Leave an IPv6 loopback mapping out of what a container publishes, reading ports from the end (hq ADR 0100)
This commit is contained in:
@@ -123,22 +123,14 @@ func Published(resources []map[string]any) map[string]map[int]int {
|
||||
protocol := "tcp"
|
||||
if cut := strings.LastIndex(written, "/"); cut >= 0 {
|
||||
protocol = written[cut+1:]
|
||||
written = written[:cut]
|
||||
}
|
||||
parts := strings.Split(written, ":")
|
||||
if len(parts) < 2 {
|
||||
// Indexed from the end, so an IPv6 address's own colons never shift the ports.
|
||||
outer, inner, address, ok := mapping(written)
|
||||
if !ok {
|
||||
continue
|
||||
}
|
||||
if len(parts) == 3 && (parts[0] == "127.0.0.1" || parts[0] == "localhost" ||
|
||||
parts[0] == "[::1]") {
|
||||
continue
|
||||
}
|
||||
outer, err := strconv.Atoi(parts[len(parts)-2])
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
inner, err := strconv.Atoi(parts[len(parts)-1])
|
||||
if err != nil {
|
||||
switch strings.Trim(address, "[]") {
|
||||
case "127.0.0.1", "localhost", "::1":
|
||||
continue
|
||||
}
|
||||
if out[protocol] == nil {
|
||||
|
||||
@@ -336,3 +336,15 @@ func TestTheGuardIsDerivedFromTakenModulesOnly(t *testing.T) {
|
||||
t.Fatalf("the guard does not follow the given ports:\n%s", got)
|
||||
}
|
||||
}
|
||||
|
||||
// A mapping bound to loopback is not published to anything off the machine — in either address
|
||||
// family — and an address's own colons never shift the ports.
|
||||
func TestPublishedLeavesOutLoopbackInBothFamilies(t *testing.T) {
|
||||
got := Published([]map[string]any{{"type": "container", "ports": []any{
|
||||
"127.0.0.1:15672:15672", "[::1]:8080:80", "localhost:9090:90",
|
||||
"[::]:8443:443", "0.0.0.0:5000:5000", "5353:53/udp"}}})
|
||||
want := map[string]map[int]int{"tcp": {8443: 443, 5000: 5000}, "udp": {5353: 53}}
|
||||
if !reflect.DeepEqual(got, want) {
|
||||
t.Fatalf("published is %v, want %v", got, want)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user