Repository navigation
Releases: OWLZOPS/owlzops-mapper
Releases · OWLZOPS/owlzops-mapper
Release list
v0.5.39
[0.5.39] - 2026-10-01
Bug Fixes
- runner: Isolate mount-namespace scanner, drop pid prefilter
- sudoers: Detect Defaults !authenticate as a passwordless grant
- sudo: Self_sudo_target must see the whole Cmnd_Spec_List
- proc_net: ENOENT on a vanished pid is not a denial (R33-05)
- ssh: Do not mask key-load failures as remote auth failures (R33-07)
- mount_namespace: Prefer the systemd cgroup on hybrid/v1 hosts (R33-10)
- scoring: Bump SCORING_VERSION to 15 for R33-03/R33-04 (R33-12)
- host: Wall-clock timestamps for dmesg_errors (R33-QW-2 follow-up)
- systemd: Restore systemctl for active timers (R33-QW-5 follow-up)
- access: Use safe_io capped read for /etc/group
- access: Empty bypassing groups are inventoried, not weighted (R33-QW-7)
- scoring: Passwordless-root class is weighted once (R34-01)
- compare: Track every root-equivalent group, not just bypassing ones (R34-02)
- access: Disclose unreadable or truncated /etc/group (R34-03)
- sec-022: Correlate per netns of interpreter (R35-01)
- sec-023: Byte-level env split; ENOENT maps is a race (R35-04, R35-11)
- sec-014: Non-UTF-8 secret must not hide key/flag (R35-04)
- sudoers: Sudoers(5) comment rules; #uid is an entry (R35-03
- utils: Trusted-exec gate; forget PGID before reap (R35-05, R35-09)
- runtime: Split size query off security inventory (R35-02)
- net: Drop tuple filter; host = pid 1 ns (R35-06)
- ebpf: ENOENT silent, other errors disclosed (R35-08)
- ui: Sanitize remote report fields (R35-07)
- ssh: Derive host ceiling from stage budgets (R35-10)
- main: Host ceiling + no-panic signal task; cli range validation (R35-10, R35-12)
- ui: Cell() is the only table-cell constructor (R35-14)
- utils: Signal children while holding the registry lock (R35-15)
- sec-022: Disclose coverage only when the gap is real (R35-16)
- ui: Preserve our own newlines in multi-line cells
Build System
- deps: Bump taiki-e/install-action from 2.87.11 to 2.87.15 (#297)
- deps: Bump clap from 4.6.6 to 4.6.7 (#298)
- deps: Bump rust_xlsxwriter from 0.99.0 to 0.99.1 (#299)
- deps: Bump taiki-e/install-action from 2.87.15 to 2.87.20 (#309)
- deps: Bump rand from 0.10.2 to 0.10.3 (#311)
- deps: Bump io-uring from 0.7.14 to 0.7.15 (#312)
CI/CD
- Gate bare Cell::new in ui.rs (R35-14)
Documentation
- fields: Exe_path is never null in mount_namespace_anomalies
- models: ContainerNetnsMapping.pid is not serialized (R33-13)
- readme: SEC-060 and SEC-061 in findings table
- fields: CpuVulnerability and RootEquivalentGroup schemas
- r33-qw: Align SEC-061 weight and passwordless-root class (R34-01)
- fields: R35 updates for netns, runtime sizes, dlp, sudoers, ebpf, reverse-shell
Features
- access: Emit SudoersEntry for Defaults !authenticate
- host: NTP truth via clock_adjtime(2) (R33-QW-1)
- host: OOM count from /proc/vmstat, dmesg via /dev/kmsg (R33-QW-2)
- host: GPU inventory from sysfs PCI class (R33-QW-3)
- host: Os_install_date via statx birth time (R33-QW-4)
- ui: Show GPU inventory in System Overview (R33-QW-3)
- ui: Show OS install date in System Overview (R33-QW-4)
- systemd: Read active-state from /run/systemd/units (R33-QW-5)
- security: CPU mitigation state via sysfs (R33-QW-6)
- access: Root-equivalent groups outside sudoers policy (R33-QW-7)
- ui: Dashboard sections for SEC-060 and SEC-061
- security: Sshd login-path directives, replaceable targets (R33-QW-8)
- security: Authorized_keys options and environment= gate (R33-QW-9)
- security: Immutable/append-only trust anchors (R33-QW-10)
Miscellaneous
- sudoers: Drop temporary allow(dead_code) on the new predicates
- scoring: SCORING_VERSION 15 → 16 (R33-QW batch)
Refactoring
- mount_namespace: Share the /proc miss classifier
- main: Extract missing_hosts helper (R33-11)
