fix(web): bound the fetch SSRF pre-flight DNS lookup - #6852
Merged
Merged
Conversation
The SSRF pre-flight in `validate_fetch_target` resolves the target host with an unbounded `tokio::net::lookup_host`. The lookup runs before the guarded request — and once more per redirect — so a wedged resolver stalled the fetch tool past its own 60s HARD_MAX_TIMEOUT envelope with no way for the caller to recover. Bound the pre-flight resolution at 10 seconds. A resolver that does not answer in time now fails the pre-flight with an explicit "timed out resolving host" permission error instead of stalling the tool; the documented request hard cap itself is unchanged. A test pins the bound below the fetch hard cap, and the existing unresolved-host regressions cover the preserved DNS-failure error path. Signed-off-by: asto <asto18089@126.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The SSRF pre-flight in
validate_fetch_targetresolved the target host with an unboundedtokio::net::lookup_host. The lookup runs before the guarded request — and once per redirect — so a wedged resolver stalled the fetch tool past its own 60sHARD_MAX_TIMEOUTenvelope with no recovery.Bound the pre-flight at 10s (
DNS_PREFLIGHT_TIMEOUT). A hung resolver now fails the pre-flight with an explicit "timed out resolving host" permission error; the DNS-failure error path and message are unchanged, and the existing resolution-failure regression still holds. Literal-IP and localhost targets don't resolve and are unaffected. A test pins the bound below the fetch hard cap so the two constants cannot drift.Testing
cargo test -p codewhale-tui --lib web::guardcargo clippy -p codewhale-tui --all-targets --all-features --lockedDisclosure: the timeout branch itself is not exercised by a test (that would require intercepting OS DNS); coverage is the constant-relationship pin plus the preserved, still-tested resolution-failure path.
Adapted from the Pinvou fork's timeout audit (Pinvou/CodeWhale
d349f2537, the DNS pre-flight slice only).Checklist
CHANGELOG.mdchanges