Bug #338

connmark and ipv6 iptables are a bad combination

Added by Dave Täht on Feb 11, 2012. Updated on Apr 21, 2012.
New Urgent Dave Täht


I have been battling various ipv6 related bugs for a while. For example, I tried
to make openwrt’s shaper do ipv6 and stuff like this will hang the interface
on x86 AND cerowrt.

  1. This is my bad boy
    ip6tables -t mangle -A qos_Default -p tcp -m length –length :128 -m mark ! –mark 4/0xff -m tcp –tcp-flags ALL SYN -j MARK –set-mark 1/0xff
    ip6tables -t mangle -A qos_Default -p tcp -m length –length :128 -m mark ! –mark 4/0xff -m tcp –tcp-flags ALL ACK -j MARK –set-mark 1/0xff


  • simple_bug (application/octet-stream; 3.0 kiB) Dave Täht Feb 11, 2012


Updated by Dave Täht on Feb 11, 2012.
It may not be limited to the negate mark option, either.

I suspect there are more ipv6 related bugs than this lurking in ip6tables

Updated by Dave Täht on Feb 12, 2012.
and, after duplicating this on 3 machines, rebooted them all…

and with the simplified script, they no longer go boom. Have to recreate the complex scenario now.

Updated by Dave Täht on Feb 15, 2012.
and then, I managed to get it to happen again. But it’s subtle.

I don’t know what to point at anymore. ifb? ip6tables? conntrack?

Updated by Dave Täht on Apr 21, 2012.

This is a static export of the original bufferbloat.net issue database. As such, no further commenting is possible; the information is solely here for archival purposes.
RSS feed

Recent News & Articles

Mar 21, 2019 Wiki page
Dave Taht's Take on TCP
Mar 17, 2019 Wiki page
Jake Holland's Stance on ECN
Sep 6, 2018 Wiki page
Pete Heist's Thoughts on ECN
Sep 5, 2018 Wiki page
Dave Taht's Stance on ECN
Sep 4, 2018 Wiki page
Jonathan Morton's Take on ECN

Find us elsewhere

Bufferbloat Mailing Lists
#bufferbloat on Twitter
Google+ group
Archived Bufferbloat pages from the Wayback Machine


Comcast Research Innovation Fund
Nlnet Foundation
Shuttleworth Foundation

Bufferbloat Related Projects

Congestion Control Blog
Lede Project (OpenWrt)
Flent Network Test Suite
The Cake shaper

Network Performance Related Resources

Jim Gettys' Blog - The chairman of the Fjord
Toke's Blog - Karlstad University's work on bloat
Voip Users Conference - Weekly Videoconference mostly about voip
Candelatech - A wifi testing company that "gets it".