Skip to content

Bind remoted to a set <local_ip> in that address family only (#1611) - #2304

Merged
atomicturtle merged 3 commits into
ossec:mainfrom
atomicturtle:fix/1611-local-ip-bind
Aug 26, 2026
Merged

atomicturtle merged 3 commits into
ossec:mainfrom
atomicturtle:fix/1611-local-ip-bind

Conversation

@atomicturtle

Copy link
Copy Markdown
Member
  • OS_Bindport now treats a numeric <local_ip> as that address only. Family comes from the address (getaddrinfo + AI_NUMERICHOST); <ipv6> is ignored when <local_ip> is set. An IPv4 local_ip is no longer mapped onto a dual-stack IPv6 socket (AI_V4MAPPED), which is what made netstat show udp6 for 192.168.x.x:1514.
  • With no <local_ip>, default bind is unchanged (Linux dual-stack wildcard). <ipv6>no</ipv6> binds IPv4-only (0.0.0.0). <ipv6> defaults remain unset (OS_BIND_IPV6_DEFAULT) so existing configs do not become IPv4-only.
  • Adds src/tests/regressions/issue_1611_local_ip_bind.c. CHANGELOG is left for the release pass.

closes issue #1611

A set local_ip binds only that address; ipv6 yes/no applies only when local_ip is omitted.
Review found leftover sockets on bind failure, a possible fds overflow, and a wildcard test that could send IPv4 and IPv6 to different ephemeral ports.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates OSSEC’s network binding behavior so that a numeric <local_ip> binds strictly to that address and its address family (avoiding IPv4-mapped IPv6 dual-stack sockets that appear as udp6), while preserving existing wildcard/<ipv6> behavior when <local_ip> is not set. Adds a targeted regression test to prevent the issue from recurring.

Changes:

  • Extend OS_Bindport* APIs to accept an ipv6 binding mode and implement numeric-local_ip family-specific binding (with IPV6_V6ONLY for explicit IPv6 local binds).
  • Wire the new ipv6 flag through remoted and os_auth server binding paths and tighten <ipv6> config parsing (yes/no only).
  • Add regression test issue_1611_local_ip_bind and integrate it into the regressions build.

Reviewed changes

Copilot reviewed 9 out of 9 changed files in this pull request and generated 2 comments.

Show a summary per file
File Description
src/tests/regressions/README.md Documents the new regression test entry.
src/tests/regressions/Makefile Builds and runs the new regression test binary.
src/tests/regressions/issue_1611_local_ip_bind.c New regression verifying bind family behavior for numeric local_ip, wildcard, and ipv6=no.
src/remoted/remoted.c Passes the configured ipv6 mode into TCP/UDP bind calls.
src/os_net/os_net.h Introduces OS_BIND_IPV6_* constants and updates OS_Bindport* prototypes.
src/os_net/os_net.c Implements numeric-IP family selection and ipv6-mode-aware wildcard binding behavior.
src/os_auth/main-server.c Updates bind call to pass OS_BIND_IPV6_DEFAULT.
src/config/remote-config.h Clarifies that ipv6 mode is ignored when lip is set.
src/config/remote-config.c Parses <ipv6> into OS_BIND_IPV6_* values and rejects invalid values.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/os_net/os_net.h
Comment on lines +74 to +75
OSNetInfo *OS_Bindporttcp(char *_port, const char *_ip, int ipv6);
OSNetInfo *OS_Bindportudp(char *_port, const char *_ip, int ipv6);
Comment thread src/os_net/os_net.h
Comment on lines +56 to +60
/*
* OS_Bindport ipv6 flag (used only when _ip is unset).
* DEFAULT/YES: dual-stack IPv4+IPv6. NO: IPv4-only wildcard.
* A numeric _ip always wins; the ipv6 flag is ignored.
*/
The previous comment said the flag was used only when _ip was unset; getaddrinfo also takes that path for hostnames.
@atomicturtle
atomicturtle merged commit 84f200f into ossec:main Aug 26, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants