From c6dcaac6161c2d6f991c6173c2e5c158e30118d1 Mon Sep 17 00:00:00 2001 From: robobun <117481402+robobun@users.noreply.github.com> Date: Sun, 12 Jul 2026 17:08:47 +0000 Subject: [PATCH 1/3] test(proxy-stress): dial 127.0.0.1 instead of 'localhost' for the proxy's upstream connect On darwin, localhost resolves to [::1, 127.0.0.1] and net.connect with autoSelectFamily tries ::1 first. The adversarial origins bind 127.0.0.1 only, so when an unrelated process on the CI host happens to be listening on [::1]:P at the same ephemeral port, the test proxy connects to that instead of the intended origin. Observed as a stray 204 on 'OPTIONS via https-proxy -> http-origin' in build 72283 on darwin 26 aarch64. The origin URL remains http(s)://localhost:P so Host header, CONNECT target, SNI, and checkServerIdentity assertions are unchanged. --- test/js/bun/http/proxy-stress-helpers.ts | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/test/js/bun/http/proxy-stress-helpers.ts b/test/js/bun/http/proxy-stress-helpers.ts index 24dd0e044378..a5714267eb76 100644 --- a/test/js/bun/http/proxy-stress-helpers.ts +++ b/test/js/bun/http/proxy-stress-helpers.ts @@ -365,6 +365,15 @@ export async function createAdversarialProxy(opts: AdversarialProxyOptions = {}) // and getaddrinfo want the bare literal. if (host.startsWith("[") && host.endsWith("]")) host = host.slice(1, -1); + // Every origin in this suite binds 127.0.0.1, but its URL says + // `localhost`. net.connect(.., "localhost") goes through + // autoSelectFamily, which on darwin tries `::1` first. IPv4 and IPv6 + // ephemeral-port spaces are independent, so an unrelated process on the + // CI host can be answering at `[::1]:port` while our origin holds + // `127.0.0.1:port` (observed as a stray 204 in build 72283). Dial the + // bound address directly; the IPv6-literal tests pass `[::1]` explicitly. + if (host === "localhost") host = "127.0.0.1"; + upstream = net.connect(port, host); let clientEnded = false; const endClient = () => { From 2c5ba2390859e0e398c4a0e78a287946739948e1 Mon Sep 17 00:00:00 2001 From: robobun <117481402+robobun@users.noreply.github.com> Date: Sun, 12 Jul 2026 17:20:37 +0000 Subject: [PATCH 2/3] tighten comment to 3 lines --- test/js/bun/http/proxy-stress-helpers.ts | 10 +++------- 1 file changed, 3 insertions(+), 7 deletions(-) diff --git a/test/js/bun/http/proxy-stress-helpers.ts b/test/js/bun/http/proxy-stress-helpers.ts index a5714267eb76..9303240e6700 100644 --- a/test/js/bun/http/proxy-stress-helpers.ts +++ b/test/js/bun/http/proxy-stress-helpers.ts @@ -365,13 +365,9 @@ export async function createAdversarialProxy(opts: AdversarialProxyOptions = {}) // and getaddrinfo want the bare literal. if (host.startsWith("[") && host.endsWith("]")) host = host.slice(1, -1); - // Every origin in this suite binds 127.0.0.1, but its URL says - // `localhost`. net.connect(.., "localhost") goes through - // autoSelectFamily, which on darwin tries `::1` first. IPv4 and IPv6 - // ephemeral-port spaces are independent, so an unrelated process on the - // CI host can be answering at `[::1]:port` while our origin holds - // `127.0.0.1:port` (observed as a stray 204 in build 72283). Dial the - // bound address directly; the IPv6-literal tests pass `[::1]` explicitly. + // Origins bind 127.0.0.1 but advertise `localhost`; on darwin that + // resolves `::1` first, and v4/v6 ephemeral-port spaces are independent, + // so dial the bound address. IPv6-literal tests pass `[::1]` explicitly. if (host === "localhost") host = "127.0.0.1"; upstream = net.connect(port, host); From 637f1ddf757228b2f01fb4dc45d3b1a461b498bb Mon Sep 17 00:00:00 2001 From: robobun <117481402+robobun@users.noreply.github.com> Date: Sun, 12 Jul 2026 17:41:42 +0000 Subject: [PATCH 3/3] ci: retrigger