Skip to content

Add support for unix domain sockets - #109

Merged
Tony133 merged 2 commits into
fastify:mainfrom
fenichelar:main
Sep 4, 2026
Merged

Tony133 merged 2 commits into
fastify:mainfrom
fenichelar:main

Conversation

@fenichelar

@fenichelar fenichelar commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Adds support for unix domain sockets (i.e., req.socket.remoteAddress is undefined).

Checklist

Signed-off-by: Alec Fenichel <alec.fenichel@transnexus.com>

@mcollina mcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@Tony133 Tony133 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Could you also update the README? It currently says that the returned array includes the socket address and that index 0 is the socket address. This is no longer accurate for Unix domain sockets after this change, since no socket address is included and the returned array can be empty.

Signed-off-by: Alec Fenichel <alec.fenichel@transnexus.com>
@fenichelar
fenichelar requested a review from Tony133 September 4, 2026 19:45

@Tony133 Tony133 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Tony133
Tony133 merged commit 90ece3b into fastify:main Sep 4, 2026
17 checks passed
@gurgunday

Copy link
Copy Markdown
Member

This should be reverted, Fastify's CI is affected and there are issues with it

  • When the socket has no remoteAddress, the trust function never gets to check the immediate peer. The client-supplied X-Forwarded-For value comes back as request.ip no matter what the trust setting is.
  • trustProxy: '127.0.0.1' with a gone socket and X-Forwarded-For: 6.6.6.6 gives request.ip === '6.6.6.6'.
  • It also defeats the numeric trustProxy fix in 5.x (8acfea7e).
  • A missing remoteAddress happens on unix sockets, which is the use case of the new feature, and on destroyed sockets, for example reading request.ip after a client disconnects. Anything that uses request.ip for rate limiting, allowlists or audit logs can be spoofed in those cases.

Honestly, this was not the right place for the fix. It should be in proxy-addr

@fastify/plugins

Eomm pushed a commit that referenced this pull request Oct 10, 2026
This reverts commit 90ece3b.

Dropping a missing socket address from the result shifts every entry
down by one, so @fastify/proxy-addr treats the last X-Forwarded-For
entry as the socket address. Since 3.1.0, fastify's CI fails on
test/trust-proxy.test.js ("trust proxy with number and null socket
remoteAddress ignores forwarded headers"): request.ip is '1.1.1.1'
instead of null. Reverting restores the behavior of 3.0.x and fixes
fastify's CI.

Signed-off-by: Gürgün Dayıoğlu <hey@gurgun.day>
@fenichelar

Copy link
Copy Markdown
Contributor Author

@gurgunday

When the socket has no remoteAddress, the trust function never gets to check the immediate peer. The client-supplied X-Forwarded-For value comes back as request.ip no matter what the trust setting is.

If the reason the socket has no remoteAddress is because it is a unix domain socket, then what alterantive would you want to happen in this case?

trustProxy: '127.0.0.1' with a gone socket and X-Forwarded-For: 6.6.6.6 gives request.ip === '6.6.6.6'.

Again, if unix sockets are being used, this is likely the desired behavior.

A missing remoteAddress happens on unix sockets, which is the use case of the new feature, and on destroyed sockets, for example reading request.ip after a client disconnects. Anything that uses request.ip for rate limiting, allowlists or audit logs can be spoofed in those cases.

I agree the destroyed socket spoofing case is a concern but note that prior to this change when a socket was destroyed this library would return undefined so rate limiting, allowlists, or audit logs didn't work before either.

Honestly, this was not the right place for the fix. It should be in proxy-addr

I agree this is not the right place for this, but I also am not sure it can be fixed in just proxy-addr given how forwarded behaves in the case of an undefined remoteAddress.

@fenichelar

Copy link
Copy Markdown
Contributor Author

PR submitted to proxy-addr: fastify/proxy-addr#119. Removed dependency on forwarded in order to be able to control whether the remoteAddress is used.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants