From: Thomas Haller <thaller@redhat.com>
To: Hannes Frederic Sowa <hannes@stressinduktion.org>
Cc: Jiri Pirko <jiri@resnulli.us>,
netdev@vger.kernel.org, stephen@networkplumber.org
Subject: Re: [patch iproute2 v2 0/2] add support for IFA_F_MANAGETEMPADDR
Date: Sat, 04 Jan 2014 12:21:51 +0100 [thread overview]
Message-ID: <1388834511.7407.5.camel@weing> (raw)
In-Reply-To: <20140104111546.GB25828@order.stressinduktion.org>
[-- Attachment #1: Type: text/plain, Size: 1554 bytes --]
Hi,
On Sat, 2014-01-04 at 12:15 +0100, Hannes Frederic Sowa wrote:
> On Sat, Jan 04, 2014 at 12:05:57PM +0100, Jiri Pirko wrote:
> > Sure. NM should set use_tempaddr accordingly. You are right that kernel
> > generate temporary adresses, but only for the prefixes received via
> > neighbor discovery (see addrconf_prefix_rcv). The ones that are set by
> > hand are not handled. That is the reason we introduced IFA_F_MANAGETEMPADDR.
>
> Ah, sorry. So NM sets use_tempaddr == 2 but disables accept_ra? That's fine,
> sorry to bother!
yes, that is the plan. use_tempaddr is to configure the preference for
address selection, and without accept_ra, the kernel will not add
autoconf addresses himself -- only NM adds them with
IFA_F_MANAGETEMPADDR. I think this will work out fine.
>
> > >So currently privacy addresses are correctly installed, but we cannot control
> > >if we want prefer them to global addresses for outgoing connections where the
> > >socket is not bound to a specific address.
> > >
> > >Also, I saw that NetworkManager switched to install autoconf addresses
> > >as /128, doesn't this break with IFA_F_MANAGETEMPADDR, as you expect a /64
> > >prefixlen?
> >
> > /64 is required
>
> Ok, currently NM seems to "violate" that as it installs autoconf addresses
> with 128 prefixlen, so IFA_F_MANAGETEMPADDR should not work on them.
> (currently observed on Fedora 20).
True, I noticed that too. I think that is a bug in NM to add the
addresses as /128. Probably, we will fix that soon.
Thomas
[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 819 bytes --]
next prev parent reply other threads:[~2014-01-04 11:22 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-01-02 15:34 [patch iproute2 v2 0/2] add support for IFA_F_MANAGETEMPADDR Jiri Pirko
2014-01-02 15:34 ` [patch iproute2 v2 1/2] add support for extended ifa_flags Jiri Pirko
2014-01-02 15:34 ` [patch iproute2 v2 2/2] add support for IFA_F_MANAGETEMPADDR Jiri Pirko
2014-01-02 15:50 ` [PATCH 1/1] fixup! " Thomas Haller
2014-01-04 10:44 ` Jiri Pirko
2014-01-02 17:29 ` [patch iproute2 v2 0/2] " Hannes Frederic Sowa
2014-01-04 10:43 ` Jiri Pirko
2014-01-04 10:55 ` Hannes Frederic Sowa
2014-01-04 11:05 ` Jiri Pirko
2014-01-04 11:15 ` Hannes Frederic Sowa
2014-01-04 11:21 ` Thomas Haller [this message]
2014-01-04 11:35 ` Hannes Frederic Sowa
2014-01-06 15:41 ` Thomas Haller
2014-01-06 16:01 ` Hannes Frederic Sowa
2014-01-06 17:29 ` [PATCH 1/1] ipv6 addrconf: add IFA_F_NOPREFIXROUTE flag to suppress creation of IP6 routes Thomas Haller
2014-01-06 17:38 ` Jiri Pirko
2014-01-07 9:39 ` Hannes Frederic Sowa
2014-01-07 12:01 ` Hannes Frederic Sowa
2014-01-07 12:14 ` Thomas Haller
2014-01-07 12:22 ` Hannes Frederic Sowa
2014-01-07 14:39 ` [PATCH v2 0/2] " Thomas Haller
2014-01-07 14:39 ` [PATCH v2 1/2] " Thomas Haller
2014-01-07 14:39 ` [PATCH v2 2/2] ipv6 addrconf: don't cleanup route prefix for IFA_F_NOPREFIXROUTE Thomas Haller
2014-01-07 16:28 ` Hannes Frederic Sowa
2014-01-07 18:32 ` Thomas Haller
2014-01-07 19:01 ` Hannes Frederic Sowa
2014-01-07 22:54 ` Thomas Haller
2014-01-07 23:09 ` Hannes Frederic Sowa
2014-01-07 16:03 ` [PATCH v2 0/2] ipv6 addrconf: add IFA_F_NOPREFIXROUTE flag to suppress creation of IP6 routes Hannes Frederic Sowa
2014-01-07 21:42 ` Thomas Haller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1388834511.7407.5.camel@weing \
--to=thaller@redhat.com \
--cc=hannes@stressinduktion.org \
--cc=jiri@resnulli.us \
--cc=netdev@vger.kernel.org \
--cc=stephen@networkplumber.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).