mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* fix(core): enforce owner-only Windows ACLs on sensitive files and dirs set_dir_owner_only/set_file_owner_only were unconditional no-ops on Windows, so the CLI's mTLS client private key, OIDC/edge tokens, cached SSH keys, and the gateway's key-encryption key relied entirely on inherited NTFS ACLs with no OpenShell-applied restriction. Apply an owner-only DACL via SetEntriesInAclW/SetNamedSecurityInfoW with PROTECTED_DACL_SECURITY_INFORMATION to strip inherited ACEs, matching the 0700/0600 guarantee already provided on Unix. is_file_permissions_too_open now also works on Windows instead of being Unix-only, closing the detection gap alongside the prevention gap. Signed-off-by: Prashant Khodade <pkhodade@nvidia.com> (cherry picked from commit 71560e947f85819efbcddf70ddda94befab62b0b) * fix(core): treat a NULL DACL as too open in is_file_permissions_too_open has_foreign_trustee conflated a NULL DACL with an unreadable/invalid ACL and returned Some(false) (not too open) for both. Per the Win32 contract, a NULL DACL means the object grants full access to everyone -- the most permissive state possible -- so it must be flagged as too open. Split the null and invalid-ACL branches: null now returns Some(true), invalid ACL keeps the existing unreadable-ACL fallback (None, which the caller maps to false via unwrap_or). Adds a regression test that constructs a real NULL DACL via a SetNamedSecurityInfoW helper confined to the windows_acl module, consistent with the existing unsafe-FFI confinement in that module. Found by CodeRabbit review on MR !113. Signed-off-by: Prashant Khodade <pkhodade@nvidia.com> (cherry picked from commit 46e635a4ef1d6937cdb088f46aa85baee3d6ad28) * fix(core): close three false-negative gaps in the Windows ACL audit restrict_to_current_user() updated only the DACL, leaving a foreign owner's implicit WRITE_DAC right intact -- they could later replace the DACL we just set. Query OWNER_SECURITY_INFORMATION and take ownership in the same SetNamedSecurityInfoW call; if the caller can't (a genuinely foreign-owned object), the call now fails instead of silently leaving the object insecure. is_file_permissions_too_open() mapped every Win32 inspection failure (missing READ_CONTROL, an invalid ACL, a token-query failure) to "not too open" via unwrap_or(false). Fail closed instead: an inspection failure is a security false-negative risk, not a green light. has_foreign_trustee()'s ACE loop only recognized plain ACCESS_ALLOWED_ACE_TYPE and treated every other type as non-granting. Windows also defines access-allowed object, callback, and callback-object ACE variants that can grant rights to a foreign trustee; this audit doesn't parse their wider layouts, so their mere presence is now conservatively flagged as too open instead of silently skipped. Also updates architecture/gateway.md, which still described the SQLite file-tightening behavior only in terms of Unix mode 0o600, to distinguish it from the owner-only DACL behavior on Windows. Addresses review comments on PR #3495. Signed-off-by: Prashant Khodade <pkhodade@nvidia.com> * fix(core): conditional owner claim and audit owner in Windows ACL helpers restrict_to_current_user: query the current owner before calling SetNamedSecurityInfoW. Include OWNER_SECURITY_INFORMATION only when the path has a foreign owner -- requesting it unconditionally fails with