Guard::resolve() combined gethostbynamel(), which is IPv4 only, with a
DNS AAAA query, which skips the hosts file. IPv6 addresses from the
hosts file, such as ::1 for localhost, were never found, so safe mode
couldn't reach a server listening only on them. Use getaddrinfo via
socket_addrinfo_lookup() when ext-sockets is available, falling back to
the previous lookups otherwise.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
curl keeps only the last CURLOPT_RESOLVE entry for a given host and
port, so passing one entry per address meant a host with both IPv6 and
IPv4 addresses was only ever tried on the last one. A server reachable
on just the other address (e.g. listening only on ::1) failed to
connect. Pass all the addresses in a single entry instead, which curl
has supported since 7.59.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>