Skip to content

build(snitchwatch): re-pin snitchwatch to c088132 for the r9 candidate - #88

Closed
bearyjd wants to merge 3 commits into
feat/snitchwatch-daemon-blocklistsfrom
build/snitchwatch-r9-repin
Closed

bearyjd wants to merge 3 commits into
feat/snitchwatch-daemon-blocklistsfrom
build/snitchwatch-r9-repin

Conversation

@bearyjd

@bearyjd bearyjd commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Stacked on #87. Re-pins Snitchwatch for the r9 candidate. Together with #86 (Wants= on the bridge gRPC socket) and #87 (the 44-file blocklist daemon patch), this is the image the r9 VM gate tests.

Summary

Test plan

  • Python suites (image-build 25, daemon 23, system 61), shellcheck, just check.
  • Code review: APPROVE. The traversal-guard gap it found is now tested; 6 of 6 mutations caught.
  • r9 clean image build a5e4992d…; smoke exit=0, including the new 755:root:root rules-dir assertion.
  • Independent r9 image review: PASS.
  • r9 first boot found a bug, fixed in e600c1a: readiness refused the new /etc manifest entry ("unsafe system manifest entry"). It now accepts exactly that path and refuses a symlinked parent; 3 tests; review APPROVE.
  • r10 image f5f22e8f… from e600c1a; independent review PASS (no package drift vs r9).
  • r10 VM gate: PASS. Evidence: output/snitchwatch-fresh-vm-r10.0N0Fnn/R10-VM-ACCEPTANCE-RESULT.json.
    • Blocklists: subscribe, "Rule installed", a listed host is blocked, modes, 0 AVCs, no resend on bridge restart, unsubscribe.
    • Fetch rule: no compile error in /var/log/opensnitchd.log; a fetch succeeds with no prompt on deny-default; read-only row.
    • fix(snitchwatch): keep a rule in the daemon when deleting its file fails #93 pause: a waiting prompt is allowed once with the label; new connections pass during the pause; prompts return after resume.
    • Empty process path: with the shipped InterceptUnknown: false there is no prompt. With a VM-only true, an <unknown> prompt appears; Deny shows "couldn't identify this program's file … only to this connection" and writes no rule.
    • fix(snitchwatch): keep the firewall up when the bridge gRPC socket stops #86: stop/start of the gRPC socket keeps the firewall up and it reconnects.
    • Background-connection capture: for the Snitchwatch session.
    • Reboot loop: 10/10 clean.
  • CI green

Snitchwatch c088132 (post-merge CI green) adds blocklist enforcement and
the packaged bridge-fetch rule (#91), SQLite store hardening (#90), rule
import/export (#89), pause answering waiting prompts once (#93) and a test
fix (#95). Its stage.sh now installs one opensnitchd rule,
/etc/opensnitchd/rules/000-snitchwatch-bridge-fetch.json: allow/always for
/usr/bin/snitchwatch-bridge-cli as user snitchwatch to TCP 443, precedence
false so denies and blocklists still win.

The pins add that rule as a source file. The system manifest verifier now
inventories it as a pinned immutable file: exactly that one /etc path is
allowed, with the symlink walk, mode and hash checks, and errors that name
it as reserved. Tests cover tamper, missing, mode, symlink and path
traversal cases; smoke and boot-check assert it in the system profile.
The Cargo package set is unchanged (two new dependency edges).
The r9 VM's first boot refused readiness with 'unsafe system manifest
entry': the readiness helper still required every system manifest entry
to live under /usr, but the manifest now inventories the packaged
/etc/opensnitchd/rules/000-snitchwatch-bridge-fetch.json. Accept exactly
that one /etc path, require it like the other installed assets, and
refuse it if any directory on its path is a symlink (/etc is mutable).
Tests cover another /etc entry, a missing fetch rule and a symlinked
rules directory; removing any of the three guards fails them.
@bearyjd

bearyjd commented Oct 9, 2026

Copy link
Copy Markdown
Owner Author

Included via #92 (merge commit af32644): this PR's commits are in main as part of the stacked merge; the r12 image was VM-accepted at 21adea3.

@bearyjd bearyjd closed this Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant