Skip to content

Listen on IPv6; fix MariaDB 11 restart loop and dovecot start race - #1

Merged
MarvAmBass merged 2 commits into
masterfrom
ipv6-listen
Sep 28, 2026
Merged

MarvAmBass merged 2 commits into
masterfrom
ipv6-listen

Conversation

@MarvAmBass

Copy link
Copy Markdown
Member

IPv6

Postfix was hardcoded to inet_protocols = ipv4. With Docker NATing IPv6 straight into the container (ip6tables, default from Docker 27), IPv6 SMTP connections reached the container and found nothing listening. With docker-proxy (Docker default < 27) IPv6 clients were all logged as the network gateway 172.x.0.1.

  • entrypoint: inet_protocols=all when the container has IPv6 (/proc/net/if_inet6 non-empty), else ipv4 — IPv4-only containers stay quiet (no Postfix IPv6 warnings). New INET_PROTOCOLS env overrides.
  • default mynetworks gains [::1]/128 when IPv6 is on
  • list-available-networks.sh (AUTO_TRUST_NETWORKS) rewritten on top of connected routes from ip route: IPv4 + IPv6 in Postfix notation ([prefix]/len), link-local/multicast excluded. The old ifconfig parser stripped everything but digits and dots, so on an IPv6-enabled network inet6 lines became invalid mynetworks entries.
  • README: INET_PROTOCOLS and an IPv6 section
  • Dockerfile: add iproute2 (for ip route)

MariaDB 11 restart loop (trixie)

The process is mariadbd now, so killall mysqld after the first-start DB setup matched nothing (mysqld: no process found). The setup instance kept running unsupervised and runit's mysqld service looped once a second on A mysqld process already exists (plus a mysqld_safe: Deprecated program name line each time). Now: mariadbd-safe, and the setup instance is stopped with mariadb-admin shutdown, waiting for the socket to go.

Dovecot start race

Dovecot's auth/lmtp sockets live in /var/spool/postfix/private, which only exists once Postfix has started; runit starts both at once, so dovecot logged Fatal: Failed to start listeners on first start. The directory is now created before runit starts.

Tested

  • ./test.sh passes (fresh %BASE%)
  • IPv4-only network: listens on 0.0.0.0 and :::, clean log
  • IPv6 network + AUTO_TRUST_NETWORKS: inet_protocols=all, mynetworks=127.0.0.0/8,172.30.66.0/24,[::1]/128,[fd00:66:66::]/64, SMTP answers over IPv6 from another container
  • mysqld runit service stays up (no restart loop), no dovecot listener errors

Remaining log line: mariadbd: io_uring_queue_init() failed with EPERM — Docker's seccomp profile blocks io_uring; MariaDB falls back to libaio.

🤖 Generated with Claude Code

MarvAmBass and others added 2 commits September 28, 2026 10:44
IPv6:
- entrypoint: inet_protocols=all if the container has IPv6 (Docker
  network with enable_ipv6), else ipv4; INET_PROTOCOLS overrides
- mynetworks default gains [::1]/128 when IPv6 is on
- list-available-networks.sh: use connected routes from `ip route`
  (iproute2 added) instead of parsing ifconfig; emits IPv4 and IPv6
  (Postfix [prefix]/len notation). The old parser turned inet6 lines
  into invalid mynetworks entries on IPv6-enabled networks.
- README: INET_PROTOCOLS and an IPv6 section

MariaDB 11 (trixie): the process is `mariadbd`, so `killall mysqld` after
the first-start DB setup matched nothing. The setup instance kept running
unsupervised and runit's mysqld service looped on "A mysqld process
already exists" once a second. Use mariadbd-safe and stop the setup
instance with `mariadb-admin shutdown`, waiting for the socket to go.

Dovecot: create /var/spool/postfix/private before runit starts, so
dovecot's auth/lmtp sockets don't fail with "Failed to start listeners"
when it wins the race against postfix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both start in parallel under runit. Dovecot now starts cleanly on the first
try (no more listener race), so it is often up a few seconds before
`service postfix start` has finished — the test then checked for the
postfix master too early and failed intermittently in CI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@MarvAmBass
MarvAmBass merged commit 546833f into master Sep 28, 2026
2 checks passed
@MarvAmBass
MarvAmBass deleted the ipv6-listen branch September 28, 2026 08:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant