diff --git a/bot_bottle/backend/docker/gateway.py b/bot_bottle/backend/docker/gateway.py index 689ba5f0..1b44a9ed 100644 --- a/bot_bottle/backend/docker/gateway.py +++ b/bot_bottle/backend/docker/gateway.py @@ -148,6 +148,13 @@ class DockerGateway(Gateway): ) proc = run_docker([ "docker", "network", "create", + # bot-bottle attribution pins IPv4 source IPs; it has no IPv6 + # support. Disable IPv6 explicitly so a daemon that default-enables + # it (default-address-pools) can't attach an fdd0::/64 subnet — a + # malformed `::1/64` gateway address then trips docker's own + # ParseAddr in `network inspect`/`ls`, which poisons every launch + # that reads this network's subnet. + "--ipv6=false", "--subnet", self._subnet, "--label", f"{_GATEWAY_SUBNET_LABEL}={self._subnet}", self.network, diff --git a/tests/unit/test_orchestrator_gateway.py b/tests/unit/test_orchestrator_gateway.py index 7c8cbd2e..98ccdd49 100644 --- a/tests/unit/test_orchestrator_gateway.py +++ b/tests/unit/test_orchestrator_gateway.py @@ -215,6 +215,9 @@ class TestDockerGateway(unittest.TestCase): self.assertEqual( [[ "docker", "network", "create", + # IPv6 is disabled so a default-IPv6 daemon can't attach a + # malformed fdd0::/64 subnet that breaks `network inspect`. + "--ipv6=false", "--subnet", DEFAULT_GATEWAY_SUBNET, "--label", f"bot-bottle.gateway-subnet={DEFAULT_GATEWAY_SUBNET}",