Skip to content

Refuse a malformed IP range in an egress rule instead of reading it as /0 - #706

Merged
davidmckayv merged 3 commits into
CopilotKit:mainfrom
Chebaleomkar:fix/egress-cidr-strict
Oct 2, 2026
Merged

davidmckayv merged 3 commits into
CopilotKit:mainfrom
Chebaleomkar:fix/egress-cidr-strict

Conversation

@Chebaleomkar

Copy link
Copy Markdown
Contributor

What this changes

parseCidr in agent-computer/src/egress.ts accepted IP ranges that meant something other than what was written:

  • 10.0.0.5/ became /0, because Number("") is 0. In an allowlist_only policy, egressDecision(policy, "8.8.8.8", 443) then answered allowed.
  • 10.0.0.0/0x8 and 10.0.0.0/8/9 were accepted.
  • fe80::1%eth0 passed isIP, was stored, and then BlockList.addSubnet threw ERR_INVALID_IP_ADDRESS from decide on the first connection the policy judged.

The prefix must now be 1–3 decimal digits. Extra / segments and zone ids are refused, with the existing "is not an IP address or range" sentence.

Where it runs

The agent computer's egress filter, and wherever egress rules are validated (parseEgressRules).

Boundary and audit

Stricter only. A rule like this already saved now matches nothing, so an allow-list refuses rather than opens.

Changelog

Entry under Unreleased.

Proof

New cases in agent-computer/tests/egress-policy.test.ts. They fail on main (18 pass, 1 fail) and pass with the fix (19/19). Biome format and lint are clean.

…s /0

parseCidr read an empty prefix as 0 ("10.0.0.5/" allowed every IPv4
address), took hex and extra segments, and accepted IPv6 zone ids that
BlockList then threw on inside the filter. Parse the prefix as 1-3
decimal digits, refuse extra segments and zone ids.
@davidmckayv
davidmckayv merged commit 8b9dca5 into CopilotKit:main Oct 2, 2026
davidmckayv added a commit that referenced this pull request Oct 2, 2026
…722)

The banner offering help self-hosting OpenBot stays on by default, but a
deployment whose Intelligence entitlement is active on a paid plan (pro,
team, team_self_hosted, enterprise) or comes from an AWS Marketplace
licence no longer shows it. Free, developer, inactive and unreadable
entitlements still show it.

The server reads the entitlement through the Intelligence client it
already holds, keeps the answer for ten minutes, refreshes it in the
background when stale, waits at most a second for the first answer, and
falls back to showing the bar on any error, logged once per run of
failures.

The changelog's upgrade note also names the banner and the malformed
egress range change from #706, which refuses a saved network policy
that contains such a range as a whole.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants