Bug 2223204
| Summary: | Rootful IPv6 masquerade does not route packets | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | François Rigault <francois.rigault> |
| Component: | podman | Assignee: | Matthew Heon <mheon> |
| Status: | NEW --- | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 39 | CC: | bbaude, container-sig, debarshir, dwalsh, go-sig, jnovy, lsm5, mheon, patrick, rh.container.bot, santiago |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://github.com/containers/netavark/issues/636 | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
François Rigault
2023-07-16 14:13:13 UTC
This is a known problem specific to localhost. Localhost masquerade with IPv4 is allowed by the kernel, but not localhost IPv6 masquerade (my understanding is that this is for security reasons, but I'm not entirely familiar with why it is a security issue). We've considered ways around this (which mostly amount to opening the sockets ourselves and forwarding traffic manually) but such a fix is currently low priority given that the forwarding does function correctly aside from localhost issues and the implications of having to maintain our own local forwarder. ok thanks for the feedback. For my particular use case I could use Kind apiServerAddress option, so I am not impacted by this behavior at all. https://github.com/kubernetes-sigs/kind/blob/3610f606516ccaa88aa098465d8c13af70937050/site/content/docs/user/configuration.md?plain=1#L161 This bug appears to have been reported against 'rawhide' during the Fedora Linux 39 development cycle. Changing version to 39. |