▚▚ fix(relay): key IPv6 proxy mappings the way packets look them up - #124
Merged
Merged
Conversation
breken-ai
requested review from
miloschwartz and
oschwartz10612
as code owners
September 25, 2026 19:15
Member
|
Thanks |
oschwartz10612
approved these changes
Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Community Contribution License Agreement
By creating this pull request, I grant the project maintainers an unlimited,
perpetual license to use, modify, and redistribute these contributions under any terms they
choose, including both the AGPLv3 and the Fossorial Commercial license terms. I
represent that I have the right to grant this license for all contributed content.
AI Disclosure
This pull request was written by an AI coding agent (Anthropic Claude, running in Claude Code) operating the
breken-aiaccount. The agent found the bug by reading the code, wrote the fix and the regression test, and ran the checks listed under "How to test?". The red/green runs below are real output from those runs.Description
The relay can't forward packets for a client that connects over IPv6.
handleWireGuardPacketlooks the mapping up byremoteAddr.String(), which for IPv6 is[2001:db8::1]:51820. The two paths that add mappings at runtime build the key withfmt.Sprintf("%s:%d", ...), which gives2001:db8::1:51820:notifyServer, after a hole punch (/gerbil/update-hole-punchresponse)UpdateProxyMapping, from/update-destinationsSo the lookup misses and every WireGuard packet from that client is dropped with
No proxy mapping found for [2001:db8::1]:51820. Mappings loaded at startup from/gerbil/get-all-relaysdo work, because Pangolin keys them withformatEndpoint([ip]:port). That means an IPv6 client that connects after gerbil starts isn't relayed until gerbil restarts.getCachedAddrhas the same problem with IPv6 destinations:net.ResolveUDPAddr("udp", "2001:db8::5:51820")fails withtoo many colons in address.Fix
relay/relay.go: build these three keys withnet.JoinHostPort(ip, strconv.Itoa(port)), which brackets IPv6 and matchesUDPAddr.String(). IPv4 keys come out the same as before.Not changed
containsIP.How to test?
go test ./relay/: newTestRelayForwardsIPv6Peerstarts the relay on[::1]:0, registers a mapping for an IPv6 client withUpdateProxyMapping(the/update-destinationspath), sends a handshake initiation from that client, and checks that it reaches an IPv6 destination.main): the relay logsNo proxy mapping found for [::1]:59684and the test fails withdestination did not receive the forwarded initiation: read udp6 [::1]:50044: i/o timeout.go test ./...,go vet ./relay/,gofmt -l relay/andgo build ./...are clean.▚▚ Shipped by breken — self-healing software. This one's on us. breken.ai