HAOS 18.x: Kernel forces IPv6 forwarding = 0 → OTBR broken → Matter-over-Thread commissioning fails
Describe the issue you are experiencing
Since HAOS 18.x, the kernel forces net.ipv6.conf.all.forwarding = 0 at boot. This disables IPv6 routing on the host and breaks the OpenThread Border Router (OTBR) add-on, making Matter-over-Thread commissioning impossible.
Even after rolling back to HAOS 17.3, IPv6 forwarding remains stuck at 0 because the inactive boot slot (A) still contains HAOS 18.x. HAOS refuses to downgrade the inactive slot, so the system continues to boot with the 18.x kernel even when the active slot is 17.3.
This regression makes OTBR unusable on HAOS 18.x for EFR32MG21-based Thread radios (Sonoff Dongle‑E, etc.).
What operating system image do you use?
generic-x86-64 (Generic UEFI capable x86-64 systems)
What version of Home Assistant Operating System is installed?
18.3
Did the problem occur after upgrading the Operating System?
No
Hardware details
Host machine:
Intel NUC (Haswell generation)
Internal storage: Kingston SM2280S3G2/120G SSD
Network: Gigabit Ethernet (Wi‑Fi disabled)Connected USB devices:
Sonoff ZBDongle‑E (EFR32MG21)
Running in RCP mode for OTBR
Connected directly to USB port (no hub)
Sonoff ZBDongle‑P
Used as Zigbee coordinator for Zigbee2MQTT
Connected directly to USB port
No other USB devices attachedThread / Matter setup:
OTBR add-on using the Sonoff Dongle‑E
Matter server enabled
IKEA DIRIGERA also present on the network (used as secondary Thread BR)Steps to reproduce the issue
Steps to reproduce the issue
Install HAOS 18.x on bare‑metal x86‑64
Use an Intel NUC (Haswell) with a Kingston SSD as system disk.
No hypervisor, direct HAOS install.
Attach Thread and Zigbee radios
Plug in Sonoff ZBDongle‑E (EFR32MG21) for OTBR (RCP mode).
Plug in Sonoff ZBDongle‑P for Zigbee2MQTT.
Both directly on USB ports (no hub).
Enable OTBR and Matter in Home Assistant
Install and start the OTBR add-on using the ZBDongle‑E.
Enable Matter server in Home Assistant.
Check IPv6 forwarding on HAOS 18.x
Open the HAOS terminal and run:
bash
cat /proc/sys/net/ipv6/conf/all/forwarding
Observe that the value is always 0.
Attempt Matter-over-Thread commissioning
Try to commission a Matter-over-Thread device (e.g. IKEA GRILLPLATS).
Commissioning fails; OTBR logs show NoAck, SRP DNS drops, and Secure Pairing Failed.
Rollback HAOS to 17.3
Use the Supervisor / CLI to roll back to HAOS 17.3.
After rollback, check boot slots via:
bash
ha os info
Slot B is booted, version 17.3, slot A is inactive, version 18.3.
Verify kernel and forwarding after rollback
Check kernel version:
bash
uname -a
→ still shows a 6.8.x-haos kernel (from 18.x).
Check IPv6 forwarding again:
bash
cat /proc/sys/net/ipv6/conf/all/forwarding
→ still 0.
Attempt to downgrade inactive slot A
Try to update slot A to 17.3 via:
bash
ha os boot-slot A
ha os update --version 17.3
HAOS blocks the operation with messages like:
OSManager.update blocked from execution, system is not running – startup
and refuses to downgrade the inactive slot.
Result
System continues to boot with the 18.x kernel even when the active slot is 17.3.
IPv6 forwarding remains 0.
OTBR and Matter-over-Thread commissioning remain broken.Anything in the Supervisor logs that might be useful for us?
Supervisor logs do not show any OSManager, slot, downgrade or IPv6-related errors.Anything in the Host logs that might be useful for us?
Host logs unavailable.
Home Assistant OS 18.x no longer exposes systemd/journalctl to SSH add-ons.
The Advanced SSH & Web Terminal add-on runs in a restricted host shell without journalctl.
I will provide host logs after accessing the physical console of the NUC.System information
System Information
| version | core-2026.9.3 |
|---|---|
| installation_type | Home Assistant OS |
| dev | false |
| hassio | true |
| docker | true |
| container_arch | amd64 |
| user | root |
| virtualenv | false |
| python_version | 3.14.6 |
| os_name | Linux |
| os_version | 6.18.52-haos |
| arch | x86_64 |
| timezone | Europe/Zurich |
| config_dir | /config |
| logged_in | false |
|---|---|
| can_reach_cert_server | ok |
| can_reach_cloud_auth | ok |
| can_reach_cloud | ok |
| GitHub API | ok |
|---|---|
| GitHub Content | ok |
| GitHub Web | ok |
| HACS Data | ok |
| GitHub API Calls Remaining | 5000 |
| Installed Version | 2.0.5 |
| Stage | running |
| Available Repositories | 4127 |
| Downloaded Repositories | 29 |
| host_os | Home Assistant OS 18.3 |
|---|---|
| update_channel | stable |
| supervisor_version | supervisor-2026.09.2 |
| agent_version | 1.14.0 |
| docker_version | 29.7.2 |
| disk_total | 109.3 GB |
| disk_used | 77.7 GB |
| nameservers | 192.168.178.1, 2002:c2bf:e731:0:d624:ddff:fe96:e9f5, fdd8:eb2e:646b:0:d624:ddff:fe96:e9f5 |
| healthy | true |
| supported | true |
| host_connectivity | true |
| supervisor_connectivity | true |
| ntp_synchronized | true |
| virtualization | |
| board | generic-x86-64 |
| supervisor_api | ok |
| version_api | ok |
| installed_addons | Matter Server (9.2.0), Studio Code Server (7.1.1), Mosquitto broker (7.1.1), Zigbee2MQTT (2.14.1-1), Music Assistant (2.10.4), Whisper (3.5.3), Piper (2.5.2), openWakeWord (2.1.1), OpenCode (2.5.5), Sendspin Bluetooth Bridge (2.75.0), SMART Sniffer App (0.2.12), OpenThread Border Router (3.2.0), Speech-to-Phrase (1.4.5), ESPHome 2026.4 (2026.4.5), Home Assistant Time Machine (2.3.1), Glances (0.23.0), File editor (6.1.0), Advanced SSH & Web Terminal (24.1.5) |
| dashboards | 6 |
|---|---|
| resources | 15 |
| views | 12 |
| mode | storage |
| adapters | lo (disabled), enp0s25 (enabled, default, auto), wlp2s0 (disabled), docker0 (disabled), hassio (disabled), veth7bb5aae (disabled), veth1414ccb (disabled), vethfa837e5 (disabled), vetha155e2a (disabled), veth40bc36b (disabled), vethd13cc96 (disabled), veth354755a (disabled), veth40b791d (disabled), veth2470a03 (disabled), veth823d14c (disabled), wpan0 (disabled) |
|---|---|
| ipv4_addresses | lo (127.0.0.1/8), enp0s25 (192.168.178.65/24), wlp2s0 (192.168.178.64/24), docker0 (172.30.232.1/23), hassio (172.30.32.1/23), veth7bb5aae (), veth1414ccb (), vethfa837e5 (), vetha155e2a (), veth40bc36b (), vethd13cc96 (), veth354755a (), veth40b791d (), veth2470a03 (), veth823d14c (), wpan0 () |
| ipv6_addresses | lo (::1/128), enp0s25 (2002:c2bf:e731:0:baac:930:3d45:6de8/64, fdd8:eb2e:646b:0:4fbe:7ee4:1501:5045/64, fe80::c133:b1:388b:69b3/64), wlp2s0 (2002:c2bf:e731:0:364e:25b8:46c3:3fd1/64, fdd8:eb2e:646b:0:7079:96ba:fcea:e0d9/64, fe80::f438:45f8:9c74:65bf/64), docker0 (fdb3:2c6d:c501::1/64, fe80::d483:3ff:febb:d1fa/64), hassio (fd0c:ac1e:2100::1/48, fe80::3817:12ff:fefa:ef0/64), veth7bb5aae (fe80::d445:8ff:feb4:3725/64), veth1414ccb (fe80::686d:19ff:fef4:a48c/64), vethfa837e5 (fe80::b42b:fdff:febe:a43a/64), vetha155e2a (fe80::5cdc:44ff:fef8:7cf1/64), veth40bc36b (fe80::3856:2fff:fe3e:4279/64), vethd13cc96 (fe80::e454:b1ff:fe50:e9e1/64), veth354755a (fe80::5047:8cff:fed4:6a80/64), veth40b791d (fe80::9c3e:87ff:fe51:f1dc/64), veth2470a03 (fe80::90b8:4cff:fe2f:b9e5/64), veth823d14c (fe80::5cd6:35ff:fe8a:86e6/64), wpan0 (fdb1:7a5d:888a:c0cc:0:ff:fe00:fc11/64, fda1:1ce7:b9ad:1:68ad:d7b:ce2c:601a/64, fdb1:7a5d:888a:c0cc:0:ff:fe00:fc38/64, fdb1:7a5d:888a:c0cc:0:ff:fe00:fc10/64, fdb1:7a5d:888a:c0cc:0:ff:fe00:cc00/64, fdb1:7a5d:888a:c0cc:3091:1fb:cc96:5a65/64, fe80::9809:15c0:9358:4d6c/64) |
| announce_addresses | 192.168.178.65, 2002:c2bf:e731:0:baac:930:3d45:6de8, fdd8:eb2e:646b:0:4fbe:7ee4:1501:5045, fe80::c133:b1:388b:69b3 |
| oldest_recorder_run | 8 septembre 2026 à 16:19 |
|---|---|
| current_recorder_run | 19 septembre 2026 à 19:12 |
| estimated_db_size | 1280.63 MiB |
| database_engine | sqlite |
| database_version | 3.53.2 |
| api_endpoint_reachable | ok |
|---|
Additional information
No response
Source: home-assistant/operating-system