Repository navigation
Listen on IPv6 when the container has it - #11
Merged
Merged
Conversation
- entrypoint: inet_protocols=all if the container has IPv6 (Docker network with enable_ipv6), else ipv4; INET_PROTOCOLS overrides - mynetworks default gains [::1]/128 when IPv6 is on - list-available-networks.sh: use connected routes from `ip route` instead of parsing ifconfig; emits IPv4 and IPv6 (Postfix [prefix]/len notation). The old parser turned inet6 lines into invalid mynetworks entries on IPv6-enabled networks. - README: INET_PROTOCOLS and an IPv6 section Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
IPv6
Postfix was hardcoded to
inet_protocols = ipv4. With Docker NATing IPv6 straight into the container (ip6tables, default from Docker 27), IPv6 SMTP connections reached the container and found nothing listening. With docker-proxy (Docker default < 27) IPv6 clients were all logged as the network gateway172.x.0.1.inet_protocols=allwhen the container has IPv6 (/proc/net/if_inet6non-empty), elseipv4— IPv4-only containers stay quiet (no Postfix IPv6 warnings). NewINET_PROTOCOLSenv overrides.mynetworksgains[::1]/128when IPv6 is onlist-available-networks.sh(AUTO_TRUST_NETWORKS) rewritten on top of connected routes fromip route: IPv4 + IPv6 in Postfix notation ([prefix]/len), link-local/multicast excluded. The old ifconfig parser stripped everything but digits and dots, so on an IPv6-enabled networkinet6lines became invalidmynetworksentries.INET_PROTOCOLSand an IPv6 sectioniproute2(forip route)Tested
./test.shpasses (fresh%BASE%)0.0.0.0and:::, clean logAUTO_TRUST_NETWORKS:inet_protocols=all,mynetworks=127.0.0.0/8,172.30.66.0/24,[::1]/128,[fd00:66:66::]/64, SMTP answers over IPv6 from another containerNote: freshclam warns
ClamAV installation is OUTDATED(1.4.3 vs 1.4.6) — that is the newest in trixie/trixie-updates; signatures still update.🤖 Generated with Claude Code