Skip to content

Releases: OWLZOPS/owlzops-mapper

v0.5.39

Choose a tag to compare

@github-actions github-actions released this 01 Oct 14:08
2194794

[0.5.39] - 2026-10-01

Bug Fixes

  • runner: Isolate mount-namespace scanner, drop pid prefilter
  • sudoers: Detect Defaults !authenticate as a passwordless grant
  • sudo: Self_sudo_target must see the whole Cmnd_Spec_List
  • proc_net: ENOENT on a vanished pid is not a denial (R33-05)
  • ssh: Do not mask key-load failures as remote auth failures (R33-07)
  • mount_namespace: Prefer the systemd cgroup on hybrid/v1 hosts (R33-10)
  • scoring: Bump SCORING_VERSION to 15 for R33-03/R33-04 (R33-12)
  • host: Wall-clock timestamps for dmesg_errors (R33-QW-2 follow-up)
  • systemd: Restore systemctl for active timers (R33-QW-5 follow-up)
  • access: Use safe_io capped read for /etc/group
  • access: Empty bypassing groups are inventoried, not weighted (R33-QW-7)
  • scoring: Passwordless-root class is weighted once (R34-01)
  • compare: Track every root-equivalent group, not just bypassing ones (R34-02)
  • access: Disclose unreadable or truncated /etc/group (R34-03)
  • sec-022: Correlate per netns of interpreter (R35-01)
  • sec-023: Byte-level env split; ENOENT maps is a race (R35-04, R35-11)
  • sec-014: Non-UTF-8 secret must not hide key/flag (R35-04)
  • sudoers: Sudoers(5) comment rules; #uid is an entry (R35-03
  • utils: Trusted-exec gate; forget PGID before reap (R35-05, R35-09)
  • runtime: Split size query off security inventory (R35-02)
  • net: Drop tuple filter; host = pid 1 ns (R35-06)
  • ebpf: ENOENT silent, other errors disclosed (R35-08)
  • ui: Sanitize remote report fields (R35-07)
  • ssh: Derive host ceiling from stage budgets (R35-10)
  • main: Host ceiling + no-panic signal task; cli range validation (R35-10, R35-12)
  • ui: Cell() is the only table-cell constructor (R35-14)
  • utils: Signal children while holding the registry lock (R35-15)
  • sec-022: Disclose coverage only when the gap is real (R35-16)
  • ui: Preserve our own newlines in multi-line cells

Build System

  • deps: Bump taiki-e/install-action from 2.87.11 to 2.87.15 (#297)
  • deps: Bump clap from 4.6.6 to 4.6.7 (#298)
  • deps: Bump rust_xlsxwriter from 0.99.0 to 0.99.1 (#299)
  • deps: Bump taiki-e/install-action from 2.87.15 to 2.87.20 (#309)
  • deps: Bump rand from 0.10.2 to 0.10.3 (#311)
  • deps: Bump io-uring from 0.7.14 to 0.7.15 (#312)

CI/CD

  • Gate bare Cell::new in ui.rs (R35-14)

Documentation

  • fields: Exe_path is never null in mount_namespace_anomalies
  • models: ContainerNetnsMapping.pid is not serialized (R33-13)
  • readme: SEC-060 and SEC-061 in findings table
  • fields: CpuVulnerability and RootEquivalentGroup schemas
  • r33-qw: Align SEC-061 weight and passwordless-root class (R34-01)
  • fields: R35 updates for netns, runtime sizes, dlp, sudoers, ebpf, reverse-shell

