Title: fix(mcp): pin outbound connections to IPv4 to avoid unreachable-IPv6 hangs by waleedlatif1 · Pull Request #5798 · simstudioai/sim · GitHub
Open Graph Title: fix(mcp): pin outbound connections to IPv4 to avoid unreachable-IPv6 hangs by waleedlatif1 · Pull Request #5798 · simstudioai/sim
X Title: fix(mcp): pin outbound connections to IPv4 to avoid unreachable-IPv6 hangs by waleedlatif1 · Pull Request #5798 · simstudioai/sim
Description: The real root cause (empirically confirmed) The MCP "connecting forever" / tool-discovery 30s timeouts in production — affecting Gauge, Exa, and PlanetScale alike — were caused by IP-family pinning, not OAuth or HTTP/2 (which the earlier PRs fixed but were different layers). The chain, every link verified against production: SSRF protection pins each outbound connection to a single resolved IP (createPinnedLookup), which strips Happy Eyeballs' IPv4 fallback. dns.lookup(host, { verbatim: true }) returns the IPv6 address first for Cloudflare-fronted dual-stack hosts — verified: app.withgauge.com → 2606:4700:…, api.exa.ai → 2606:4700:…. Production's app subnets have zero IPv6 egress — no IPv6 CIDR, IPv4-only via NAT Gateway (AWS NAT Gateways are IPv4-only). Verified on both subnets + route tables. So the connection pinned to IPv6 connects into a void and hangs → the SDK's 30s timeout fires (AbortError, durationMs=30002). Intermittent because the resolver rotates A/AAAA order (works on retry when it picks IPv4). This explains everything that didn't add up: why #5797 (h1.1) didn't fix it (protocol-independent), and why it never reproduced locally (dev machines have IPv6 egress). Empirical proof (undici, pinned lookup): pin IPv6-blackhole ONLY (current behavior) → FAIL after 8001ms (TimeoutError) ← the prod hang prefer IPv4 / include IPv4 in the set → status 200 in ~600ms ← reachable Fix At both pinned-resolution sites — validateMcpServerSsrf (MCP) and validateUrlWithDNS (providers / A2A / SMTP, same latent bug) — resolve all addresses ({ all: true, verbatim: true }) and prefer an IPv4 address; IPv6-only hosts still pin their sole address. This keeps the single-IP pinning API and threading untouched (near-zero blast radius) and SSRF validation of the pinned IP is unchanged. Verified end-to-end: app.withgauge.com and api.exa.ai now pin their IPv4 address instead of the unreachable IPv6. Type of Change Bug fix Testing Full lib/mcp suite green (374); lib/core/security green; tsc + biome clean. Added tests: dual-stack host prefers IPv4; IPv6-only host pins its sole address. The definitive confirmation is re-testing on staging/prod once deployed. Note A fuller fix (pin the validated set of all resolved IPs and let undici do Happy Eyeballs, so it's egress-agnostic) is a good follow-up, but it threads string → string[] through ~10 security-critical sites; preferring IPv4 fixes the confirmed bug now with minimal risk. Checklist Code follows project style guidelines Self-reviewed my changes Tests added/updated and passing No new warnings introduced I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)
Open Graph Description: The real root cause (empirically confirmed) The MCP "connecting forever" / tool-discovery 30s timeouts in production — affecting Gauge, Exa, and PlanetScale alike — were caused by IP-fami...
X Description: The real root cause (empirically confirmed) The MCP "connecting forever" / tool-discovery 30s timeouts in production — affecting Gauge, Exa, and PlanetScale alike — were caused by...
Opengraph URL: https://github.com/simstudioai/sim/pull/5798
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/files(.:format) |
| route-controller | pull_requests |
| route-action | files |
| fetch-nonce | v2:83550284-cf3b-a863-9ed5-7ae422523861 |
| current-catalog-service-hash | ae870bc5e265a340912cde392f23dad3671a0a881730ffdadd82f2f57d81641b |
| request-id | D78C:C1BD7:FA3CD7:169333C:6A632D74 |
| html-safe-nonce | 84c626c666f083321551138a0674713764493bf0f176bb7e6300f126b69fa161 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJENzhDOkMxQkQ3OkZBM0NENzoxNjkzMzNDOjZBNjMyRDc0IiwidmlzaXRvcl9pZCI6IjE5ODQxNTAxNzA5ODE1NzYwNTIiLCJyZWdpb25fZWRnZSI6ImlhZCIsInJlZ2lvbl9yZW5kZXIiOiJpYWQifQ== |
| visitor-hmac | 0bafe3c2119577e8adabe4d4483c554d800cc7f25e3a5fe403f59812b3d03fcc |
| hovercard-subject-tag | pull_request:4096742160 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/simstudioai/sim/pull/5798/files |
| twitter:image | https://avatars.githubusercontent.com/u/40672544?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/40672544?s=400&v=4 |
| og:image:alt | The real root cause (empirically confirmed) The MCP "connecting forever" / tool-discovery 30s timeouts in production — affecting Gauge, Exa, and PlanetScale alike — were caused by IP-fami... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 30c644d502bce6cd2e59f9000b4744f2b64819abea8e8f959b18e3ad793125aa |
| turbo-cache-control | no-preview |
| diff-view | unified |
| go-import | github.com/simstudioai/sim git https://github.com/simstudioai/sim.git |
| octolytics-dimension-user_id | 199344406 |
| octolytics-dimension-user_login | simstudioai |
| octolytics-dimension-repository_id | 912559512 |
| octolytics-dimension-repository_nwo | simstudioai/sim |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 912559512 |
| octolytics-dimension-repository_network_root_nwo | simstudioai/sim |
| turbo-body-classes | logged-out env-production page-responsive full-width |
| disable-turbo | true |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 331492a48ebd91d66ef2de38e1901bb911c9fe9b |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width