test(e2e): regression for Gost-Target destination-policy bypass

Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the
echo server; verifies the control request is 403, a checksum-valid
Gost-Target header naming an allowed authority cannot reach the blocked
backend, and a malformed header is fail-closed. Verified to catch the bug
by reverting the fix (exploit returned the backend response).
This commit is contained in:
ginuerzh
2026-08-27 20:16:34 +08:00
parent 35f7cd912c
commit 76467efc59
2 changed files with 126 additions and 0 deletions
+18
View File
@@ -0,0 +1,18 @@
# Service-level destination bypass (blacklist) on an HTTP forward proxy.
# Blocks the echo server's address ({{.ServerAddr}}). Used by
# TestHTTPProxyGostTargetPolicyBypass to verify that a Gost-Target header
# cannot separate the authority evaluated by the policy from the authority the
# transport dials.
bypasses:
- name: bypass-0
matchers:
- "{{.ServerAddr}}"
services:
- name: http-policy
addr: ":8080"
handler:
type: http
listener:
type: tcp
bypass: bypass-0