github / github/app

web_fetch network failure: Blocks Fake-IP (198.18.x.x) and ignores OS System Proxy

オープン
#1,867 コメント 0 件 リアクション 2 件 担当者 0 名 GitHub で見る
Bugs
主要言語
言語のデータがありません
スター
2.1k
フォーク
153
PR マージ指標
30日以内にマージされた PR はありません

説明

### Short summary

web_fetch cannot access the internet in standard proxy environments (e.g., Clash/Mihomo/Surge). It aggressively blocks RFC 2544 Fake-IP ranges due to SSRF protection when TUN mode is on, while simultaneously ignoring OS system proxy settings when TUN mode is off

### Affected version or release

v1.019

### Installation context

windows x64

### What happened?

When using proxy tools (Clash/Mihomo) to access globally blocked sites (like Google), the app's web_fetch fails entirely under both common network setups. The issue stems from two overlapping networking limitations in the app:

Scenario 1: Using TUN Mode (Fake-IP)
When TUN mode is enabled, the proxy router resolves DNS to the 198.18.0.0/15 range (Standard RFC 2544 Fake-IP). web_fetch intercepts this locally and throws an SSRF protection error, refusing to connect:

WebFetchBlockedUrlError: Error: web_fetch URL "https://www.google.com/" resolves to blocked address 198.18.0.9. URLs must not target loopback, private, or link-local addresses.

Scenario 2: Using Standard OS System Proxy (TUN disabled)
If I disable TUN mode and use standard OS proxy routing (Rule Mode), websites that are not blocked (like baidu.com) can be fetched. However, blocked sites (like google.com or httpbin.org) throw:

TypeError: fetch failed or status code 503

This occurs because the underlying Node.js fetch implementation natively ignores OS System Proxy settings and attempts a direct connection, which then hits the firewall.

### Steps to reproduce

case1:use poxy tools like clash verge, turn off TUN mode, then try github copilot app's webfetch tool, you will see webfetch tool ignoring OS system proxy settings.
case2:use poxy tools like clash verge, turn on TUN mode, then try github copilot app's webfetch tool, you will see: WebFetchBlockedUrlError: Error: web_fetch URL "https://www.google.com/" resolves to blocked address 198.18.0.9. URLs must not target loopback, private, or link-local addresses.

### Expected behavior

Comparison & Expected Behavior:
Other AI IDEs and desktop clients (like Trae and OpenCode) handle this environment flawlessly because they:

Provide a bypass/whitelist for the 198.18.0.0/15 range in their SSRF policies.

Explicitly inject OS proxy settings into their fetch agents.

Suggested Fixes:

Please whitelist the 198.18.0.0/15 subnet for SSRF checks, as this is the industry standard for Fake-IP environments.

Provide a configuration option to respect OS system proxies or at least read HTTP_PROXY / HTTPS_PROXY environment variables.

### Additional context

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

web_fetch のネットワークリクエストから調査を開始し、その SSRF アドレスチェックと基盤となる Node.js fetch の設定を確認します。Issue に記載されている 2 つの Clash/Mihomo 構成を再現してください。web_fetch が Fake-IP のケースを処理し、SSRF 保護を失うことなくブロックされたサイトにはシステムプロキシを使用できれば完了です。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
node.js
領域
networking
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。