Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
fc720bfeee | ||
|
|
a7dfbf4414 |
+4
-8
@@ -13,12 +13,9 @@ RUN go mod download
|
|||||||
# Copy source code
|
# Copy source code
|
||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
# Run formatting check and linter. The linter is invoked directly, not
|
# Run formatting check and linter
|
||||||
# via `make lint`: `make lint` now builds Dockerfile.lint, and there is
|
|
||||||
# no Docker inside a Docker build. This is the same linter, image, and
|
|
||||||
# config that Dockerfile.lint and script/lint run.
|
|
||||||
RUN make fmt-check
|
RUN make fmt-check
|
||||||
RUN golangci-lint run --config .golangci.yml ./...
|
RUN make lint
|
||||||
|
|
||||||
# Build stage
|
# Build stage
|
||||||
# golang:1.25.4-alpine, 2026-02-25
|
# golang:1.25.4-alpine, 2026-02-25
|
||||||
@@ -70,9 +67,8 @@ RUN adduser -D -H -s /sbin/nologin pixad && \
|
|||||||
mkdir -p /var/lib/pixa /etc/pixa && \
|
mkdir -p /var/lib/pixa /etc/pixa && \
|
||||||
chown pixad:pixad /var/lib/pixa
|
chown pixad:pixad /var/lib/pixa
|
||||||
|
|
||||||
# Copy the image config; signing_key comes from PIXA_SIGNING_KEY.
|
# Copy default config (edit signing_key before use)
|
||||||
# Mount a file over /etc/pixa/config.yml to override anything else.
|
COPY config.example.yml /etc/pixa/config.yml
|
||||||
COPY config.docker.yml /etc/pixa/config.yml
|
|
||||||
|
|
||||||
USER pixad
|
USER pixad
|
||||||
WORKDIR /var/lib/pixa
|
WORKDIR /var/lib/pixa
|
||||||
|
|||||||
@@ -1,41 +0,0 @@
|
|||||||
# Dockerfile.lint: the one and only path that runs golangci-lint.
|
|
||||||
#
|
|
||||||
# golangci-lint is never installed on the host; it runs only inside this
|
|
||||||
# build. A clean build of this file therefore IS a clean lint over the
|
|
||||||
# whole tree. It runs the same linter and config as Dockerfile's lint
|
|
||||||
# stage, pinned to the same image so the two cannot drift to different
|
|
||||||
# linter versions.
|
|
||||||
#
|
|
||||||
# golangci/golangci-lint:v2.12.2-alpine, 2026-08-07
|
|
||||||
FROM golangci/golangci-lint:v2.12.2-alpine@sha256:91b27804074a0bacea298707f016911e60cf0cdbc6c7bf5ccacb5f0606d18d60
|
|
||||||
|
|
||||||
# pixa is CGO/libvips: the type-aware linters compile every package, so
|
|
||||||
# this image needs the same C libraries the build does.
|
|
||||||
RUN apk add --no-cache build-base vips-dev libheif-dev pkgconfig
|
|
||||||
|
|
||||||
WORKDIR /src
|
|
||||||
|
|
||||||
# Modules first for layer caching; go.mod/go.sum settle this layer's
|
|
||||||
# result, so it may safely be reused between runs.
|
|
||||||
COPY go.mod go.sum ./
|
|
||||||
RUN go mod download
|
|
||||||
|
|
||||||
COPY . .
|
|
||||||
|
|
||||||
# Caching is deliberately waived for the lint step: an unchanged tree
|
|
||||||
# must still run the linter, not return a cached success in well under a
|
|
||||||
# second having linted nothing. CACHEBUST carries a value that differs
|
|
||||||
# on every run (script/lint supplies it and refuses to build without
|
|
||||||
# one). The lint RUN below references it, so BuildKit cannot serve that
|
|
||||||
# step from cache. Keep the ${CACHEBUST} reference on that step: dropping
|
|
||||||
# it lets the linter cache again and report a green that linted nothing.
|
|
||||||
ARG CACHEBUST
|
|
||||||
RUN test -n "${CACHEBUST}" || { \
|
|
||||||
echo "Dockerfile.lint requires the CACHEBUST build-arg; build it via script/lint." >&2; \
|
|
||||||
exit 1; }
|
|
||||||
|
|
||||||
# `golangci-lint config verify` is deliberately not run: it fetches its
|
|
||||||
# JSON schema over an unpinned live HTTPS call, which REPO_POLICIES.md
|
|
||||||
# forbids for external references.
|
|
||||||
RUN echo "pixa-lint: running golangci-lint (${CACHEBUST})" && \
|
|
||||||
golangci-lint run --config .golangci.yml ./...
|
|
||||||
@@ -15,25 +15,14 @@ git clone https://git.eeqj.de/sneak/pixa.git
|
|||||||
cd pixa
|
cd pixa
|
||||||
make build
|
make build
|
||||||
|
|
||||||
# run with a config file: copy the example and set a real signing key
|
# run with a config file
|
||||||
# (the example placeholder is refused at startup), e.g. with
|
./bin/pixad --config config.example.yml
|
||||||
# openssl rand -base64 32
|
|
||||||
cp config.example.yml config.yml
|
|
||||||
$EDITOR config.yml # replace the signing_key placeholder
|
|
||||||
./bin/pixad --config config.yml
|
|
||||||
|
|
||||||
# or build and run via Docker
|
# or build and run via Docker
|
||||||
make docker
|
make docker
|
||||||
docker run -p 8080:8080 -e PIXA_SIGNING_KEY="$(openssl rand -base64 32)" pixa:latest
|
docker run -p 8080:8080 pixad:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
A container is configured two ways. The signing key comes from the
|
|
||||||
`PIXA_SIGNING_KEY` environment variable, which the baked-in config
|
|
||||||
reads; if it is unset the container exits at startup naming the
|
|
||||||
variable. Everything else uses built-in defaults, so to change any
|
|
||||||
other setting mount your own file over `/etc/pixa/config.yml` (see
|
|
||||||
`config.example.yml` for the full set of keys).
