Repository navigation
1.4.4 — Security hardening
Security hardening
This release addresses the security boundaries reviewed in PR #112:
- Keep failed-CI diagnosis deterministic; do not feed untrusted logs to a credentialed agent.
- Authenticate worker RPC, rotate credentials on restart and give question tools expiring capabilities scoped to one job.
- Bound RPC frames/connections, streamed attachment downloads and concurrent side replies.
- Enforce direct app-server network, search, writable-root and Git-workspace controls.
- Serialize recovery snapshot updates and prevent late updates from recreating completed tasks.
- Reject upload/photo symlink escapes and send validated photo bytes instead of reopening paths.
- Require private chats and explicit
BACKUP_ADMIN_USER_IDSfor full backups; an empty list permits nobody.
Upgrade notes
- Drain active jobs and pending final deliveries, then restart both bot and worker to load the authenticated RPC protocol.
- Review sandbox configuration. Same-user processes are not isolated by RPC credentials. Sidecar generation now requires explicitly trusted
danger-full-access; unsupported sandboxed sidecar jobs fail closed. Do not weaken sandbox settings just to bypass this refusal. - For sandboxed execution, stop the worker and set
CODEX_WORKER_MODE=inline,CODEX_STEERING=falseandCODEX_INTERACTIVE_QUESTIONS=false. The example env files select this configuration. Existing unspecified runtime defaults are retained. - Configure backup administrator IDs explicitly. Chat-specific exports keep their existing behavior.
- Descriptor-based attachment validation currently requires Linux
/proc/self/fd; unsupported platforms fail closed.
See security hardening and compatibility details.
Validation
The public distribution passed 987 tests with one pre-existing skipped test and no failures. Dependency audit reported zero vulnerabilities. The release PR is checked on Node 18, 20, 22, 24 and 26, with integration coverage and a dedicated security audit.
Full changelog: v1.4.3...v1.4.4