it to 
> > IPPROTO_IPV6/IPV6_TCLASS
> > 
> > 2. For programs which are pledged, allow that through
> > 
> > Index: netinet6/ip6_output.c
> > ===================================================================
> > RCS file: /cvs/src/sys/netinet6/ip6_output.c,v
> > diff -u -p -u -r1.308 ip6_output.c
> > --- netinet6/ip6_output.c   5 Aug 2026 09:43:19 -0000       1.308
> > +++ netinet6/ip6_output.c   8 Sep 2026 23:53:46 -0000
> > @@ -1032,6 +1032,12 @@ ip6_ctloutput(int op, struct socket *so,
> >     privileged = (inp->inp_socket->so_state & SS_PRIV);
> >     uproto = (int)so->so_proto->pr_protocol;
> >  
> > +   /* Linux poisoned the ecosystem */
> > +   if (level == IPPROTO_IP && optname == IP_TOS) {
> > +           level = IPPROTO_IPV6;
> > +           optname = IPV6_TCLASS;
> > +   }
> > +
> >     if (level != IPPROTO_IPV6)
> >             return (EINVAL);
> >  
> > 
> > Index: kern/kern_pledge.c
> > ===================================================================
> > RCS file: /cvs/src/sys/kern/kern_pledge.c,v
> > diff -u -p -u -r1.365 kern_pledge.c
> > --- kern/kern_pledge.c      4 Sep 2026 02:38:28 -0000       1.365
> > +++ kern/kern_pledge.c      8 Sep 2026 23:37:52 -0000
> > @@ -1451,9 +1464,17 @@ pledge_sockopt(struct proc *p, int set, 
> >             }
> >             break;
> >     case AF_INET6:
> > -           if (level == IPPROTO_IPV6) {
> > +           switch (level) {
> > +           case IPPROTO_IPV6:
> >                     switch (optname) {
> >                     case IPV6_TCLASS:
> > +                           return (0);
> > +                   }
> > +                   break;
> > +           /* Because Linux makes the universe stink */
> > +           case IPPROTO_IP:
> > +                   switch (optname) {
> > +                   case IP_TOS:
> >                             return (0);
> >                     }
> >             }
> > 
> 

-- 
wbr, Kirill

Reply via email to