mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 16:39:35 +08:00
A DNS64 answer like 64:ff9b::a00:5 is really 10.0.0.5, but the SSRF checks treated it as a public IPv6 address. Addresses inside a NAT64 prefix are now checked as the IPv4 address they embed, in policy DNS and in the CONNECT path. The well-known prefix is always known; other prefixes come from the new nat64_prefixes driver setting, or from ipv4only.arpa discovery when the supervisor starts. policy_dns_ipv6_egress and nat64_prefixes can now be set in the Docker, Podman, Kubernetes and VM driver configs. Before this, only auto was reachable in practice. The supervisor logs its IPv6 egress decision (requested mode, result, default routes, route state) and the NAT64 prefixes it uses as OCSF config events. Tests: route detection fixtures per backend, a start_mediated test with a fake mediation source and DNS64 upstream, driver arg tests, and an e2e check of the decision event. Signed-off-by: Joffref <mjoffre@blaxel.ai>