From d7f11daa85900a65a5dada47940acb0be47137a1 Mon Sep 17 00:00:00 2001 From: Kris Hicks Date: Thu, 17 Sep 2026 10:17:36 -0700 Subject: [PATCH] fix(podman): route local clients to the primary listener As part of the RFC-0012 changes, Podman Machine uses the IPv4 loopback listener for compute-driver callbacks while the local gateway launcher binds the primary listener to IPv6. The launcher still registered that primary endpoint using localhost. This meant hostname resolution could direct CLI requests to the IPv4 callback-only listener instead of the primary gateway listener. Now, we register the literal IPv6 loopback address when using the macOS default while preserving explicit bind-address overrides. Signed-off-by: Kris Hicks --- tasks/scripts/gateway-podman.sh | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/tasks/scripts/gateway-podman.sh b/tasks/scripts/gateway-podman.sh index a45c1d35d4..bda3c82586 100644 --- a/tasks/scripts/gateway-podman.sh +++ b/tasks/scripts/gateway-podman.sh @@ -151,11 +151,12 @@ EOF if [[ -z "${OPENSHELL_BIND_ADDRESS:-}" && "$(uname -s)" == "Darwin" ]]; then # Podman Machine reserves IPv4 loopback for its callback-only listener. - # Keep the primary listener distinct while using a hostname that resolves - # to IPv6 loopback for local CLI connections. An explicit bind address - # overrides this platform default. + # Keep the primary listener distinct and register its literal IPv6 address: + # `localhost` can resolve to IPv4 first, which would route CLI requests to + # the callback-only listener. An explicit bind address overrides this + # platform default. PRIMARY_BIND_IP="::1" - CLI_ENDPOINT_HOST="localhost" + CLI_ENDPOINT_HOST="[::1]" fi if [[ ! "${GATEWAY_NAME}" =~ ^[A-Za-z0-9._-]+$ ]]; then