Skip to content

v0.2.0

Choose a tag to compare

@crashdump crashdump released this 20 Aug 11:35
· 8 commits to main since this release

fidelity 0.2.0 adds three detectors, an optional tracing feature, and a Rust 1.85 build fix.

  • The Instrumentation category gains a second detector. instrumentation.dispatch_targets
    reports Medium when a call target of the main image points somewhere else than at start. It
    catches a hook that maps no new executable region, such as one that redirects a call to code that
    already exists, which the runtime baseline cannot see. Every platform answers it. Linux answers it
    through the jump-slot relocations of the main image, and Windows through the import address table
    of the main module. macOS and iOS answer it through the non-lazy symbol pointers of the main
    image, and only when that image carries LC_DYLD_CHAINED_FIXUPS, which a deployment target of
    macOS 13 or iOS 15 produces and the v1 floor exceeds. An image below that threshold binds an
    import on its first call, so the probe reports Unsupported rather than a false finding. Android
    reads the jump-slot relocations of the library that holds Fidelity, and not of the main image: an
    application forks from zygote, so its main image is /system/bin/app_process64, which every
    application shares and which no call of the host reaches. Evidence gains a DispatchRedirected
    variant, which is an additive change.
  • The Virtualization category gains its first detector. virtualization.machine_host reports
    Medium when the system states that a virtual machine monitor runs below it. Four platforms
    answer. macOS reads kern.hv_vmm_present, Linux reads the firmware tables and the virtio
    devices, Windows reads the firmware tables, and Android reads the bootloader properties. iOS
    reports Unsupported, because a simulator process reads the kernel of the Mac below it and this
    project has read no device. Evidence gains a VirtualMachineHost variant, which is an additive
    change.
  • The UiAbuse category gains its first detector. ui_abuse.host_report reports Medium when the
    host reports that another application drew over its window, or that a recorder captured one. It
    reads no operating system, because two measurements showed that no operating system answers this
    question to a library. Handle::report_ui_abuse and UiObservation are the surface, and both are
    additive.
  • A tracing feature reports internal events, and it is off by default. The engine reports every
    one, and each names the detector, the category, the strength, and the action. Fidelity installs
    no subscriber, so a host that turns the feature on installs its own. A default build still
    resolves to no external crate.
  • A build on Rust 1.85 works again. Cargo.toml names 1.85 as the minimum version and
    docs/plan/06-delivery.md makes that normative, and two let chains that need 1.88 had landed
    after the 0.1.0 release. A host that took the named minimum could not build the workspace at all.
    Both are written the older way now, and the platform harness builds the pinned version on every
    run, so the claim and the check cannot separate again.
  • An x64 image that runs under the emulation of an ARM64 Windows reports unaccounted code on every
    clean run, because the translator writes code that no file backs. The test record states the
    figure, and an ARM64 image on the same machine reports clean.