Conversation
This was referenced Sep 25, 2026
david-yu
added this pull request to stack #12
September 25, 2026 16:16
The resolver has returned AAAA records since the initial IPv6 support (2f35731), but its c-ares socket glue still dates from the IPv4-only days (fea5d80): it created every UDP socket as AF_INET and rejected any AF_INET6 sockaddr with "No ipv6 yet". A host whose resolv.conf lists an IPv6 nameserver could not resolve anything: c-ares reported ARES_ECONNREFUSED for every server. That is what an IPv6-only Kubernetes pod looks like (CoreDNS over IPv6), and what an IPv6-only VM with a link-local or ULA resolver looks like. - do_socket creates the datagram channel with the family c-ares asked for instead of hardcoding AF_INET. - sock_addr accepts AF_INET6, checks the sockaddr length, and copies the address out instead of reading it through a reinterpret_cast. - do_recvfrom copies the source address by its real length; sockaddr is only wide enough for AF_INET, so an IPv6 source was being truncated and its length misreported. - options.servers is installed with ares_set_servers_csv after channel creation; ARES_OPT_SERVERS carries in_addr only. IPv4 nameservers take the same AF_INET branches as before. Adds a unit test that answers a query from a mock nameserver bound to [::1]. Fixes scylladb#2288
david-yu
force-pushed
the
ipv6/02-dns-ipv6-nameservers
branch
from
September 25, 2026 18:11
23ecbcb to
83b0ae3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 2 of 10 of the IPv6 series, split out of #1 and rebased on current
scylladb/seastarmaster. Based on #2, so the diff here is only this PR's commit.Why
The resolver has returned AAAA records since the initial IPv6 support (
2f3573178, 2019), but its c-ares socket glue is still what it was when the resolver was added (fea5d80d2, 2016: "Like seastar, only handles ipv4 atm"). It opensAF_INETsockets and throws "No ipv6 yet" for anAF_INET6nameserver, so a host whose only nameserver is IPv6 (an IPv6-only Kubernetes pod, an IPv6-only VM) cannot resolve anything: c-ares reportsARES_ECONNREFUSEDfor every server.What
83b0ae335) — datagram channels follow the family c-ares asks for,sock_addracceptsAF_INET6,do_recvfromcopies the source by its real length, and servers reach c-ares throughares_set_servers_csv(ARES_OPT_SERVERScarriesin_addronly).sock_addrnow copies the address out withmemcpyinstead of reading it through areinterpret_cast, which fixesscylladb/seastar#2288.Relation to recent resolver work
705ead2b6(scylladb/seastar#3456) setARES_AI_NOSORTbecause c-ares' RFC 6724 probe could not run through Seastar's socket hooks: IPv4-only socket creation, a throwing IPv6 connect, nogetsocknamehook. This PR removes the first two.getsocknameis still missing, soNOSORTstays, and callers should still try each resolved address in turn, as that commit says.725128d8f(a TCP nameserver closing the connection) is untouched; its test runs next to the new one.Testing
test_resolve_udp_ipv6_nameserveranswers an A query from a mock nameserver bound to[::1]; on master it fails withstd::invalid_argument: Servers must be ipv4 addresses. IPv4 nameservers take the sameAF_INETbranches as before.On the core-aws VM (Ubuntu 24.04, GCC 14, C++23, RelWithDebInfo, GnuTLS and OpenSSL in one tree), this PR's head builds and passes
dns,ipv6,socket,rpc,httpd,httpd_openssl,tls,tls_openssl,network_interface,websocketandunix_domainwithSEASTAR_TEST_REQUIRE_IPV6=1, so none of their IPv6 cases skipped.Stack