Skip to content

Bug: WARP WireGuard fails on IPv4-only VPS — IPv6 address removal sed rule doesn't work #5416

Description

@EricPrometheus

Bug Description

On IPv4-only VPS (no IPv6 address, net.ipv6.conf.all.disable_ipv6 = 1), the WARP WireGuard tunnel (wg-quick@warp) fails to start with:

RTNETLINK answers: Permission denied

This causes the entire WARP interface to be torn down, making WARP completely non-functional.

Root Cause

File: other/warp/wireguard/run.sh.j2, line 43

The generate_warp_config() function has logic to detect IPv6-disabled systems and strip IPv6 addresses from wgcf-profile.conf. However, the sed rule is incorrect:

# Current (broken)
sed -i '/Address = [0-9a-fA-F:]\{4,\}/s/^/# /' wgcf-profile.conf

This rule is designed to comment out lines containing IPv6 addresses, but wgcf generate produces output where IPv4 and IPv6 are on the same line:

Address = 172.16.0.2/32, 2606:4700:110:8961:16c9:4520:593:6a9e/128

The sed pattern only matches lines where the Address value starts with an IPv6-looking pattern. Since the line starts with 172.16.0.2 (IPv4), the rule doesn't match, and the IPv6 address remains in the config.

When wg-quick@warp tries to bring up the interface, it attempts ip -6 address add 2606:4700:.../128 dev warp, which fails because IPv6 is disabled at the kernel level. wg-quick then tears down the entire interface as a cleanup step.

Reproduction

  1. Deploy Hiddify Manager on an IPv4-only VPS (e.g., RackNerd KVM with IPv6 disabled via sysctl)
  2. Enable WARP in Hiddify panel (warp_mode != "disable")
  3. Run install.sh or wait for daily auto-update
  4. wg-quick@warp fails to start

Environment

  • Hiddify Manager v12.3.0
  • Ubuntu 22.04, kernel 5.15.0-46-generic
  • VPS: IPv4-only (no IPv6 assigned), net.ipv6.conf.all.disable_ipv6 = 1
  • wgcf generates configs with both IPv4 and IPv6 addresses

Suggested Fix

Replace the sed rule in other/warp/wireguard/run.sh.j2 line 43 to strip the IPv6 portion from the combined Address line:

# Replace this:
sed -i '/Address = [0-9a-fA-F:]\{4,\}/s/^/# /' wgcf-profile.conf

# With this:
sed -i 's/, [0-9a-fA-F:]*\/[0-9]*//' wgcf-profile.conf

This removes the , <ipv6-address>/<prefix> portion from the Address line, leaving only the IPv4 address:

# Before:
Address = 172.16.0.2/32, 2606:4700:110:8961:16c9:4520:593:6a9e/128

# After:
Address = 172.16.0.2/32

Workaround

Manually edit /etc/wireguard/warp.conf to remove the IPv6 address:

sed -i 's/, 2606:[^ ]*//' /etc/wireguard/warp.conf
systemctl restart wg-quick@warp

Note: This workaround will be overwritten on the next Hiddify auto-update that regenerates WARP config.

Activity

  1. EricPrometheus commented on Sep 27, 2026

    @EricPrometheus
    Author

    Reproduced again today on 13.0.3 (IPv4-only KVM VPS, wgcf regenerated the profile with a combined Address = 172.16.0.2/32, <ipv6>/128 line and the removal sed missed it — ip -6 address add → RTNETLINK answers: Permission denied → wg-quick@warp fails). Related protections-bypass family tracked in #5569.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions