diff --git a/CHANGES b/CHANGES index a2b76a55b3..29d7766c44 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,13 @@ +7.0.0-dev.224 | 2024-05-07 10:26:40 -0700 + + * Clarify membership in the Site::private_address_space prefix list. [skip ci] (Christian Kreibich, Corelight) + + IANA's IPv6 special-purpose address registry now has members that technically + meet the definition of not being globally reachable, but don't imply operating + locally. An example: https://datatracker.ietf.org/doc/draft-ietf-6man-sids/06/ + + This change just explains that distinction. + 7.0.0-dev.222 | 2024-05-07 10:25:55 -0700 * Avoid segfault when generating Zeekygen docs on Zeek-internal identifiers. (Christian Kreibich, Corelight) diff --git a/VERSION b/VERSION index 8381135257..0e4d1deadb 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -7.0.0-dev.222 +7.0.0-dev.224 diff --git a/scripts/base/utils/site.zeek b/scripts/base/utils/site.zeek index e3e309da66..ec9fd69e79 100644 --- a/scripts/base/utils/site.zeek +++ b/scripts/base/utils/site.zeek @@ -7,7 +7,11 @@ module Site; export { ## A list of subnets that are considered private address space. ## - ## By default, it has address blocks defined by IANA as not being routable over the Internet. + ## By default, it has address blocks defined by IANA as not being + ## routable over the Internet. Some address blocks are reserved for + ## purposes inconsistent with the address architecture (such as + ## 5f00::/16), making them neither clearly private nor routable. We do + ## not include such blocks in this list. ## ## See the `IPv4 Special-Purpose Address Registry `_ ## and the `IPv6 Special-Purpose Address Registry `_