Skip to content

[ENG-4057] Classify more non-public addresses and keep fetch options across redirects - #296

Merged
patchstackdave merged 1 commit into
mainfrom
fix/egress-address-ranges
Sep 29, 2026
Merged

patchstackdave merged 1 commit into
mainfrom
fix/egress-address-ranges

Conversation

@patchstackdave

Copy link
Copy Markdown
Contributor

Two changes to outbound request screening.

Non-public address space. internal_host now also treats these as non-public:

  • IPv4 multicast (224.0.0.0/4), reserved space (240.0.0.0/4, including the broadcast address), benchmarking (198.18.0.0/15) and the IETF protocol block (192.0.0.0/24);
  • IPv6 site-local (fec0::/10) and multicast (ff00::/8).

IPv6 transition addresses are classified by the IPv4 address they carry: NAT64 64:ff9b::/96 and 6to4 2002::/16. The NAT64 local-use prefix 64:ff9b:1::/48 is always non-public. A NAT64 or 6to4 address that carries a public IPv4 address stays public.

Redirects. When the guard follows redirects on the caller's behalf, every hop is now sent with the caller's own fetch options, such as a custom dispatcher, keepalive or referrer policy. The final response reports redirected: true, as native redirect following does. A streamed request body is still sent once, with the first hop.

Tests pair each range with its nearest public neighbour, so an off-by-one boundary fails. They cover the redirect behaviour with a stubbed transport and with a real local server and dispatcher.

Validation: full suite (3,427 passed, 7 skipped), typecheck and build.

Refs ENG-4057

🤖 Generated with Claude Code

…redirects

internal_host now treats the IPv4 multicast, reserved, benchmarking and
IETF protocol blocks as non-public, along with IPv6 site-local and
multicast space. IPv6 transition addresses (NAT64 and 6to4) are
classified by the IPv4 destination they carry.

When the guard follows redirects on the caller's behalf, every hop is
sent with the caller's own fetch options, and the final response
reports that it was redirected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderbuds

coderbuds Bot commented Sep 28, 2026

Copy link
Copy Markdown

Well-structured egress guard enhancement with comprehensive internal-address classification.

🎯 Quality: 100% Elite · 📦 Size: Medium

📈 This month: Your 148th PR — above team average · Averaging Excellent

See how your team is trending →

@patchstackdave

Copy link
Copy Markdown
Contributor Author

/review

@patchstackdave
patchstackdave merged commit 65a7b66 into main Sep 29, 2026
18 checks passed
@patchstackdave
patchstackdave deleted the fix/egress-address-ranges branch September 29, 2026 09:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants