TapTap
fc560246c1
fix(daemon): close ACL fail-opens (v4-mapped peers, invalid patterns) and cap auth delay
2026-09-13 02:51:07 +02:00
TapTap
dff6609976
feat(daemon): host ACL, configurable max connections, peer audit, auth-failure delay
2026-09-13 02:36:15 +02:00
TapTap
a90e234eb3
harden: overflow guards, auth-user validation, TLS1.3 policy, build hardening
2026-09-13 00:59:21 +02:00
TapTap
e3840c8326
fix(p8-security): enforce daemon ownership policy, gate fake-super replay, drop implicit numeric-ids, make copy-as failures per-entry
...
A1: daemon refuses every client-chosen ownership/super-user request
(--numeric-ids/--chown/--usermap/--groupmap/--fake-super/--copy-as/--super)
unless the selected module opts in with 'client owner = yes'.
A2: fake-super owner replay requires an explicit ownership identity policy.
A3: --super no longer implies --numeric-ids (ownership stays opt-in).
A5: a failed --copy-as chown marks the entry failed instead of reporting
success with the wrong owner.
2026-09-12 14:00:55 +02:00
TapTap
7c55409a6b
fix(d5-daemon-core): cppcheck const-correctness, wire module length cap, daemonize chdir/umask, daemon confinement tests
...
- daemon_conf.c/server.c/test_daemon_conf.c: const-qualify parse/loop pointers;
scope user_path static inside its block (clears the 9-wave-A cppcheck findings)
- config.c receive_daemon_module: reject invalid/over-long wire module names
(> DAEMON_MAX_MODULE_NAME) with a clean STATUS_ERROR; client side already
enforced via daemon_module_name_valid in config_parse_daemon_dest
- server.c daemonize: chdir(/) and umask(0) so module paths resolve from /
and config-requested file modes are honored; PROTOCOL_VERSION stays 2.15.0
- test_daemon.py: confinement (read-only/unknown no-write anywhere), module-less
and dot-dot destination refusal, real daemon_detach double-fork path
2026-09-09 18:30:52 +02:00
TapTap
b3d7d64347
feat(d5-daemon-core): daemon lifecycle, module config, ::dest, PROTOCOL 2.15.0
2026-09-09 17:48:07 +02:00