Could be an indication that in the long run, just forcing applications that need both protocols to have separation so you are sure of what they are doing was the correct choice.
eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
11–20 of 35 posts
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#12Just run
sysctl -w net.ipv6.bindv6only=1
so IPv6 will not include IPv4-mapped addresses.https://www.kernel.org/doc/Documentation/networking/ip-sysct...
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#13If you think that's wild, just wait until you learn about 6to4 [1] (not to be confused with 6over4 [2] ...) TL;DR: Given a globally unique IPv4 address, you can create automatic tunneling IPv6 networks with the IPv4 address embedded into the IPv6 address space. [1] https://en.wikipedia.org/wiki/6to4 [2] https://en.wikipedia.org/wiki/6over4
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#14For Linux, there's a kernel setting for that. Just run sysctl -w net.ipv6.bindv6only=1 so IPv6 will not include IPv4-mapped addresses. https://www.kernel.org/doc/Documentation/networking/ip-sysct...
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#15If you think that's wild, just wait until you learn about 6to4 [1] (not to be confused with 6over4 [2] ...) TL;DR: Given a globally unique IPv4 address, you can create automatic tunneling IPv6 networks with the IPv4 address embedded into the IPv6 address space. [1] https://en.wikipedia.org/wiki/6to4 [2] https://en.wikipedia.org/wiki/6over4
It's a mess when you learn there are also 6in4, 6rd and teredo...
Not just that, but also 4in6 (IPv4 in modern networks) and 4over6 (an extension to DS-Lite), and don't forget 6in4 being called SIT in an early draft, followed by SIIT being used in another protocol with a similar purpose (though that's more of a "Linux kept the old name around while everyone else moved on" problem).
Like most actually-used transition mechanisms, 6rd the result of someone inventing a transition strategy for a very specific use case, a company with that use case actually using that solution, and followed by standardization for good measure.
6to4 has been disabled for a few in Windows and has been disabled by default in Windows 11 since release, so in practice you probably won't see it outside of legacy networks and the routing systems designed to support 6rd or legacy networks.
Teredo was a weird Microsoft thing (like so many other network protocols) that could've replaced stupid shit like STUN and TURN had it been used. I'm pretty sure only Microsoft ever bothered to host Teredo servers to the mainstream. It would've been nice to live in a world where STUN and TURN worked for any protocol without having to set up your own servers rather than just supporting UDP and the server of an ad company (like we use today).
6in4 was a naive attempt at making the transition to IPv6 possible in the very early days (1996). It's the response to all of the "what if we just added a bunch of bits to IPv4" suggestion, and it turns out that nobody who says that actually seriously cares about supporting IPv6.
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#16I think of that as the opposite - an IPv6 socket pretending to be IPv4 in order to route to an IPv4 endpoint.
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#17I think OpenBSD (and other OSes) that do not allow v4 on v6 sockets might be on to something. It was felt convenient for application programmers to only have to listen to one socket for two protocols, but then code after needs to make very sure they know how to handle both families in the correct way for logging and so on, and now much later on it confuses someone that has to dig very deep into why the v4-box talks v…
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#18For Linux, there's a kernel setting for that. Just run sysctl -w net.ipv6.bindv6only=1 so IPv6 will not include IPv4-mapped addresses. https://www.kernel.org/doc/Documentation/networking/ip-sysct...
(I should try this, not entirely sure tbh.)
It won't help you though if the resolver library gives you a ::ffff:ma.p.p.ed address (yes they can do that), then you just fail to connect…
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#19I think OpenBSD (and other OSes) that do not allow v4 on v6 sockets might be on to something. It was felt convenient for application programmers to only have to listen to one socket for two protocols, but then code after needs to make very sure they know how to handle both families in the correct way for logging and so on, and now much later on it confuses someone that has to dig very deep into why the v4-box talks v…
are there actually other OSes doing this?
(- by default?)
Re: eBPF Mystery: When is IPv4 not IPv4? When it's pretending to be IPv6
#20I mean... it's literally one of the officially defined unicast IPv6 address types. If you ever read the Wikipedia page to learn about what link-local, global unicast, etc. addresses are you surely would have seen it.