Skip to content

[CHERRY-PICK] wg-quick: linux: do not unnecessarily set sysctl - #45

Open
texhobeer wants to merge 1 commit into
amnezia-vpn:masterfrom
texhobeer:dev/cherry-pick-sysctl-bug
Open

[CHERRY-PICK] wg-quick: linux: do not unnecessarily set sysctl#45
texhobeer wants to merge 1 commit into
amnezia-vpn:masterfrom
texhobeer:dev/cherry-pick-sysctl-bug

Conversation

@texhobeer

Copy link
Copy Markdown

Found a bug in some scenario while using docker. There is a fix in original WG-Quick repo for it already. TBH, I don't know the sync process of the repo, probably the maintainers are going to update the repo in the nearest future... Anyway, PTAL

--- Original commit comment ---
In some restrictive container namespaces, sysctl is locked down and can't be changed. This shouldn't be a problem, though, at least in theory, because net.ipv4.conf.all.src_valid_mark is already 1. However, currently wg-quick unconditionally sets it. Instead, check to see if it's already 1 before trying make it 1.

Suggested-by: Dean P dean@apakossa.org

In some restrictive container namespaces, sysctl is locked down and
can't be changed. This shouldn't be a problem, though, at least in
theory, because net.ipv4.conf.all.src_valid_mark is already 1. However,
currently wg-quick unconditionally sets it. Instead, check to see if
it's already 1 before trying make it 1.

Suggested-by: Dean P <dean@apakossa.org>
Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants