Conversation
This was referenced Sep 25, 2026
david-yu
added this pull request to stack #12
September 25, 2026 16:16
Whether a wildcard [::] listener also accepts IPv4 clients (as IPv4-mapped IPv6 peers) has so far followed the host's net.ipv6.bindv6only default, and a [::]:P listener could never share a port with a 0.0.0.0:P one. Add listen_options::ipv6_only. When set, posix_listen applies it with IPV6_V6ONLY before bind on AF_INET6 sockets; other families are untouched and the default (unset) keeps today's behaviour. Tested by a listener on [::]:0 reached from 127.0.0.1 with the option false (accepted, peer ::ffff:127.0.0.1) and true (ECONNREFUSED).
An IPv4 client of a dual-stack [::] listener is reported by the kernel as ::ffff:a.b.c.d. inet_address already unwrapped that form in its in_addr conversion but nowhere else: operator==, hashing and is_loopback() treated it as a different address from a.b.c.d, and http_server / rpc::server handed the mapped form to handlers and filter_connection, so address-keyed policies written as IPv4 never matched. Add inet_address::is_ipv4_mapped() and unmapped() (the in_addr conversion now reuses them), socket_address::unmapped(), and normalise the peer and local addresses http_server and rpc::server record. Non-mapped addresses of either family are returned unchanged. Sockets keep reporting what the kernel returns, as datagram channels do since 731ac07; only the two servers that hand the address to application policy normalise it.
david-yu
force-pushed
the
ipv6/04-dual-stack-listeners
branch
from
September 25, 2026 18:11
55a3348 to
a788a96
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part 4 of 10 of the IPv6 series, split out of #1 and rebased on current
scylladb/seastarmaster. Based on #4, so the diff here is only this PR's 2 commits.Why
On a dual-stack host a
[::]listener's IPv4 clients arrive as::ffff:a.b.c.d, which does not compare, hash or test as loopback likea.b.c.d.http_serverandrpc::serverhanded that form to handlers andfilter_connection, so address-keyed policies written for IPv4 stopped matching once a listener moved to[::]. Whether a[::]listener accepts IPv4 at all also followed the host'snet.ipv6.bindv6only, with no way to ask.What
372fb6ffd) —listen_options::ipv6_only(std::optional<bool>; unset keeps today's behaviour).a788a963a) —inet_address::is_ipv4_mapped()/unmapped()andsocket_address::unmapped();http_serverandrpc::serverrecord unmapped peer and local addresses.Builds on
inet_address'sin_addrconversion already unwrapped the mapped form;unmapped()is that logic, made reusable. Sockets keep reporting what the kernel returns, as datagram channels do since731ac075f(scylladb/seastar#3700); only the two servers that hand the address to application code normalise it.Testing
A
[::]:0listener reached from127.0.0.1withipv6_onlyfalse (accepted, peer::ffff:127.0.0.1) and true (ECONNREFUSED); anhttp_serveron[::]reports its IPv4 client as127.0.0.1.unmapped()is the identity for anything that is not::ffff:a.b.c.d.On the core-aws VM (Ubuntu 24.04, GCC 14, C++23, RelWithDebInfo, GnuTLS and OpenSSL in one tree), this PR's head builds and passes
dns,ipv6,socket,rpc,httpd,httpd_openssl,tls,tls_openssl,network_interface,websocketandunix_domainwithSEASTAR_TEST_REQUIRE_IPV6=1, so none of their IPv6 cases skipped.Stack