Reach IPv6 addresses over plain HTTP and through an IPv6 upstream in the egress filter - #710
Merged
davidmckayv merged 4 commits intoOct 2, 2026
Conversation
URL.hostname keeps an IPv6 address's brackets, and forwardPlain and upstreamAddress passed it to the socket as written, so the address was looked up as a name and the request answered 502. Strip the brackets there, and bracket an IPv6 host in the CONNECT line sent upstream.
Chebaleomkar
requested review from
MikeRyanDev,
davidmckayv,
guidovizoso,
mxmzb and
tylerslaton
as code owners
October 2, 2026 19:10
# Conflicts: # CHANGELOG.md
The computer runs on Bun, which already reaches a bracketed IPv6 host over plain HTTP, so that 502 never happened in the shipped image. The fix is an upstream proxy at an IPv6 address and the brackets on a CONNECT target.
Contributor
|
I pushed one commit that rewrites the CHANGELOG entry. The computer image runs on Bun ( |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
URL.hostnamekeeps an IPv6 address's brackets (new URL("http://[::1]:8080/").hostnameis"[::1]"). The egress filter passed that string to the socket in two places:forwardPlain: a plain-HTTP request tohttp://[::1]:port/was looked up as a name and answered502 Bad Gateway. An IP literal is not resolved and pinned, so nothing else caught it.CONNECT [::1]:portalready worked, becausesplitHostPortstrips the brackets.upstreamAddress: an upstream proxy configured ashttp://[::1]:8080could not be reached.In addition,
tunnelwroteCONNECT ::1:443to the upstream, which is not a valid authority. An IPv6 host is now bracketed there.Where it runs
The agent computer's egress filter.
Boundary and audit
None. Decisions already used
normalizeHost, which strips brackets. Only the forwarding is fixed.Changelog
Entry under Unreleased.
Proof
Two live tests in
agent-computer/tests/egress-policy.test.ts(an origin and a fake upstream listening on::1). Both fail onmain(19 pass, 2 fail) and the file passes 21/21 with the fix. Biome format and lint are clean, andtscreports nothing in the changed files.