|
|
||||||
|
|
||||||
## Rationale
|
## Rationale
|
||||||
|
|
||||||
Image-heavy web applications need a fast, caching reverse proxy that
|
Image-heavy web applications need a fast, caching reverse proxy that
|
||||||
@@ -122,6 +111,10 @@ Configured via YAML file (`--config`). Key settings:
|
|||||||
|
|
||||||
- `access_control_allow_origin` — CORS origin
|
- `access_control_allow_origin` — CORS origin
|
||||||
- `allowlist_hosts` — list of allowed upstream hosts
|
- `allowlist_hosts` — list of allowed upstream hosts
|
||||||
|
- `blocked_networks` — list of CIDR ranges to refuse for SSRF protection,
|
||||||
|
added to the always-enforced built-in ranges (loopback, private,
|
||||||
|
link-local, CGNAT, benchmark, NAT64, and the like); an invalid CIDR
|
||||||
|
aborts startup
|
||||||
- `upstream_fetch_timeout` — timeout for origin requests
|
- `upstream_fetch_timeout` — timeout for origin requests
|
||||||
- `upstream_max_response_size` — max origin response size
|
- `upstream_max_response_size` — max origin response size
|
||||||
- `downstream_timeout` — client response timeout
|
- `downstream_timeout` — client response timeout
|
||||||
|
|||||||
@@ -25,19 +25,20 @@ The disk cache is now size-bounded with LRU eviction
|
|||||||
|
|
||||||
# Next Step
|
# Next Step
|
||||||
|
|
||||||
P1: implement blocked networks configuration to extend SSRF protection
|
P1: rate limit global concurrent upstream fetches to prevent resource
|
||||||
|
exhaustion
|
||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-09-21 run all linting in Docker via `Dockerfile.lint` +
|
- 2026-09-21 blocked networks configuration extending SSRF protection: a
|
||||||
`script/lint` (closes #104): `script/lint` builds a hash-pinned root
|
`blocked_networks` config key taking a list of CIDRs (parsed with
|
||||||
`Dockerfile.lint`, and no host or nix-shell `golangci-lint` path
|
`net/netip`, an invalid entry aborts startup naming the key and value),
|
||||||
remains; a per-run `CACHEBUST` build-arg forces the lint step to
|
added to the built-in blocklist rather than replacing it; the built-in
|
||||||
execute every run, so an unchanged tree cannot return a cached green
|
ranges extended to CGNAT `100.64.0.0/10`, IETF protocol assignments
|
||||||
that linted nothing; `Dockerfile`'s lint stage runs `golangci-lint`
|
`192.0.0.0/24`, benchmark `198.18.0.0/15`, and NAT64 `64:ff9b::/96`
|
||||||
directly, since `make lint` now builds a container and there is no
|
(IPv4-mapped forms covered); enforcement stays in the dial-time
|
||||||
Docker inside a build; `golangci-lint config verify` stays out, as it
|
re-resolution so the DNS-rebinding window remains closed; documented in
|
||||||
fetches its schema over an unpinned live HTTPS call
|
`README.md` and `config.example.yml`.
|
||||||
- 2026-09-21 http.Server hardening (closes #92): added
|
- 2026-09-21 http.Server hardening (closes #92): added
|
||||||
`HTTPReadHeaderTimeout` (10s, bounds the slowloris header dribble) and
|
`HTTPReadHeaderTimeout` (10s, bounds the slowloris header dribble) and
|
||||||
`HTTPIdleTimeout` (120s, bounds keep-alive reuse) alongside the
|
`HTTPIdleTimeout` (120s, bounds keep-alive reuse) alongside the
|
||||||
@@ -139,8 +140,6 @@ P1: implement blocked networks configuration to extend SSRF protection
|
|||||||
|
|
||||||
# Future Steps
|
# Future Steps
|
||||||
|
|
||||||
- P1: rate limit global concurrent upstream fetches to prevent
|
|
||||||
resource exhaustion
|
|
||||||
- P1: strip EXIF and other metadata from processed images (privacy)
|
- P1: strip EXIF and other metadata from processed images (privacy)
