Skip to content

Fix ipv4 forwarding when both v4 and v6 ports are listening - #41672

Merged
Keith Horton (keith-horton) merged 1 commit into
masterfrom
user/chemwolf6922/fix-ipv4-not-forwarded-when-both-v4-and-v6-are-listened
Sep 28, 2026
Merged

Keith Horton (keith-horton) merged 1 commit into
masterfrom
user/chemwolf6922/fix-ipv4-not-forwarded-when-both-v4-and-v6-are-listened

Conversation

@chemwolf6922

Copy link
Copy Markdown
Contributor

Summary of the Pull Request

The NAT localhost scanner ignores dual-stack listeners and only creates IPV6 forwarders in Windows.

This PR checks the INET_DIAG_SKV6ONLY field of the v6 port. And adds a v4 windows forwarder when it's dual stack.
This PR also fixes the misuse of NetlinkMessage.Attributes where the TMessage was specified as const void* instead of the actual message type. Causing wrong return types and wrong size checks.

PR Checklist

  • Closes: Link to issue #xxx
  • Communication: I've discussed this with core contributors already. If work hasn't been agreed, this work might be rejected
  • Tests: Added/updated if needed and all pass
  • Localization: All end user facing strings can be localized
  • Dev docs: Added/updated if needed
  • Documentation updated: If checked, please file a pull request on our docs repo and link it here: #xxx

Detailed Description of the Pull Request / Additional comments

Validation Steps Performed

Add / update tests:
NetworkTests::NetworkTests::NatLocalhostRelayDualStack
NetworkTests::NetworkTests::NatLocalhostRelayIpv6Only
NetworkTests::NetworkTests::NatLocalhostRelay
NetworkTests::NetworkTests::NatLocalhostRelayNoIpv6

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It changes localhost forwarding behavior and netlink parsing in core networking paths, which warrants final human review despite the added test coverage.

Review effort: Lite
Findings: None

What changed in this PR

This PR addresses a WSL2 NAT localhost relay gap where dual-stack (IPv6 socket with IPV6_V6ONLY=0) listeners were only resulting in IPv6 Windows forwarders, breaking IPv4 localhost forwarding. It also tightens netlink attribute typing/parsing so attribute access returns correctly typed pointers and uses correct payload-size checks.

Changes:

  • Extend the sock_diag-based listener scan to detect dual-stack IPv6 wildcard listeners and synthesize a corresponding IPv4 wildcard socket entry when INET_DIAG_SKV6ONLY == 0.
  • Fix netlink attribute parsing to use typed attributes (in_addr / in6_addr) and validate attribute payload length with RTA_PAYLOAD().
  • Update/expand NAT localhost relay tests to cover dual-stack and IPv6-only scenarios.
File Description
test/​windows/​NetworkTests.cpp Adds dual-stack and IPv6-only NAT localhost relay coverage; refactors relay traffic validation to reuse a single guest listener.
src/​linux/​netlinkutil/​RoutingTable.cpp Switches route address attribute reads to typed netlink attributes keyed off rtm_family.
src/​linux/​netlinkutil/​NetlinkMessage.hxx Adds inet_diag_msg attribute traversal and corrects attribute size checks to use payload size.
src/​linux/​netlinkutil/​Interface.cpp Fixes address enumeration to use typed netlink attributes based on ifa_family.
src/​linux/​init/​localhost.cpp Detects dual-stack IPv6 wildcard listeners via INET_DIAG_SKV6ONLY and adds an IPv4 forwarder candidate.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing these!

@keith-horton

Copy link
Copy Markdown
Member

Ben Hillis (@benhillis) , some of this fixes the WSL Relay interaction. The changes looks good to me.
Do you or Pierre want to review this?

@keith-horton

Copy link
Copy Markdown
Member

Ben Hillis (@benhillis) , Catalin is out for a while. Can he be removed from one of the required reviewers?

@OneBlue

Copy link
Copy Markdown
Collaborator

Ben Hillis (Ben Hillis (@benhillis)) , Catalin is out for a while. Can he be removed from one of the required reviewers?

He's not a required reviewer. The change can be merged now that it's approved by wsl-reviewers

@keith-horton

Copy link
Copy Markdown
Member

Ben Hillis (Ben Hillis (Ben Hillis (@benhillis))) , Catalin is out for a while. Can he be removed from one of the required reviewers?

He's not a required reviewer. The change can be merged now that it's approved by wsl-reviewers

Thanks! Sorry - I saw him listed as a 'pending review' and thought policy might now require him.

@keith-horton
Keith Horton (keith-horton) merged commit 56e260a into master Sep 28, 2026
12 checks passed
@keith-horton
Keith Horton (keith-horton) deleted the user/chemwolf6922/fix-ipv4-not-forwarded-when-both-v4-and-v6-are-listened branch September 28, 2026 20:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants