Skip to content

Commit db8f7b0

Browse files
committed
cli/command/container: validate --link-local-ip values
The --link-local-ip flag had no validator, and since the move to netip (v29.0.0) its values are converted with toNetipAddrSlice, which skips any value it cannot parse. A mistyped address, for example: docker run --network mynet --link-local-ip 169.254.1.1000 alpine was silently dropped, and the container was created without it. Before v29 the value was sent as-is, and the daemon rejected it. Validate the flag with opts.ValidateIPAddress, the same validator the --dns flag uses, so an invalid value fails when the flags are parsed. Assisted-By: Claude Code Signed-off-by: breken-ai <312387581+breken-ai@users.noreply.github.com>
1 parent b48c22e commit db8f7b0

2 files changed

Lines changed: 6 additions & 1 deletion

File tree

‎cli/command/container/opts.go‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -170,7 +170,7 @@ func addFlags(flags *pflag.FlagSet) *containerOptions {
170170
groupAdd: opts.NewListOpts(nil),
171171
labels: opts.NewListOpts(opts.ValidateLabel),
172172
labelsFile: opts.NewListOpts(nil),
173-
linkLocalIPs: opts.NewListOpts(nil),
173+
linkLocalIPs: opts.NewListOpts(opts.ValidateIPAddress),
174174
links: opts.NewListOpts(opts.ValidateLink),
175175
loggingOpts: opts.NewListOpts(nil),
176176
publish: opts.NewListOpts(nil),

‎cli/command/container/opts_test.go‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -766,6 +766,11 @@ func TestParseNetworkConfig(t *testing.T) {
766766
flags: []string{"--network", "net1", "--ip6", "172.20.88.22"},
767767
expectedErr: "invalid IPv6 address for --ip6: 172.20.88.22",
768768
},
769+
{
770+
name: "invalid-link-local-ip",
771+
flags: []string{"--network", "net1", "--link-local-ip", "foobar"},
772+
expectedErr: `invalid argument "foobar" for "--link-local-ip" flag: IP address is not correctly formatted: foobar`,
773+
},
769774
}
770775

771776
for _, tc := range tests {

0 commit comments

Comments
 (0)