Skip to content

v2.1.0-lts (LTS)

Choose a tag to compare

@Geekstrange Geekstrange released this 29 Aug 05:54
· 3 commits to lts since this release
v2.1.0-lts
0f0b5ad

📌 LTS (Long Term Support) branch maintenance release
This is a long-term support update for the legacy architecture (2.x series), containing security hardening and stability fixes. No user-facing features are added.


🔒 Security Fixes

  • History file hardening: Use a 64‑bit random suffix (/dev/urandom) and open with O_NOFOLLOW + 0600 permissions for the /tmp history file to prevent symlink truncation attacks. On open failure, fall back to in‑memory‑only history without aborting shell startup.
  • Audit log permission tightening: Set audit log file permissions to 0600 (enforced at creation and corrected for pre‑existing files) so command lines containing sensitive data are not world‑readable.
  • Password hash upgrade: Upgrade password hashes from unsalted plain SHA‑256 to a salt$iterations$digest format (16‑byte salt, iterated SHA‑256, 100,000 iterations by default, capped at 10M) with constant‑time comparison. Legacy hashes still verify but warn to regenerate. A hidden dpshell --hash-password flag is added to generate new‑format hashes.
  • Plugin timeout enforcement: Poll with try_wait and, on timeout, send SIGKILL to the plugin's process group, reap it, and join the stdout reader thread, ensuring no root‑privileged children or threads are leaked. Plugins now spawn in their own process group so the entire tree can be terminated.
  • Plugin command injection prevention: Sanitise replacement commands by stripping \n, \r, and \0 to prevent newline injection across command boundaries.
  • Unknown [core] mode rejection: Reject an unknown [core] mode at startup (exit 2) instead of silently degrading per command.
  • Audit coverage: cd commands are now logged to close the audit gap.

🛠 Stability Fixes

  • Enable rustyline's buffer-redux feature to fix a permanent hang where bytes beyond the first line of a multi‑line read were dropped, leaving the shell blocked at the next readline call after an external command.
  • Startup animation no longer panics when stdout is closed or piped.

🐛 Bug Fixes

  • exit 0 / exit N now actually exit the shell (the argument was previously swallowed).
  • cd ~ / cd ~/... now expand $HOME correctly (previously failed silently).

📝 Other

  • rules.rs: Fix the Replace action doc examples (\s* only consumes whitespace, flags remain in the suffix; behaviour unchanged).
  • config.rs: Document the new password_hash format.

✅ Testing

  • cargo build --release passes.
  • PTY smoke tests cover exit authentication (new and legacy hash formats), plugin timeout group kill, history file permissions and cleanup, unknown‑mode startup error, and path‑protection regression.

📦 Upgrade Notes

LTS users are strongly encouraged to upgrade to this release, especially if using password authentication, the plugin system, or history logging. This update includes multiple security hardening improvements.