Merge pull request #273510 from rnhmjoj/pr-fix-ping

nixos/networking-interfaces: fix rootless ping
This commit is contained in:
Martin Weinelt 2023-12-11 20:47:49 +01:00 committed by GitHub
commit a0f49243e4
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -1396,6 +1396,8 @@ in
"net.ipv4.conf.all.forwarding" = mkDefault (any (i: i.proxyARP) interfaces);
"net.ipv6.conf.all.disable_ipv6" = mkDefault (!cfg.enableIPv6);
"net.ipv6.conf.default.disable_ipv6" = mkDefault (!cfg.enableIPv6);
# allow all users to do ICMP echo requests (ping)
"net.ipv4.ping_group_range" = mkDefault "0 2147483647";
# networkmanager falls back to "/proc/sys/net/ipv6/conf/default/use_tempaddr"
"net.ipv6.conf.default.use_tempaddr" = tempaddrValues.${cfg.tempAddresses}.sysctl;
} // listToAttrs (forEach interfaces