Features

  • access: Emit SudoersEntry for Defaults !authenticate
  • host: NTP truth via clock_adjtime(2) (R33-QW-1)
  • host: OOM count from /proc/vmstat, dmesg via /dev/kmsg (R33-QW-2)
  • host: GPU inventory from sysfs PCI class (R33-QW-3)
  • host: Os_install_date via statx birth time (R33-QW-4)
  • ui: Show GPU inventory in System Overview (R33-QW-3)
  • ui: Show OS install date in System Overview (R33-QW-4)
  • systemd: Read active-state from /run/systemd/units (R33-QW-5)
  • security: CPU mitigation state via sysfs (R33-QW-6)
  • access: Root-equivalent groups outside sudoers policy (R33-QW-7)
  • ui: Dashboard sections for SEC-060 and SEC-061
  • security: Sshd login-path directives, replaceable targets (R33-QW-8)
  • security: Authorized_keys options and environment= gate (R33-QW-9)
  • security: Immutable/append-only trust anchors (R33-QW-10)

Miscellaneous

  • sudoers: Drop temporary allow(dead_code) on the new predicates
  • scoring: SCORING_VERSION 15 → 16 (R33-QW batch)

Refactoring

  • mount_namespace: Share the /proc miss classifier
  • main: Extract missing_hosts helper (R33-11)
  • env: One byte-level KEY=VALUE splitter (R35-04 verification)
  • sec-023: Share env record splitter, test R35-11 race (R35-04/R35-11 verification)
  • sec-014: Share env record splitter, single mysql predicate (R35-04 verification)

Testing

  • net: Behavioural check for R35-06 tuple filter (R35-06 verification)
  • utils: Exercise the trust-gate refusal branch without root (R35-05 verification)

v0.5.38

Choose a tag to compare

@github-actions github-actions released this 15 Sep 12:49
9846264

[0.5.38] - 2026-09-15

Bug Fixes

  • runtime: Treat deleted-after-upgrade mappings as advisory, not IOC (R29-01)
  • proc_net: Avoid double /proc/net parse and surface netns read failures
  • netns: R29-03/04/05/06 — dead PID, determinism, sentinel, shared netns
  • cli: Wire signed report parsing and capped I/O for sign/verify
  • install: Use curl -f so an HTTP error fails loudly instead of piping HTML into sh and gpg
  • readme: Use curl -f so an HTTP error fails loudly instead of piping HTML to sh
  • signing: Enforce namespace, improve verify output, reject unsigned reports
  • signing: Prompt for encrypted private key passphrase (R30-04)
  • signing: Compare key data instead of full PublicKey in verify
  • signing: Expand verify output, add embedded key parse test
  • signing: Harden passphrase handling and key load diagnostics
  • compare: Add mount namespace anomaly drift detection
  • mount-namespace: Filter systemd services and system binaries
  • mount-namespace: Skip kernel worker threads in scan
  • mount-namespace: Label systemd/system paths instead of dropping, cap coverage, key diff by exe
  • ui: Group mount-namespace rows by namespace+exe, refine systemd filter
  • ui: Recognize container scopes and /bin|/sbin prefix
  • library-injection: Resolve paths through /proc//root
  • deep: Use lazy then in managed-JIT attribution

Build System

  • deps: Bump taiki-e/install-action from 2.87.0 to 2.87.5 (#268)
  • deps: Bump russh from 0.63.1 to 0.63.2 (#271)
  • deps: Bump base64 from 0.22.1 to 0.23.1 (#272)
  • deps: Bump softprops/action-gh-release from 3.0.2 to 3.0.3
  • deps: Bump taiki-e/install-action from 2.87.5 to 2.87.11 (#282)
  • deps: Bump russh from 0.63.2 to 0.63.3 (#284)
  • deps: Bump uuid from 1.26.0 to 1.26.1 (#283)

CI/CD

  • Guard overflow-checks in [profile.release] (R32-01)

Documentation

  • security: Document report signature verification chain
  • ui: Fix comment describing mount-namespace grouping key
  • library_injection: Ns_root is set for all PIDs, not only containers

Features

  • network: Surface listeners hidden in foreign netns
  • network: Inventory foreign netns listeners (R29-02)
  • ui: Render foreign netns listeners in terminal report
  • signing: Add Ed25519 report signing and verification
  • cli: Add sign/verify subcommands for report signatures
  • signing: Allow verify without --key via embedded public keys
  • security: Add mount namespace anomaly detection
  • ui: Render mount namespace anomalies
  • mount-namespace: Attribute anomalies to containers by mnt_ns

