Listen on IPv6; fix MariaDB 11 restart loop and dovecot start race - #1
Merged
Merged
Conversation
IPv6: - entrypoint: inet_protocols=all if the container has IPv6 (Docker network with enable_ipv6), else ipv4; INET_PROTOCOLS overrides - mynetworks default gains [::1]/128 when IPv6 is on - list-available-networks.sh: use connected routes from `ip route` (iproute2 added) instead of parsing ifconfig; emits IPv4 and IPv6 (Postfix [prefix]/len notation). The old parser turned inet6 lines into invalid mynetworks entries on IPv6-enabled networks. - README: INET_PROTOCOLS and an IPv6 section MariaDB 11 (trixie): the process is `mariadbd`, so `killall mysqld` after the first-start DB setup matched nothing. The setup instance kept running unsupervised and runit's mysqld service looped on "A mysqld process already exists" once a second. Use mariadbd-safe and stop the setup instance with `mariadb-admin shutdown`, waiting for the socket to go. Dovecot: create /var/spool/postfix/private before runit starts, so dovecot's auth/lmtp sockets don't fail with "Failed to start listeners" when it wins the race against postfix. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Both start in parallel under runit. Dovecot now starts cleanly on the first try (no more listener race), so it is often up a few seconds before `service postfix start` has finished — the test then checked for the postfix master too early and failed intermittently in CI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
IPv6
Postfix was hardcoded to
inet_protocols = ipv4. With Docker NATing IPv6 straight into the container (ip6tables, default from Docker 27), IPv6 SMTP connections reached the container and found nothing listening. With docker-proxy (Docker default < 27) IPv6 clients were all logged as the network gateway172.x.0.1.inet_protocols=allwhen the container has IPv6 (/proc/net/if_inet6non-empty), elseipv4— IPv4-only containers stay quiet (no Postfix IPv6 warnings). NewINET_PROTOCOLSenv overrides.mynetworksgains[::1]/128when IPv6 is onlist-available-networks.sh(AUTO_TRUST_NETWORKS) rewritten on top of connected routes fromip route: IPv4 + IPv6 in Postfix notation ([prefix]/len), link-local/multicast excluded. The old ifconfig parser stripped everything but digits and dots, so on an IPv6-enabled networkinet6lines became invalidmynetworksentries.INET_PROTOCOLSand an IPv6 sectioniproute2(forip route)MariaDB 11 restart loop (trixie)
The process is
mariadbdnow, sokillall mysqldafter the first-start DB setup matched nothing (mysqld: no process found). The setup instance kept running unsupervised and runit's mysqld service looped once a second onA mysqld process already exists(plus amysqld_safe: Deprecated program nameline each time). Now:mariadbd-safe, and the setup instance is stopped withmariadb-admin shutdown, waiting for the socket to go.Dovecot start race
Dovecot's auth/lmtp sockets live in
/var/spool/postfix/private, which only exists once Postfix has started; runit starts both at once, so dovecot loggedFatal: Failed to start listenerson first start. The directory is now created before runit starts.Tested
./test.shpasses (fresh%BASE%)0.0.0.0and:::, clean logAUTO_TRUST_NETWORKS:inet_protocols=all,mynetworks=127.0.0.0/8,172.30.66.0/24,[::1]/128,[fd00:66:66::]/64, SMTP answers over IPv6 from another containerRemaining log line:
mariadbd: io_uring_queue_init() failed with EPERM— Docker's seccomp profile blocks io_uring; MariaDB falls back to libaio.🤖 Generated with Claude Code