Found by the review of #339 (#339 (comment)). Out of that PR's scope, since it changes the list rather than documents it.
The SSRF guard's lists in internal/delivery/ssrf.go (blockedNetworks and alwaysBlockedNetworks) do not cover the IPv6 unspecified address ::. On Linux a connection to [::] reaches the host's own loopback, so a delivery target such as http://[::]:8080/ passes the guard with no allowlist set. IPv6 multicast (ff00::/8) and documentation space (2001:db8::/32) are not listed either. The IPv4 unspecified address is worth checking at the same time.
Definition of done
::/128 is refused wherever 0.0.0.0 is today, or in alwaysBlockedNetworks if it can reach loopback, because the allowlist must never reopen loopback.
ff00::/8 and 2001:db8::/32 are refused by default.
Each entry has a one-line comment naming what it is.
Tests:
each address is refused at target creation and at delivery, with no allowlist set;
each fails when its entry is removed.
The README's blocklist description matches the list.
Model: opus-5-5
Found by the review of https://git.eeqj.de/sneak/webhooker/pulls/339 (https://git.eeqj.de/sneak/webhooker/pulls/339#issuecomment-106662). Out of that PR's scope, since it changes the list rather than documents it.
The SSRF guard's lists in `internal/delivery/ssrf.go` (`blockedNetworks` and `alwaysBlockedNetworks`) do not cover the IPv6 unspecified address `::`. On Linux a connection to `[::]` reaches the host's own loopback, so a delivery target such as `http://[::]:8080/` passes the guard with no allowlist set. IPv6 multicast (`ff00::/8`) and documentation space (`2001:db8::/32`) are not listed either. The IPv4 unspecified address is worth checking at the same time.
## Definition of done
- `::/128` is refused wherever `0.0.0.0` is today, or in `alwaysBlockedNetworks` if it can reach loopback, because the allowlist must never reopen loopback.
- `ff00::/8` and `2001:db8::/32` are refused by default.
- Each entry has a one-line comment naming what it is.
- Tests:
- each address is refused at target creation and at delivery, with no allowlist set;
- each fails when its entry is removed.
- The README's blocklist description matches the list.
Model: opus-5-5
clawbot
self-assigned this 2026-09-29 11:10:38 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by the review of #339 (#339 (comment)). Out of that PR's scope, since it changes the list rather than documents it.
The SSRF guard's lists in
internal/delivery/ssrf.go(blockedNetworksandalwaysBlockedNetworks) do not cover the IPv6 unspecified address::. On Linux a connection to[::]reaches the host's own loopback, so a delivery target such ashttp://[::]:8080/passes the guard with no allowlist set. IPv6 multicast (ff00::/8) and documentation space (2001:db8::/32) are not listed either. The IPv4 unspecified address is worth checking at the same time.Definition of done
::/128is refused wherever0.0.0.0is today, or inalwaysBlockedNetworksif it can reach loopback, because the allowlist must never reopen loopback.ff00::/8and2001:db8::/32are refused by default.Model: opus-5-5