|
||||||
- P2: security
|
- P2: security
|
||||||
- referer blacklist
|
- referer blacklist
|
||||||
|
|||||||
@@ -1,11 +0,0 @@
|
|||||||
# Pixa configuration baked into the Docker image.
|
|
||||||
#
|
|
||||||
# The signing key is read from the PIXA_SIGNING_KEY environment
|
|
||||||
# variable; startup aborts naming it when it is unset. Every other key
|
|
||||||
# is omitted so its default applies. Operators who need more (an
|
|
||||||
# allowlist, metrics, and so on) mount their own file over
|
|
||||||
# /etc/pixa/config.yml.
|
|
||||||
|
|
||||||
signing_key: "${ENV:PIXA_SIGNING_KEY}"
|
|
||||||
state_dir: /var/lib/pixa
|
|
||||||
port: 8080
|
|
||||||
@@ -22,6 +22,15 @@ allowlist_hosts:
|
|||||||
- github.com
|
- github.com
|
||||||
- user-images.githubusercontent.com
|
- user-images.githubusercontent.com
|
||||||
|
|
||||||
|
# Additional CIDR ranges to refuse when fetching upstream, extending the
|
||||||
|
# SSRF protection. These are added to the always-enforced built-in ranges
|
||||||
|
# (loopback, RFC 1918 private, link-local, CGNAT, benchmark, NAT64, and
|
||||||
|
# similar), never replacing them. Each entry must be a valid CIDR in IPv4
|
||||||
|
# or IPv6 form; an invalid entry aborts startup.
|
||||||
|
# blocked_networks:
|
||||||
|
# - 100.64.0.0/10
|
||||||
|
# - 2001:db8::/32
|
||||||
|
|
||||||
# Allow HTTP upstream (only for testing, always use HTTPS in production)
|
# Allow HTTP upstream (only for testing, always use HTTPS in production)
|
||||||
allow_http: false
|
allow_http: false
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,90 @@
|
|||||||
|
package config
|
||||||
|
|
||||||
|
import (
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestBlockedNetworksParsed loads a valid blocked_networks list and checks
|
||||||
|
// each CIDR is parsed into the resolved prefixes in order.
|
||||||
|
func TestBlockedNetworksParsed(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
yamlContent := signingKeyLine + `blocked_networks:
|
||||||
|
- 203.0.113.0/24
|
||||||
|
- 2001:db8::/32
|
||||||
|
`
|
||||||
|
|
||||||
|
c, err := configFromYAML(t, yamlContent)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("valid blocked_networks should load, got error: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
want := []string{"203.0.113.0/24", "2001:db8::/32"}
|
||||||
|
if len(c.BlockedNetworks) != len(want) {
|
||||||
|
t.Fatalf("BlockedNetworks = %v, want %d entries", c.BlockedNetworks, len(want))
|
||||||
|
}
|
||||||
|
|
||||||
|
for i, w := range want {
|
||||||
|
if got := c.BlockedNetworks[i].String(); got != w {
|
||||||
|
t.Errorf("BlockedNetworks[%d] = %q, want %q", i, got, w)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestBlockedNetworksOmittedIsEmpty confirms an omitted key leaves the
|
||||||
|
// operator list empty; the built-in defaults still apply in the fetcher.
|
||||||
|
func TestBlockedNetworksOmittedIsEmpty(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
c, err := configFromYAML(t, signingKeyLine)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("minimal config should be valid, got error: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(c.BlockedNetworks) != 0 {
|
||||||
|
t.Errorf("BlockedNetworks = %v, want empty", c.BlockedNetworks)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestBlockedNetworksInvalidAbortsStartup checks that malformed values abort
|
||||||
|
// startup with an error naming the key and the offending value.
|
||||||
|
func TestBlockedNetworksInvalidAbortsStartup(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
runAbortCases(t, []abortCase{
|
||||||
|
{
|
||||||
|
name: "not-a-cidr",
|
||||||
|
yaml: signingKeyLine + `blocked_networks:
|
||||||
|
- not-a-cidr
|
||||||
|
`,
|
||||||
|
wantErrSubstrings: []string{keyBlockedNetworks, "not-a-cidr"},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "bare-address-without-prefix",
|
||||||
|
yaml: signingKeyLine + `blocked_networks:
|
||||||
|
- 10.0.0.1
|
||||||
|
`,
|
||||||
|
wantErrSubstrings: []string{keyBlockedNetworks, "10.0.0.1"},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "empty-entry",
|
||||||
|
yaml: signingKeyLine + `blocked_networks:
|
||||||
|
- ""
|
||||||
|
`,
|
||||||
|
wantErrSubstrings: []string{keyBlockedNetworks},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "non-string-entry",
|
||||||
|
yaml: signingKeyLine + `blocked_networks:
|
||||||
|
- 42
|
||||||
|
`,
|
||||||
|
wantErrSubstrings: []string{keyBlockedNetworks},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "null-value",
|
||||||
|
yaml: signingKeyLine + `blocked_networks:
|
||||||
|
`,
|
||||||
|
wantErrSubstrings: []string{keyBlockedNetworks, nullValueText},
|
||||||
|
},
|
||||||
|
})
|
||||||
|
}
|
||||||
+104
-30
@@ -6,6 +6,7 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"math"
|
"math"
|
||||||
|
"net/netip"
|
||||||
"net/url"
|
"net/url"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
@@ -42,14 +43,9 @@ const (
|
|||||||
keyAllowHTTP = "allow_http"
|
keyAllowHTTP = "allow_http"
|
||||||
keyUpstreamConnectionsPerHost = "upstream_connections_per_host"
|
keyUpstreamConnectionsPerHost = "upstream_connections_per_host"
|
||||||
keyCacheMaxBytes = "cache_max_bytes"
|
keyCacheMaxBytes = "cache_max_bytes"
|
||||||
|
keyBlockedNetworks = "blocked_networks"
|
||||||
)
|
)
|
||||||
|
|
||||||
// placeholderSigningKey is the dummy signing_key shipped in
|
|
||||||
// config.example.yml. It is 45 characters, so it passes the length
|
|
||||||
// check, but it is public in this repository and must be rejected at
|
|
||||||
// startup so no deployment ever signs URLs with it.
|
|
||||||
const placeholderSigningKey = "CHANGE_ME_generate_with_openssl_rand_base64_32"
|
|
||||||
|
|
||||||
// Static validation errors. Each use site attaches the offending key
|
// Static validation errors. Each use site attaches the offending key
|
||||||
// and value by wrapping these with fmt.Errorf and %w.
