hyper-util: SOCKS5 connector sends a bracketed IPv6 literal as a domain name
维护者通常 2 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 88/100
- Issue 类型
- 缺陷
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- rust
- 领域
- networking
调研方向
从 src/client/legacy/connect/proxy/socks/v5/mod.rs 开始,检查目标主机如何被解析为 SOCKS5 地址。对 https://[::1]:443 执行一次 SocksV5 请求,然后验证编码后的请求使用的是带有 16 个原始 IPv6 字节的 ATYP 0x04,而不是带有方括号文本的 ATYP 0x03。
由索引模型根据 Issue 内容生成。
描述
My Claude discovered this.
Fable:
Affects hyper-util 0.1.20 (src/client/legacy/connect/proxy/socks/v5/mod.rs), seen through reqwest 0.13.5 with a socks5:// proxy (local DNS mode).
What happens
reqwest resolves the target locally and builds the destination URI with the address; an IPv6 address is written in brackets, as a URI requires (https://[2606:4700::6810:102]:443). SocksV5 then takes dst.host(), which for an IPv6 authority still carries the brackets ([2606:4700::6810:102]), and does:
let address = match host.parse::<IpAddr>() {
Ok(ip) => Address::Socket(SocketAddr::new(ip, port)),
Err(_) => ... Address::Domain(host, port)
"[2606:4700::6810:102]".parse::<IpAddr>() fails, so the literal goes out as ATYP 0x03 (domain name) with the brackets in the string. A SOCKS5 server that joins host and port (tailscaled's does, with Go's net.JoinHostPort) ends up with [[2606:4700::6810:102]]:443 and fails with "missing port in address". IPv4 literals have no brackets, so they parse and go out as ATYP 0x01.
Fix
Strip the URI brackets before parsing the host as an IP address, so an IPv6 literal goes out as ATYP 0x04:
- let address = match host.parse::<IpAddr>() {
+ let bare = host.strip_prefix('[').and_then(|h| h.strip_suffix(']')).unwrap_or(&host);
+ let address = match bare.parse::<IpAddr>() {
Ok(ip) => Address::Socket(SocketAddr::new(ip, port)),
A test: a SocksV5 request to https://[::1]:443 must encode ATYP 0x04 with the 16 raw bytes, not ATYP 0x03 with the text [::1].
How it showed up
A Rust server fetching pages through a Tailscale exit node (tailscaled --socks5-server) with reqwest::Proxy::all("socks5://…") and a custom resolver: every host with an AAAA record failed with error sending request (cause: the proxy's "missing port in address"), and hosts with only A records worked. Ordering the resolver's answers IPv4-first works around it.
- 主要语言
- Rust
- 星标
- 16.3k
- 派生
- 1.8k
- 平均合并
- 4 天 7 小时
- 30 天内合并 PR
- 10
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
hyperium/hyper 的其他 Issue
-
C-feature
难度 1/5 1 小时以内 新手友好度 65/100
hyperium/hyper#2652 · 4 个 reaction ·
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 74/100
维护者通常 2 天内回复
-
难度 4/5 3-5 天 新手友好度 55/100
维护者通常 2 天内回复
-
难度 3/5 1-2 天 新手友好度 35/100
维护者通常 2 天内回复
-
难度 4/5 3-5 天 新手友好度 62/100
维护者通常 2 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
aws-samples/sample-pacer#76 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 68/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 86/100
axodotdev/cargo-dist#2523 ·
维护者通常 2 天内回复