Skip to content

v0.11.0

Choose a tag to compare

@github-actions github-actions released this 07 Sep 11:30
· 151 commits to devel since this release
v0.11.0
5729f8a

Syver 0.11.0 makes Windows checks tell the truth. Fourteen sites were returning success for checks that had never actually run, and this release converts every one of them into an explicit error. The upgrade is therefore expected to turn some passing Windows specs red, and that is the intent: those specs were not being checked. Re-run your Windows specs after upgrading, and read docs/windows.md, which is new in this release and lists every flip alongside what to do instead.

The four that matter most.

  • package: passed for any package name at all, because Windows has no package-manager backend and syver fell through to the RPM one, where a missing rpm binary read as "not installed".
  • service: passed for a service that does not exist, so a typo in a service name was indistinguishable from a disabled service. registry: reported a key that exists but cannot be read as absent, which is backwards for the hardening specs registry checks are usually written for.
  • user:, group: and interface: could not tell a lookup that found nothing from a lookup that failed, so an unreachable domain controller on a domain-joined host looked like a missing account. Genuinely absent still reports exist

syver add was writing fabricated values from the same bad readings. It now fails for a package or a service it cannot honestly describe, and omits mode, owner and group on Windows rather than writing "-1" for each.

There is a security fix that predates this release. A service name taken from a gossfile was interpolated into a PowerShell command line using Go string quoting, which is not PowerShell quoting, so a name containing a subexpression was executed rather than treated as text. Anyone able to write or generate your gossfile could run commands as syver on Windows. Names are now rendered so nothing in them is evaluated. Windows only.
Two things are now documented as broken rather than left to be discovered: user: groups: fails for every user on Windows, and port: is not implemented there. uid and gid are unavailable rather than unimplemented, since Windows id

Outside Windows, a malformed --vars-inline is now rejected while the flag is parsed, with the error naming the flag and quoting the value syver actually received. cmd.exe is where this bites, since it does not treat ' as a quote cnd GOSS_VARS_INLINE are validated the same way. Three dependenciesmoved (golang.org/x/crypto v0.56.0, gopsutil/v4 v4.26.8, prometheus/common v0.71.0) with no effect on gossfiles.

No breaking changes to the gossfile format or the CLI. This is a MInges are real, not because anything was removed. Linux and macOS are unaffected.

Changelog

  • bfb7230 Merge branch 'devel' into feature/windows-truthfulness
  • 30f2de0 Merge pull request #34 from krameff/feature/windows-truthfulness
  • 5729f8a Merge pull request #35 from krameff/devel
  • 7cae2c8 Merge remote-tracking branch 'origin/devel' into feature/windows-truthfulness
  • b0d6199 Releases details udpated
  • e1f36d8 deps: gopsutil to v4.26.8 and prometheus/common to v0.71.0
  • 788b588 docs(windows): add a Windows page and re-skip the package fixture
  • 692800f docs(windows): add a Windows page, document the serve disclosure
  • 0502d63 docs(windows): show the registry key-vs-value distinction
  • 7fabf91 feat: make Windows report unsupported paths honestly
  • b0baf33 feat: reject a malformed --vars-inline while parsing the flag
  • 19cb3aa fix(ci): drop package from the Windows gossfile aggregate
  • ea04bd2 fix(ci): let the validate harness host a fixture that is meant to fail
  • df0bb39 fix(ci): log in to GHCR before the scheduled Trivy scan
  • f407b3d fix(windows): treat ERROR_NONE_MAPPED as a genuine absence
  • e8ca7df test(windows): pin the registry key-vs-value distinction
  • 006282c test(windows): raise the google.com timeout and document the network dependency
  • 965adb2 test(windows): real assertions for interface, service, SIDs and stderr
  • e62abbe test(windows): replace the fake user and group fixtures with real ones
  • f15754c test(windows): use only assertions verified on both Windows hosts