- env: One byte-level KEY=VALUE splitter (R35-04 verification)
- sec-023: Share env record splitter, test R35-11 race (R35-04/R35-11 verification)
- sec-014: Share env record splitter, single mysql predicate (R35-04 verification)
Testing
- net: Behavioural check for R35-06 tuple filter (R35-06 verification)
- utils: Exercise the trust-gate refusal branch without root (R35-05 verification)
v0.5.38
[0.5.38] - 2026-09-15
Bug Fixes
- runtime: Treat deleted-after-upgrade mappings as advisory, not IOC (R29-01)
- proc_net: Avoid double /proc/net parse and surface netns read failures
- netns: R29-03/04/05/06 — dead PID, determinism, sentinel, shared netns
- cli: Wire signed report parsing and capped I/O for sign/verify
- install: Use curl -f so an HTTP error fails loudly instead of piping HTML into sh and gpg
- readme: Use curl -f so an HTTP error fails loudly instead of piping HTML to sh
- signing: Enforce namespace, improve verify output, reject unsigned reports
- signing: Prompt for encrypted private key passphrase (R30-04)
- signing: Compare key data instead of full PublicKey in verify
- signing: Expand verify output, add embedded key parse test
- signing: Harden passphrase handling and key load diagnostics
- compare: Add mount namespace anomaly drift detection
- mount-namespace: Filter systemd services and system binaries
- mount-namespace: Skip kernel worker threads in scan
- mount-namespace: Label systemd/system paths instead of dropping, cap coverage, key diff by exe
- ui: Group mount-namespace rows by namespace+exe, refine systemd filter
- ui: Recognize container scopes and /bin|/sbin prefix
- library-injection: Resolve paths through /proc//root
- deep: Use lazy
thenin managed-JIT attribution
Build System
- deps: Bump taiki-e/install-action from 2.87.0 to 2.87.5 (#268)
- deps: Bump russh from 0.63.1 to 0.63.2 (#271)
- deps: Bump base64 from 0.22.1 to 0.23.1 (#272)
- deps: Bump softprops/action-gh-release from 3.0.2 to 3.0.3
- deps: Bump taiki-e/install-action from 2.87.5 to 2.87.11 (#282)
- deps: Bump russh from 0.63.2 to 0.63.3 (#284)
- deps: Bump uuid from 1.26.0 to 1.26.1 (#283)
CI/CD
- Guard overflow-checks in [profile.release] (R32-01)
Documentation
- security: Document report signature verification chain
- ui: Fix comment describing mount-namespace grouping key
- library_injection: Ns_root is set for all PIDs, not only containers
Features
- network: Surface listeners hidden in foreign netns
- network: Inventory foreign netns listeners (R29-02)
- ui: Render foreign netns listeners in terminal report
- signing: Add Ed25519 report signing and verification
- cli: Add sign/verify subcommands for report signatures
- signing: Allow verify without --key via embedded public keys
- security: Add mount namespace anomaly detection
- ui: Render mount namespace anomalies
- mount-namespace: Attribute anomalies to containers by mnt_ns
Miscellaneous
- Ignore private signing keys, keep public keys in assets
Performance Improvements
- proc_net: Aggregate foreign-netns listeners per namespace
Refactoring
- utils: Share is_system_managed_path with mount_namespace
v0.5.37
[0.5.37] - 2026-09-02
Bug Fixes
- dlp: Single SecretLeak construction and source-aware self attribution
- ssh_engine: Check_server_key signature for russh 0.63
- Handle truncation of /proc/mounts in ghost_pid (R27-47)
- Handle truncation in kprobe_events and /proc//maps
- Handle procfs truncation as unobservable in ghost_pid, preload
- Disclose unreadable pid_max in ghost_pid sync fallback (R27-50)
- Make ghost_pid helpers use proc_root consistently (R27-51)
- Make socket_owning_pids use proc_root (R27-52)
- ghost-pid: R27-55 — io_uring path respects proc_root and discloses pid_max fallback
- verdict-cache: R27-56 — treat backward clock as stale, not fresh
- verdict-cache: R27-56 — treat backward clock as stale, not fresh
- capabilities: R27-59 — partial degradation, keep malware sweep on truncated status
- ghost-pid: R27-54 — correct starttime position in make_proc fixture
- capabilities: R27-60 — report suspicious-store overflow; align identity parser
- dlp: Exclude non-secret XDG_ACTIVATION_TOKEN from SEC-014
- audit: R27-61, R27-62, R27-63 — deep budget disclosure, blocked-vs-not-attempted, orchestrator coverage leak
- audit: R27-64, R27-65 — disclose unread deep regions and unscanned PIDs
- audit: R27-66 — restore environ scan after MAPS cap, fix counter
- sudoers: R27-67 — deep alias chain must be UNKNOWN, not negative
- mounts: R27-68 — disclose SEC-021 finding cap, stop silent truncation
- audit: R27-69, R27-70 — disclose eBPF pin truncation and zypper patch cap
- ssh_engine: Route remote coverage facts to RemoteCoverage::notes (R28-01)
- models: Apply container serde(default) to inventory structs and drop skip_serializing_if (R28-04/R28-05)
- compare: Diff exe_path for ports and container security fields (R28-02/R28-03)
- ssh_engine, known_hosts: Route remote coverage facts to RemoteCoverage::notes (R28-01)
- ssh_engine,ci: Record main exec truncation in coverage notes and broaden R28-05 gate (R28-12/R28-13)
- ssh_engine: Return ReportTruncated for truncated remote stdout (R28-15)
- runtime: Keep uninspectable containers in inventory (R28-18)
- runtime: Record coverage when container inspect fails (R28-18)
- compare: Inventory disappearance is Changed, not Improved (R28-21)
Build System
- deps: Bump russh from 0.62.6 to 0.63.0
- deps: Bump io-uring from 0.7.13 to 0.7.14 (#200)
- deps: Bump uuid from 1.24.1 to 1.26.0 (#252)
- deps: Bump rust_xlsxwriter from 0.97.1 to 0.99.0 (#253)
- deps: Bump taiki-e/install-action from 2.86.5 to 2.87.0 (#255)
- deps: Bump russh from 0.63.0 to 0.63.1 (#254)
CI/CD
- Avoid cross-OS cargo cache poisoning
- Add gates for coverage sink, serde defaults, and JSONL key stability (R28-01/R28-04/R28-05)
- Pin MIN_STRUCTS to actual count (R28-16)
Documentation
- scoring: Mark SCORING_VERSION entries as v0.5.36
- Added a new URL for install.sh
- fields: Document image_id and runtime_bounding_caps (R28-14)
- fields: Clarify image_id semantics
Features
- containers: Diff image digest, not just tag (M-2)
Performance Improvements
- proc_net: Cache comm reads per PID; fix(utils): join reader threads on timeout (R28-06/R28-07)
- main: Bound fleet admission to max_concurrent live tasks (R28-08)
Refactoring
- scanners: Deduplicate exec-cluster logic between deep.rs and library_injection.rs
Testing
- Exercise real socket_owning_pids and update comments (R27-53)
- Protect R28 guards with positive self-tests and determinism checks (R28-09/R28-10/R28-11)
- scoring: Use Default for ContainerInfo fixtures (R28-17)
v0.5.36
[0.5.36] - 2026-08-27
Bug Fixes
- security: Apply R27-15 and R27-16
- security: Apply R27-13, R27-14, R27-15, R27-16
- build: Gate take_entry_value to linux/test to avoid dead_code on macOS
- build: Gate Zeroize import behind linux/test cfg
- security: Correct SEC-014 attribution and bump scoring version
- security: Redact SecretString Debug output (R27-17)
- security: Do not close borrowed fd in read_sudo_pass_from_fd (R27-18)
- security: Remove Clone from SecretString (R27-19)
- security: Attribute self-inflicted /proc denial in DLP (R27-22)
- security: Align --sudo-pass-fd docs and behavior (R27-23)
- security: Correct EACCES attribution for own /proc/self/cmdline (R27-27)
- ci: Make doctrine gate portable and executable (R27-28)
- dlp: Correct process age handling and scoring tiers
- dlp: Split short-lived secrets into SEC-059
- dlp: Centralize process age arithmetic and harden ghost_pid
- scoring: Align SCORING_VERSION with documented entries
- deep: Consolidate process-time arithmetic into proc_time
- proc_time: Raise /proc/stat cap and surface btime failures