ACCESS_DENIED (0x80070005) on standard credentials even when the current user is already the owner, because WRITE_OWNER is not implied by object ownership. A foreign-owned path still triggers an ownership claim and fails hard if the claim is denied, preserving the security contract. has_foreign_trustee: request OWNER_SECURITY_INFORMATION alongside DACL_SECURITY_INFORMATION and reject paths with a foreign owner immediately, before inspecting the DACL. A foreign owner has implicit WRITE_DAC rights and can replace any DACL we set, so a clean DACL is not sufficient evidence of safety on a foreign-owned object. architecture/gateway.md: clarify that the Windows path-hardening behavior sets mode 0o600 on Unix and applies a protected owner-only DACL on Windows, with conditional ownership claim and fail-hard semantics for foreign-owned objects. Signed-off-by: Prashant Khodade <pkhodade@nvidia.com> --------- Signed-off-by: Prashant Khodade <pkhodade@nvidia.com>
181 lines
6.1 KiB
TOML
181 lines
6.1 KiB
TOML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
[workspace]
|
|
resolver = "2"
|
|
members = ["crates/*"]
|
|
|
|
[workspace.package]
|
|
version = "0.0.0"
|
|
edition = "2024"
|
|
rust-version = "1.94"
|
|
license = "Apache-2.0"
|
|
repository = "https://github.com/NVIDIA/OpenShell"
|
|
|
|
[workspace.dependencies]
|
|
# Async runtime
|
|
tokio = { version = "1.43", features = ["full"] }
|
|
|
|
# gRPC/Protobuf
|
|
tonic = "0.14"
|
|
tonic-types = "0.14"
|
|
tonic-prost = "0.14"
|
|
tonic-prost-build = "0.14"
|
|
prost = "0.14"
|
|
prost-types = "0.14"
|
|
prost-reflect = { version = "0.16.5", features = ["serde"] }
|
|
|
|
# HTTP server
|
|
axum = { version = "0.8", features = ["ws"] }
|
|
tower = "0.5"
|
|
tower-http = { version = "0.6", features = ["cors", "trace", "request-id"] }
|
|
hyper = { version = "1.6", features = ["full"] }
|
|
hyper-util = { version = "0.1", features = ["tokio", "server-auto"] }
|
|
http = "1.2"
|
|
http-body = "1.0"
|
|
http-body-util = "0.1"
|
|
|
|
# TLS
|
|
tokio-rustls = { version = "0.26", default-features = false, features = ["logging", "tls12", "aws_lc_rs"] }
|
|
rustls = { version = "0.23", default-features = false, features = ["std", "logging", "tls12", "aws_lc_rs"] }
|
|
rustls-pemfile = "2"
|
|
rcgen = { version = "0.13", default-features = false, features = ["crypto", "pem", "aws_lc_rs"] }
|
|
webpki-roots = "1"
|
|
rustls-native-certs = "0.8"
|
|
|
|
# CLI
|
|
clap = { version = "4.5", features = ["derive", "env"] }
|
|
clap_complete = { version = "4.5", features = ["unstable-dynamic"] }
|
|
indicatif = "0.17"
|
|
owo-colors = "4"
|
|
ratatui = "0.26"
|
|
crossterm = "0.28"
|
|
terminal-colorsaurus = "1.0"
|
|
|
|
# Error handling
|
|
miette = { version = "7", features = ["fancy"] }
|
|
thiserror = "2"
|
|
|
|
# Windows platform APIs (MXC audit, host-proxy process identity, ACL enforcement; Windows-only)
|
|
windows = { version = "0.62", features = ["Wdk_System_Threading", "Win32_Foundation", "Win32_NetworkManagement_IpHelper", "Win32_Networking_WinSock", "Win32_Security", "Win32_Security_Authorization", "Win32_Storage_FileSystem", "Win32_System_Diagnostics_Etw", "Win32_System_Memory", "Win32_System_SystemServices", "Win32_System_Threading", "Win32_System_Time"] }
|
|
anyhow = "1"
|
|
|
|
# Logging/Tracing
|
|
tracing = "0.1"
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter", "json"] }
|
|
tracing-appender = "0.2"