Miscellaneous

  • Ignore private signing keys, keep public keys in assets

Performance Improvements

  • proc_net: Aggregate foreign-netns listeners per namespace

Refactoring

  • utils: Share is_system_managed_path with mount_namespace

v0.5.37

Choose a tag to compare

@github-actions github-actions released this 02 Sep 18:38
v0.5.37
1e4efcf

[0.5.37] - 2026-09-02

Bug Fixes

  • dlp: Single SecretLeak construction and source-aware self attribution
  • ssh_engine: Check_server_key signature for russh 0.63
  • Handle truncation of /proc/mounts in ghost_pid (R27-47)
  • Handle truncation in kprobe_events and /proc//maps
  • Handle procfs truncation as unobservable in ghost_pid, preload
  • Disclose unreadable pid_max in ghost_pid sync fallback (R27-50)
  • Make ghost_pid helpers use proc_root consistently (R27-51)
  • Make socket_owning_pids use proc_root (R27-52)
  • ghost-pid: R27-55 — io_uring path respects proc_root and discloses pid_max fallback
  • verdict-cache: R27-56 — treat backward clock as stale, not fresh
  • verdict-cache: R27-56 — treat backward clock as stale, not fresh
  • capabilities: R27-59 — partial degradation, keep malware sweep on truncated status
  • ghost-pid: R27-54 — correct starttime position in make_proc fixture
  • capabilities: R27-60 — report suspicious-store overflow; align identity parser
  • dlp: Exclude non-secret XDG_ACTIVATION_TOKEN from SEC-014
  • audit: R27-61, R27-62, R27-63 — deep budget disclosure, blocked-vs-not-attempted, orchestrator coverage leak
  • audit: R27-64, R27-65 — disclose unread deep regions and unscanned PIDs
  • audit: R27-66 — restore environ scan after MAPS cap, fix counter
  • sudoers: R27-67 — deep alias chain must be UNKNOWN, not negative
  • mounts: R27-68 — disclose SEC-021 finding cap, stop silent truncation
  • audit: R27-69, R27-70 — disclose eBPF pin truncation and zypper patch cap
  • ssh_engine: Route remote coverage facts to RemoteCoverage::notes (R28-01)
  • models: Apply container serde(default) to inventory structs and drop skip_serializing_if (R28-04/R28-05)
  • compare: Diff exe_path for ports and container security fields (R28-02/R28-03)
  • ssh_engine, known_hosts: Route remote coverage facts to RemoteCoverage::notes (R28-01)
  • ssh_engine,ci: Record main exec truncation in coverage notes and broaden R28-05 gate (R28-12/R28-13)
  • ssh_engine: Return ReportTruncated for truncated remote stdout (R28-15)
  • runtime: Keep uninspectable containers in inventory (R28-18)
  • runtime: Record coverage when container inspect fails (R28-18)
  • compare: Inventory disappearance is Changed, not Improved (R28-21)

Build System

  • deps: Bump russh from 0.62.6 to 0.63.0
  • deps: Bump io-uring from 0.7.13 to 0.7.14 (#200)
  • deps: Bump uuid from 1.24.1 to 1.26.0 (#252)
  • deps: Bump rust_xlsxwriter from 0.97.1 to 0.99.0 (#253)
  • deps: Bump taiki-e/install-action from 2.86.5 to 2.87.0 (#255)
  • deps: Bump russh from 0.63.0 to 0.63.1 (#254)

CI/CD

  • Avoid cross-OS cargo cache poisoning
  • Add gates for coverage sink, serde defaults, and JSONL key stability (R28-01/R28-04/R28-05)
  • Pin MIN_STRUCTS to actual count (R28-16)

Documentation

  • scoring: Mark SCORING_VERSION entries as v0.5.36
  • Added a new URL for install.sh
  • fields: Document image_id and runtime_bounding_caps (R28-14)
  • fields: Clarify image_id semantics

Features

  • containers: Diff image digest, not just tag (M-2)

Performance Improvements

  • proc_net: Cache comm reads per PID; fix(utils): join reader threads on timeout (R28-06/R28-07)
  • main: Bound fleet admission to max_concurrent live tasks (R28-08)

Refactoring

  • scanners: Deduplicate exec-cluster logic between deep.rs and library_injection.rs

Testing

  • Exercise real socket_owning_pids and update comments (R27-53)
  • Protect R28 guards with positive self-tests and determinism checks (R28-09/R28-10/R28-11)
  • scoring: Use Default for ContainerInfo fixtures (R28-17)

v0.5.36

Choose a tag to compare

@github-actions github-actions released this 27 Aug 20:43
41fba0f

[0.5.36] - 2026-08-27

Bug Fixes

  • security: Apply R27-15 and R27-16
  • security: Apply R27-13, R27-14, R27-15, R27-16
  • build: Gate take_entry_value to linux/test to avoid dead_code on macOS
  • build: Gate Zeroize import behind linux/test cfg
  • security: Correct SEC-014 attribution and bump scoring version
  • security: Redact SecretString Debug output (R27-17)
  • security: Do not close borrowed fd in read_sudo_pass_from_fd (R27-18)
  • security: Remove Clone from SecretString (R27-19)
  • security: Attribute self-inflicted /proc denial in DLP (R27-22)
  • security: Align --sudo-pass-fd docs and behavior (R27-23)
  • security: Correct EACCES attribution for own /proc/self/cmdline (R27-27)
  • ci: Make doctrine gate portable and executable (R27-28)
  • dlp: Correct process age handling and scoring tiers
  • dlp: Split short-lived secrets into SEC-059
  • dlp: Centralize process age arithmetic and harden ghost_pid
  • scoring: Align SCORING_VERSION with documented entries
  • deep: Consolidate process-time arithmetic into proc_time
  • proc_time: Raise /proc/stat cap and surface btime failures
  • dlp: Memoize process age and separate path buffers

Build System

  • deps: Bump taiki-e/install-action from 2.86.4 to 2.86.5 (#219)
  • deps: Bump uuid from 1.24.0 to 1.24.1 (#217)

CI/CD

  • Extend process-time gate to deep.rs

Documentation

  • readme: Add owlzops-mapper logo
  • security: Document sudo password handling for remote scans
  • security: Declare SecretString handling commitments
  • security: Fix and scope secret handling commitments
  • security: Correct job-control kill and clarify SecretString guarantee

Features

  • security: Harden process dumpability at startup (QW1)
  • ci: Add env var manipulation gate (QW2)
  • security: Add SecretString with mlock/madvise protection
  • security: Add --sudo-pass-fd and deprecate OWLZOPS_SUDO_PASS
  • ci: Add doctrine gates for env mutation and unsafe fd handling (R27-26)
  • dlp: Weight secret leaks by process lifetime

Miscellaneous

  • Polish SecretString and startup comments
  • Polish startup warnings and document secret invariants

Refactoring

  • security: Unify capped secret reader for stdin and fd (R27-21)
  • Centralize EACCES attribution and env password warning

v0.5.35

Choose a tag to compare

@github-actions github-actions released this 23 Aug 20:36
0b98ff1

[0.5.35] - 2026-08-23

Bug Fixes

  • scanners: Use capped-regular for /etc/passwd in access alignment (R26-17)
  • sudoers: Single walk, capped passwd and scanner-resolved
  • scoring: Key SEC-005 on scanner-resolved ALL marker (R26-19)
  • scoring: Expose sudoers module internally for marker access
  • models: Move sudo markers to always-compiled module
  • ghost-pid: Gate io_uring imports to glibc Linux
  • scoring: Bump scoring version for sudoers and backup weighting changes (R26-22)
  • sudoers: Parse multiple Cmnd_Alias specs on one line (R26-23)
  • host: Derive last_restic_snapshot from local cache mtime (R26-25)
  • sudoers: Parse transitive sudo tags for NOPASSWD: ALL (R26-27)
  • compare: Detect sudo NOPASSWD grant drift (R26-28)
  • runner: Use capped-regular for /etc/passwd and add doctrine CI guard (R26-29)
  • compare: Flag cross-version collection semantics change (R26-30)
  • scanners: Use read_file_capped_regular for cron and DNS host files (R26-37)
  • provenance: Use read_file_capped_regular for dpkg/apk databases (R26-38)
  • safe_io: Allow dead_code for streaming opener on remote-only builds
  • main: Import Read for streaming JSONL parser (R26-40)
  • safe-io: Remove /dev from procfs doctrine; add literal path check (R26-43, R26-44)
  • ci: Close R26-48 (multi-line literal guard and PCRE2 probe)
  • ci: Install ripgrep, add -U and PCRE2 probe
  • release: Harden release workflow
  • doc: Regenerate changelog
  • security: Close R27-08, R27-09, R27-04
  • output: Sanitize XLSX filename against hostname traversal (R27-11)
  • release: Clear OWLZOPS_SUDO_PASS from environ (R27-12)
  • release: Avoid duplicate .asc upload and harden signature/changelog checks

Build System

  • deps: Bump taiki-e/install-action from 2.85.10 to 2.86.4 (#201)

CI/CD

  • Catch read_file_capped on host-controlled paths (R26-31)
  • Enable raw-open guard and convert operator file readers (R26-40)
  • Enable raw-open guard and annotate remaining operator/procfs exceptions
  • release: Fix SBOM filename and validate artifact set before signing

Features

  • safe_io: Add streaming regular-open primitive (R26-39)

Refactoring

  • safe_io: Rename procfs readers and make capped-I/O guard exact (R26-31/R26-33/R26-36)
  • scanners: Fix misleading comment and dead branch (R26-45, R26-46)
  • scanners: Fix misleading comment and dead branch

Testing

  • sudoers: Parameterize walk and add cross-file alias coverage (R26-24)
  • compare: Add binary-version drift regression test

