State what the default blocklist covers (closes #244)
check / check (push) Successful in 4m50s

The default blocklist covers the IPv4 private and reserved ranges, IPv6
loopback, unique local and link-local addresses, and public addresses
that hand credentials, user data or bootstrap material to whatever can
reach them, without the caller presenting anything. A provider's other
public addresses, such as 161.26.0.0/16 and 166.8.0.0/14, are not
refused: they hand out no credentials that way, reaching them can be
legitimate, and every cloud has some, so a partial list would promise
coverage it does not give.

The README's egress section and the comment above blockedNetworks now
state this rule, naming the same material as the rule above
alwaysBlockedNetworks, so nobody infers wider coverage and a future
candidate can be accepted or refused against it. No list change.

Model: opus-5-5
This commit is contained in:
2026-10-01 21:33:46 +00:00
committed by sneak
parent a56f1fe0c8
commit 5a81d23dfe
2 changed files with 22 additions and 0 deletions
+7
View File
@@ -43,6 +43,13 @@ var (
// permit specific blocks out of this set with
// ALLOWED_EGRESS_CIDRS; see Guard.
//
// A public address belongs on the default blocklist only if it
// hands credentials, user data or bootstrap material to whatever
// can reach it, without the caller presenting anything. A
// provider's other public addresses are not refused, since
// reaching them can be legitimate and no list of them could be
// complete.
//
//nolint:gochecknoglobals // package-level network list is appropriate here
var blockedNetworks []*net.IPNet