Report an allocated IPv4 address that is not on the host

IPv6 works end to end between two machines; IPv4 silently did not, and the
agent said nothing useful about why.

Allocation moved the address from something derivable before startup to
something agreed at run time, so an interface configured by an earlier
`tun-setup` carries a different address than the one allocated. The kernel
then sends packets with that stale source and every peer drops them as not
belonging to us — correct behaviour, invisible cause. Meanwhile pings to
our own allocated address fall into the tunnel and land in the "nobody
owns this" counter.

The agent now checks whether its allocated address is assigned anywhere on
the host — by binding a UDP socket to it, which needs no privileges and no
platform code — and reports the exact `ip address add` command until it
is, mentioning that another address of the range has to go.

`tun-setup` no longer prints a derived IPv4 address, because that number
is now wrong by construction. It says the agent will print the real one.

The unroutable counter keeps one destination as a sample, in status output
too. A bare count says something is wrong; the address says what.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
tsunagi
2026-09-21 13:53:42 +01:00
co-authored by Claude Opus 5
parent 84c06c6cac
commit 8b333455f1
9 changed files with 162 additions and 18 deletions
+9
View File
@@ -126,6 +126,15 @@ wins, and the agent adopts it. So the flag matters for whoever starts the
network and is harmless afterwards. Pass `--ipv4-range none` for an IPv6-only
overlay.
Putting the address on the interface still needs privileges, and the agent
cannot do it. Since the address is only known once the agent has agreed with
its peers, `tsunagi tun-setup` cannot print it up front either. So the agent
checks whether the address is assigned anywhere on the host — by binding a UDP
socket to it, which needs no privileges — and reports the exact command until
it is. This matters: with the wrong address on the interface, packets leave
with the wrong source and every peer drops them as not belonging to us, which
looks like a broken network rather than a missing command.
A release tombstone exists in the record type and merges correctly, but
nothing emits one yet, so an address stays claimed until the network is
forgotten.