Skip to content

Adopt srt 0.0.70-ltic.4: tlsTerminate, GH_TOKEN masking, working SSH, violations pipeline - #7

Merged
smolyn merged 1 commit into
mainfrom
srt-070-adoption
Aug 6, 2026
Merged

smolyn merged 1 commit into
mainfrom
srt-070-adoption

Conversation

@smolyn

@smolyn smolyn commented Aug 6, 2026

Copy link
Copy Markdown
Collaborator

Adopts the srt 0.66–0.70 features (plus fork deltas through 0.0.70-ltic.4) across both config templates, the shell wrappers, and the docs. Retires two long-standing workarounds and lights up sandboxed SSH for the first time. Everything below was verified live on the deployed setup before committing.

Workarounds retired

  • CA-bundle staging is gone. network.tlsTerminate makes srt build/inject its own trust bundle (MITM CA + host roots) and set SSL_CERT_FILE / CURL_CA_BUNDLE / CARGO_HTTP_CAINFO / GIT_SSL_CAINFO / REQUESTS_CA_BUNDLE itself — the wrapper's cp /etc/ssl/cert.pem and five env exports are deleted (they'd now shadow srt's values and break TLS).
  • Plaintext GH_TOKEN is gone. credentials.envVars masks it: the sandbox sees a structurally-valid fake; the proxy injects the real token only toward github.com/*.github.com. Exfiltrating $GH_TOKEN anywhere else leaks a worthless sentinel.

New capabilities

  • git-over-SSH works inside the sandbox (GitHub + repo.code.ubc.ca verified): ssh-agent socket forwarded via per-launch network.allowUnixSockets injection (Seatbelt gates unix sockets with network rules; the launchd socket path is random per login), transport via srt's authenticated socat ProxyCommand (fork delta 5, upstream PR #452, brew install socat). Keys stay unreadable — the agent signs. IdentitiesOnly yes setups need the sandbox-scoped Match override documented in DETAILS.
  • Violations pipeline shipped in-repo (srt-violations.mjs + settings snippet + config blocks): sandbox denials land in the agent's context with their configured deniedDomainReasons, so a policy block reads as policy instead of a broken tool. Includes the security invariant: ~/.local/state/srt must never be sandbox-writable.
  • Persistent MITM CA (~/.config/srt/mitm-ca.{crt,key}, generated by the wrapper, key mode 600 + glob-denied): trusted once via security add-trusted-cert so trustd-verifying tools (gh, Go binaries) accept proxy-minted certs — srt's default per-session CA can't be meaningfully trusted.
  • Cheap exfil hardening: port-scoped SMTP denies (*:25/587/465) with reasons; ignoreViolations filters benign macOS noise.

Docs

README (setup steps incl. socat + CA-trust + hook install, simplified functional check, rewritten gotchas) and DETAILS (five fork deltas, MITM TLS section, violations pipeline, SSH section rebuilt around agent forwarding) updated to match. allowLocalBinding in the denyall template synced to the deployed true.

Verified live

curl/cargo/git TLS through the injected bundle (no staging), gh api user succeeding with a masked token, git ls-remote over SSH to GitHub and GitLab, gist/SMTP denies returning 403 with reasons on the violation lines, pnpm store pin unchanged.

… violations pipeline

Retires the CA-staging hack and closes the plaintext-token hole, and
makes git-over-SSH work inside the sandbox for the first time.

Configs (both postures):
- network.tlsTerminate: srt MITMs TLS, builds/injects its own trust
  bundle, and sets SSL_CERT_FILE/CURL_CA_BUNDLE/CARGO_HTTP_CAINFO/
  GIT_SSL_CAINFO/REQUESTS_CA_BUNDLE itself — the wrapper's cp of
  /etc/ssl/cert.pem and five env exports are gone.
- credentials.envVars masks GH_TOKEN: the sandbox sees a fake token;
  the proxy injects the real one only toward github.com hosts.
  injectHosts is explicit (mandatory here — the default resolves to
  the empty allowedDomains; a load-time error since ltic.3).
- Port-scoped SMTP denies (*:25/587/465) + deniedDomainReasons for
  every deny; ignoreViolations filters benign macOS noise.
- denyall: allowLocalBinding synced to the deployed true.

Wrapper (.zshrc.example / .bashrc.example):
- Generates a persistent MITM CA (~/.config/srt/mitm-ca.{crt,key}) so
  trustd-verifying tools (gh, Go binaries) can trust it once via
  security add-trusted-cert; srt's default per-session CA is
  untrustable in practice. Key is mode 600 + sandbox-unreadable.
- Per-launch config copy injects the ssh-agent socket path
  (network.allowUnixSockets — Seatbelt gates unix sockets with
  network rules and the launchd path is random per login) and the CA
  paths (tlsTerminate does no tilde expansion).
- SSH agent forwarding: keys stay unreadable; the agent signs.
  Transport rides srt's socat ProxyCommand (fork 0.0.70-ltic.4,
  upstream PR #452; brew install socat). Configs with
  IdentitiesOnly yes need the sandbox-scoped Match override
  documented in DETAILS.

New: srt-violations.mjs — PostToolUse(Bash) hook that surfaces
sandbox denials (with configured reasons) into the agent's context,
so policy blocks read as policy instead of broken tools.

Docs: README setup/gotchas and DETAILS rewritten to match (five fork
deltas, MITM TLS section, violations pipeline + its security
invariant, SSH section around agent forwarding, simplified
functional check). All verified live: curl/cargo/git TLS through the
injected bundle, gh api user with a masked token, git ls-remote over
SSH to GitHub and repo.code.ubc.ca, gist/SMTP denies with reasons.
@smolyn
smolyn merged commit 74f0eda into main Aug 6, 2026
@smolyn
smolyn deleted the srt-070-adoption branch August 6, 2026 19:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant