Repository navigation
Conversation
Snitchwatch #45 PR B lets the system bridge install blocklist rules. The 44-file OpenSnitch patch now accepts a lists.domains/lists.ips operand from the UI channel only via CHANGE_RULE, only for a z00-blocklist:<list> rule bound to /var/lib/snitchwatch/blocklists/<list>/<kind>, and at most 64 of them; AskRule replies and any other lists operand are refused. Those files are read through a confined reader (component-wise openat with O_NOFOLLOW, no FUSE, regular single-link files, 80 MiB and 1M entries per file) under a 640 MiB budget that admits the contract's 2M hosts plus one reload, with a soft 896 MiB Go memory limit unless GOMEMLIMIT is set. A list over budget keeps its last good version, retries with backoff and logs an error. Reloads are rate-limited per path, a replaced or reloaded unchanged rule keeps its loaded list, and stopped or displaced monitors never read. Upstream's list parser panicked on a bare-IP line; only a compromised bridge, something running as snitchwatch, or an edited or leftover file can write one (the honest bridge writes only '0.0.0.0 <host>' or IPv4 lines). Five security and code review rounds. The patch gate now sets SNITCHWATCH_REQUIRE_CONFINED_TESTS=1 so those tests fail instead of skipping when no non-FUSE temporary directory exists.
7 of 8 tasks
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #86. This adds daemon-side support for Snitchwatch blocklists (#45 PR B) to the OpenSnitch patch. The patch grows from 35 to 44 files, sha256
c1ac91ac….What the daemon accepts
lists.domains/lists.ipsoperand from the UI channel, but only:CHANGE_RULE;z00-blocklist:<list>rule whose data is exactly/var/lib/snitchwatch/blocklists/<list>/<kind>;CHANGE_RULE/DELETE_RULEonly (now confirmed as policy).How the files are read
openatwalk withO_NOFOLLOWthat refuses FUSE, FIFOs and anything other than a regular, single-link file.GOMEMLIMITis set._. It refuses empty or hyphen-edged labels. In ips lists it refuses multi-field lines, loopback and unspecified addresses.Threat model (wording agreed with Snitchwatch)
Upstream's list parser panicked on a malformed line such as a bare
127.0.0.1. Such a line can come only from:snitchwatch;The honest bridge writes only
0.0.0.0 <host>or canonical IPv4 lines, atomically (tmp + rename), with no comments. It does not resend unchanged rules.Review
Five security and five code review rounds (opus). Notable findings, all fixed:
Final state: security APPROVE (confirmed with re-run probes), code APPROVE. The executor's mutation tests killed every guard added in the last two rounds except two, both documented as redundant backstops or timing-dependent.
Known and accepted:
Reloaddoes not hand lists over (there is a comment; the bridge can't reach it).Test plan
just test-snitchwatch-daemon-patch: PASS. It applies the patch to upstream b404c4c, runs gofmt on the patched files and vet, and runsgo test -racefor root, netfilter, nftables,./rule(124 s) and./ui, plus the plain pass and the C harness. Confined tests are required (SNITCHWATCH_REQUIRE_CONFINED_TESTS=1).test-snitchwatch-image-build-daemon.pywith 44 patched files,test-snitchwatch-image-build.py,test-snitchwatch-system.py); shellcheck;just checkR10-VM-ACCEPTANCE-RESULT.json):ls -lamodes; 0 AVCs;