v0.5.34

Choose a tag to compare

@github-actions github-actions released this 20 Aug 19:40
062f5fa

Bug Fixes

  • SEC-058 config slot test – change parent mode after file creation
  • SEC-058 config slot test – change parent mode after file creation
  • cli: Move default remote_path out of /tmp (R24-41)
  • deps: Use russh with ring backend for glibc 2.35 compat
  • deps: Use russh with ring backend for glibc 2.35 compat
  • remote: Harden --remote-path handling (R24-41/R24-96)
  • output: Handle empty report list in output_multi
  • deps: Enable rsa feature for russh ring backend
  • ssh: Restore rsa auth and clean up sudo error output
  • utils: Harden sanitize_for_log against ANSI and control chars
  • ssh: Bound probes, classify sudo failures, keep staging path across timeout
  • ssh: Harden remote probes and sudo error handling (R25 batch 1)
  • remote: Complete R25 batch — staging ownership, sudo classification, coverage propagation
  • ssh: Bound sudo NOPASSWD probe and handle wedged PAM
  • ssh: Surface remote upload stderr instead of hanging on permission errors
  • ssh: Fail fast on non-writable upload target
  • cli: Refuse --keep-binary without explicit --remote-path
  • remote: Use real write probe and keep static tmp blocklist
  • security: Treat host key algorithm change as a key change, not TOFU
  • ftrace: Classify hooks by callback symbol, not substring match
  • reverse-shell: Require stdio fd before raising SEC-022
  • scoring: Ignore findings from failed scanners
  • provenance: Treat rpm exit code 1 as not-owned, not a failure
  • ssh_engine: Harden upload teardown and write-probe validation
  • ssh_engine: Use unique upload part and noclobber to avoid symlink race
  • scoring: Failed scanners produce incomplete verdict
  • ssh_engine: Generate unique upload part for owned staging dir
  • ftrace: Module-tagged callbacks are never kernel builtin sources
  • provenance: Rpm errors are not negative ownership answers
  • cli: Usage errors exit 64 outside verdict band
  • cli: Exit 4 when scanner failed and verdict incomplete
  • reverse_shell: Deterministic candidate selection
  • remote: Persist remote_privileged into reports and drift
  • ssh_engine: Bound sudo preflight by SUDO_PROBE_BUDGET
  • ssh: Pin host key algorithms to known_hosts
  • scoring: Replace manual scanner ID maps with Finding source
  • ssh_engine: Remove write probe to avoid FIM noise
  • utils: Strip unicode bidi and format controls from logs
  • ui: Avoid EPIPE panic when stderr is closed early
  • ssh_engine: Harden upload loop and sudo auth
  • scoring: Let incomplete outrank critical and close scanner mapping seam
  • cli: Restore degraded exit for scan warnings
  • ci: Address R25-53 cleanup items
  • known_hosts: Fail-closed trust store and per-host filtering
  • main: Aggregate fleet exit by verdict rank, not numeric max
  • main: Allow dead_code for compute_exit_code without local-scan
  • main: Return EX_SOFTWARE on panic, not interrupt code
  • known_hosts: Normalize RSA key type before comparison
  • ssh_engine: Bound upload tail after EOF
  • scoring: Move scanner-name warning out of evaluate
  • runner: Persist remote privilege fact in snapshots
  • compare: Remove unreachable panics from diff paths
  • ui: Strip Unicode TAG block in terminal sanitizer
  • main: Suspend progress bars before warning from scan tasks
  • Correct fleet exit-code polarity and reject truncated trust store (R25-62, R25-63)
  • Log channel message shape instead of remote payload (R25-68)
  • Classify remote privilege coverage loss as degraded (R25-69)
  • Make remediation ref check PR-aware and deletion-friendly (R25-70)
  • Make all structured logs progress-bar aware (R25-71)
  • Fleet aggregation prefers Critical over Incomplete (R25-72)
  • Strict UTF-8 and line numbers for known_hosts trust store (R25-72)
  • main: Restore is_running_as_root and honour --fail-on-incomplete on output errors
  • known_hosts: Fail closed on unsupported trust markers; ignore revoked keys
  • main: Remove duplicate host-failure output
  • compare: Derive privileged fact from remote_privileged and is_root_execution
  • safe_io: Report trust-store truncation before UTF-8 error
  • Close remaining R25-81 cleanup items
  • exit-codes: Output failure must not erase the security verdict
  • main: Allow dead code for local helpers on non-local-scan targets
  • models: Host getuid() outranks orchestrator sudo intent
  • exit-codes: Align docs, tests and drift fields after two-axis model
  • main: Log fleet coverage facts before returning exit code
  • main: Separate verdict and coverage explanations
  • utils: Kill child group before reaping to avoid PID recycling race
  • known_hosts: Support wildcard host patterns and defer marker check
  • scoring: Extract evaluate side effects, call once per report
  • scoring: Allow warn_evaluate_side_effects on non-local-scan targets
  • main: Report missing fleet hosts by input address
  • models: Detect privilege claim disagreement in both directions
  • main: Never let SIGINT hide a recorded compromise
  • main: Aggregate fleet outcome outside writer task
  • ghost-pid: Record sync fallback coverage once per invocation
  • Close R25-100 and R25-73
  • Close R25-101
  • utils: Close PGID reuse race in run_with_timeout_inner via wait_group_safe (R26-01)
  • compare: Refuse multi-host diff when JSONL lines are unreadable (R26-05)
  • fleet: Count lost channel sends in records_lost (R26-09
  • Fix(scanners): use read_file_capped_regular for host-controlled paths (R26-02)
  • Prevent FIFO/device hangs on /etc/passwd, /etc/ssh/sshd_config, /etc/sudoers and /var/run/reboot-required.pkgs. Non-regular files are now recorded as tampering instead of blocking open(2)
  • deep: Replace chunks_exact(8) with as_chunks::<8>() for clippy
  • host: Detect backup posture from local evidence, drop which/restic/borg probes (R26-03/R26-04)
  • xlsx: Neutralize bidi/zero-width in document sanitizer (R26-07)
  • sudoers: Resolve Cmnd_Alias indirection in NOPASSWD: ALL detection (R26-06)
  • models: Add container-level serde(default) to SecurityInfo/PortInfo/NetworkInfo (R26-11)
  • sudoers: Avoid double space when joining continuations (R26-08)

Build System

  • deps: Bump rust_xlsxwriter from 0.97.0 to 0.97.1 (#190)
  • deps: Bump taiki-e/install-action from 2.85.5 to 2.85.10 (#194)
  • deps: Bump clap from 4.6.5 to 4.6.6 (#192)
  • deps: Bump data-encoding from 2.11.0 to 2.11.1 (#191)
  • deps: Bump dtolnay/rust-toolchain
  • deps: Bump Swatinem/rust-cache from 2.9.1 to 2.9.2 (#189)
  • deps: Bump thiserror from 2.0.19 to 2.0.20 (#198)
  • deps: Bump russh from 0.62.5 to 0.62.6 (#199)

CI/CD

  • Fail when commit message references a remediation ID not in diff
  • Check remediation refs against diff, not full file
  • Check each commit against its own diff
  • Check only latest commit for remediation IDs
  • commit-refs: Restore per-commit PR validation

Documentation

  • Update CHANGELOG for v0.5.33
  • Update exit codes and remote flags after R25 remediation
  • Add remote_privileged, failed_scanners and self_integrity to FIELDS
  • Document fleet verdict ordering (R25-72)
  • known_hosts: Document canonical_key_type scope
  • Document two-axis exit-code model and --fail-on-incomplete
  • models: Add R26-11 reference for CI

Features

  • SEC-058 detect writable PAM config slots (IoC)
  • ssh: Include sudo stderr in error message for incorrect password
  • remote: Use mktemp staging, add sudo NOPASSWD probe and requiretty detection
  • remote: Show kept binary path when --keep-binary is used
  • ssh: Pre-validate sudo password and show kept-binary path
  • ssh: Validate sudo password before binary upload
  • Honor @Revoked and @cert-authority known_hosts markers (R25-66)

Miscellaneous

  • Address R25-61 minor review items
  • Apply R25-72 minor cleanups
  • Bump version to 0.5.34

Performance Improvements

  • utils: Exponential backoff for run_child_with_timeout

Refactoring

  • Unify terminal-unsafe codepoint classification (R25-65)
  • Single exit-code mapping for local and fleet paths (R25-67)
  • Centralize remote coverage application (R25-72)
  • exit-codes: Two-axis security verdict and coverage
  • safe_io: Strict capped read returns String, not impossible bool

Testing

  • Make canonical_key_type regression test actually fail without fix (R25-64)
  • utils: Gate wait_group_safe test to Linux

style

  • Fix formatting

v0.5.33

Choose a tag to compare

@github-actions github-actions released this 10 Aug 18:12
v0.5.33
e9a3870

Bug Fixes

  • R24-01 correct PAM line parsing (whitespace runs, bracketed control)
  • R24-01 correct PAM line parsing (whitespace runs, bracketed control), R24-02 capped safe read for authorized_keys
  • R24-05 fail-closed for /proc/net/* read errors
  • R24-05 fail-closed for /proc/net/* read errors in reverse_shell and proc_net
  • R24-06 snapshot --hosts with unreadable/empty file fails loudly instead of falling back to local scan
  • R24-07 one‑way switch vanishing between snapshots is now a Degraded drift event
  • R24-04 use setsid for child processes, kill entire process group on timeout
  • R24-11 capped-regular read for authorized_keys, R24-13 audit --hosts fails loud, pub(crate) CAP_AUTHORIZED_KEYS
  • R24-12 InvalidInput -> InvalidData in access.rs
  • R24-07 union-loop for one‑way switches, detect vanished keys as Degraded
  • R24-14 replace remaining child.kill() with kill_group_and_reap in utils.rs
  • R24-08 rename one‑way switch labels (no spaces), R24-09 make PAM uid/gid Option
  • R24-15 restore one-way switch direction severity, add tests
  • R24-16 record coverage when one-way switch contains a non-numeric value

