Skip to content

fix(iroh): handle IPv6 literal relay URLs in QAD probes - #4527

Merged
flub merged 11 commits into
n0-computer:mainfrom
William-Herly:upstream-fix/qad-ipv6-server-name
Oct 2, 2026
Merged

flub merged 11 commits into
n0-computer:mainfrom
William-Herly:upstream-fix/qad-ipv6-server-name

Conversation

@William-Herly

Copy link
Copy Markdown
Contributor

Description

Fixes #4526

QAD probes pass the relay URL's host_str() to QUIC as the TLS server name. For IPv6 literals this includes brackets, causing invalid server name before certificate verification.

Extract the name from the parsed URL host instead, and use it in both QAD probe paths. Certificate verification and QAD port selection remain unchanged.

The regression uses a local IPv6 QAD server with a trusted certificate for ::1. A connection using the bare IP succeeds; probing through the IPv6 relay URL fails before the fix and succeeds afterwards. The relay URL and QAD configuration use different ports. A unit test also covers domain, IPv4 and IPv6 names.

Validation on macOS arm64:

cargo test --locked -p iroh --lib net_report::
# 9 passed
cargo clippy --locked -p iroh --lib --tests -- -D warnings
cargo +nightly make format-check

API Changes

None.

Notes & open questions

None

Change checklist

  • Self-review.
  • Documentation updates following the style guide, if relevant.
  • Tests if relevant.
  • All API changes documented.
  • This PR was created by a human that thought critically about the
    proposed change and wrote an as clear and concise description as
    they could.
  • This PR isn't slop, and is carefully crafted to do have the
    intented effect.

@n0bot n0bot Bot added this to iroh Sep 10, 2026
@github-project-automation github-project-automation Bot moved this to 🚑 Needs Triage in iroh Sep 10, 2026
@William-Herly
William-Herly marked this pull request as ready for review September 10, 2026 22:14

@flub flub left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey, thanks for this PR and for bearing with. It has been a busy few weeks on this side. One small nit, let me know if you'd like to address it. It would be kinda neat if we did, but it is not absolutely required.

Comment thread iroh/src/net_report.rs Outdated
}

#[cfg(not(wasm_browser))]
fn relay_tls_server_name(relay: &RelayConfig) -> Option<String> {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To make this extra neat it could return an std::borrow::Cow<str>, so that the common case does not need an allocation. But also this isn't on a hot path so probably doesn't matter that much.

@flub

flub commented Sep 29, 2026

Copy link
Copy Markdown
Collaborator

ah, and it seems like the tests will need some tweaks for windows.

@William-Herly

Copy link
Copy Markdown
Contributor Author

@flub Thanks for the review! I’ve updated the PR as suggested.

@flub flub left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thanks!

@flub
flub enabled auto-merge October 2, 2026 13:47
@flub
flub added this pull request to the merge queue Oct 2, 2026
Merged via the queue into n0-computer:main with commit a152c9b Oct 2, 2026
38 checks passed
gsnaiper pushed a commit to gsnaiper/iroh that referenced this pull request Oct 8, 2026
…4527)

## Description

Fixes n0-computer#4526

QAD probes pass the relay URL's `host_str()` to QUIC as the TLS server
name. For IPv6 literals this includes brackets, causing `invalid server
name` before certificate verification.

Extract the name from the parsed URL host instead, and use it in both
QAD probe paths. Certificate verification and QAD port selection remain
unchanged.

The regression uses a local IPv6 QAD server with a trusted certificate
for `::1`. A connection using the bare IP succeeds; probing through the
IPv6 relay URL fails before the fix and succeeds afterwards. The relay
URL and QAD configuration use different ports. A unit test also covers
domain, IPv4 and IPv6 names.

Validation on macOS arm64:

```sh
cargo test --locked -p iroh --lib net_report::
# 9 passed
cargo clippy --locked -p iroh --lib --tests -- -D warnings
cargo +nightly make format-check
```

## API Changes

None.

## Notes & open questions

None

## Change checklist

- [x] Self-review.
- [x] Documentation updates following the [style
guide](https://rust-lang.github.io/rfcs/1574-more-api-documentation-conventions.html#appendix-a-full-conventions-text),
if relevant.
- [x] Tests if relevant.
- [x] All API changes documented.
- [x] This PR was created by a human that thought critically about the
      proposed change and wrote an as clear and concise description as
      they could.
- [x] This PR isn't slop, and is carefully crafted to do have the
      intented effect.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

QAD probes fail for relay URLs with IPv6 literals

2 participants