From 717c1c02f107d7f978171e4e49c2ca3a250c4e70 Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Thu, 29 Jan 2026 20:40:17 +0000 Subject: [PATCH] confd: use force_forwarding sysctl for IPv6 Introduced in Linux 6.17, the force_forwding flag corresponds to the ipv4 forwarding flag, which maps perfectly to the ietf-ip.yang model. Fixes #515 Signed-off-by: Joachim Wiberg --- src/confd/src/interfaces.c | 38 +------------------------------------- 1 file changed, 1 insertion(+), 37 deletions(-) diff --git a/src/confd/src/interfaces.c b/src/confd/src/interfaces.c index ddf42605..86639ebd 100644 --- a/src/confd/src/interfaces.c +++ b/src/confd/src/interfaces.c @@ -337,7 +337,7 @@ static int netdag_gen_sysctl(struct dagger *net, node = lydx_get_descendant(lyd_child(dif), "ipv6", "forwarding", NULL); err = err ? : netdag_gen_sysctl_setting(net, ifname, &sysctl, 1, "0", node, - "net.ipv6.conf.%s.forwarding", ifname); + "net.ipv6.conf.%s.force_forwarding", ifname); if (!strcmp(ifname, "lo")) /* skip for now */ goto skip_mtu; @@ -353,39 +353,6 @@ skip_mtu: return err; } -/* - * The global IPv6 forwarding lever is off by default, enabled when any - * interface has IPv6 forwarding enabled. - */ -static int netdag_ipv6_forwarding(struct lyd_node *cifs, struct dagger *net) -{ - struct lyd_node *cif; - FILE *sysctl = NULL; - int ena = 0; - - LYX_LIST_FOR_EACH(cifs, cif, "interface") - ena |= lydx_is_enabled(lydx_get_child(cif, "ipv6"), "forwarding"); - - if (ena) - sysctl = dagger_fopen_next(net, "init", "@post", NETDAG_INIT_POST, "ipv6.sysctl"); - else - sysctl = dagger_fopen_current(net, "exit", "@pre", NETDAG_EXIT_PRE, "ipv6.sysctl"); - if (!sysctl) { - /* - * Cannot create exit code in gen: -1. Safe to ignore - * since ipv6 forwarding is disabled by default. - */ - if (dagger_is_bootstrap(net) && !ena) - return 0; - return -EIO; - } - - fprintf(sysctl, "net.ipv6.conf.all.forwarding = %d\n", ena); - fclose(sysctl); - - return 0; -} - static int dummy_gen(struct lyd_node *dif, struct lyd_node *cif, FILE *ip) { const char *ifname = lydx_get_cattr(cif, "name"); @@ -782,9 +749,6 @@ static sr_error_t ifchange_post(sr_session_ctx_t *session, struct dagger *net, { int err = 0; - /* Figure out value of global IPv6 forwarding flag. Issue #785 */ - err |= netdag_ipv6_forwarding(cifs, net); - /* For each configured bridge, the corresponding multicast * querier settings depend on both the bridge config and on * the presence of matching VLAN uppers. Since these can be