Bind remoted to a set <local_ip> in that address family only (#1611) - #2304
Merged
Merged
Conversation
A set local_ip binds only that address; ipv6 yes/no applies only when local_ip is omitted.
Review found leftover sockets on bind failure, a possible fds overflow, and a wildcard test that could send IPv4 and IPv6 to different ephemeral ports.
Contributor
There was a problem hiding this comment.
Pull request overview
Updates OSSEC’s network binding behavior so that a numeric <local_ip> binds strictly to that address and its address family (avoiding IPv4-mapped IPv6 dual-stack sockets that appear as udp6), while preserving existing wildcard/<ipv6> behavior when <local_ip> is not set. Adds a targeted regression test to prevent the issue from recurring.
Changes:
- Extend
OS_Bindport*APIs to accept anipv6binding mode and implement numeric-local_ipfamily-specific binding (withIPV6_V6ONLYfor explicit IPv6 local binds). - Wire the new
ipv6flag throughremotedandos_authserver binding paths and tighten<ipv6>config parsing (yes/noonly). - Add regression test
issue_1611_local_ip_bindand integrate it into the regressions build.
Reviewed changes
Copilot reviewed 9 out of 9 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| src/tests/regressions/README.md | Documents the new regression test entry. |
| src/tests/regressions/Makefile | Builds and runs the new regression test binary. |
| src/tests/regressions/issue_1611_local_ip_bind.c | New regression verifying bind family behavior for numeric local_ip, wildcard, and ipv6=no. |
| src/remoted/remoted.c | Passes the configured ipv6 mode into TCP/UDP bind calls. |
| src/os_net/os_net.h | Introduces OS_BIND_IPV6_* constants and updates OS_Bindport* prototypes. |
| src/os_net/os_net.c | Implements numeric-IP family selection and ipv6-mode-aware wildcard binding behavior. |
| src/os_auth/main-server.c | Updates bind call to pass OS_BIND_IPV6_DEFAULT. |
| src/config/remote-config.h | Clarifies that ipv6 mode is ignored when lip is set. |
| src/config/remote-config.c | Parses <ipv6> into OS_BIND_IPV6_* values and rejects invalid values. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+74
to
+75
| OSNetInfo *OS_Bindporttcp(char *_port, const char *_ip, int ipv6); | ||
| OSNetInfo *OS_Bindportudp(char *_port, const char *_ip, int ipv6); |
Comment on lines
+56
to
+60
| /* | ||
| * OS_Bindport ipv6 flag (used only when _ip is unset). | ||
| * DEFAULT/YES: dual-stack IPv4+IPv6. NO: IPv4-only wildcard. | ||
| * A numeric _ip always wins; the ipv6 flag is ignored. | ||
| */ |
The previous comment said the flag was used only when _ip was unset; getaddrinfo also takes that path for hostnames.
This was referenced Aug 26, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OS_Bindportnow treats a numeric<local_ip>as that address only. Family comes from the address (getaddrinfo+AI_NUMERICHOST);<ipv6>is ignored when<local_ip>is set. An IPv4local_ipis no longer mapped onto a dual-stack IPv6 socket (AI_V4MAPPED), which is what madenetstatshowudp6for192.168.x.x:1514.<local_ip>, default bind is unchanged (Linux dual-stack wildcard).<ipv6>no</ipv6>binds IPv4-only (0.0.0.0).<ipv6>defaults remain unset (OS_BIND_IPV6_DEFAULT) so existing configs do not become IPv4-only.src/tests/regressions/issue_1611_local_ip_bind.c. CHANGELOG is left for the release pass.closes issue #1611