All of lore.kernel.org
 help / color / mirror / Atom feed
From: David Ahern <dsahern@kernel.org>
To: Alex Henrie <alexhenrie24@gmail.com>,
	netdev@vger.kernel.org, jbohac@suse.cz,
	benoit.boissinot@ens-lyon.org, davem@davemloft.net,
	hideaki.yoshifuji@miraclelinux.com, pabeni@redhat.com,
	kuba@kernel.org
Subject: Re: [PATCH net-next v2 2/4] net: ipv6/addrconf: clamp preferred_lft to the minimum required
Date: Wed, 25 Oct 2023 18:43:22 -0600	[thread overview]
Message-ID: <862dc7d4-d5a3-4a17-984b-d3dcc1015e61@kernel.org> (raw)
In-Reply-To: <20231024212312.299370-3-alexhenrie24@gmail.com>

On 10/24/23 3:23 PM, Alex Henrie wrote:
> If the preferred lifetime was less than the minimum required lifetime,
> ipv6_create_tempaddr would error out without creating any new address.
> On my machine and network, this error happened immediately with the
> preferred lifetime set to 1 second, after a few minutes with the
> preferred lifetime set to 4 seconds, and not at all with the preferred
> lifetime set to 5 seconds. During my investigation, I found a Stack
> Exchange post from another person who seems to have had the same
> problem: They stopped getting new addresses if they lowered the
> preferred lifetime below 3 seconds, and they didn't really know why.
> 
> The preferred lifetime is a preference, not a hard requirement. The
> kernel does not strictly forbid new connections on a deprecated address,
> nor does it guarantee that the address will be disposed of the instant
> its total valid lifetime expires. So rather than disable IPv6 privacy
> extensions altogether if the minimum required lifetime swells above the
> preferred lifetime, it is more in keeping with the user's intent to
> increase the temporary address's lifetime to the minimum necessary for
> the current network conditions.
> 
> With these fixes, setting the preferred lifetime to 3 or 4 seconds "just
> works" because the extra fraction of a second is practically
> unnoticeable. It's even possible to reduce the time before deprecation
> to 1 or 2 seconds by also disabling duplicate address detection (setting
> /proc/sys/net/ipv6/conf/*/dad_transmits to 0). I realize that that is a
> pretty niche use case, but I know at least one person who would gladly
> sacrifice performance and convenience to be sure that they are getting
> the maximum possible level of privacy.
> 
> Link: https://serverfault.com/a/1031168/310447
> Signed-off-by: Alex Henrie <alexhenrie24@gmail.com>
> ---
>  net/ipv6/addrconf.c | 18 +++++++++++++-----
>  1 file changed, 13 insertions(+), 5 deletions(-)
> 

Reviewed-by: David Ahern <dsahern@kernel.org>



  parent reply	other threads:[~2023-10-26  0:43 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-10-24 21:23 [PATCH net-next v2 0/4] net: ipv6/addrconf: ensure that temporary addresses' preferred lifetimes are in the valid range Alex Henrie
2023-10-24 21:23 ` [PATCH net-next v2 1/4] net: ipv6/addrconf: clamp preferred_lft to the maximum allowed Alex Henrie
2023-10-25 12:23   ` Jiri Pirko
2023-10-25 16:28     ` Alex Henrie
2023-10-26  5:11       ` Jiri Pirko
2023-10-26  0:41   ` David Ahern
2023-10-24 21:23 ` [PATCH net-next v2 2/4] net: ipv6/addrconf: clamp preferred_lft to the minimum required Alex Henrie
2023-10-25 12:25   ` Jiri Pirko
2023-10-26  0:43   ` David Ahern [this message]
2023-10-24 21:23 ` [PATCH net-next v2 3/4] Documentation: networking: explain what happens if temp_valid_lft is too small Alex Henrie
2023-10-26  0:43   ` David Ahern
2023-10-24 21:23 ` [PATCH net-next v2 4/4] Documentation: networking: explain what happens if temp_prefered_lft is too small or too large Alex Henrie
2023-10-26  0:44   ` David Ahern
2023-10-26  1:30 ` [PATCH net-next v2 0/4] net: ipv6/addrconf: ensure that temporary addresses' preferred lifetimes are in the valid range patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=862dc7d4-d5a3-4a17-984b-d3dcc1015e61@kernel.org \
    --to=dsahern@kernel.org \
    --cc=alexhenrie24@gmail.com \
    --cc=benoit.boissinot@ens-lyon.org \
    --cc=davem@davemloft.net \
    --cc=hideaki.yoshifuji@miraclelinux.com \
    --cc=jbohac@suse.cz \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.