Skip to content

1.4.4 — Security hardening

Choose a tag to compare

@woosungchoi woosungchoi released this 08 Oct 00:46
· 2 commits to main since this release
3cff7be

Security hardening

This release addresses the security boundaries reviewed in PR #112:

  • Keep failed-CI diagnosis deterministic; do not feed untrusted logs to a credentialed agent.
  • Authenticate worker RPC, rotate credentials on restart and give question tools expiring capabilities scoped to one job.
  • Bound RPC frames/connections, streamed attachment downloads and concurrent side replies.
  • Enforce direct app-server network, search, writable-root and Git-workspace controls.
  • Serialize recovery snapshot updates and prevent late updates from recreating completed tasks.
  • Reject upload/photo symlink escapes and send validated photo bytes instead of reopening paths.
  • Require private chats and explicit BACKUP_ADMIN_USER_IDS for full backups; an empty list permits nobody.

Upgrade notes

  1. Drain active jobs and pending final deliveries, then restart both bot and worker to load the authenticated RPC protocol.
  2. Review sandbox configuration. Same-user processes are not isolated by RPC credentials. Sidecar generation now requires explicitly trusted danger-full-access; unsupported sandboxed sidecar jobs fail closed. Do not weaken sandbox settings just to bypass this refusal.
  3. For sandboxed execution, stop the worker and set CODEX_WORKER_MODE=inline, CODEX_STEERING=false and CODEX_INTERACTIVE_QUESTIONS=false. The example env files select this configuration. Existing unspecified runtime defaults are retained.
  4. Configure backup administrator IDs explicitly. Chat-specific exports keep their existing behavior.
  5. Descriptor-based attachment validation currently requires Linux /proc/self/fd; unsupported platforms fail closed.

See security hardening and compatibility details.

Validation

The public distribution passed 987 tests with one pre-existing skipped test and no failures. Dependency audit reported zero vulnerabilities. The release PR is checked on Node 18, 20, 22, 24 and 26, with integration coverage and a dedicated security audit.

Full changelog: v1.4.3...v1.4.4