Documentation

  • Update CHANGELOG for v0.5.32
  • Update FIELDS.md for pam_injections uid/gid nullable (R24-09)

Miscellaneous

  • Bump version to 0.5.33, finalise R24 documentation

Performance Improvements

  • R24-03 memoize resolve_batch with negative caching

v0.5.32

Choose a tag to compare

@github-actions github-actions released this 10 Aug 12:48
v0.5.32
a1978fa

Bug Fixes

  • PAM scanner audit fixes (R23-60, R23-61, R23-62, R23-63)
  • pam: Resolve audit findings R23-68–R23-73
  • pam: R23-74 parent_takeable for pam_exec, R23-75 remove root-only guard, R23-76 resolve_module mimics libpam
  • pam: Close R23-80 (missing continue), R23-81 (.. bypass), R23-83 (test gap)
  • pam: R23-85 detect pam_exec scripts hidden behind sh -c wrapper
  • pam: R23-88 exclude non-executable data arguments from pam_exec targets

Documentation

  • Update CHANGELOG for v0.5.31
  • SEC-055/056/057 weights in README, pam_injections schema in FIELDS.md, bump SCORING_VERSION to v11
  • Updated README
  • README: Fixed Security Findings table

Features

  • PAM stack injection scanner (SEC-055/056/057)

Miscellaneous

  • pam: R23-82 replace PamScriptInfo with target_kind, R23-86 add declared_as, R23-87 cleanup tests and dead sort
  • Bump version to 0.5.32

v0.5.31

Choose a tag to compare

@github-actions github-actions released this 07 Aug 12:07
v0.5.31
ba20730

Bug Fixes

  • Gate provenance resolution behind local-scan feature, fix fmt
  • Gate generators and integrity modules behind local-scan feature
  • Gate SEC-052 scoring block behind local-scan feature
  • Exhaustive match in classify_generator, EACCES handling, misc R23-56
  • Distinguish EACCES from Missing in assess_writability (R23-57)
  • Gate BTreeMap import behind local-scan feature

Documentation

  • Update CHANGELOG for v0.5.30

Features

  • One-way kernel switches as a drift class (R23-08 ext)

Miscellaneous

  • Reference PERSISTENCE_IDS in runner comment to prevent drift
  • Bump version to 0.5.31

SEC-052

  • Systemd generator persistence scanner

style

  • Fix formatting

v0.5.30

Choose a tag to compare

@github-actions github-actions released this 04 Aug 12:47
v0.5.30
e9821d9

Build System

  • deps: Bump russh from 0.62.4 to 0.62.5 (#165)
  • deps: Bump clap from 4.6.4 to 4.6.5 (#166)
  • deps: Bump taiki-e/install-action from 2.85.2 to 2.85.5 (#168)
  • deps: Bump rust_xlsxwriter from 0.96.0 to 0.97.0 (#167)
  • deps: Bump thiserror from 2.0.18 to 2.0.19 (#169)

Documentation

  • Update CHANGELOG for v0.5.29
  • Updated README.md

Miscellaneous

  • Release v0.5.30 — SEC-051, docs, scoring version bump

SEC-050

  • Detect ld.so.conf.d library path injection
  • Add drift detection for ld_so_conf_injections

SEC-051

  • Detect ld.so.conf.d library path injection
  • Implement ld.so.conf injection scanner (R23 audit fixes)
  • Address R23-40..R23-44 audit findings
  • Fix volatile regression and directory include (R23-45, R23-46)
  • Fix false positive on stale missing directories (R23-48)