hyper-util: SOCKS5 connector sends a bracketed IPv6 literal as a domain name
Los mantenedores suelen responder en 2 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 88/100
- Tipo de issue
- Error
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- rust
- Área
- networking
Línea de trabajo
Comienza en src/client/legacy/connect/proxy/socks/v5/mod.rs e inspecciona cómo se analiza el host de destino en una dirección SOCKS5. Ejecuta una solicitud SocksV5 a https://[::1]:443 y verifica después que la solicitud codificada usa ATYP 0x04 con los 16 bytes IPv6 sin procesar, en lugar de ATYP 0x03 con el texto entre corchetes.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
My Claude discovered this.
Fable:
Affects hyper-util 0.1.20 (src/client/legacy/connect/proxy/socks/v5/mod.rs), seen through reqwest 0.13.5 with a socks5:// proxy (local DNS mode).
What happens
reqwest resolves the target locally and builds the destination URI with the address; an IPv6 address is written in brackets, as a URI requires (https://[2606:4700::6810:102]:443). SocksV5 then takes dst.host(), which for an IPv6 authority still carries the brackets ([2606:4700::6810:102]), and does:
let address = match host.parse::<IpAddr>() {
Ok(ip) => Address::Socket(SocketAddr::new(ip, port)),
Err(_) => ... Address::Domain(host, port)
"[2606:4700::6810:102]".parse::<IpAddr>() fails, so the literal goes out as ATYP 0x03 (domain name) with the brackets in the string. A SOCKS5 server that joins host and port (tailscaled's does, with Go's net.JoinHostPort) ends up with [[2606:4700::6810:102]]:443 and fails with "missing port in address". IPv4 literals have no brackets, so they parse and go out as ATYP 0x01.
Fix
Strip the URI brackets before parsing the host as an IP address, so an IPv6 literal goes out as ATYP 0x04:
- let address = match host.parse::<IpAddr>() {
+ let bare = host.strip_prefix('[').and_then(|h| h.strip_suffix(']')).unwrap_or(&host);
+ let address = match bare.parse::<IpAddr>() {
Ok(ip) => Address::Socket(SocketAddr::new(ip, port)),
A test: a SocksV5 request to https://[::1]:443 must encode ATYP 0x04 with the 16 raw bytes, not ATYP 0x03 with the text [::1].
How it showed up
A Rust server fetching pages through a Tailscale exit node (tailscaled --socks5-server) with reqwest::Proxy::all("socks5://…") and a custom resolver: every host with an AAAA record failed with error sending request (cause: the proxy's "missing port in address"), and hosts with only A records worked. Ordering the resolver's answers IPv4-first works around it.
- Lenguaje dominante
- Rust
- Estrellas
- 16.3k
- Forks
- 1.8k
- Merge medio
- 2 d 13 h
- PR fusionados (30 d)
- 10
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de hyperium/hyper
-
Publicly reexport the http crateAbiertoC-feature
Dificultad 1/5 Menos de una hora Aptitud para principiantes 65/100
hyperium/hyper#2652 · 4 reacciones ·
Los mantenedores suelen responder en 2 días
-
Upgraded HTTP/2 CONNECT streams cannot be reset, so a failed tunnel looks like a clean closeAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 55/100
Los mantenedores suelen responder en 2 días
-
Dificultad 3/5 1-2 días Aptitud para principiantes 35/100
Los mantenedores suelen responder en 2 días
-
Dificultad 4/5 3-5 días Aptitud para principiantes 62/100
Los mantenedores suelen responder en 2 días
-
C-feature
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
hyperium/hyper#4186 · 1 comentario ·
Los mantenedores suelen responder en 2 días
Todos los issues de hyperium/hyper
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
-
area: cli bug priority: P2 ready-for-agent
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día