|
// and value by wrapping these with fmt.Errorf and %w.
|
||||||
var (
|
var (
|
||||||
@@ -60,6 +56,7 @@ var (
|
|||||||
errNotAnInteger = errors.New("not an integer")
|
errNotAnInteger = errors.New("not an integer")
|
||||||
errNotABoolean = errors.New("not a boolean")
|
errNotABoolean = errors.New("not a boolean")
|
||||||
errNotAStringList = errors.New("not a list of strings")
|
errNotAStringList = errors.New("not a list of strings")
|
||||||
|
errNotAValidCIDR = errors.New("not a valid CIDR network")
|
||||||
errNotAMetricsMap = errors.New("not a map of metrics settings")
|
errNotAMetricsMap = errors.New("not a map of metrics settings")
|
||||||
errEmptyListEntry = errors.New("list contains an empty entry")
|
errEmptyListEntry = errors.New("list contains an empty entry")
|
||||||
errEmptyEntry = errors.New("contains an empty entry")
|
errEmptyEntry = errors.New("contains an empty entry")
|
||||||
@@ -67,9 +64,6 @@ var (
|
|||||||
errPortOutOfRange = errors.New("outside the valid port range")
|
errPortOutOfRange = errors.New("outside the valid port range")
|
||||||
errTooFewConnections = errors.New("must be at least 1")
|
errTooFewConnections = errors.New("must be at least 1")
|
||||||
errValueTooShort = errors.New("value too short")
|
errValueTooShort = errors.New("value too short")
|
||||||
errPlaceholderKey = errors.New(
|
|
||||||
"is the placeholder from config.example.yml; " +
|
|
||||||
"generate a real key with: openssl rand -base64 32")
|
|
||||||
errMustBeSetTogether = errors.New("must be set together")
|
errMustBeSetTogether = errors.New("must be set together")
|
||||||
errMustNotBeNegative = errors.New("must not be negative")
|
errMustNotBeNegative = errors.New("must not be negative")
|
||||||
errOverflowsInt64 = errors.New("overflows a 64-bit integer")
|
errOverflowsInt64 = errors.New("overflows a 64-bit integer")
|
||||||
@@ -109,6 +103,11 @@ type Config struct {
|
|||||||
AllowHTTP bool // Allow non-TLS upstream (testing only)
|
AllowHTTP bool // Allow non-TLS upstream (testing only)
|
||||||
UpstreamConnectionsPerHost int // Max concurrent connections per upstream host
|
UpstreamConnectionsPerHost int // Max concurrent connections per upstream host
|
||||||
|
|
||||||
|
// BlockedNetworks are operator-supplied CIDR ranges to refuse in
|
||||||
|
// addition to the built-in SSRF blocklist. Enforced by the upstream
|
||||||
|
// fetcher's dialer; the built-in ranges always apply.
|
||||||
|
BlockedNetworks []netip.Prefix
|
||||||
|
|
||||||
// CacheMaxBytes is the disk cache size limit in bytes. Zero
|
// CacheMaxBytes is the disk cache size limit in bytes. Zero
|
||||||
// disables the disk cache entirely. When cache_max_bytes is
|
// disables the disk cache entirely. When cache_max_bytes is
|
||||||
// omitted from the configuration, this holds the computed default
|
// omitted from the configuration, this holds the computed default
|
||||||
@@ -177,6 +176,11 @@ func newFromSmartConfig(sc *smartconfig.Config) (*Config, error) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
blockedNetworks, err := getBlockedNetworks(sc)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
loader := &strictLoader{sc: sc}
|
loader := &strictLoader{sc: sc}
|
||||||
|
|
||||||
c := &Config{
|
c := &Config{
|
||||||
@@ -193,6 +197,7 @@ func newFromSmartConfig(sc *smartconfig.Config) (*Config, error) {
|
|||||||
UpstreamConnectionsPerHost: loader.intVal(
|
UpstreamConnectionsPerHost: loader.intVal(
|
||||||
keyUpstreamConnectionsPerHost, DefaultUpstreamConnectionsPerHost),
|
keyUpstreamConnectionsPerHost, DefaultUpstreamConnectionsPerHost),
|
||||||
CacheMaxBytes: loader.int64Val(keyCacheMaxBytes, 0),
|
CacheMaxBytes: loader.int64Val(keyCacheMaxBytes, 0),
|
||||||
|
BlockedNetworks: blockedNetworks,
|
||||||
}
|
}
|
||||||
|
|
||||||
// The computed default for cache_max_bytes needs a validated
|
// The computed default for cache_max_bytes needs a validated
|
||||||
@@ -224,7 +229,7 @@ func newFromSmartConfig(sc *smartconfig.Config) (*Config, error) {
|
|||||||
return nil, loader.err
|
return nil, loader.err
|
||||||
}
|
}
|
||||||
|
|
||||||
err := c.validate()
|
err = c.validate()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
@@ -308,7 +313,7 @@ func isKnownConfigKey(key string) bool {
|
|||||||
switch key {
|
switch key {
|
||||||
case keyDebug, keyMaintenanceMode, keyPort, keyStateDir, keySentryDSN,
|
case keyDebug, keyMaintenanceMode, keyPort, keyStateDir, keySentryDSN,
|
||||||
keyDBURL, keyMetrics, keySigningKey, keyAllowlistHosts, keyAllowHTTP,
|
keyDBURL, keyMetrics, keySigningKey, keyAllowlistHosts, keyAllowHTTP,
|
||||||
keyUpstreamConnectionsPerHost, keyCacheMaxBytes, "env":
|
keyUpstreamConnectionsPerHost, keyCacheMaxBytes, keyBlockedNetworks, "env":
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -350,10 +355,10 @@ func (c *Config) ensureStateDirWritable() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// validateSigningKey checks that the signing key is present, long
|
// validate checks that all required configuration values are set and
|
||||||
// enough, and not the public placeholder from config.example.yml. The
|
// that every value is within its valid range.
