From 4ba2be8ce5871b9931ff0d420348672daa67fa5b Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Wed, 23 Sep 2026 22:12:32 +0200 Subject: [PATCH] nixos/systemd/network: use upstream default for privacy extensions Privacy extensions were previously enabled through a udev rule, which was then ported to networkd in [1]. But because networkd ships with IPv6PrivacyExtensions=no by default[2], the udev rule used to get overruled when the interface was managed through networkd. The migration thereforce introduced a serious undocumented behavior change by enabling IPv6 privacy extensions for all links managed by networkd. [1] https://github.com/nixos/nixpkgs/commit/bb954cddf529ba4d37c5c675cde34e116699031f [2] https://www.freedesktop.org/software/systemd/man/latest/systemd.network.html#IPv6PrivacyExtensions= (cherry picked from commit 428bcb1fbe9328d5e484dc6e450a06696f7a7b14) --- nixos/modules/system/boot/networkd.nix | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/nixos/modules/system/boot/networkd.nix b/nixos/modules/system/boot/networkd.nix index 2b14caac86fa..c812a9dc6479 100644 --- a/nixos/modules/system/boot/networkd.nix +++ b/nixos/modules/system/boot/networkd.nix @@ -2497,11 +2497,6 @@ let networkdOptions = { networkConfig = mkOption { default = { }; - defaultText = lib.literalExpression '' - { - IPv6PrivacyExtensions = true; - } - ''; example = { SpeedMeter = true; ManageForeignRoutingPolicyRules = false; @@ -4001,10 +3996,7 @@ let }; config = { - networkConfig = { - IPv6PrivacyExtensions = lib.mkOptionDefault true; - } - // optionalAttrs (config.routeTables != { }) { + networkConfig = optionalAttrs (config.routeTables != { }) { RouteTable = mapAttrsToList (name: number: "${name}:${toString number}") config.routeTables; }; };