Adopt srt 0.0.70-ltic.4: tlsTerminate, GH_TOKEN masking, working SSH, violations pipeline - #7
Merged
Merged
Conversation
… violations pipeline
Retires the CA-staging hack and closes the plaintext-token hole, and
makes git-over-SSH work inside the sandbox for the first time.
Configs (both postures):
- network.tlsTerminate: srt MITMs TLS, builds/injects its own trust
bundle, and sets SSL_CERT_FILE/CURL_CA_BUNDLE/CARGO_HTTP_CAINFO/
GIT_SSL_CAINFO/REQUESTS_CA_BUNDLE itself — the wrapper's cp of
/etc/ssl/cert.pem and five env exports are gone.
- credentials.envVars masks GH_TOKEN: the sandbox sees a fake token;
the proxy injects the real one only toward github.com hosts.
injectHosts is explicit (mandatory here — the default resolves to
the empty allowedDomains; a load-time error since ltic.3).
- Port-scoped SMTP denies (*:25/587/465) + deniedDomainReasons for
every deny; ignoreViolations filters benign macOS noise.
- denyall: allowLocalBinding synced to the deployed true.
Wrapper (.zshrc.example / .bashrc.example):
- Generates a persistent MITM CA (~/.config/srt/mitm-ca.{crt,key}) so
trustd-verifying tools (gh, Go binaries) can trust it once via
security add-trusted-cert; srt's default per-session CA is
untrustable in practice. Key is mode 600 + sandbox-unreadable.
- Per-launch config copy injects the ssh-agent socket path
(network.allowUnixSockets — Seatbelt gates unix sockets with
network rules and the launchd path is random per login) and the CA
paths (tlsTerminate does no tilde expansion).
- SSH agent forwarding: keys stay unreadable; the agent signs.
Transport rides srt's socat ProxyCommand (fork 0.0.70-ltic.4,
upstream PR #452; brew install socat). Configs with
IdentitiesOnly yes need the sandbox-scoped Match override
documented in DETAILS.
New: srt-violations.mjs — PostToolUse(Bash) hook that surfaces
sandbox denials (with configured reasons) into the agent's context,
so policy blocks read as policy instead of broken tools.
Docs: README setup/gotchas and DETAILS rewritten to match (five fork
deltas, MITM TLS section, violations pipeline + its security
invariant, SSH section around agent forwarding, simplified
functional check). All verified live: curl/cargo/git TLS through the
injected bundle, gh api user with a masked token, git ls-remote over
SSH to GitHub and repo.code.ubc.ca, gist/SMTP denies with reasons.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adopts the srt 0.66–0.70 features (plus fork deltas through
0.0.70-ltic.4) across both config templates, the shell wrappers, and the docs. Retires two long-standing workarounds and lights up sandboxed SSH for the first time. Everything below was verified live on the deployed setup before committing.Workarounds retired
network.tlsTerminatemakes srt build/inject its own trust bundle (MITM CA + host roots) and setSSL_CERT_FILE/CURL_CA_BUNDLE/CARGO_HTTP_CAINFO/GIT_SSL_CAINFO/REQUESTS_CA_BUNDLEitself — the wrapper'scp /etc/ssl/cert.pemand five env exports are deleted (they'd now shadow srt's values and break TLS).GH_TOKENis gone.credentials.envVarsmasks it: the sandbox sees a structurally-valid fake; the proxy injects the real token only towardgithub.com/*.github.com. Exfiltrating$GH_TOKENanywhere else leaks a worthless sentinel.New capabilities
network.allowUnixSocketsinjection (Seatbelt gates unix sockets with network rules; the launchd socket path is random per login), transport via srt's authenticated socatProxyCommand(fork delta 5, upstream PR #452,brew install socat). Keys stay unreadable — the agent signs.IdentitiesOnly yessetups need the sandbox-scopedMatchoverride documented in DETAILS.srt-violations.mjs+ settings snippet + config blocks): sandbox denials land in the agent's context with their configureddeniedDomainReasons, so a policy block reads as policy instead of a broken tool. Includes the security invariant:~/.local/state/srtmust never be sandbox-writable.~/.config/srt/mitm-ca.{crt,key}, generated by the wrapper, key mode 600 + glob-denied): trusted once viasecurity add-trusted-certso trustd-verifying tools (gh, Go binaries) accept proxy-minted certs — srt's default per-session CA can't be meaningfully trusted.*:25/587/465) with reasons;ignoreViolationsfilters benign macOS noise.Docs
README (setup steps incl. socat + CA-trust + hook install, simplified functional check, rewritten gotchas) and DETAILS (five fork deltas, MITM TLS section, violations pipeline, SSH section rebuilt around agent forwarding) updated to match.
allowLocalBindingin the denyall template synced to the deployedtrue.Verified live
curl/cargo/gitTLS through the injected bundle (no staging),gh api usersucceeding with a masked token,git ls-remoteover SSH to GitHub and GitLab, gist/SMTP denies returning 403 with reasons on the violation lines, pnpm store pin unchanged.