nstun: block cloud-local service destinations#282
Open
carrerasdarren-cell wants to merge 1 commit into
Open
Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
Author
|
@googlebot rescan |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
fd00:ec2::/32instance-local service rangeRationale
nstuncreates host-side sockets for destinations requested by the jailed process. Its destination gate already rejects loopback, broadcast, IPv6 link-local, and IPv6 site-local addresses, but it permits IPv4169.254.0.0/16and AWS's IPv6 instance-local service range.That leaves cloud metadata and other host-provided services reachable through the parent-side network bridge. Common IMDS endpoints include
169.254.169.254and[fd00:ec2::254]. AWS reserves the fullfd00:ec2::/32range for instance-local services.The IPv4 check blocks the RFC 3927 link-local range, matching the existing IPv6 link-local policy. The IPv6 check is limited to AWS's documented reserved range; neighboring ULA space remains allowed.
Testing
make nstun_ip_test-Werrorflags169.254.169.254; jailed request was blockedfd00:ec2::254; jailed request was blockedfd00:ec3::254remained reachable from the jailnsjailsmoke commandgit diff --checkNo real cloud metadata endpoint or third-party service was queried during testing.