Files
hermes-agent/contributors/emails/yinz7032@gmail.com
teknium1 e4c00097b4 fix(url_safety): trim the fake-ip salvage to the existing cache shape and two invariants
Follow-up to the cherry-picked #112536 (@AYin-Z):

- The range cache now bypasses the process-global cache when a profile
  override is active, exactly like _global_allow_private_urls — a multiplex
  gateway serving several profiles must not apply the first profile's
  declaration to later ones (A->B->A probe: True/False/True).
- _reset_allow_private_cache() resets both caches; the separate test-only
  _reset_fake_ip_cache() is gone.
- _is_declared_fake_ip() is a plain predicate folded into the one
  _resolved_ip_block_reason() condition; the metadata floor is still tested
  first, so a declared block can never cover 169.254.0.0/16 or the metadata
  IPs. Dropped the comma-split string parsing (a single string is still
  accepted as one entry) and the debug log line.
- Tests trimmed from five to two invariants: declared sentinel dialable at
  pre-flight and connect time; the declaration excuses only the declared
  block (RFC 1918 + metadata still blocked, sentinel blocked again once the
  declaration is removed).
2026-09-16 17:12:11 -07:00

2 lines
7 B
Plaintext