|
|
|
|
# OpenTelemetry — OTLP/gRPC export. Kept in lockstep with the workspace's
|
|
# tonic 0.14 / prost 0.14 via opentelemetry-proto's `grpc-tonic` feature.
|
|
opentelemetry = "0.32"
|
|
opentelemetry_sdk = { version = "0.32", features = ["rt-tokio"] }
|
|
opentelemetry-otlp = { version = "0.32", default-features = false, features = ["grpc-tonic", "trace"] }
|
|
tracing-opentelemetry = { version = "0.33", default-features = false, features = ["tracing-log"] }
|
|
|
|
# Metrics
|
|
metrics = "0.24"
|
|
metrics-exporter-prometheus = { version = "0.18", default-features = false, features = ["http-listener"] }
|
|
|
|
# Unix/Process
|
|
nix = { version = "0.29", features = ["signal", "process", "user", "fs", "term"] }
|
|
rustix = { version = "1.1", features = ["process"] }
|
|
socket2 = "0.6"
|
|
|
|
# Serialization
|
|
serde = { version = "1", features = ["derive"] }
|
|
serde_json = "1"
|
|
serde_yml = { package = "noyalib", version = "0.0.28", default-features = false, features = ["std", "compat-serde-yaml"] }
|
|
toml = "0.8"
|
|
apollo-parser = "0.8.5"
|
|
tower-mcp-types = "0.12.0"
|
|
regex = "1"
|
|
|
|
# HTTP client
|
|
reqwest = { version = "0.12.28", default-features = false, features = ["json", "rustls-tls-native-roots-no-provider"] }
|
|
|
|
# AWS SDK
|
|
aws-config = { version = "1", default-features = false, features = ["default-https-client", "rt-tokio", "behavior-version-latest"] }
|
|
aws-sdk-sts = { version = "1", default-features = false, features = ["default-https-client", "rt-tokio", "behavior-version-latest"] }
|
|
|
|
# WebSocket
|
|
tokio-tungstenite = { version = "0.26", default-features = false, features = ["connect", "rustls-tls-native-roots"] }
|
|
|
|
# Clipboard (OSC 52)
|
|
base64 = "0.22"
|
|
|
|
# Crypto / Auth
|
|
sha2 = "0.10"
|
|
rand = "0.9"
|
|
jsonwebtoken = { version = "10", features = ["aws_lc_rs"] }
|
|
getrandom = "0.3"
|
|
aws-lc-rs = "1.16"
|
|
spiffe = { version = "0.15", default-features = false, features = ["workload-api-jwt", "jwt-verify-rust-crypto", "tracing"] }
|
|
|
|
# Filesystem embedding
|
|
include_dir = "0.7"
|
|
|
|
# Glob matching
|
|
glob = "0.3"
|
|
|
|
# Utilities
|
|
futures = "0.3"
|
|
bytes = "1"
|
|
hickory-proto = "0.26.1"
|
|
pin-project-lite = "0.2"
|
|
tokio-stream = "0.1"
|
|
protoc-bin-vendored = "3.2.0"
|
|
url = "2"
|
|
indexmap = "2"
|
|
|
|
# Database
|
|
sqlx = { version = "0.9", default-features = false, features = ["runtime-tokio", "tls-rustls-aws-lc-rs", "postgres", "sqlite", "migrate", "macros"] }
|
|
# SQLx's facade couples native roots to ring; select native roots independently.
|
|
sqlx-core = { version = "0.9", default-features = false, features = ["rustls-native-certs"] }
|
|
|
|
# Kubernetes
|
|
kube = { version = "0.99", default-features = false, features = ["client", "runtime", "derive", "rustls-tls", "aws-lc-rs"] }
|
|
kube-runtime = "0.99"
|
|
k8s-openapi = { version = "0.24", features = ["v1_29"] }
|
|
|
|
# IDs
|
|
uuid = { version = "1.10", features = ["v4"] }
|
|
|
|
# SMT solver (uses system libz3; enable z3/bundled via the prover's bundled-z3 feature for local dev without system z3)
|
|
z3 = "0.20"
|
|
|
|
[workspace.lints.rust]
|
|
unsafe_code = "warn"
|
|
rust_2018_idioms = { level = "warn", priority = -1 }
|
|
trivial_casts = "warn"
|
|
trivial_numeric_casts = "warn"
|
|
unused_lifetimes = "warn"
|
|
unused_qualifications = "warn"
|
|
|
|
[workspace.lints.clippy]
|
|
all = { level = "warn", priority = -1 }
|
|
pedantic = { level = "warn", priority = -1 }
|
|
nursery = { level = "warn", priority = -1 }
|
|
|
|
# Allow certain pedantic lints that are too noisy
|
|
module_name_repetitions = "allow"
|
|
must_use_candidate = "allow"
|
|
missing_errors_doc = "allow"
|
|
missing_panics_doc = "allow"
|
|
|
|
# Allow noisy nursery lints
|
|
significant_drop_tightening = "allow" # Often gives incorrect suggestions
|
|
missing_const_for_fn = "allow" # Too noisy for async code patterns
|
|
|
|
# Allow noisy pedantic lints
|
|
too_many_lines = "allow" # Function length limits are subjective
|
|
needless_pass_by_value = "allow" # Common pattern in async handlers
|
|
ref_option = "allow" # Common pattern for optional references
|
|
missing_fields_in_debug = "allow" # Manual Debug impls often intentionally omit fields
|
|
|
|
[profile.release]
|
|
strip = true
|
|
|
|
[profile.dev]
|
|
# Faster compile times for dev builds
|
|
debug = 1
|