v0.6.0
v0.6.0 - Signal Interception & Filtering
This release adds signal interception capabilities, allowing policy-based control over which signals can be sent between processes. On Linux, signals can be blocked, redirected, or audited using seccomp user-notify.
Features
Signal Interception
Intercept and control signal delivery between processes using policy rules:
signal_rules:
# Allow signals to self and children
- name: allow-self
signals: ["@all"]
target:
type: self
decision: allow
- name: allow-children
signals: ["@all"]
target:
type: children
decision: allow
# Redirect SIGKILL to graceful SIGTERM
- name: graceful-kill
signals: ["SIGKILL"]
target:
type: descendants
decision: redirect
redirect_to: SIGTERM
# Block fatal signals to external processes
- name: deny-external-fatal
signals: ["@fatal"]
target:
type: external
decision: denyPlatform Support
| Platform | Blocking | Redirect | Audit |
|---|---|---|---|
| Linux | ✅ seccomp user-notify | ✅ | ✅ |
| macOS | ❌ | ❌ | ✅ ES Framework |
| Windows | ❌ | ✅ ETW |
Signal Groups
Pre-defined signal groups for common use cases:
| Group | Signals |
|---|---|
@all |
All signals (1-31) |
@fatal |
SIGKILL, SIGTERM, SIGQUIT, SIGABRT |
@job |
SIGSTOP, SIGCONT, SIGTSTP, SIGTTIN, SIGTTOU |
@reload |
SIGHUP, SIGUSR1, SIGUSR2 |
@ignore |
SIGCHLD, SIGURG, SIGWINCH |
Target Types
Control which processes can receive signals:
| Target | Description |
|---|---|
self |
Process signaling itself |
children |
Direct child processes |
descendants |
All descendant processes |
siblings |
Processes with same parent |
session |
Any process in agentsh session |
parent |
The agentsh supervisor |
external |
PIDs outside session |
system |
PID 1 and kernel threads |
user |
Other processes owned by same user |
process |
Match by process name pattern |
pid_range |
Match by PID range |
Decision Types
| Decision | Behavior |
|---|---|
allow |
Signal delivered normally |
deny |
Returns EPERM to sender |
redirect |
Changes signal (e.g., SIGKILL → SIGTERM) |
audit |
Allow + log event |
approve |
Require manual approval |
absorb |
Silently drop (no error to sender) |
Implementation Details
Linux (seccomp user-notify)
- Traps signal syscalls:
kill,tkill,tgkill,rt_sigqueueinfo,pidfd_send_signal - PID registry tracks all session processes for target classification
- Signal handler runs in parent process, evaluating policies in real-time
- Supports redirect by modifying signal number before continuing syscall
Architecture
Agent Process → kill(pid, sig) → seccomp filter → notify fd → agentsh handler
↓
Target classify → Policy evaluate → Decision
↓
allow/deny/redirect → syscall continues or EPERM
Pull Requests
PR #65: Wire signal filter into runtime supervisor
- Wire the signal filter into the runtime supervisor for signal rule enforcement
- Mirror unix socket notify pattern: wrapper config → filter installation → FD to parent → handler loop
- Add
SignalFilterEnabledto wrapper config, passed viaAGENTSH_SECCOMP_CONFIG - Create separate socket pair for signal filter FD (
AGENTSH_SIGNAL_SOCK_FD=4) - Add signal handler mirroring
notify_linux.gopattern - Add signal fields to
extraProcConfig(signalParentSock, signalEngine, signalRegistry) - Register spawned processes in signal registry for classification
- Add Windows stubs for cross-compilation support
PR #64: Add signal interception for process signal control
- Add signal interception subsystem using Linux seccomp user-notify
- Implement signal policy engine with comprehensive target types
- Support signal groups (@fatal, @job, @reload, @ignore, @ALL)
- Support decisions: allow, deny, audit, approve, redirect, absorb
- Add PID registry for session process tracking with UID-based classification
- Integrate with policy engine via
SignalEngine()accessor - Platform detection with runtime check for seccomp capability
- Proper handling of process group signals:
kill(0),kill(-pgid),tkill
Commits
Signal Runtime Integration (PR #65)
b824720fix(signal): add Windows stubs for cross-compilationf053443test(signal): add integration test for signal filterec3eba9feat(signal): use separate socket for signal filter fdb8029defeat(signal): wire signal filter into core exec flow99367fefeat(signal): start signal handler in runCommandWithResourcesf852030feat(signal): add signal fields to extraProcConfig00bafa9feat(signal): add signal handler for API05bf556feat(signal): install signal filter in wrapper81829affeat(signal): add signal filter config to wrappera553402docs: add signal runtime integration plan
Signal Interception Core (PR #64)
a79803adocs: add signal interception to README and platform comparison5865e89fix(signal): use platform detection for blocking capabilitya63ba0ffix(signal): handle process group signals and tkill correctlyeb85916fix(signal): correct TargetSystem to match only PID 1 and 246463d3fix(signal): track UID for accurate SameUser classification42b7a17fix(signal): remove arch-specific syscall number testa5d3046fix(policy): add Windows build support for signal rules0140273docs: add plan for fixing code review issues90e8b74test(signal): add integration testsae0494adocs: add signal rules documentationfbaea62fix(signal): add @ALL signal group3c58f34feat(policy): add signal rules to policies01989b1feat(policy): integrate signal engine into policy engine1212640feat(signal): add signal notification handler75d3d89feat(signal): add Linux seccomp filter for signal syscalls32bbaa9feat(events): add signal event types4e84556feat(signal): add policy engine for signal evaluationa5943c4feat(signal): add PID registry for session tracking4188e2afeat(policy): add SignalRule to policy modeldff7fb1feat(signal): add target type definitions and matchingb7d64dbfix(signal): address code review feedbacke4050d0feat(signal): add signal types and group expansionb2e7079docs: add signal interception implementation plan7aec733docs: add signal interception design document
Release Fix
9ebabf3fix(release): add libfuse-dev to release workflow
Documentation
- Added Signal Filtering section to README.md
- Added Section 8.6 Signal Interception to docs/spec.md
- Added signal protection to SECURITY.md threat model
- Updated docs/seccomp.md with signal interception details
- Updated docs/operations/policies.md with signal rules reference
- Added signal interception to docs/platform-comparison.md
Full Changelog: v0.5.0...v0.6.0
🤖 Generated with Claude Code