fix(network): cover regional Kiro service origins

This commit is contained in:
elky
2026-09-04 19:09:46 +08:00
parent e89c3aa674
commit 9362c34fcd
@@ -503,15 +503,30 @@ fn execution_host_allows_benchmarking_dns_answer(host: &str) -> bool {
return looks_like_cloud_region_label(region); return looks_like_cloud_region_label(region);
} }
// Kiro uses q.<region>.amazonaws.com. Match exactly that three-label // Kiro uses a small, fixed set of regional service origins. Match each
// service shape; this intentionally does not allow arbitrary AWS // supported AWS partition explicitly; never use a broad suffix check that
// subdomains or lookalikes such as q.us-east-1.evil.amazonaws.com. // could accept an attacker-controlled subdomain.
let labels = host.split('.').collect::<Vec<_>>(); matches_regional_service_host(&host, "q", ".amazonaws.com")
labels.len() == 4 || matches_regional_service_host(&host, "q-fips", ".amazonaws.com")
&& labels[0] == "q" || matches_regional_service_host(&host, "codewhisperer", ".amazonaws.com")
&& labels[2] == "amazonaws" || matches_regional_service_host(&host, "oidc", ".amazonaws.com")
&& labels[3] == "com" || matches_regional_service_host(&host, "prod", ".auth.desktop.kiro.dev")
&& looks_like_cloud_region_label(labels[1]) || matches_regional_service_host(&host, "q", ".c2s.ic.gov")
|| matches_regional_service_host(&host, "q", ".sc2s.sgov.gov")
|| matches_regional_service_host(&host, "q", ".csp.hci.ic.gov")
}
fn matches_regional_service_host(host: &str, service: &str, suffix: &str) -> bool {
let Some(region) = host
.strip_prefix(service)
.and_then(|value| value.strip_prefix('.'))
.and_then(|value| value.strip_suffix(suffix))
else {
return false;
};
// A single region label is required. This rejects values such as
// `q.us-east-1.evil.amazonaws.com` and suffix lookalikes.
!region.contains('.') && looks_like_cloud_region_label(region)
} }
fn looks_like_cloud_region_label(value: &str) -> bool { fn looks_like_cloud_region_label(value: &str) -> bool {
@@ -5527,6 +5542,13 @@ mod tests {
"CHATGPT.COM.", "CHATGPT.COM.",
"us-central1-aiplatform.googleapis.com", "us-central1-aiplatform.googleapis.com",
"q.us-east-1.amazonaws.com", "q.us-east-1.amazonaws.com",
"q-fips.us-gov-west-1.amazonaws.com",
"codewhisperer.us-west-2.amazonaws.com",
"oidc.us-east-1.amazonaws.com",
"prod.us-east-1.auth.desktop.kiro.dev",
"q.us-iso-east-1.c2s.ic.gov",
"q.us-isob-east-1.sc2s.sgov.gov",
"q.us-isof-east-1.csp.hci.ic.gov",
] { ] {
assert!( assert!(
super::validate_execution_dns_answers(host, vec![fake]).is_ok(), super::validate_execution_dns_answers(host, vec![fake]).is_ok(),
@@ -5541,6 +5563,14 @@ mod tests {
"q.us-east-1.evil.amazonaws.com", "q.us-east-1.evil.amazonaws.com",
"q.us-east-1.amazonaws.com.attacker.test", "q.us-east-1.amazonaws.com.attacker.test",
"q.localhost.amazonaws.com", "q.localhost.amazonaws.com",
"q-fips.us-gov-west-1.evil.amazonaws.com",
"codewhisperer.us-west-2.evil.amazonaws.com",
"oidc.us-east-1.evil.amazonaws.com",
"prod.us-east-1.auth.desktop.kiro.dev.attacker.test",
"prod.us-east-1.evil.auth.desktop.kiro.dev",
"q.us-iso-east-1.evil.c2s.ic.gov",
"q.us-iso-east-1.c2s.ic.gov.attacker.test",
"q.us-iso-east-1.c2s.ic.gov.evil",
"198.18.75.234", "198.18.75.234",
] { ] {
assert!( assert!(