From nobody Sun Mar 1 13:31:35 2026 X-Original-To: bugs@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fP2yv6ZZjz6SysH for ; Sun, 01 Mar 2026 13:31:35 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fP2yv63Ybz45Cq for ; Sun, 01 Mar 2026 13:31:35 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1772371895; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=hbKOzocaBM/404PWV/1UTBd6Yd5W5iktrsRS0WqPk5w=; b=qf/hr0lCWGIvSzmLmtS9cy7ip+bNVeohuHruLsIcVFxNSkGObs4rv8FrC4N//Ro11UTwwv /sE4Rc0S+JORkK2jCYCWmmxWlyNOuz5WE9CMp25Vc17JwZcNSJHtjAV7I2LvlC6+7P7U74 ZMxy/B5AoW24NFOoExq2lhsByPe0p6SS5A72zf8iJDKwLRZbYCiGhiv5hQ7Or0W5D8BxEU TJyYfbVgJ8nxvqvorPIQrLda+/68FnEiCh0oMVW8NWfjxZYR/cDjv1HiYIICwGMQa9fDcM M3ay9TbcjrVyMN05xTWz4kawOeeBfyWFxIQTVzBAqQRt1ZqM03bSS2g617C6cw== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1772371895; a=rsa-sha256; cv=none; b=fDobSuQU5533GVub1168JRapyRT8i79+ba7zQeVCiaYiacV6qQelpQLLuaKRZ2IC/RZ4tv nkmsY6bgLmk4Tt15Kgd5JWx8zzePwCq2e5nB6nNjsNDllgGnXYm7Kn7BLPmRU6D6Mnj3Ke IccTVLe20CFD3hdSWB5Flpe9DSua9dM1zJnjIu/KaTG0bLxSmDnyBoJPalVdDtDiPjAHLw wZYtR3pkgnCnjK6bGt6yeLGZAGY2sFt54jCw2dcPvnAB0+MA2GaNeeuPe0kjRfYH8FRcdu wIqEIytc3eJSeX4oLT3P2OzzNq6SKDvZG/cAvbCPqaislRkCV1iUQQDOtn6p3A== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1772371895; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=hbKOzocaBM/404PWV/1UTBd6Yd5W5iktrsRS0WqPk5w=; b=scVPaJc59i8mNyTo9N1Nfzp8EhQzksOtMGrpAN8HF4Da6AsQzm2fWDY/0QhNLL36jjeqPy 3rN8C3Tjo+rGe2/DKK0HCjtItonTMkSqGY13jkVdVj+VzAStSg6h6xQYNtQEj8h479R1Po HeMsL+u0FsTOkw639BMRbeuBGo6VKQMwpVuIamxEVLOWB3MACRQJLrx8ZDJllRxuRBPM5q 4R4pLIYdgIETXJPT9gw217HkgLkQA7c3YRlKHs3UcAFNdH88uetEd7THG8CqBamxtYIK6I ViVAsyPcB9+CS1/ukFWlLto00n8yjdEIkLYTtqUDNuTAUKOWJODjBB2AuXw37w== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4fP2yv5f2Czrg3 for ; Sun, 01 Mar 2026 13:31:35 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 621DVZ0G039372 for ; Sun, 1 Mar 2026 13:31:35 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 621DVZcn039361 for bugs@FreeBSD.org; Sun, 1 Mar 2026 13:31:35 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: bugs@FreeBSD.org Subject: [Bug 293525] netinet6: IPV6_MINHOPCOUNT is missing (IPv6 support for RFC 5082) Date: Sun, 01 Mar 2026 13:31:35 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: new X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Many People X-Bugzilla-Who: bms@FreeBSD.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: bugs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_id short_desc product version rep_platform op_sys bug_status bug_severity priority component assigned_to reporter Message-ID: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Bug reports List-Archive: https://lists.freebsd.org/archives/freebsd-bugs List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-bugs@FreeBSD.org MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D293525 Bug ID: 293525 Summary: netinet6: IPV6_MINHOPCOUNT is missing (IPv6 support for RFC 5082) Product: Base System Version: CURRENT Hardware: Any OS: Any Status: New Severity: Affects Many People Priority: --- Component: kern Assignee: bugs@FreeBSD.org Reporter: bms@FreeBSD.org Normative reference: https://datatracker.ietf.org/doc/html/rfc5082 This is not an immediate priority for me at the moment, however, it is prob= ably out of scope for delegating to a GSoC student, and needs to be handled for IXP/route-reflector consumers in particular, as FRR/BIRD and others use thi= s. It can be considered part of the minimum viable product (MVP) for a secure route reflector in that regard. Passing it back up the transport layer is another issue which I will raise a separate Bugzilla for to track the chang= e. OpenBSD has this already, cherry-picking the change should be a drop-in: https://sourcegraph.com/r/github.com/openbsd/src/-/commit/e5ff19c718a7f8106= 479296f9aa531519e06c0f7 rwatson touched the IPv4 path for this, IP_MINTTL, a long long time ago: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D128790 Then IP_MINTTL broke in the 11-STABLE, 12-CURRENT lifetime, fixed by ae@: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D239799 NOTE: As of writing, the svnweb links for the relevant commits are down. Here's the LLM prompt and output, good for a week from 2026-02-28: https://search.brave.com/ask?q=3DDo+FreeBSD+or+Linux+implement+RFC+5082%2C+= The+Generalized+TTL+Security+Mechanism+%28GTSM%29+%3F&conversation=3D08caf1= 32688a19b59df3fa68b90435890ead#TSdEZVG_Da_N9qbmjzDxylNgz3sKI0joIaDZDCBqdBY Parrot: "As noted in a 2011 mailing list discussion, ICMP packets are not passed with their TTL to upper-layer protocols, making it impossible to enforce GTSM on ICMP error messages without kernel modifications." --=20 You are receiving this mail because: You are the assignee for the bug.=