- dlp: Memoize process age and separate path buffers
Build System
- deps: Bump taiki-e/install-action from 2.86.4 to 2.86.5 (#219)
- deps: Bump uuid from 1.24.0 to 1.24.1 (#217)
CI/CD
- Extend process-time gate to deep.rs
Documentation
- readme: Add owlzops-mapper logo
- security: Document sudo password handling for remote scans
- security: Declare SecretString handling commitments
- security: Fix and scope secret handling commitments
- security: Correct job-control kill and clarify SecretString guarantee
Features
- security: Harden process dumpability at startup (QW1)
- ci: Add env var manipulation gate (QW2)
- security: Add SecretString with mlock/madvise protection
- security: Add --sudo-pass-fd and deprecate OWLZOPS_SUDO_PASS
- ci: Add doctrine gates for env mutation and unsafe fd handling (R27-26)
- dlp: Weight secret leaks by process lifetime
Miscellaneous
- Polish SecretString and startup comments
- Polish startup warnings and document secret invariants
Refactoring
- security: Unify capped secret reader for stdin and fd (R27-21)
- Centralize EACCES attribution and env password warning
v0.5.35
[0.5.35] - 2026-08-23
Bug Fixes
- scanners: Use capped-regular for /etc/passwd in access alignment (R26-17)
- sudoers: Single walk, capped passwd and scanner-resolved
- scoring: Key SEC-005 on scanner-resolved ALL marker (R26-19)
- scoring: Expose sudoers module internally for marker access
- models: Move sudo markers to always-compiled module
- ghost-pid: Gate io_uring imports to glibc Linux
- scoring: Bump scoring version for sudoers and backup weighting changes (R26-22)
- sudoers: Parse multiple Cmnd_Alias specs on one line (R26-23)
- host: Derive last_restic_snapshot from local cache mtime (R26-25)
- sudoers: Parse transitive sudo tags for NOPASSWD: ALL (R26-27)
- compare: Detect sudo NOPASSWD grant drift (R26-28)
- runner: Use capped-regular for /etc/passwd and add doctrine CI guard (R26-29)
- compare: Flag cross-version collection semantics change (R26-30)
- scanners: Use read_file_capped_regular for cron and DNS host files (R26-37)
- provenance: Use read_file_capped_regular for dpkg/apk databases (R26-38)
- safe_io: Allow dead_code for streaming opener on remote-only builds
- main: Import Read for streaming JSONL parser (R26-40)
- safe-io: Remove /dev from procfs doctrine; add literal path check (R26-43, R26-44)
- ci: Close R26-48 (multi-line literal guard and PCRE2 probe)
- ci: Install ripgrep, add -U and PCRE2 probe
- release: Harden release workflow
- doc: Regenerate changelog
- security: Close R27-08, R27-09, R27-04
- output: Sanitize XLSX filename against hostname traversal (R27-11)
- release: Clear OWLZOPS_SUDO_PASS from environ (R27-12)
- release: Avoid duplicate .asc upload and harden signature/changelog checks
Build System
- deps: Bump taiki-e/install-action from 2.85.10 to 2.86.4 (#201)
CI/CD
- Catch read_file_capped on host-controlled paths (R26-31)
- Enable raw-open guard and convert operator file readers (R26-40)
- Enable raw-open guard and annotate remaining operator/procfs exceptions
- release: Fix SBOM filename and validate artifact set before signing
Features
- safe_io: Add streaming regular-open primitive (R26-39)
Refactoring
- safe_io: Rename procfs readers and make capped-I/O guard exact (R26-31/R26-33/R26-36)
- scanners: Fix misleading comment and dead branch (R26-45, R26-46)
- scanners: Fix misleading comment and dead branch
Testing
- sudoers: Parameterize walk and add cross-file alias coverage (R26-24)
- compare: Add binary-version drift regression test
v0.5.34
Bug Fixes
- SEC-058 config slot test – change parent mode after file creation
- SEC-058 config slot test – change parent mode after file creation
- cli: Move default remote_path out of /tmp (R24-41)
- deps: Use russh with ring backend for glibc 2.35 compat
- deps: Use russh with ring backend for glibc 2.35 compat
- remote: Harden --remote-path handling (R24-41/R24-96)
- output: Handle empty report list in output_multi
- deps: Enable rsa feature for russh ring backend
- ssh: Restore rsa auth and clean up sudo error output
- utils: Harden sanitize_for_log against ANSI and control chars
- ssh: Bound probes, classify sudo failures, keep staging path across timeout
- ssh: Harden remote probes and sudo error handling (R25 batch 1)
- remote: Complete R25 batch — staging ownership, sudo classification, coverage propagation
- ssh: Bound sudo NOPASSWD probe and handle wedged PAM
- ssh: Surface remote upload stderr instead of hanging on permission errors
- ssh: Fail fast on non-writable upload target
- cli: Refuse --keep-binary without explicit --remote-path
- remote: Use real write probe and keep static tmp blocklist
- security: Treat host key algorithm change as a key change, not TOFU
- ftrace: Classify hooks by callback symbol, not substring match
- reverse-shell: Require stdio fd before raising SEC-022
- scoring: Ignore findings from failed scanners
- provenance: Treat rpm exit code 1 as not-owned, not a failure
- ssh_engine: Harden upload teardown and write-probe validation
- ssh_engine: Use unique upload part and noclobber to avoid symlink race
- scoring: Failed scanners produce incomplete verdict
- ssh_engine: Generate unique upload part for owned staging dir
- ftrace: Module-tagged callbacks are never kernel builtin sources
- provenance: Rpm errors are not negative ownership answers
- cli: Usage errors exit 64 outside verdict band
- cli: Exit 4 when scanner failed and verdict incomplete
- reverse_shell: Deterministic candidate selection
- remote: Persist remote_privileged into reports and drift
- ssh_engine: Bound sudo preflight by SUDO_PROBE_BUDGET
- ssh: Pin host key algorithms to known_hosts
- scoring: Replace manual scanner ID maps with Finding source
- ssh_engine: Remove write probe to avoid FIM noise
- utils: Strip unicode bidi and format controls from logs
- ui: Avoid EPIPE panic when stderr is closed early
- ssh_engine: Harden upload loop and sudo auth
- scoring: Let incomplete outrank critical and close scanner mapping seam
- cli: Restore degraded exit for scan warnings
- ci: Address R25-53 cleanup items
- known_hosts: Fail-closed trust store and per-host filtering
- main: Aggregate fleet exit by verdict rank, not numeric max
- main: Allow dead_code for compute_exit_code without local-scan
- main: Return EX_SOFTWARE on panic, not interrupt code
- known_hosts: Normalize RSA key type before comparison
- ssh_engine: Bound upload tail after EOF
- scoring: Move scanner-name warning out of evaluate
- runner: Persist remote privilege fact in snapshots
- compare: Remove unreachable panics from diff paths
- ui: Strip Unicode TAG block in terminal sanitizer
- main: Suspend progress bars before warning from scan tasks
- Correct fleet exit-code polarity and reject truncated trust store (R25-62, R25-63)
- Log channel message shape instead of remote payload (R25-68)
- Classify remote privilege coverage loss as degraded (R25-69)
- Make remediation ref check PR-aware and deletion-friendly (R25-70)
- Make all structured logs progress-bar aware (R25-71)
- Fleet aggregation prefers Critical over Incomplete (R25-72)
- Strict UTF-8 and line numbers for known_hosts trust store (R25-72)
- main: Restore is_running_as_root and honour --fail-on-incomplete on output errors
- known_hosts: Fail closed on unsupported trust markers; ignore revoked keys
- main: Remove duplicate host-failure output
- compare: Derive privileged fact from remote_privileged and is_root_execution
- safe_io: Report trust-store truncation before UTF-8 error
- Close remaining R25-81 cleanup items
- exit-codes: Output failure must not erase the security verdict
- main: Allow dead code for local helpers on non-local-scan targets
