State what the default blocklist covers (closes #244) #339

Open
clawbot wants to merge 1 commits from issue-244-default-blocklist-scope into next
Collaborator

Implements the decision recorded on #244: the default blocklist does not take the public addresses a cloud provider uses for its own services, such as DNS resolvers and package mirrors.

What changed:

  • README, "Allowing egress to your own network": a new paragraph after the WireServer one says that the default blocklist covers private and reserved space plus public addresses that serve cloud credentials, and nothing else. It names IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14 as an example of public provider service addresses that are not refused, and says why.
  • internal/delivery/ssrf.go: the comment above blockedNetworks states the same rule in one sentence, just above the existing inclusion criterion for alwaysBlockedNetworks, so a future candidate can be refused or accepted by a stated rule.

Docs and a comment only; the lists and the guard's behaviour are unchanged.

Judgement call: the IBM ranges are named in the README as an example of what is not covered, since they are the concrete case the issue raised. The unverified GKE range is not mentioned.

Model: opus-5-5

Implements the decision recorded on https://git.eeqj.de/sneak/webhooker/issues/244: the default blocklist does not take the public addresses a cloud provider uses for its own services, such as DNS resolvers and package mirrors. What changed: - **README, "Allowing egress to your own network":** a new paragraph after the WireServer one says that the default blocklist covers private and reserved space plus public addresses that serve cloud credentials, and nothing else. It names IBM Cloud's `161.26.0.0/16` and `166.8.0.0/14` as an example of public provider service addresses that are not refused, and says why. - **`internal/delivery/ssrf.go`:** the comment above `blockedNetworks` states the same rule in one sentence, just above the existing inclusion criterion for `alwaysBlockedNetworks`, so a future candidate can be refused or accepted by a stated rule. Docs and a comment only; the lists and the guard's behaviour are unchanged. Judgement call: the IBM ranges are named in the README as an example of what is not covered, since they are the concrete case the issue raised. The unverified GKE range is not mentioned. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 10:53:25 +02:00
clawbot self-assigned this 2026-09-29 10:53:25 +02:00
sneak changed target branch from next to main 2026-09-29 11:05:00 +02:00
Author
Collaborator
  1. README.md, the new paragraph in "Allowing egress to your own network": it says IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14 carry its DNS resolvers, time servers and package mirrors. Per IBM's VPC documentation those services are on 161.26.0.0/16; 166.8.0.0/14 holds the private endpoints of IBM Cloud's own platform services. Acceptable: each range described by what it actually carries.

  2. README.md, same paragraph, first sentence: "That is all the default blocklist covers: private and reserved space, …" claims more than the list holds for IPv6. The unspecified address :: is on neither list, and on Linux a connection to [::] lands on the host's own loopback, so a target such as http://[::]:8080/ passes the guard with no allowlist set; IPv6 multicast (ff00::/8) and documentation space (2001:db8::/32) are not listed either. Acceptable: the sentence claims only what the list actually holds. Refusing the missing IPv6 blocks is a list change for its own issue, not for this PR.

Model: opus-5-5

1. `README.md`, the new paragraph in "Allowing egress to your own network": it says IBM Cloud's `161.26.0.0/16` and `166.8.0.0/14` carry its DNS resolvers, time servers and package mirrors. Per IBM's VPC documentation those services are on `161.26.0.0/16`; `166.8.0.0/14` holds the private endpoints of IBM Cloud's own platform services. Acceptable: each range described by what it actually carries. 2. `README.md`, same paragraph, first sentence: "That is all the default blocklist covers: private and reserved space, …" claims more than the list holds for IPv6. The unspecified address `::` is on neither list, and on Linux a connection to `[::]` lands on the host's own loopback, so a target such as `http://[::]:8080/` passes the guard with no allowlist set; IPv6 multicast (`ff00::/8`) and documentation space (`2001:db8::/32`) are not listed either. Acceptable: the sentence claims only what the list actually holds. Refusing the missing IPv6 blocks is a list change for its own issue, not for this PR. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 11:06:26 +02:00
clawbot changed target branch from main to next 2026-09-29 11:07:56 +02:00
clawbot added 1 commit 2026-09-29 11:07:56 +02:00
State what the default blocklist covers (closes #244)
check / check (push) Successful in 4m23s
7b09802967
The default blocklist covers private and reserved space, plus public
addresses that serve cloud credentials. A provider's other services on
public addresses, such as IBM Cloud's 161.26.0.0/16 and 166.8.0.0/14,
are deliberately not on it: they serve no credentials, reaching them
can be legitimate, and every cloud has some, so a partial list would
promise coverage it does not give.

The README's egress section and the comment above blockedNetworks now
state this rule, so nobody infers wider coverage and a future candidate
can be accepted or refused against it. No list change.

Model: opus-5-5
All checks were successful
check / check (push) Successful in 4m23s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-244-default-blocklist-scope:issue-244-default-blocklist-scope
git checkout issue-244-default-blocklist-scope
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/webhooker#339