Skip to content

sshutil: Avoid double brackets on IPv6 hosts - #7164

Merged
tonistiigi merged 1 commit into
moby:masterfrom
a3ylf:fix/ssh-ipv6-default-port
Sep 29, 2026
Merged

tonistiigi merged 1 commit into
moby:masterfrom
a3ylf:fix/ssh-ipv6-default-port

Conversation

@a3ylf

@a3ylf a3ylf commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #7215, which includes the runnable llb.Git reproducer and before/after output.

A Git URL such as ssh://git@[::1]/repo.git supplies [::1] as its host. Adding the default SSH port currently produces [[::1]]:22, which cannot be dialed.

Remove existing brackets before calling net.JoinHostPort when no port is present. Tests cover bracketed and bare IPv6 addresses, zone identifiers, explicit ports, IPv4, and hostnames.

Validation: regression tests fail before the fix and pass afterward.

go test -race ./util/sshutil ./util/gitutil

The configured golangci-lint checks pass for the changed package(s).

@Karthik-Chowdary Karthik-Chowdary left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The normalization is correctly limited to the no-port path: SplitHostPort first preserves valid [v6]:port inputs, then existing brackets are removed before JoinHostPort adds the default. This avoids double brackets without changing explicit-port behavior, and the coverage includes bare/bracketed IPv6, zone identifiers, IPv4, and hostnames. I fetched the PR head and independently ran go test -race ./util/sshutil ./util/gitutil; both packages pass.

@jsternberg

Copy link
Copy Markdown
Collaborator

Can you create an issue for this with a reproducer? I highly suspect this is an LLM generated pull request but it's bordering on authentic enough that I could be convinced to take a look if there's an appropriate paper trail.

@a3ylf

a3ylf commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor Author

Can you create an issue for this with a reproducer? I highly suspect this is an LLM generated pull request but it's bordering on authentic enough that I could be convinced to take a look if there's an appropriate paper trail.

i'm a Brazilian currently finishing cs college, my english is not great so I prefer letting a LLM write the PRs for me, I did not make a issue because the bug seemed easily seen and solvable, but since it's a requirement I made a issue here: #7215

@jsternberg jsternberg left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor change to add some documentation to the new section of code but otherwise looks fine to me.

Comment thread util/sshutil/keyscan.go
Comment on lines +34 to +36
if strings.HasPrefix(hostport, "[") && strings.HasSuffix(hostport, "]") {
hostport = hostport[1 : len(hostport)-1]
}

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Add a comment to this section mentioning that this is to strip the brackets from an IPv6 host address. I'm a bit surprised the Go functions here for SplitHostPort and JoinHostPort don't handle this at all. SplitHostPort seems to fail if there's no port so we can't use that so this does seem to be the correct way to handle this. It might also be useful to include a comment about how SplitHostPort can't be used here.

@a3ylf

a3ylf commented Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Minor change to add some documentation to the new section of code but otherwise looks fine to me.

done

@jsternberg jsternberg left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Squash the commits into one and it LGTM.

A Git URL such as `ssh://git@[::1]/repo.git` supplies `[::1]` as its host. Adding the default SSH port currently produces `[[::1]]:22`, which cannot be dialed.

Remove existing brackets before calling `net.JoinHostPort` when no port is present. Tests cover bracketed and bare IPv6 addresses, zone identifiers, explicit ports, IPv4, and hostnames.

Signed-off-by: Alexandre Rodrigues <alexandre3ylf@gmail.com>
@a3ylf
a3ylf force-pushed the fix/ssh-ipv6-default-port branch from 1e91461 to 521a1be Compare September 29, 2026 16:39
@tonistiigi tonistiigi added this to the v0.34.0 milestone Sep 29, 2026
@tonistiigi
tonistiigi merged commit 36c2600 into moby:master Sep 29, 2026
215 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

llb.Git omits known SSH hosts for IPv6 URLs without an explicit port

4 participants