AI: smart unblock, TypeSafe anomaly triage, device identification (v1.34.0) - #6
Merged
Merged
Conversation
Hypervisor OUIs (Proxmox, VMware, Xen, Parallels) are servers. Devices the rules still cannot name are judged by TypeSafe from hostname, vendor and the names they look up; a class or OS is applied at 0.6 or better and never over a real classification. Opt-in via ai.typesafe.identify. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Beaconing skips local, broadcast and tailnet destinations and records the destination's port, country, operator and app. With TypeSafe on, each finding is judged on its own and can only be lowered from the detector's severity. The unblocker asks what the most-refused names are for; push, sign-in, app-API, update and content hosts blocked by three or fewer ad lists become allow suggestions, and with auto_unblock the clearest (two lists or fewer, not content) are allowed, three a day at most, announced, undoable, and withdrawn after a week unused. Bypass, malware, policy and the operator's own blocks are never touched. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
# Conflicts: # internal/api/helpers.go # internal/app/app.go # internal/config/config.go
…o for automatic unblocks Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…usal from an ad list, operator wildcard blocks respected, LAN addresses redacted from triage ClientRegistry handed out copies sharing the live Meta map that DHCP writes under the lock; the identifier (and API encoding) read it outside, a fatal concurrent map access. The unblocker kept only the oldest refusal's source from a newest-first log, so a name also refused by a policy could pass. AutoAllow ignored an operator's wildcard block on a parent. Port-scan and DGA findings carried LAN addresses in titles, details and evidence. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
…e; unblock reason grammar The Samsung-TV example in the device question anchored a Samsung phone (Android push and connectivity checks plus one Samsung service) to tv at 0.87; with balanced hints it reads phone 0.68 and the real TV 0.89. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Three TypeSafe-backed features on top of v1.33.0, plus fixes found in review.
Smart unblock (
internal/ai/unblock.go, opt-inai.typesafe.unblock/ai.typesafe.auto_unblock)store.BlockSources, including wildcard parents) is an ads or tracking list, and every refusal in the window came from one of those lists. Malware, bypass, policy, service and operator blocks are never considered.local_ruleswith originai.ai.AutoAllowrefuses when the operator has a rule on the name or a wildcard block on a parent.airules and marks the name dismissed.Anomaly triage. With TypeSafe on, each finding is judged on its own. The severity can only be lowered: unexplained ≥ 0.5 keeps it, 0.2 to 0.5 caps it at notice, below 0.2 makes it info. LAN addresses are redacted from the state sent to TypeSafe. If the key is refused, nothing is recorded and triage falls back to the chat model. Beaconing now skips private, loopback, multicast, link-local, CGNAT and broadcast destinations, and records the destination's port, country, operator and app.
Device identification (
internal/ai/identify.go, opt-inai.typesafe.identify)server.ClientRegistry.SetClass, which never overwrites an existing classification.Review fixes
ClientRegistrycopies now cloneMeta. Before, they shared the live map that DHCP writes under the lock: a fatal concurrent map access that predates this branch. A regression test fails under-racewithout the fix.Testing
go vet ./...andgo test -race ./...pass locally.unblock_test.go: the gates, and the daily cap.typesafe_test.go: triage severities and no LAN or hardware addresses in the request.identify_test.go.clients_test.go:SetClassbehaviour, and the Meta race.TestLocalDestination.v1.33.0-ai3.clientservices.googleapis.comandapi.naea1.uds.lenovo.comallowed automatically;settings-win.data.microsoft.comsuggested.🤖 Generated with Claude Code