v0.14.0
New Features
- CIDR rule destinations: rules whose destination contains a
/are now interpreted as CIDR (e.g.192.168.0.0/16,2001:db8::/32) and matched via IP containment instead of being treated as literal glob patterns (#39) - HTTP Host header peeking on port 80 / 8080: SOCKS5 CONNECT requests that arrive with a bare IP and a non-Allow / non-Deny verdict now defer policy evaluation, peek the request's
Hostheader, and re-evaluate against the recovered hostname. Mirrors the existing TLS SNI peek path. Eliminates the need for one approval rule per IP behind a hostname rule (e.g. tailscale's DERP probes hitting dozens ofderp[N].tailscale.comIPs) (#39)
Security hardening for the new HTTP Host path
- Spoofing guard verifies the recovered Host actually binds to the destination IP via the DNS interceptor's reverse cache or a forward DNS lookup. A claim like
Host: api.openai.comto an arbitrary IP is rejected before the verdict is upgraded (#39) - Peek failure on a deferred port-80 connection attaches a per-request policy checker bound to the IP destination so the broker still gets to ask, instead of silently upgrading the original Ask verdict to an allow (#39)
- HTTP-host deferral is gated on broker presence so Ask-without-broker continues to collapse to Deny via the IP-based path before SOCKS5 success goes out, avoiding success-then-reset on the client side (#39)