Refuse a malformed IP range in an egress rule instead of reading it as /0 - #706
Merged
Merged
Conversation
…s /0
parseCidr read an empty prefix as 0 ("10.0.0.5/" allowed every IPv4
address), took hex and extra segments, and accepted IPv6 zone ids that
BlockList then threw on inside the filter. Parse the prefix as 1-3
decimal digits, refuse extra segments and zone ids.
Chebaleomkar
requested review from
MikeRyanDev,
davidmckayv,
guidovizoso,
mxmzb and
tylerslaton
as code owners
October 2, 2026 19:02
davidmckayv
added a commit
that referenced
this pull request
Oct 2, 2026
…722) The banner offering help self-hosting OpenBot stays on by default, but a deployment whose Intelligence entitlement is active on a paid plan (pro, team, team_self_hosted, enterprise) or comes from an AWS Marketplace licence no longer shows it. Free, developer, inactive and unreadable entitlements still show it. The server reads the entitlement through the Intelligence client it already holds, keeps the answer for ten minutes, refreshes it in the background when stale, waits at most a second for the first answer, and falls back to showing the bar on any error, logged once per run of failures. The changelog's upgrade note also names the banner and the malformed egress range change from #706, which refuses a saved network policy that contains such a range as a whole.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
parseCidrinagent-computer/src/egress.tsaccepted IP ranges that meant something other than what was written:10.0.0.5/became/0, becauseNumber("")is 0. In anallowlist_onlypolicy,egressDecision(policy, "8.8.8.8", 443)then answered allowed.10.0.0.0/0x8and10.0.0.0/8/9were accepted.fe80::1%eth0passedisIP, was stored, and thenBlockList.addSubnetthrewERR_INVALID_IP_ADDRESSfromdecideon the first connection the policy judged.The prefix must now be 1–3 decimal digits. Extra
/segments and zone ids are refused, with the existing "is not an IP address or range" sentence.Where it runs
The agent computer's egress filter, and wherever egress rules are validated (
parseEgressRules).Boundary and audit
Stricter only. A rule like this already saved now matches nothing, so an allow-list refuses rather than opens.
Changelog
Entry under Unreleased.
Proof
New cases in
agent-computer/tests/egress-policy.test.ts. They fail onmain(18 pass, 1 fail) and pass with the fix (19/19). Biome format and lint are clean.