nixos/systemd/network: use upstream default for privacy extensions

Privacy extensions were previously enabled through a udev rule, which
was then ported to networkd in [1]. But because networkd ships with
IPv6PrivacyExtensions=no by default[2], the udev rule used to get
overruled when the interface was managed through networkd.

The migration thereforce introduced a serious undocumented behavior
change by enabling IPv6 privacy extensions for all links managed by
networkd.

[1] bb954cddf5
[2] https://www.freedesktop.org/software/systemd/man/latest/systemd.network.html#IPv6PrivacyExtensions=

(cherry picked from commit 428bcb1fbe)
This commit is contained in:
Martin Weinelt
2026-09-23 22:12:32 +02:00
committed by github-actions[bot]
parent 471aaa4dc6
commit 4ba2be8ce5

View File

@@ -2497,11 +2497,6 @@ let
networkdOptions = {
networkConfig = mkOption {
default = { };
defaultText = lib.literalExpression ''
{
IPv6PrivacyExtensions = true;
}
'';
example = {
SpeedMeter = true;
ManageForeignRoutingPolicyRules = false;
@@ -4001,10 +3996,7 @@ let
};
config = {
networkConfig = {
IPv6PrivacyExtensions = lib.mkOptionDefault true;
}
// optionalAttrs (config.routeTables != { }) {
networkConfig = optionalAttrs (config.routeTables != { }) {
RouteTable = mapAttrsToList (name: number: "${name}:${toString number}") config.routeTables;
};
};