- models: Host getuid() outranks orchestrator sudo intent
- exit-codes: Align docs, tests and drift fields after two-axis model
- main: Log fleet coverage facts before returning exit code
- main: Separate verdict and coverage explanations
- utils: Kill child group before reaping to avoid PID recycling race
- known_hosts: Support wildcard host patterns and defer marker check
- scoring: Extract evaluate side effects, call once per report
- scoring: Allow warn_evaluate_side_effects on non-local-scan targets
- main: Report missing fleet hosts by input address
- models: Detect privilege claim disagreement in both directions
- main: Never let SIGINT hide a recorded compromise
- main: Aggregate fleet outcome outside writer task
- ghost-pid: Record sync fallback coverage once per invocation
- Close R25-100 and R25-73
- Close R25-101
- utils: Close PGID reuse race in run_with_timeout_inner via wait_group_safe (R26-01)
- compare: Refuse multi-host diff when JSONL lines are unreadable (R26-05)
- fleet: Count lost channel sends in records_lost (R26-09
- Fix(scanners): use read_file_capped_regular for host-controlled paths (R26-02)
- Prevent FIFO/device hangs on /etc/passwd, /etc/ssh/sshd_config, /etc/sudoers and /var/run/reboot-required.pkgs. Non-regular files are now recorded as tampering instead of blocking open(2)
- deep: Replace chunks_exact(8) with as_chunks::<8>() for clippy
- host: Detect backup posture from local evidence, drop which/restic/borg probes (R26-03/R26-04)
- xlsx: Neutralize bidi/zero-width in document sanitizer (R26-07)
- sudoers: Resolve Cmnd_Alias indirection in NOPASSWD: ALL detection (R26-06)
- models: Add container-level serde(default) to SecurityInfo/PortInfo/NetworkInfo (R26-11)
- sudoers: Avoid double space when joining continuations (R26-08)
Build System
- deps: Bump rust_xlsxwriter from 0.97.0 to 0.97.1 (#190)
- deps: Bump taiki-e/install-action from 2.85.5 to 2.85.10 (#194)
- deps: Bump clap from 4.6.5 to 4.6.6 (#192)
- deps: Bump data-encoding from 2.11.0 to 2.11.1 (#191)
- deps: Bump dtolnay/rust-toolchain
- deps: Bump Swatinem/rust-cache from 2.9.1 to 2.9.2 (#189)
- deps: Bump thiserror from 2.0.19 to 2.0.20 (#198)
- deps: Bump russh from 0.62.5 to 0.62.6 (#199)
CI/CD
- Fail when commit message references a remediation ID not in diff
- Check remediation refs against diff, not full file
- Check each commit against its own diff
- Check only latest commit for remediation IDs
- commit-refs: Restore per-commit PR validation
Documentation
- Update CHANGELOG for v0.5.33
- Update exit codes and remote flags after R25 remediation
- Add remote_privileged, failed_scanners and self_integrity to FIELDS
- Document fleet verdict ordering (R25-72)
- known_hosts: Document canonical_key_type scope
- Document two-axis exit-code model and --fail-on-incomplete
- models: Add R26-11 reference for CI
Features
- SEC-058 detect writable PAM config slots (IoC)
- ssh: Include sudo stderr in error message for incorrect password
- remote: Use mktemp staging, add sudo NOPASSWD probe and requiretty detection
- remote: Show kept binary path when --keep-binary is used
- ssh: Pre-validate sudo password and show kept-binary path
- ssh: Validate sudo password before binary upload
- Honor @Revoked and @cert-authority known_hosts markers (R25-66)
Miscellaneous
- Address R25-61 minor review items
- Apply R25-72 minor cleanups
- Bump version to 0.5.34
Performance Improvements
- utils: Exponential backoff for run_child_with_timeout
Refactoring
- Unify terminal-unsafe codepoint classification (R25-65)
- Single exit-code mapping for local and fleet paths (R25-67)
- Centralize remote coverage application (R25-72)
- exit-codes: Two-axis security verdict and coverage
- safe_io: Strict capped read returns String, not impossible bool
Testing
