Implements the decision recorded on #244: the default blocklist does not take the public addresses a cloud provider uses for its own services, such as DNS resolvers and package mirrors.
What changed:
README, "Allowing egress to your own network": a new paragraph after the WireServer one says that the default blocklist covers private and reserved space plus public addresses that serve cloud credentials, and nothing else. It names IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14 as an example of public provider service addresses that are not refused, and says why.
internal/delivery/ssrf.go: the comment above blockedNetworks states the same rule in one sentence, just above the existing inclusion criterion for alwaysBlockedNetworks, so a future candidate can be refused or accepted by a stated rule.
Docs and a comment only; the lists and the guard's behaviour are unchanged.
Judgement call: the IBM ranges are named in the README as an example of what is not covered, since they are the concrete case the issue raised. The unverified GKE range is not mentioned.
Model: opus-5-5
Implements the decision recorded on https://git.eeqj.de/sneak/webhooker/issues/244: the default blocklist does not take the public addresses a cloud provider uses for its own services, such as DNS resolvers and package mirrors.
What changed:
- **README, "Allowing egress to your own network":** a new paragraph after the WireServer one says that the default blocklist covers private and reserved space plus public addresses that serve cloud credentials, and nothing else. It names IBM Cloud's `161.26.0.0/16` and `166.8.0.0/14` as an example of public provider service addresses that are not refused, and says why.
- **`internal/delivery/ssrf.go`:** the comment above `blockedNetworks` states the same rule in one sentence, just above the existing inclusion criterion for `alwaysBlockedNetworks`, so a future candidate can be refused or accepted by a stated rule.
Docs and a comment only; the lists and the guard's behaviour are unchanged.
Judgement call: the IBM ranges are named in the README as an example of what is not covered, since they are the concrete case the issue raised. The unverified GKE range is not mentioned.
Model: opus-5-5
README.md, the new paragraph in "Allowing egress to your own network": it says IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14 carry its DNS resolvers, time servers and package mirrors. Per IBM's VPC documentation those services are on 161.26.0.0/16; 166.8.0.0/14 holds the private endpoints of IBM Cloud's own platform services. Acceptable: each range described by what it actually carries.
README.md, same paragraph, first sentence: "That is all the default blocklist covers: private and reserved space, …" claims more than the list holds for IPv6. The unspecified address :: is on neither list, and on Linux a connection to [::] lands on the host's own loopback, so a target such as http://[::]:8080/ passes the guard with no allowlist set; IPv6 multicast (ff00::/8) and documentation space (2001:db8::/32) are not listed either. Acceptable: the sentence claims only what the list actually holds. Refusing the missing IPv6 blocks is a list change for its own issue, not for this PR.
Model: opus-5-5
1. `README.md`, the new paragraph in "Allowing egress to your own network": it says IBM Cloud's `161.26.0.0/16` and `166.8.0.0/14` carry its DNS resolvers, time servers and package mirrors. Per IBM's VPC documentation those services are on `161.26.0.0/16`; `166.8.0.0/14` holds the private endpoints of IBM Cloud's own platform services. Acceptable: each range described by what it actually carries.
2. `README.md`, same paragraph, first sentence: "That is all the default blocklist covers: private and reserved space, …" claims more than the list holds for IPv6. The unspecified address `::` is on neither list, and on Linux a connection to `[::]` lands on the host's own loopback, so a target such as `http://[::]:8080/` passes the guard with no allowlist set; IPv6 multicast (`ff00::/8`) and documentation space (`2001:db8::/32`) are not listed either. Acceptable: the sentence claims only what the list actually holds. Refusing the missing IPv6 blocks is a list change for its own issue, not for this PR.
Model: opus-5-5
The default blocklist covers private and reserved space, plus public
addresses that serve cloud credentials. A provider's other services on
public addresses, such as IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14,
are deliberately not on it: they serve no credentials, reaching them
can be legitimate, and every cloud has some, so a partial list would
promise coverage it does not give.
The README's egress section and the comment above blockedNetworks now
state this rule, so nobody infers wider coverage and a future candidate
can be accepted or refused against it. No list change.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements the decision recorded on #244: the default blocklist does not take the public addresses a cloud provider uses for its own services, such as DNS resolvers and package mirrors.
What changed:
161.26.0.0/16and166.8.0.0/14as an example of public provider service addresses that are not refused, and says why.internal/delivery/ssrf.go: the comment aboveblockedNetworksstates the same rule in one sentence, just above the existing inclusion criterion foralwaysBlockedNetworks, so a future candidate can be refused or accepted by a stated rule.Docs and a comment only; the lists and the guard's behaviour are unchanged.
Judgement call: the IBM ranges are named in the README as an example of what is not covered, since they are the concrete case the issue raised. The unverified GKE range is not mentioned.
Model: opus-5-5
README.md, the new paragraph in "Allowing egress to your own network": it says IBM Cloud's161.26.0.0/16and166.8.0.0/14carry its DNS resolvers, time servers and package mirrors. Per IBM's VPC documentation those services are on161.26.0.0/16;166.8.0.0/14holds the private endpoints of IBM Cloud's own platform services. Acceptable: each range described by what it actually carries.README.md, same paragraph, first sentence: "That is all the default blocklist covers: private and reserved space, …" claims more than the list holds for IPv6. The unspecified address::is on neither list, and on Linux a connection to[::]lands on the host's own loopback, so a target such ashttp://[::]:8080/passes the guard with no allowlist set; IPv6 multicast (ff00::/8) and documentation space (2001:db8::/32) are not listed either. Acceptable: the sentence claims only what the list actually holds. Refusing the missing IPv6 blocks is a list change for its own issue, not for this PR.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.