|
||||||
// key value itself is never echoed in error messages.
|
func (c *Config) validate() error {
|
||||||
func (c *Config) validateSigningKey() error {
|
// The signing key value is never echoed in error messages.
|
||||||
if c.SigningKey == "" {
|
if c.SigningKey == "" {
|
||||||
return fmt.Errorf("config key %q: %w", keySigningKey, errValueRequired)
|
return fmt.Errorf("config key %q: %w", keySigningKey, errValueRequired)
|
||||||
}
|
}
|
||||||
@@ -365,21 +370,6 @@ func (c *Config) validateSigningKey() error {
|
|||||||
keySigningKey, errValueTooShort, minKeyLength, len(c.SigningKey))
|
keySigningKey, errValueTooShort, minKeyLength, len(c.SigningKey))
|
||||||
}
|
}
|
||||||
|
|
||||||
if c.SigningKey == placeholderSigningKey {
|
|
||||||
return fmt.Errorf("config key %q: %w", keySigningKey, errPlaceholderKey)
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// validate checks that all required configuration values are set and
|
|
||||||
// that every value is within its valid range.
|
|
||||||
func (c *Config) validate() error {
|
|
||||||
err := c.validateSigningKey()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
const maxPort = 65535
|
const maxPort = 65535
|
||||||
if c.Port < 1 || c.Port > maxPort {
|
if c.Port < 1 || c.Port > maxPort {
|
||||||
return fmt.Errorf("config key %q: value %d is %w 1-%d",
|
return fmt.Errorf("config key %q: value %d is %w 1-%d",
|
||||||
@@ -802,3 +792,87 @@ func getStringSlice(sc *smartconfig.Config) []string {
|
|||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// getBlockedNetworks parses the blocked_networks value into CIDR prefixes,
|
||||||
|
// or returns nil if the key is omitted. It accepts a YAML list of strings
|
||||||
|
// or a comma-separated string. An explicitly null value, a wrong type, an
|
||||||
|
// empty entry, a non-string entry, or an unparseable CIDR aborts startup
|
||||||
|
// naming the key and the offending value; a default (the built-in
|
||||||
|
// blocklist alone) applies only to an omitted key.
|
||||||
|
func getBlockedNetworks(sc *smartconfig.Config) ([]netip.Prefix, error) {
|
||||||
|
if sc == nil {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
raw, ok := sc.Get(keyBlockedNetworks)
|
||||||
|
if !ok {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
if raw == nil {
|
||||||
|
return nil, errNullConfigValue(keyBlockedNetworks)
|
||||||
|
}
|
||||||
|
|
||||||
|
entries, err := blockedNetworkEntries(raw)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
prefixes := make([]netip.Prefix, 0, len(entries))
|
||||||
|
|
||||||
|
for _, entry := range entries {
|
||||||
|
prefix, err := netip.ParsePrefix(entry)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("config key %q: value %q is %w",
|
||||||
|
keyBlockedNetworks, entry, errNotAValidCIDR)
|
||||||
|
}
|
||||||
|
|
||||||
|
prefixes = append(prefixes, prefix)
|
||||||
|
}
|
||||||
|
|
||||||
|
return prefixes, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// blockedNetworkEntries extracts the raw blocked_networks entries as
|
||||||
|
// trimmed, non-empty strings, from either a YAML list of strings or a
|
||||||
|
// comma-separated string. Any other shape is a configuration error.
|
||||||
|
func blockedNetworkEntries(raw any) ([]string, error) {
|
||||||
|
switch val := raw.(type) {
|
||||||
|
case []any:
|
||||||
|
entries := make([]string, 0, len(val))
|
||||||
|
|
||||||
|
for _, item := range val {
|
||||||
|
str, ok := item.(string)
|
||||||
|
if !ok {
|
||||||
|
return nil, fmt.Errorf("config key %q: list entry %v (%T) is %w",
|
||||||
|
keyBlockedNetworks, item, item, errNotAString)
|
||||||
|
}
|
||||||
|
|
||||||
|
if strings.TrimSpace(str) == "" {
|
||||||
|
return nil, fmt.Errorf("config key %q: %w",
|
||||||
|
keyBlockedNetworks, errEmptyListEntry)
|
||||||
|
}
|
||||||
|
|
||||||
|
entries = append(entries, strings.TrimSpace(str))
|
||||||
|
}
|
||||||
|
|
||||||
|
return entries, nil
|
||||||
|
case string:
|
||||||
|
entries := make([]string, 0)
|
||||||
|
|
||||||
|
for part := range strings.SplitSeq(val, ",") {
|
||||||
|
trimmed := strings.TrimSpace(part)
|
||||||
|
if trimmed == "" {
|
||||||
|
return nil, fmt.Errorf("config key %q: value %q %w",
|
||||||
|
keyBlockedNetworks, val, errEmptyEntry)
|
||||||
|
}
|
||||||
|
|
||||||
|
entries = append(entries, trimmed)
|
||||||
|
}
|
||||||
|
|
||||||
|
return entries, nil
|
||||||
|
default:
|
||||||
|
return nil, fmt.Errorf("config key %q: value %v (%T) is %w",
|
||||||
|
keyBlockedNetworks, raw, raw, errNotAStringList)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
@@ -303,11 +303,6 @@ func invalidHostAndCredentialCases() []abortCase {
|
|||||||
yaml: "signing_key: short\n",
|
yaml: "signing_key: short\n",
|
||||||
wantErrSubstrings: []string{keySigningKey},
|
