State what the default blocklist covers (closes #244)
check / check (push) Successful in 5m21s

The default blocklist covers the IPv4 private and reserved ranges, IPv6
loopback, unique local and link-local addresses, and public addresses
that serve cloud credentials. A provider's other services on public
addresses, such as 161.26.0.0/16 and 166.8.0.0/14, are deliberately not
on it: they serve no credentials, reaching them can be legitimate, and
every cloud has some, so a partial list would promise coverage it does
not give.

The README's egress section and the comment above blockedNetworks now
state this rule, so nobody infers wider coverage and a future candidate
can be accepted or refused against it. No list change.

Model: opus-5-5
This commit is contained in:
2026-10-01 18:47:23 +00:00
committed by sneak
parent b79e4649a1
commit 1f22ab2b65
2 changed files with 17 additions and 0 deletions
+6
View File
@@ -43,6 +43,12 @@ var (
// permit specific blocks out of this set with
// ALLOWED_EGRESS_CIDRS; see Guard.
//
// A public address belongs here only if it serves cloud
// credentials; a provider's other services on public addresses,
// such as its DNS resolvers or package mirrors, stay out, since
// reaching them can be legitimate and no list of them could be
// complete.
//
//nolint:gochecknoglobals // package-level network list is appropriate here
var blockedNetworks []*net.IPNet