Repository navigation
Conversation
Snitchwatch c088132 (post-merge CI green) adds blocklist enforcement and the packaged bridge-fetch rule (#91), SQLite store hardening (#90), rule import/export (#89), pause answering waiting prompts once (#93) and a test fix (#95). Its stage.sh now installs one opensnitchd rule, /etc/opensnitchd/rules/000-snitchwatch-bridge-fetch.json: allow/always for /usr/bin/snitchwatch-bridge-cli as user snitchwatch to TCP 443, precedence false so denies and blocklists still win. The pins add that rule as a source file. The system manifest verifier now inventories it as a pinned immutable file: exactly that one /etc path is allowed, with the symlink walk, mode and hash checks, and errors that name it as reserved. Tests cover tamper, missing, mode, symlink and path traversal cases; smoke and boot-check assert it in the system profile. The Cargo package set is unchanged (two new dependency edges).
The r9 VM's first boot refused readiness with 'unsafe system manifest entry': the readiness helper still required every system manifest entry to live under /usr, but the manifest now inventories the packaged /etc/opensnitchd/rules/000-snitchwatch-bridge-fetch.json. Accept exactly that one /etc path, require it like the other installed assets, and refuse it if any directory on its path is a symlink (/etc is mutable). Tests cover another /etc entry, a missing fetch rule and a symlinked rules directory; removing any of the three guards fails them.
4 of 5 tasks
Owner
Author
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #87. Re-pins Snitchwatch for the r9 candidate. Together with #86 (Wants= on the bridge gRPC socket) and #87 (the 44-file blocklist daemon patch), this is the image the r9 VM gate tests.
Summary
b224adf→c088132(post-merge CI green). This covers 16 commits, including:stage.shnow installs one opensnitchd rule,/etc/opensnitchd/rules/000-snitchwatch-bridge-fetch.json. It is allow/always for/usr/bin/snitchwatch-bridge-clias usersnitchwatchto TCP 443, with precedence false, so denies and blocklists still win. If the account is missing when the daemon loads rules, the rule is skipped, never broadened./etcpath is allowed;Test plan
just check.a5e4992d…; smokeexit=0, including the new 755:root:root rules-dir assertion./etcmanifest entry ("unsafe system manifest entry"). It now accepts exactly that path and refuses a symlinked parent; 3 tests; review APPROVE.f5f22e8f…from e600c1a; independent review PASS (no package drift vs r9).output/snitchwatch-fresh-vm-r10.0N0Fnn/R10-VM-ACCEPTANCE-RESULT.json./var/log/opensnitchd.log; a fetch succeeds with no prompt on deny-default; read-only row.InterceptUnknown: falsethere is no prompt. With a VM-onlytrue, an<unknown>prompt appears; Deny shows "couldn't identify this program's file … only to this connection" and writes no rule.