fix(docker): disable IPv6 on the gateway network #515
Reference in New Issue
Block a user
Delete Branch "fix-gateway-disable-ipv6"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
The docker integration suite fails intermittently with a docker-internal parse error, e.g. in run 3500 / job 6658:
The
ParseAddr(...)text is docker's own Go stderr —docker network inspectitself is failing (the same run also showsdocker network lsexiting non-zero), so it is a daemon-state problem, not a code regression.Root cause
default-address-poolswith anfdd0::/48ULA range)._ensure_networkcreates the gateway net with only--subnet(gateway.py), so the daemon also attaches an IPv6 subnet whose gateway is stored asfdd0:0:0:N::1/64.docker network inspect/lschoke callingnetip.ParseAddron that::1/64value, poisoning every command that reads the network — so_network_cidrcan't read the subnet and the launch aborts.It looks flaky because the
Nis the daemon's IPv6 pool index (runner-state-dependent): integration-docker failed on #507 and #511 but passed on #513, #508, and main with identical code.Fix
bot-bottle attribution pins IPv4 source IPs and has no IPv6 support, so pass
--ipv6=falseexplicitly atdocker network create. That keeps the gateway network IPv4-only regardless of the daemon default, so the malformed IPv6 gateway can never be attached.Note for the runner
An already-poisoned runner still needs a one-time
docker network rm bot-bottle-gateway(and possibly a docker daemon restart, sincenetwork ls/inspectare poisoned) to clear the existing malformed network. This PR prevents recurrence.Tests
Updated
test_ensure_running_creates_network_when_missingto assert--ipv6=falseis in the create argv. Fulltest_orchestrator_gatewaysuite passes (29 tests).🤖 Generated with Claude Code
On a docker daemon that default-enables IPv6 (default-address-pools), creating the gateway network with only `--subnet` lets the daemon also attach an fdd0::/64 IPv6 subnet. Its gateway is stored as `::1/64`, which trips docker's own netip.ParseAddr in `network inspect`/`ls`: ParseAddr("fdd0:0:0:6::1/64"): unexpected character, want colon That poisons every `_network_cidr`/`network ls` read and fails the docker integration suite intermittently (whichever run the runner's IPv6 pool index lands on a broken network). bot-bottle attribution pins IPv4 source IPs and has no IPv6 support, so pass `--ipv6=false` explicitly at network create to keep the gateway network IPv4-only regardless of the daemon default. Note: an already-poisoned runner still needs a one-time `docker network rm bot-bottle-gateway` (and possibly a daemon restart) to clear the malformed network. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>