- Make canonical_key_type regression test actually fail without fix (R25-64)
- utils: Gate wait_group_safe test to Linux
style
- Fix formatting
v0.5.33
Bug Fixes
- R24-01 correct PAM line parsing (whitespace runs, bracketed control)
- R24-01 correct PAM line parsing (whitespace runs, bracketed control), R24-02 capped safe read for authorized_keys
- R24-05 fail-closed for /proc/net/* read errors
- R24-05 fail-closed for /proc/net/* read errors in reverse_shell and proc_net
- R24-06 snapshot --hosts with unreadable/empty file fails loudly instead of falling back to local scan
- R24-07 one‑way switch vanishing between snapshots is now a Degraded drift event
- R24-04 use setsid for child processes, kill entire process group on timeout
- R24-11 capped-regular read for authorized_keys, R24-13 audit --hosts fails loud, pub(crate) CAP_AUTHORIZED_KEYS
- R24-12 InvalidInput -> InvalidData in access.rs
- R24-07 union-loop for one‑way switches, detect vanished keys as Degraded
- R24-14 replace remaining child.kill() with kill_group_and_reap in utils.rs
- R24-08 rename one‑way switch labels (no spaces), R24-09 make PAM uid/gid Option
- R24-15 restore one-way switch direction severity, add tests
- R24-16 record coverage when one-way switch contains a non-numeric value
Documentation
- Update CHANGELOG for v0.5.32
- Update FIELDS.md for pam_injections uid/gid nullable (R24-09)
Miscellaneous
- Bump version to 0.5.33, finalise R24 documentation
Performance Improvements
- R24-03 memoize resolve_batch with negative caching
v0.5.32
Bug Fixes
- PAM scanner audit fixes (R23-60, R23-61, R23-62, R23-63)
- pam: Resolve audit findings R23-68–R23-73
- pam: R23-74 parent_takeable for pam_exec, R23-75 remove root-only guard, R23-76 resolve_module mimics libpam
- pam: Close R23-80 (missing continue), R23-81 (.. bypass), R23-83 (test gap)
- pam: R23-85 detect pam_exec scripts hidden behind sh -c wrapper
- pam: R23-88 exclude non-executable data arguments from pam_exec targets
Documentation
- Update CHANGELOG for v0.5.31
- SEC-055/056/057 weights in README, pam_injections schema in FIELDS.md, bump SCORING_VERSION to v11
- Updated README
- README: Fixed Security Findings table
Features
- PAM stack injection scanner (SEC-055/056/057)
Miscellaneous
- pam: R23-82 replace PamScriptInfo with target_kind, R23-86 add declared_as, R23-87 cleanup tests and dead sort
- Bump version to 0.5.32
v0.5.31
Bug Fixes
- Gate provenance resolution behind local-scan feature, fix fmt
- Gate generators and integrity modules behind local-scan feature
- Gate SEC-052 scoring block behind local-scan feature
- Exhaustive match in classify_generator, EACCES handling, misc R23-56
- Distinguish EACCES from Missing in assess_writability (R23-57)
- Gate BTreeMap import behind local-scan feature
Documentation
- Update CHANGELOG for v0.5.30
Features
- One-way kernel switches as a drift class (R23-08 ext)
Miscellaneous
- Reference PERSISTENCE_IDS in runner comment to prevent drift
- Bump version to 0.5.31
SEC-052
- Systemd generator persistence scanner
style
- Fix formatting
v0.5.30
Build System
- deps: Bump russh from 0.62.4 to 0.62.5 (#165)
- deps: Bump clap from 4.6.4 to 4.6.5 (#166)
- deps: Bump taiki-e/install-action from 2.85.2 to 2.85.5 (#168)
- deps: Bump rust_xlsxwriter from 0.96.0 to 0.97.0 (#167)
- deps: Bump thiserror from 2.0.18 to 2.0.19 (#169)
Documentation
- Update CHANGELOG for v0.5.29
- Updated README.md
Miscellaneous
- Release v0.5.30 — SEC-051, docs, scoring version bump
SEC-050
- Detect ld.so.conf.d library path injection
- Add drift detection for ld_so_conf_injections
SEC-051
- Detect ld.so.conf.d library path injection
- Implement ld.so.conf injection scanner (R23 audit fixes)
- Address R23-40..R23-44 audit findings
- Fix volatile regression and directory include (R23-45, R23-46)
- Fix false positive on stale missing directories (R23-48)