State what the default blocklist covers (closes #244)
check / check (push) Successful in 4m50s
check / check (push) Successful in 4m50s
The default blocklist covers the IPv4 private and reserved ranges, IPv6 loopback, unique local and link-local addresses, and public addresses that hand credentials, user data or bootstrap material to whatever can reach them, without the caller presenting anything. A provider's other public addresses, such as 161.26.0.0/16 and 166.8.0.0/14, are not refused: they hand out no credentials that way, reaching them can be legitimate, and every cloud has some, so a partial list would promise coverage it does not give. The README's egress section and the comment above blockedNetworks now state this rule, naming the same material as the rule above alwaysBlockedNetworks, so nobody infers wider coverage and a future candidate can be accepted or refused against it. No list change. Model: opus-5-5
This commit is contained in:
@@ -43,6 +43,13 @@ var (
|
||||
// permit specific blocks out of this set with
|
||||
// ALLOWED_EGRESS_CIDRS; see Guard.
|
||||
//
|
||||
// A public address belongs on the default blocklist only if it
|
||||
// hands credentials, user data or bootstrap material to whatever
|
||||
// can reach it, without the caller presenting anything. A
|
||||
// provider's other public addresses are not refused, since
|
||||
// reaching them can be legitimate and no list of them could be
|
||||
// complete.
|
||||
//
|
||||
//nolint:gochecknoglobals // package-level network list is appropriate here
|
||||
var blockedNetworks []*net.IPNet
|
||||
|
||||
|
||||
Reference in New Issue
Block a user