Skip to content

v0.2.3

Choose a tag to compare

@ripsline ripsline released this 23 Feb 02:22
· 132 commits to main since this release

v0.2.3 — Security Hardening, Paths Package, Structured Logging

Security

  • Fix shell injection in macaroon reader — replaced bash -c pipeline with safe SudoReadFile pattern (no user input reaches a shell)
  • Torrc rollback on failed install — if LND, LIT, or Syncthing install fails mid-way, the Tor config is rolled back to its pre-install state
  • Network name validation — config rejects unknown network names on load instead of silently falling back
  • Hardened NeedsInstall check — if config is missing but bitcoind is running, skip reinstall to prevent overwriting a working system

Architecture

  • internal/paths package — all filesystem paths centralized in one package, eliminating hardcoded strings across 15+ files
  • internal/logger package — structured logging with section tags ([verify], [install], [tui], [status], [system], [config]), written to /var/log/rlvpn.log
  • SudoReadFile — new system utility for safely reading privileged binary files without shell pipelines
  • GetBlockchainInfo() simplified — removed unnecessary parameters, uses paths package internally
  • fetchInFlight guard — prevents duplicate status polling when dashboard ticks overlap with slow RPC responses
  • encoding/json for version check — replaced fragile string splitting with proper JSON parsing of GitHub API responses