[28.x backport] Unmap IPv4 addresses loaded from store #50829
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
- What I did
IPv4-mapped IPv6 addresses are accepted by
iptables, and do the right thing (so there's no obvious behavioural change). But, maybe this will help with the linked issue, or at-least rule out a potential difference from rules in 28.0.x.- How I did it
When converting an endpoint's IPv4
net.IPNetto anetip.Addr, unmap it so that iptables rules don't contain IPv4-mapped IPv6 addresses - which they do otherwise, when the net.IPNet is loaded from the store.- How to verify it
docker network create b4docker run -d --rm --network b4 --name c1 busybox topWithout the change ...
With the change ...
- Human readable description for the release notes
- Fix an issue that could cause slow container restart on live-restore.