Skip to content

Report network policy denials as proxy_error events - #429

Open
meliaj wants to merge 3 commits into
mainfrom
hypeship/proxy-error-network-policy-403
Open

meliaj wants to merge 3 commits into
mainfrom
hypeship/proxy-error-network-policy-403

Conversation

@meliaj

@meliaj meliaj commented Oct 1, 2026 •

Copy link
Copy Markdown

Summary

The metro egress proxy is gaining per-session egress allowlists. When a destination isn't on the allowlist, the proxy answers with a branded 403 carrying X-Kernel-Proxy-Error: network_policy_denied. Other proxy-layer failures still return 502.

Before this change, the CDP monitor only checked branded 502s, so a denial produced no proxy_error event. This PR:

  • treats 403 as a branded-response status alongside 502. Only those two statuses pay for the header decode; other responses still cost just the status compare. A website's own 403 without the header emits nothing.
  • adds network_policy_denied to the published proxy_error code enum, so the event carries the typed code instead of unknown with a raw_code. The spec descriptions now mention the 403.
  • adds destination_route_unavailable and origin_response_incomplete to the enum as well. The proxy already serves both as branded 502s, but the image reported them as unknown with a raw_code.
  • updates the cdpmonitor README, which still described proxy_error as 502-only, and notes that a CONNECT the proxy refuses outright, such as a denied CONNECT to a port other than 443, shows up only as network_loading_failed because Chromium doesn't expose the refusal.

The 403 handling can ship before or after the proxy change: until the proxy sends these 403s, nothing changes for them. The two added codes take effect as soon as an image with this change ships. It does need to be in a released image before kernel/docs#657 is published, since that PR says denials show up as proxy_error events and drops the proxy errors page's note that origin_response_incomplete isn't reported.

Validation

  • cd server && go test ./lib/cdpmonitor/... ./lib/events/... ./lib/oapi/...
  • KERNEL_CDPMONITOR_CHROME_E2E=1 go test ./lib/cdpmonitor/ -run TestProxyErrorE2E against real Chromium, with new cases for network_policy_denied (403), destination_route_unavailable and origin_response_incomplete. The last two come back as unknown with the previous generated enum.
  • The new unit test fails with the old 502-only gate.
  • lib/oapi/oapi.go was regenerated by running the oapi-generate steps directly. Unrelated go mod tidy changes to go.sum were left out.
  • Container e2e tests pass in CI (test-server-e2e).

🤖 Generated with Claude Code


Note

Medium Risk
Changes network telemetry classification for 403 responses and expands the public proxy_error enum; mis-gating could false-positive on unrelated 403s, though the header gate limits that.

Overview
Extends CDP monitor proxy_error detection so branded metro responses with X-Kernel-Proxy-Error are recognized on 403 as well as 502, enabling typed telemetry when egress network policy blocks a destination (network_policy_denied with status 403). Plain site 403s without the header still do not emit proxy_error.

The OpenAPI/oapi proxy_error code enum gains network_policy_denied, destination_route_unavailable, and origin_response_incomplete, with docs noting 403 vs 502 and that some CONNECT refusals remain network_loading_failed only. Unit and Chromium E2E tests cover the 403 gate and new codes; README event taxonomy is updated accordingly.

Reviewed by Cursor Bugbot for commit 493f2d3. Bugbot is set up for automated code reviews on this repo. Configure here.

The metro egress proxy now answers a destination outside a session's
egress allowlist with a branded 403 carrying X-Kernel-Proxy-Error:
network_policy_denied. The monitor only classified branded 502s, so
those denials produced no proxy_error event. Accept 403 at the status
gate and add network_policy_denied to the published code enum, so the
event carries the typed code instead of unknown.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@meliaj
meliaj force-pushed the hypeship/proxy-error-network-policy-403 branch from b47b9c1 to 2fef758 Compare October 5, 2026 21:26
@meliaj
meliaj marked this pull request as ready for review October 5, 2026 21:48
@meliaj
meliaj requested review from hiroTamada and rgarcia October 5, 2026 21:48
meliaj and others added 2 commits October 5, 2026 23:00
The cdpmonitor README and the TestProxyErrorE2E comment still described
proxy_error as 502-only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The proxy already serves destination_route_unavailable and
origin_response_incomplete as branded 502s, and the API enum lists both,
but the image reported them as unknown with a raw_code.

Also rename the status-gate subtest now that 403 is classified, describe
the 403 status by when the proxy sends it, and note in the README that a
CONNECT the proxy refuses outright surfaces as network_loading_failed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant