Route Antigravity apps and AI dependencies through sensitive services - #21
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Antigravity 的请求仅靠动态 AI 域名集合不能完整覆盖:Hub 内置的 AI Code / Cloud Code、Google OAuth 和 Vertex AI 路径可能落入普通海外分流;部分已知 AI 依赖只命中宽泛关键词,其 DNS 又没有跟随敏感线路。
本次让 Mac 上 Antigravity 与独立 IDE 应用包内的公网连接进入现有「AI / Meta 服务」,默认 cstone/Reality → gcloud/CDN,并保留该业务组的手动选择。Stash 使用 4.2.0 起支持的应用包路径前缀;Mihomo 单独输出进程路径正则;iPhone 不生成进程规则。静态 LAN 仍优先 DIRECT。
将已知 AI 域名迁入共享清单,供单服务器和汇总生成器复用,汇总 DNS 从同一批精确/后缀规则推导。补充 Antigravity、地区 Vertex AI、Runway、Replicate、fal、v0 等锚点和 OpenAI 的具体监控租户;收窄 datadog/sentry/sift 全局关键词。Stash bootstrap default-nameserver 按官方 schema 输出 IP。保留原来的 8 个分组、敏感主备、手动入口、国内默认、Spotify 显式直连,以及 STUN/NTP 隐私策略。
验证:全部 97 项 Python 测试通过(包含 pinned Mihomo 1.19.30);域名/DNS正反例、应用主程序/后台/IDE路径、其他应用排除、Mac/iPhone隔离、规则优先级和客户端 schema 均有回归验证。Shell 语法检查与 git diff --check 通过。使用物理 en0 的隔离探测确认 10 个节点可连接,敏感默认 cstone,模拟主线失败切到 gcloud/CDN,手动 lax HTTPS 204 成功。
边界:应用规则不继承到外部浏览器、包外终端工具或远端进程;共享登录主机的非 AI 路径也走敏感线路。未知依赖及动态 MRS/geosite 更新差异仍需连接记录排查。完整来源与取舍见 docs/ai-routing-coverage.md。本机 Stash 4.2.0 满足应用规则要求,但既有 proxy-server-nameserver 官方要求 macOS 4.3 / iOS 3.6;未声称独立 DNS bootstrap 或真实 Stash 应用命中已验收。本 PR 不变更 VPS 服务端,合并后仅重新生成和分发 routing 客户端配置。