wantErrSubstrings: []string{keySigningKey},
|
||||||
},
|
},
|
||||||
{
|
|
||||||
name: "signing_key is the documented placeholder",
|
|
||||||
yaml: "signing_key: " + placeholderSigningKey + "\n",
|
|
||||||
wantErrSubstrings: []string{keySigningKey},
|
|
||||||
},
|
|
||||||
{
|
{
|
||||||
name: "signing_key missing",
|
name: "signing_key missing",
|
||||||
yaml: "port: 8080\n",
|
yaml: "port: 8080\n",
|
||||||
|
|||||||
@@ -111,6 +111,8 @@ func (s *Handlers) initImageService() error {
|
|||||||
fetcherCfg.MaxConnectionsPerHost = s.config.UpstreamConnectionsPerHost
|
fetcherCfg.MaxConnectionsPerHost = s.config.UpstreamConnectionsPerHost
|
||||||
}
|
}
|
||||||
|
|
||||||
|
fetcherCfg.BlockedNetworks = s.config.BlockedNetworks
|
||||||
|
|
||||||
// Create the service
|
// Create the service
|
||||||
svc, err := imgcache.NewService(&imgcache.ServiceConfig{
|
svc, err := imgcache.NewService(&imgcache.ServiceConfig{
|
||||||
Cache: cache,
|
Cache: cache,
|
||||||
|
|||||||
@@ -0,0 +1,111 @@
|
|||||||
|
package httpfetcher
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"errors"
|
||||||
|
"net"
|
||||||
|
"net/http"
|
||||||
|
"net/netip"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestIsPrivateIPBlocksSpecialRanges covers the internal and special-use
|
||||||
|
// ranges added to the built-in blocklist, in IPv4, IPv6, and IPv4-mapped
|
||||||
|
// forms, alongside public controls that must stay reachable.
|
||||||
|
func TestIsPrivateIPBlocksSpecialRanges(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
ip string
|
||||||
|
want bool
|
||||||
|
}{
|
||||||
|
{"cgnat-low", "100.64.0.1", true},
|
||||||
|
{"cgnat-high", "100.127.255.254", true},
|
||||||
|
{"ietf-protocol", "192.0.0.1", true},
|
||||||
|
{"benchmark-low", "198.18.0.1", true},
|
||||||
|
{"benchmark-high", "198.19.255.254", true},
|
||||||
|
{"nat64", "64:ff9b::1", true},
|
||||||
|
{"nat64-embeds-private", "64:ff9b::a00:1", true}, // maps 10.0.0.1
|
||||||
|
{"ipv4-mapped-private", "::ffff:10.0.0.1", true},
|
||||||
|
{"cloud-metadata", "169.254.169.254", true},
|
||||||
|
{"public-v4", "8.8.8.8", false},
|
||||||
|
{"test-net-1-public", testPublicHost, false}, // TEST-NET-1, stays public
|
||||||
|
{"public-v6", "2001:4860:4860::8888", false},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tc := range tests {
|
||||||
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
ip := net.ParseIP(tc.ip)
|
||||||
|
if ip == nil {
|
||||||
|
t.Fatalf("failed to parse IP %q", tc.ip)
|
||||||
|
}
|
||||||
|
|
||||||
|
got := isPrivateIP(ip)
|
||||||
|
if got != tc.want {
|
||||||
|
t.Errorf("isPrivateIP(%q) = %v, want %v", tc.ip, got, tc.want)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// transportOf returns the *http.Transport backing a fetcher, so a test can
|
||||||
|
// exercise the SSRF-safe dialer New installed with the operator blocklist.
|
||||||
|
func transportOf(t *testing.T, f *HTTPFetcher) *http.Transport {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
transport, ok := f.client.Transport.(*http.Transport)
|
||||||
|
if !ok {
|
||||||
|
t.Fatalf("transport is %T, want *http.Transport", f.client.Transport)
|
||||||
|
}
|
||||||
|
|
||||||
|
return transport
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestDialerEnforcesBlockedNetworks proves an operator-supplied
|
||||||
|
// blocked_networks entry is enforced by the dialer, in addition to the
|
||||||
|
// built-in ranges, while an address outside both stays dialable.
|
||||||
|
func TestDialerEnforcesBlockedNetworks(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
cfg := DefaultConfig()
|
||||||
|
// TEST-NET-2 (198.51.100.0/24) is public to the built-in check, so
|
||||||
|
// blocking it can only come from the operator-supplied list.
|
||||||
|
cfg.BlockedNetworks = []netip.Prefix{netip.MustParsePrefix("198.51.100.0/24")}
|
||||||
|
|
||||||
|
transport := transportOf(t, New(cfg))
|
||||||
|
|
||||||
|
blocked := []string{
|
||||||
|
"198.51.100.5:80", // operator-supplied range
|
||||||
|
"10.0.0.5:80", // built-in RFC 1918, still enforced
|
||||||
|
"100.64.0.1:80", // built-in CGNAT range
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, addr := range blocked {
|
||||||
|
t.Run("blocked/"+addr, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
_, err := transport.DialContext(context.Background(), "tcp", addr)
|
||||||
|
if !errors.Is(err, ErrSSRFBlocked) {
|
||||||
|
t.Errorf("DialContext(%q) = %v, want ErrSSRFBlocked", addr, err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
t.Run("public-not-blocked", func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
// A cancelled context makes the dial fail without touching the
|
||||||
|
// network; the point is only that a public literal outside every
|
||||||
|
// blocked range is not SSRF-blocked.
|
||||||
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
cancel()
|
||||||
|
|
||||||
|
_, err := transport.DialContext(ctx, "tcp", testPublicHost+":80")
|
||||||
|
if errors.Is(err, ErrSSRFBlocked) {
|
||||||
|
t.Errorf("public target SSRF-blocked with operator list set: %v", err)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
@@ -11,6 +11,7 @@ import (
|
|||||||
"net"
|
"net"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptrace"
|
"net/http/httptrace"
|
||||||
|
"net/netip"
|
||||||
neturl "net/url"
|
neturl "net/url"
|
||||||
"slices"
|
"slices"
|
||||||
"strings"
|
"strings"
|
||||||
@@ -46,6 +47,20 @@ const (
|
|||||||
localhostIPv6 = "::1"
|
localhostIPv6 = "::1"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// builtinBlockedPrefixes are internal or special-use ranges that Go's
|
||||||
|
// net.IP predicates (IsPrivate, IsLinkLocalUnicast, and the like) do not
|
||||||
|
// already cover. They are always blocked, in addition to any
|
||||||
|
// operator-supplied networks. IPv4-mapped IPv6 addresses are unmapped
|
||||||
|
// before matching, so these IPv4 ranges are caught in both forms.
|
||||||
|
//
|
||||||
|
//nolint:gochecknoglobals // immutable built-in blocklist
|
||||||
|
var builtinBlockedPrefixes = []netip.Prefix{
|
||||||
|
netip.MustParsePrefix("100.64.0.0/10"), // RFC 6598 CGNAT / carrier-grade NAT
|
||||||
|
netip.MustParsePrefix("192.0.0.0/24"), // RFC 6890 IETF protocol assignments
|
||||||
|
netip.MustParsePrefix("198.18.0.0/15"), // RFC 2544 benchmarking range
|
||||||
|
netip.MustParsePrefix("64:ff9b::/96"), // RFC 6052 NAT64 (maps onto IPv4)
|
||||||
|
}
|
||||||
|
|
||||||
// Fetcher errors.
|
// Fetcher errors.
|
||||||
var (
|
var (
|
||||||
ErrSSRFBlocked = errors.New("request blocked: private or internal IP")
|
ErrSSRFBlocked = errors.New("request blocked: private or internal IP")
|
||||||
@@ -107,6 +122,9 @@ type Config struct {
|
|||||||
AllowHTTP bool
|
AllowHTTP bool
|
||||||
// MaxConnectionsPerHost limits concurrent connections to each upstream host.
|
// MaxConnectionsPerHost limits concurrent connections to each upstream host.
|
||||||
MaxConnectionsPerHost int
|
MaxConnectionsPerHost int
|
||||||
|
// BlockedNetworks are operator-supplied CIDR ranges refused by the
|
||||||
|
// dialer, in addition to the always-enforced built-in ranges.
|
||||||
|
BlockedNetworks []netip.Prefix
|
||||||
}
|
}
|
||||||
|
|
||||||
// DefaultConfig returns a Config with sensible defaults.
|
// DefaultConfig returns a Config with sensible defaults.
|
||||||
@@ -142,9 +160,13 @@ func New(config *Config) *HTTPFetcher {
|
|||||||
config = DefaultConfig()
|
config = DefaultConfig()
|
||||||
}
|
}
|
||||||
|
|
||||||
// Create transport with SSRF-safe dialer
|
// Create transport with SSRF-safe dialer. The dialer re-resolves and
|
||||||
|
// re-checks at connect time (closing the DNS-rebinding window) against
|
||||||
|
// both the built-in ranges and the operator-supplied blocklist.
|
||||||
transport := &http.Transport{
|
transport := &http.Transport{
|
||||||
DialContext: ssrfSafeDialer,
|
DialContext: func(ctx context.Context, network, addr string) (net.Conn, error) {
|
||||||
|
return dialSSRFSafe(ctx, network, addr, config.BlockedNetworks)
|
||||||
|
},
|
||||||
TLSHandshakeTimeout: DefaultTLSTimeout,
|
TLSHandshakeTimeout: DefaultTLSTimeout,
|
||||||
MaxIdleConns: DefaultMaxIdleConns,
|
MaxIdleConns: DefaultMaxIdleConns,
|
||||||
IdleConnTimeout: DefaultIdleConnTimeout,
|
IdleConnTimeout: DefaultIdleConnTimeout,
|
||||||
@@ -451,11 +473,53 @@ func isPrivateIP(ip net.IP) bool {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return false
|
// Special-use ranges the net.IP predicates above do not cover.
|
||||||
|
addr, ok := netip.AddrFromSlice(ip)
|
||||||
|
if !ok {
|
||||||
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
// ssrfSafeDialer is a custom dialer that validates IP addresses before connecting.
|
addr = addr.Unmap()
|
||||||
|
|
||||||
|
return slices.ContainsFunc(builtinBlockedPrefixes, func(prefix netip.Prefix) bool {
|
||||||
|
return prefix.Contains(addr)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// isBlockedIP reports whether ip is refused, either by the built-in
|
||||||
|
// internal-range check or by one of the operator-supplied prefixes.
