| Filename | Latest commit message | Latest commit date |
|---|---|---|
argus caught a false negative in the shape rule, and it sits exactly in the property the change is sold on -- "a new secret type is caught by default". `split_whitespace()` yields `"<token>,"` for a token with punctuation glued to it, and the comma fails the alphabet check for the whole word, so the line passes unredacted with the credential in it. `[<token>]`, `"<token>"`, `(<token>)` and a no-whitespace-at-all blob all defeat it the same way. Whitespace is not what delimits a secret; the alphabet is. So scan the line for a maximal run of >=32 alphabet characters and let punctuation reset the counter. Simpler than the version it replaces, and it closes the gap by construction rather than by enumerating the delimiters someone might glue on next. The existing tests all passed against the broken version because I wrote them from the same mental model that produced the bug -- every fixture had a space before the token. The new test carries the six shapes that used to slip through. |
||
| .. | ||
| src | ||
| Cargo.toml | ||
| README.md | ||
hive-priv
The minimal root privileged-helper for hive-c0re. It runs as root and
exposes a narrow unix socket at /run/hive/priv.sock that accepts PrivRequest
JSON lines and performs only the handful of operations that genuinely require
root — bind-mount edits, nsenter into a container, btrfs subvolume ops. All
coordination logic (broker, HTTP, scheduling) stays in the unprivileged
hive-c0re process, which delegates here.
Why it exists
Privsep. hive-c0re runs as the unprivileged hive-core user so a bug or a
prompt-injection in the large daemon can't directly wield root. The few root
operations it needs are funnelled through this small, auditable helper instead.
See docs/boundary.md and docs/security.md for the privilege boundary.
Security model
- Strict allowlist. Every request is validated against a container-name
allowlist before any filesystem or process operation — only names matching the
hive convention (
h-*, the manager container, known sibling service containers) are accepted. - No pass-through. Every
PrivRequestvariant maps to a single known operation; there is no arbitrary-command escape hatch. - Socket-activated, always. systemd binds
/run/hive/priv.sock(SocketGroup=hive-core,0660) and passes the listener as fd 3 (LISTEN_FDS); the helper requires this and has no self-bind fallback, so dev and prod take the identical path and the group grant always holds.
The wire contract (PrivRequest / response types) lives in the separate
hive-priv-sock crate so this root binary depends on just the protocol shapes,
not the whole daemon-shared crate.