Page MenuHomePhabricator

Blocking user autoblocks many user with ipv6
Closed, ResolvedPublic

Description

Today a user on dewiki was blocked and other users getting autoblock, but that was too much user to have the same public ip address than the blocked user.

Some of the user copy and paste the autoblocktext which was shown. The IP addresse in that piece of text was 2620:0:862:1:a6ba:dbff:fe30:d853. According to utrace this is a wikimedia ipv6 address. It looks like, user with ipv6 does not reaching wikipedia with its own public ipv6, instead there are tunneling through a wikimedia gateway to wikipedia or something other, which changes the ip in the header.

Please fix this to avoid a mass block of many ipv6 users and to avoid false positive in check user. Thanks.

http://www.utrace.de/whois/2620%3A0%3A862%3A1%3AA6BA%3ADBFF%3AFE30%3AD853
NetRange: 2620:0:860:: - 2620:0:863:FFFF:FFFF:FFFF:FFFF:FFFF
CIDR: 2620:0:860::/46
OriginAS: AS14907
NetName: WIKIMEDIA6
NetHandle: NET6-2620-860-1
Parent: NET6-2620-1
NetType: Direct Assignment
Comment: http://www.wikimediafoundation.org
RegDate: 2007-10-02
Updated: 2012-03-02
Ref: http://whois.arin.net/rest/net/NET6-2620-860-1

OrgName: Wikimedia Foundation Inc.
OrgId: WIKIM
Address: 149 New Montgomery Street
Address: 3rd Floor
City: San Francisco
StateProv: CA
PostalCode: 94105
Country: US
RegDate: 2006-05-30
Updated: 2012-02-15
Ref: http://whois.arin.net/rest/org/WIKIM


Version: wmf-deployment
Severity: critical

Details

Reference
bz56681

Event Timeline

bzimport raised the priority of this task from to High.Nov 22 2014, 2:13 AM
bzimport set Reference to bz56681.
bzimport added a subscriber: Unknown Object (MLST).

Mark was just fixing a very similar issue on #wikimedia-tech a few hours ago (see also [1]). Thus this is probably fixed already, but I'll wait for him to confirm before closing.

[1] https://en.wikipedia.org/wiki/Wikipedia:VPT#Wikimedia_Foundation_IP_addresses_causing_autoblocks

We believe this is fixed as of 17:18 UTC. Are there any reports of this still occurring since?

The user on dewiki was unblocked and that removed all the autoblocks, so at the moment there is all okay. But I do not know, if there would still problems, when doing a block.

Dmitrij: Does the problem still occur with *new* blocks after 2013-11-06 17:18 UTC? The timestamp in your link says 17:16, 6 ноября 2013 (UTC).

dimar wrote:

Andre: No, I can't find any new occurrences after 2013-11-06 17:18 (UTC).

Probably it can be closed now.

Looks good now. Closing.
Thanks for the fix and hopfully the next new server does not have side effects ;-)

Reopening... we need a reliable way to avoid such situations in the future. XFF blocks shouldn't apply to WMF proxies or WMF IPs shouldn't be blockable (neither directly, nor indirectly) or something like that.

Another issue (now the new talk bar), but maybe the same cause: bug 56727

MediaWiki is seeing the ipv6 gateway as incoming ip and therefor record the edits, new talk and maybe check user under that.

No more issues after some month, so this looks fixed now.