|
||||||
|
func isBlockedIP(ip net.IP, blocked []netip.Prefix) bool {
|
||||||
|
if isPrivateIP(ip) {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
addr, ok := netip.AddrFromSlice(ip)
|
||||||
|
if !ok {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
|
||||||
|
addr = addr.Unmap()
|
||||||
|
|
||||||
|
return slices.ContainsFunc(blocked, func(prefix netip.Prefix) bool {
|
||||||
|
return prefix.Contains(addr)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// ssrfSafeDialer validates IP addresses against the built-in blocked ranges
|
||||||
|
// before connecting. New wraps dialSSRFSafe with the operator-supplied
|
||||||
|
// blocklist; this entry point enforces the built-in ranges alone.
|
||||||
func ssrfSafeDialer(ctx context.Context, network, addr string) (net.Conn, error) {
|
func ssrfSafeDialer(ctx context.Context, network, addr string) (net.Conn, error) {
|
||||||
|
return dialSSRFSafe(ctx, network, addr, nil)
|
||||||
|
}
|
||||||
|
|
||||||
|
// dialSSRFSafe re-resolves addr and refuses to connect to any built-in
|
||||||
|
// internal range or operator-supplied blocked prefix, closing the
|
||||||
|
// DNS-rebinding window at connect time.
|
||||||
|
func dialSSRFSafe(
|
||||||
|
ctx context.Context,
|
||||||
|
network, addr string,
|
||||||
|
blocked []netip.Prefix,
|
||||||
|
) (net.Conn, error) {
|
||||||
host, port, err := net.SplitHostPort(addr)
|
host, port, err := net.SplitHostPort(addr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
@@ -468,9 +532,11 @@ func ssrfSafeDialer(ctx context.Context, network, addr string) (net.Conn, error)
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Check all resolved IPs
|
// Check all resolved IPs
|
||||||
if slices.ContainsFunc(ips, isPrivateIP) {
|
for _, ip := range ips {
|
||||||
|
if isBlockedIP(ip, blocked) {
|
||||||
return nil, ErrSSRFBlocked
|
return nil, ErrSSRFBlocked
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Connect using the first valid IP
|
// Connect using the first valid IP
|
||||||
var dialer net.Dialer
|
var dialer net.Dialer
|
||||||
|
|||||||
+14
-46
@@ -1,55 +1,23 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# script/lint: run golangci-lint over the whole tree.
|
# script/lint: run the linter. CGO dependencies (pkg-config, vips,
|
||||||
#
|
# libheif) come from nix-shell when not already available (e.g. inside
|
||||||
# The linter is never installed on the host: it runs only inside the
|
# a Docker build or an existing nix-shell).
|
||||||
# Dockerfile.lint build, one way, everywhere. A clean build is a clean
|
|
||||||
# lint. See Dockerfile.lint for why the lint step cannot be cached.
|
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
main() {
|
run_with_cgo_deps() {
|
||||||
cd "$ROOT"
|
if command -v pkg-config >/dev/null 2>&1; then
|
||||||
|
sh -c "$1"
|
||||||
# A value no other run repeats. Dockerfile.lint folds it into the
|
else
|
||||||
# lint step's cache key, so the linter re-executes every run instead
|
nix-shell -p pkg-config vips libheif golangci-lint git --run "$1"
|
||||||
# of an unchanged tree returning a cached success having linted
|
|
||||||
# nothing.
|
|
||||||
cachebust="$(date +%s)-$$"
|
|
||||||
|
|
||||||
tmp="$(mktemp -d "${TMPDIR:-/tmp}/pixa-lint.XXXXXX")"
|
|
||||||
trap 'rm -rf "$tmp"' EXIT INT TERM
|
|
||||||
|
|
||||||
# --progress=plain so the lint step's own output reaches the log we
|
|
||||||
# check below; --output=type=cacheonly because we want the linter's
|
|
||||||
# verdict, not an image left in the local store. The build status
|
|
||||||
# travels through a file: a pipeline's exit status is tee's, not the
|
|
||||||
# build's.
|
|
||||||
(
|
|
||||||
set +e
|
|
||||||
docker build \
|
|
||||||
--progress=plain \
|
|
||||||
--build-arg CACHEBUST="$cachebust" \
|
|
||||||
--output=type=cacheonly \
|
|
||||||
-f Dockerfile.lint . 2>&1
|
|
||||||
echo "$?" >"$tmp/status"
|
|
||||||
) | tee "$tmp/build.log"
|
|
||||||
|
|
||||||
status="$(cat "$tmp/status" 2>/dev/null || echo 1)"
|
|
||||||
[ "${status:-1}" -eq 0 ] || exit "${status:-1}"
|
|
||||||
|
|
||||||
# The linter's start line must appear as build output, not only in
|
|
||||||
# the build's echo of the RUN instruction. A step served from cache
|
|
||||||
# prints the instruction and none of its output; a step that runs
|
|
||||||
# prints a "#<n> <elapsed> ..." output line. Requiring that output
|
|
||||||
# line means a future edit dropping the CACHEBUST reference from
|
|
||||||
# Dockerfile.lint fails here rather than passing having linted
|
|
||||||
# nothing.
|
|
||||||
if ! grep -Eq '^#[0-9]+ +[0-9]+\.[0-9]+ +pixa-lint: running golangci-lint' \
|
|
||||||
"$tmp/build.log"; then
|
|
||||||
echo "script/lint: golangci-lint did not execute (cached step?)." >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
main() {
|
||||||
|
cd "$ROOT"
|
||||||
|
echo "Running linter..."
|
||||||
|
run_with_cgo_deps "golangci-lint run"
|
||||||
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user