Skip to content

Listen on IPv6 when the container has it - #11

Merged
MarvAmBass merged 1 commit into
masterfrom
ipv6-listen
Sep 28, 2026
Merged

MarvAmBass merged 1 commit into
masterfrom
ipv6-listen

Conversation

@MarvAmBass

Copy link
Copy Markdown
Member

IPv6

Postfix was hardcoded to inet_protocols = ipv4. With Docker NATing IPv6 straight into the container (ip6tables, default from Docker 27), IPv6 SMTP connections reached the container and found nothing listening. With docker-proxy (Docker default < 27) IPv6 clients were all logged as the network gateway 172.x.0.1.

  • entrypoint: inet_protocols=all when the container has IPv6 (/proc/net/if_inet6 non-empty), else ipv4 — IPv4-only containers stay quiet (no Postfix IPv6 warnings). New INET_PROTOCOLS env overrides.
  • default mynetworks gains [::1]/128 when IPv6 is on
  • list-available-networks.sh (AUTO_TRUST_NETWORKS) rewritten on top of connected routes from ip route: IPv4 + IPv6 in Postfix notation ([prefix]/len), link-local/multicast excluded. The old ifconfig parser stripped everything but digits and dots, so on an IPv6-enabled network inet6 lines became invalid mynetworks entries.
  • README: INET_PROTOCOLS and an IPv6 section
  • Dockerfile: add iproute2 (for ip route)

Tested

  • ./test.sh passes (fresh %BASE%)
  • IPv4-only network: listens on 0.0.0.0 and :::, clean log
  • IPv6 network + AUTO_TRUST_NETWORKS: inet_protocols=all, mynetworks=127.0.0.0/8,172.30.66.0/24,[::1]/128,[fd00:66:66::]/64, SMTP answers over IPv6 from another container

Note: freshclam warns ClamAV installation is OUTDATED (1.4.3 vs 1.4.6) — that is the newest in trixie/trixie-updates; signatures still update.

🤖 Generated with Claude Code

- entrypoint: inet_protocols=all if the container has IPv6 (Docker
  network with enable_ipv6), else ipv4; INET_PROTOCOLS overrides
- mynetworks default gains [::1]/128 when IPv6 is on
- list-available-networks.sh: use connected routes from `ip route`
  instead of parsing ifconfig; emits IPv4 and IPv6 (Postfix [prefix]/len
  notation). The old parser turned inet6 lines into invalid mynetworks
  entries on IPv6-enabled networks.
- README: INET_PROTOCOLS and an IPv6 section

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MarvAmBass
MarvAmBass merged commit 6f49413 into master Sep 28, 2026
2 checks passed
@MarvAmBass
MarvAmBass deleted the ipv6-listen branch September 28, 2026 08:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant