fix(security): align SSRF denylists and reject endpoint userinfo - #8321
Conversation
Extend private-networks.yaml to the special-purpose ranges MCP already blocks, and reject credentialed endpoint URLs in plugin SSRF validation so inference and MCP share one host-safety contract. Signed-off-by: Ayush7614 <ayushknj3@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Reject both credential halves and assert error messages do not echo the supplied secret values. Signed-off-by: Ayush7614 <ayushknj3@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
…ject Add IANA 100:0:0:1::/64 to the shared SSRF denylist and MCP target filter, and confirm credentialed endpoint URLs fail before DNS lookup. Signed-off-by: Ayush7614 <ayushknj3@gmail.com> Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Security review: PASSReviewed revision
Validation completed successfully:
No blocking security findings remain. |
📝 WalkthroughWalkthroughThe change expands SSRF blocklists for special-purpose IPv4, IPv6, and metadata destinations. Endpoint validation rejects embedded URL credentials before DNS lookup. Tests add boundary, parity, and credential-redaction coverage. ChangesSSRF policy and endpoint validation
Estimated code review effort: 3 (Moderate) | ~20 minutes 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
Code Coverage OverviewLanguages: TypeScript TypeScript / code-coverage/pluginThe overall coverage in commit abee3d4 in the TypeScript / code-coverage/cliThe overall coverage in commit abee3d4 in the Show a code coverage summary of the most impacted files.
Updated |
|
🌿 Preview your docs: https://nvidia-preview-pr-8321.docs.buildwithfern.com/nemoclaw |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@nemoclaw/src/blueprint/ssrf.ts`:
- Around line 63-67: Update the URL parse-error handling near the credential
check in ssrf.ts to avoid exposing raw userinfo when new URL(url) rejects
malformed credential-bearing input; use a generic parse error or redact all
username and password values before including the URL. In ssrf.test.ts, add a
malformed credential case asserting the thrown error omits every credential
value.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Enterprise
Run ID: bc1bac98-51e7-4b65-a2fe-4afb26cd8369
📒 Files selected for processing (9)
docs/inference/custom-endpoint-security.mdxnemoclaw-blueprint/private-networks.yamlnemoclaw/src/blueprint/private-networks.tsnemoclaw/src/blueprint/ssrf.test.tsnemoclaw/src/blueprint/ssrf.tssrc/lib/private-networks.tssrc/lib/security/mcp-url-target.tstest/mcp-url-target.test.tstest/package-contract/ssrf-parity.test.ts
PR Review Advisor — No blocking findings reportedAdvisor assessment: No blocking advisor findings reported Model lanes
5 terminology differences from the second opinionAdvisory only. These are normalized differences from the primary terminology receipt.
Second-opinion terminology and E2E selections are advisory. They do not change the primary assessment or E2E / PR Gate. 2 semantic terminology decisionsTerminology decisions are advisory. They affect the assessment only when a separate finding identifies concrete semantic impact.
E2E guidanceAdvisory only. E2E / PR Gate selects and runs jobs independently. Recommended E2E: This automated review informs maintainers. Warnings and suggestions do not require a response. A maintainer decides whether to merge. |
Signed-off-by: Apurv Kumaria <akumaria@nvidia.com>
Security review update: PASSReviewed revision The earlier nine-category review remains valid. The additional change improves the secrets-and-credentials and input-validation findings: URL parse failures now return a generic message instead of including attacker-controlled input, so malformed username/password forms cannot expose credential values through the error path. The regression covers combined, username-only, and password-only malformed forms and confirms DNS is not queried. Validation passed:
No blocking security findings remain. |
|
The Nemotron advisor lane failed after completing its analysis because its own receipt validator rejected a |
|
Follow-up: the one permitted rerun of the Nemotron advisor lane passed. The current branch now has 44 passing checks, no pending or failed checks, and no unresolved review threads. The remaining merge blocker is independent approval. |
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
Sensitive-Path Security ReviewResult: PASS
Nine-Category Assessment
No blocking security finding or waiver remains. Attribution is preserved because all refreshes are signed merge commits and do not rewrite contributor commits. |
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
|
Historical gate result for PR commit
This evidence is superseded by current PR commit |
|
CI classification: the validated CLI artifact restore step fails before this PR’s target tests because This PR does not modify CLI artifact packaging or name-validation paths, so the failure is not caused by its SSRF/private-network changes. The shared packaging defect has been corrected on This PR still requires an independent approval and successful required checks before merge. |
Signed-off-by: Carlos Villela <cvillela@nvidia.com>
|
Follow-up: the repaired E2E run completed successfully across all selected lanes, including managed-image startup on both architectures, inference routing, network policy, Hermes, cloud inference, full E2E, and both security-posture variants. All 45 current checks now pass, the one advisor protocol retry passed, and no review threads remain unresolved. Independent approval is the only remaining merge gate. |
cv
left a comment
There was a problem hiding this comment.
Approved at head abee3d4 against base 2b68aa1. This hardens the existing supported SSRF boundary. The repository gate checker reports all 60 current checks green, no conflicts, no unresolved major or critical CodeRabbit findings, risky-path test coverage, a valid DCO declaration, and all nine commits GitHub Verified. The documentation writer and nine-category security reviews are current, the trusted E2E gate passed, and contributor attribution is preserved.
<!-- markdownlint-disable MD041 --> ## Summary Add the canonical dated changelog entry for the planned NemoClaw v0.0.103 release. The new `docs/changelog/2026-08-05.mdx` entry uses the exact `## v0.0.103` heading and summarizes supported user-visible changes merged since v0.0.102. ## Changes - Add the parser-safe MDX SPDX header, three-paragraph release summary, and detailed grouped bullets to `docs/changelog/2026-08-05.mdx`. - Link each release-note group to the most specific published OpenClaw, Hermes, or Deep Agents documentation routes. - Exclude dormant MXC and Podman foundations, internal managed-inference adapters, test-only changes, and maintainer tooling from the supported product narrative. ### Source summary - [#8082](#8082) -> `docs/changelog/2026-08-05.mdx`: Document the new one-command agent launch flow. - [#8314](#8314) -> `docs/changelog/2026-08-05.mdx`: Document managed vLLM host capability validation and restart handling. - [#8248](#8248) -> `docs/changelog/2026-08-05.mdx`: Record the DGX Spark Qwen profile MTP default change. - [#8223](#8223) -> `docs/changelog/2026-08-05.mdx`: Record explicit model preservation across provider switches. - [#8209](#8209) -> `docs/changelog/2026-08-05.mdx`: Document corrected Windows WSL provider selection. - [#8316](#8316) -> `docs/changelog/2026-08-05.mdx`: Record clean managed-checkout reuse after installation. - [#8239](#8239) -> `docs/changelog/2026-08-05.mdx`: Record the packaged-service teardown fallback. - [#8247](#8247) -> `docs/changelog/2026-08-05.mdx`: Document uninstall behavior for an already-removed sandbox. - [#7998](#7998) -> `docs/changelog/2026-08-05.mdx`: Record preserved container-start diagnostics. - [#8027](#8027) -> `docs/changelog/2026-08-05.mdx`: Record journal-backed not-ready repair authority. - [#7812](#7812) -> `docs/changelog/2026-08-05.mdx`: Document actionable rebuild preflight diagnostics. - [#8222](#8222) -> `docs/changelog/2026-08-05.mdx`: Record redacted top-level CLI failures. - [#8313](#8313) -> `docs/changelog/2026-08-05.mdx`: Record structured MCP bridge destruction failures. - [#8211](#8211) -> `docs/changelog/2026-08-05.mdx`: Document cleanup of incomplete snapshot captures. - [#8212](#8212) -> `docs/changelog/2026-08-05.mdx`: Document best-effort post-restore policy reconciliation. - [#8245](#8245) -> `docs/changelog/2026-08-05.mdx`: Clarify manifest-defined OpenClaw workspace persistence. - [#8254](#8254) -> `docs/changelog/2026-08-05.mdx`: Include corrected snapshot restore selection guidance. - [#8238](#8238) -> `docs/changelog/2026-08-05.mdx`: Document preservation of managed MCP policy entries. - [#7568](#7568) -> `docs/changelog/2026-08-05.mdx`: Record mutable-default Shields rollback preservation. - [#8200](#8200) -> `docs/changelog/2026-08-05.mdx`: Record truthful Shields state after a rejected transition. - [#7895](#7895) -> `docs/changelog/2026-08-05.mdx`: Record descriptor-bound Shields lock inspection. - [#7892](#7892) -> `docs/changelog/2026-08-05.mdx`: Document the canonical Hermes dashboard profile and migration. - [#7871](#7871) -> `docs/changelog/2026-08-05.mdx`: Document fail-closed Hermes cron restore. - [#7894](#7894) -> `docs/changelog/2026-08-05.mdx`: Record the reset Hermes health budget after recovery. - [#8228](#8228) -> `docs/changelog/2026-08-05.mdx`: Document Hermes build-time corporate CA trust. - [#8206](#8206) -> `docs/changelog/2026-08-05.mdx`: Document bounded Deep Agents Code failure classification. - [#8297](#8297) -> `docs/changelog/2026-08-05.mdx`: Record reuse of the published Deep Agents Code base image. - [#8321](#8321) -> `docs/changelog/2026-08-05.mdx`: Document aligned endpoint SSRF protections and userinfo rejection. - [#8299](#8299) -> `docs/changelog/2026-08-05.mdx`: Document the fail-closed `setpriv` transition in managed images. - [#7603](#7603) -> `docs/changelog/2026-08-05.mdx`: Record corrected confidentiality-root traversal. - [#8334](#8334) -> `docs/changelog/2026-08-05.mdx`: Record removal of the unsupported logs audit example. - [#8256](#8256) -> `docs/changelog/2026-08-05.mdx`: Record reordered network-policy walkthrough prerequisites. - [#7767](#7767) -> `docs/changelog/2026-08-05.mdx`: Record platform runtime shape validation. ## Type of Change - [ ] Code change (feature, bug fix, or refactor) - [ ] Code change with doc updates - [x] Doc only (prose changes, no code sample modifications) - [ ] Doc only (includes code sample changes) ## Quality Gates - [ ] Tests added or updated for changed behavior - [x] Existing tests cover changed behavior — justification: `npx vitest run test/changelog-docs.test.ts` passed all 6 tests. - [ ] Tests not applicable — justification: - [x] Docs updated for user-facing behavior changes - [ ] Docs not applicable — justification: - [ ] Sensitive paths changed (security, policy, credentials, preflight, onboarding, inference, runner, sandbox, or messaging) - [ ] Sensitive-path review completed or maintainer-approved waiver recorded — reviewer/approval link/justification: - [ ] Non-success, skipped, or missing CI check accepted by maintainer — check name, approval link, and follow-up issue: ## Documentation Writer Review - [ ] Documentation writer subagent reviewed the completed changes - Result: `docs-updated` - Evidence: `docs/changelog/2026-08-05.mdx` follows the release-prep and documentation writing rules. The changelog contract tests passed 6/6, and `npm run docs` completed with 0 errors and the repository's 2 existing Fern warnings. - Agent: Codex Desktop <!-- docs-review-head-sha: 66fcd80 --> <!-- docs-review-agents-blob-sha: 3dd7c24 --> ## DGX Station Hardware Evidence - [ ] Tested on DGX Station - Tested commit: Not applicable. - Station profile/scenario: Not applicable. - Result: Not applicable. - Supporting evidence: Not applicable. ## Verification - [x] PR description includes a `Signed-off-by:` line and every commit appears as `Verified` in GitHub - [x] Normal `pre-commit`, `commit-msg`, and `pre-push` hooks passed, or `npm run validate:pr` passed after refreshing `origin/main` when hooks were skipped or unavailable - [x] Targeted behavior tests pass for the current change set, or tests are marked not applicable above — `npx vitest run test/changelog-docs.test.ts`: 1 file and 6 tests passed. - [ ] Applicable broad gate passed — `npm test` for broad runtime/test-harness changes; `npm run check` for repo-wide validation/coverage changes — command/result: Not run for this doc-only change. - [x] Quality Gates section completed with required justifications or waivers - [x] No secrets, API keys, or credentials committed - [ ] `npm run docs` builds without warnings (doc changes only) — completed with 0 errors and 2 existing Fern warnings. - [x] Doc pages follow the [style guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md) (doc changes only) - [ ] New doc pages include SPDX header and frontmatter (new pages only) — the native changelog uses the required parser-safe MDX SPDX comment and does not use page frontmatter. --- Signed-off-by: Charan Jagwani <cjagwani@nvidia.com> <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Documentation** * Added release notes for v0.0.103. * Documented the new `nemoclaw launch` command. * Included updates covering onboarding, inference, installation, recovery, snapshots, security, integrations, endpoint validation, sandbox hardening, and related guidance. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
Summary
NemoClaw now applies the same expanded special-purpose address protections across the CLI and plugin SSRF validators. Direct blueprint runs also reject endpoint URLs with embedded credentials before DNS resolution, preventing credential-bearing URLs from reaching the resolver.
This hardens an existing supported security boundary. It does not add a product integration or require a product, business, or architecture decision.
Changes
Type of Change
Quality Gates
abee3d4a1f2c8812a05af7f04372870adbda9c21; no blocking finding or waiver remains.Documentation Writer Review
docs-updateddocs/inference/custom-endpoint-security.mdxdocuments rejection of embedded endpoint credentials before DNS and the aligned special-purpose IPv4, IPv6, and metadata destination restrictions. Reviewed the writing rules and documentation style at refreshed headabee3d4a1f2c8812a05af7f04372870adbda9c21; all nine PR-owned paths are byte-identical to the prior reviewed head, and attribution remains preserved. Generated and inspected the OpenClaw, Hermes, and Deep Agents variants, confirmed shared security guidance, correct agent-specific CLI names, omitted the section that does not apply to Deep Agents, and found no unresolved<AgentOnly>markers. The full docs build passed with 0 errors and 2 non-failing Fern warnings; 355 focused SSRF, MCP, and parity tests, both builds, both typechecks, and diff and cleanliness validation also passed.DGX Station Hardware Evidence
Verification
Signed-off-by:line and every commit appears asVerifiedin GitHubpre-commit,commit-msg, andpre-pushhooks passed, ornpm run validate:prpassed after refreshingorigin/mainwhen hooks were skipped or unavailablevalidate:prfallback and focused SSRF, cross-package parity, and MCP integration suites exercise the affected consumers.npm run docsbuilds without warnings (doc changes only) — build passed with 0 errors and 2 non-failing Fern warnings.Signed-off-by: Ayush7614 ayushknj3@gmail.com
Signed-off-by: Apurv Kumaria akumaria@nvidia.com
Summary by CodeRabbit
metadatahostname.