fix(proxy): write IPv4-mapped PROXY sources as TCP4 dotted addresses

This commit is contained in:
breken-ai
2026-09-25 12:14:16 -07:00
parent 6f47cadd45
commit 9adfc60bcf
2 changed files with 35 additions and 3 deletions
+7 -3
View File
@@ -314,10 +314,14 @@ func (p *SNIProxy) buildProxyProtocolHeaderFromInfo(proxyInfo *ProxyProtocolInfo
if srcIP == nil {
return "PROXY UNKNOWN\r\n"
}
srcIPStr := proxyInfo.SrcIP
if srcIP.To4() != nil {
// Source is IPv4, use TCP4 protocol
if srcIP4 := srcIP.To4(); srcIP4 != nil {
// Source is IPv4, use TCP4 protocol. Write it in dotted form: an
// IPv4-mapped IPv6 source ("::ffff:a.b.c.d", as sent in a TCP6 line
// by a dual-stack upstream) is not a valid TCP4 address.
protocol = "TCP4"
srcIPStr = srcIP4.String()
if targetTCP.IP.To4() != nil {
// Target is also IPv4, use as-is
targetIP = targetTCP.IP.String()
@@ -343,7 +347,7 @@ func (p *SNIProxy) buildProxyProtocolHeaderFromInfo(proxyInfo *ProxyProtocolInfo
return fmt.Sprintf("PROXY %s %s %s %d %d\r\n",
protocol,
proxyInfo.SrcIP,
srcIPStr,
targetIP,
proxyInfo.SrcPort,
targetTCP.Port)