惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
C
Check Point Blog
博客园_首页
B
Blog
D
Docker
U
Unit 42
量子位
I
InfoQ
有赞技术团队
有赞技术团队
Martin Fowler
Martin Fowler
GbyAI
GbyAI
L
LangChain Blog
云风的 BLOG
云风的 BLOG
博客园 - Franky
美团技术团队
T
The Blog of Author Tim Ferriss
阮一峰的网络日志
阮一峰的网络日志
月光博客
月光博客
Vercel News
Vercel News
Recent Announcements
Recent Announcements
雷峰网
雷峰网
大猫的无限游戏
大猫的无限游戏
小众软件
小众软件
Google DeepMind News
Google DeepMind News

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant
IPv6 zone identifiers in URLs are a quiet parser gotcha
Schiff Heimlich · 2026-06-22 · via DEV Community

Schiff Heimlich

You're debugging a URL parsing issue in your load balancer logs. Someone pasted a link like http://[fe80::1%eth0]:8080/ and your proxy choked on it.

That's the zone identifier — the %eth0 part. IPv6 link-local addresses need it to specify which interface to use. The problem is, zone identifiers don't actually belong in URLs, and different tools handle them very differently.

What zone identifiers are for

Link-local IPv6 addresses like fe80::1 are only usable on a single network segment. When you have multiple interfaces, the OS needs to know which one to send the packet out of. So you append %eth0 (or %1, %en0, whatever the interface name is) to disambiguate.

In code, this looks like:

import socket

# This is valid - bind to a specific interface
sock = socket.socket(socket.AF_INET6)
sock.bind(('fe80::1%eth0', 8080, 0, 0))

Why URLs are different

RFC 3986 is explicit: the zone identifier is not part of the URL syntax. It's a parsing artifact that only makes sense in address literals used by the local system.

Browsers know this. Chrome and Firefox strip zone identifiers before sending the URL to a server. But if you're writing a proxy, a URL parser, a DNS tool, or anything that processes URLs programmatically, you might be getting raw user input with zone identifiers still attached.

Where it breaks

  • URL parsers: stdlib urllib.parse in Python will happily parse [fe80::1%eth0] as the host, but whether it keeps or strips the zone depends on the library and version
  • Load balancers: HAProxy, nginx, Envoy all handle this differently in their URL parsing layers
  • DNS tools: Some dig or nslookup wrappers that accept URLs will fail or misinterpret the zone
  • Log parsers: If you're ingesting access logs and someone hotlinks a zone-scoped IPv6 address, your parser might silently drop the zone or fail to match the address

What to do about it

  1. Normalize on input: Strip zone identifiers from IPv6 addresses in URLs before processing, unless your code is actually doing local interface binding
  2. Be consistent: If you're storing or comparing addresses, normalize them the same way every time
  3. Check your tools: Review how your proxy, load balancer, or any URL-processing code handles link-local IPv6 addresses

The short version

Zone identifiers are for local interface routing, not for URLs. Browsers strip them. Your parsers might not. If you're building anything that touches IPv6 URLs, this is one of those details that will bite you once before you remember to handle it.


Not groundbreaking, but if you've ever spent an hour wondering why a link-local address won't bind or why a URL won't parse, this is probably why.