You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit f22b917
Browse filesBrowse the repository at this point in the historyBrowse files
## Summary
- Add repeatable, create-only `--proxy-route` with typed SDK request
construction and light syntax/count validation.
- Display returned proxy routes alongside private hosts in create/get
output, including SDK-backed JSON output.
- Upgrade kernel-go-sdk to v0.112.0 and adapt WebMCP list handling to
its updated SDK types.
## Validation
- `go test ./...` and `make test` passed.
- `make build` passed; `gofmt` and `git diff --check` clean.
- `make lint` ran with 70 existing repo-wide findings (50 errcheck, 3
ineffassign, 16 staticcheck, 1 unused); none on changed lines.
- No live API smoke test performed.
<!-- CURSOR_SUMMARY -->
---
> [!NOTE]
> **Medium Risk**
> Changes browser session egress configuration at creation time and
upgrades the SDK; incorrect routes could misroute traffic, though host
matching is API-validated and routes are create-only.
>
> **Overview**
> Adds **create-only** `--proxy-route` to `kernel browsers create`,
mapping `HOST[,HOST...]=PROXY` (proxy ID by default, or `id:` / `name:`)
into the browser network config with client-side limits (10 routes, 50
hosts per route) and rejection when combined with pool acquire flags.
>
> **Network request shaping** now omits empty `private_hosts` and only
sends `network` when private hosts or proxy routes are present;
**create/get** table output adds a **Proxy Routes** row alongside
private hosts.
>
> Bumps **kernel-go-sdk** to v0.112.0 and updates **WebMCP list** for
the new tool payload shape (`tool.name`, `readOnlyHint`) and `ListTools`
params. README documents the new flag.
>
> <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit
72f0623. Bugbot is set up for automated
code reviews on this repo. Configure
[here](https://www.cursor.com/dashboard/bugbot).</sup>
<!-- /CURSOR_SUMMARY -->
-`--region us-east|eu-west|ap-southeast` - Geographic region for the session. Fixed once the session is created; requires a Start-Up or Enterprise plan and defaults to `us-east`.
257
257
-`--private-host <host>` - Destination the browser reaches directly through the session's own network instead of Kernel-managed egress, for private hosts on a VPN or tunnel the session joins (repeatable or comma-separated, max 32). Accepts hostname patterns (`*.example.ts.net`), IPs (`10.1.30.63`, `[fd00::1]`), and private CIDRs (`100.64.0.0/10`). Replaces the default private ranges (RFC1918, `100.64.0.0/10`, `fc00::/7`); omit to keep them. Fixed once the session is created. Unrelated to a proxy's `--bypass-host`, which only chooses between upstream proxy and Kernel-managed direct egress.
258
+
-`--proxy-route '<host>[,<host>...]=<proxy>'` - Route matching browser requests through a selected proxy (repeatable, max 10 routes with 1–50 hosts each). Example: `--proxy-route 'api.ipify.org,*.ipify.org=name:my-dc-proxy'`. The proxy is an ID by default; use `id:<id>` or `name:<name>` explicitly. Exact hostnames beat wildcards; longer wildcard suffixes beat shorter ones. `*.example.com` matches subdomains, not `example.com`. Matching ignores case and ports. Unmatched hosts use `--proxy-*` or default egress, while `--start-url` uses the top-level proxy during setup. Routes are create-only and are not available on pool sessions.
258
259
-`--start-url <url>` - Initial page to open on launch
259
260
-`--proxy-id <id>` / `--proxy-name <name>` - Use that proxy for the session regardless of stealth (mutually exclusive with each other and with `--proxy-mode`)
260
261
-`--proxy-mode direct|default` - Egress mode instead of a selected proxy: `direct` for no proxy regardless of stealth, `default` for the stealth-derived default (Kernel's stealth proxy with `--stealth`, direct egress otherwise). Omit all proxy flags to get the default.
@@ -3172,6 +3247,7 @@ unrestricted code execution inside the browser VM and is not sandboxed.`,
3172
3247
browsersCreateCmd.Flags().String("proxy-mode", "", "Proxy egress mode instead of a selected proxy: 'direct' for no proxy regardless of stealth, or 'default' for the browser default (Kernel's stealth proxy when --stealth is set, direct egress otherwise)")
3173
3248
browsersCreateCmd.Flags().String("region", "", "Geographic region for the session: 'us-east', 'eu-west', or 'ap-southeast'. Fixed once the session is created; requires a Start-Up or Enterprise plan and defaults to us-east")
3174
3249
browsersCreateCmd.Flags().StringSlice("private-host", nil, "Destinations the browser reaches directly through its own network instead of Kernel-managed egress, for private hosts on a VPN or tunnel the session joins (repeat or comma-separated, max 32). Accepts hostname patterns ('*.example.ts.net'), IPs ('10.1.30.63', '[fd00::1]'), and private CIDRs ('100.64.0.0/10'). Replaces the default private ranges (RFC1918, 100.64.0.0/10, fc00::/7); omit to keep them. Fixed once the session is created")
3250
+
browsersCreateCmd.Flags().StringArray("proxy-route", nil, "Route HOST[,HOST...]=PROXY through a proxy (repeatable, max 10 routes and 50 hosts per route). PROXY is an ID by default; use id:ID or name:NAME explicitly. Exact hosts beat wildcards (longer suffixes win); *.example.com excludes example.com. Unmatched hosts use --proxy-* or default egress; start_url uses the top-level proxy. Create-only")
3175
3251
browsersCreateCmd.Flags().String("start-url", "", "Initial page to open on launch")
3176
3252
browsersCreateCmd.Flags().StringSlice("extension", []string{}, "Extension IDs or names to load (repeatable; may be passed multiple times or comma-separated)")
constwebMCPToolsFixture=`{"tools":[{"name":"search","tool_ref":"opaque/ref+==","description":"Search the page","input_schema":{"type":"object"},"annotations":{"read_only":true,"autosubmit":false,"consequential":false,"untrusted_content":true},"source":{"window_id":1,"tab_id":42,"page_url":"https://example.com","page_title":"Example","frame":null}}],"future_field":true}`
39
+
constwebMCPToolsFixture=`{"tools":[{"tool":{"name":"search","description":"Search the page","inputSchema":{"type":"object"},"annotations":{"readOnlyHint":true,"autosubmit":false}},"tool_ref":"opaque/ref+==","source":{"window_id":1,"tab_id":42,"page_url":"https://example.com","page_title":"Example","frame":null}}],"future_field":true}`
0 commit comments