Skip to content

fix: confine static cover files and hide private paths - #44

Merged
cppla merged 1 commit into
mainfrom
codex/static-cover-root-confinement
Oct 2, 2026
Merged

cppla merged 1 commit into
mainfrom
codex/static-cover-root-confinement

Conversation

@cppla

@cppla cppla commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Confine static cover requests with a request-owned os.Root; keep standard HTTP index, listing, redirect, HEAD and Range behavior.
  • Return ordinary 404 for dot-prefixed paths and denied links, filter hidden listing entries, and retain root /.well-known/ plus confined relative symlinks.
  • Reject backslash paths and Windows colon/alternate-data-stream paths; add fail-closed actual Windows CI test selection.
  • Document absolute-symlink migration, fresh-per-request root selection and operator trust boundaries. Reverse-proxy and tunnel code are unchanged.

Evidence

  • Owned synthetic-file baseline actually reproduced hidden/outside reads: unit cases 20 expected failures/12 controls plus a separate 1 policy failure/2 controls; live verified-TLS H1/H2/H3 cases 30 expected failures/30 controls.
  • Final-source make check and make race passed on macOS Go 1.25.13.
  • Focused Go 1.25.13 race runs: 231 unit RUN/PASS plus 192 live-wire RUN/PASS, zero skips/failures; live target dial/resolution counters stayed 0/0.
  • Go 1.27.1 focused ×3: 423 RUN/PASS, ten exact top-level names each executed three times, zero skips/failures.
  • Isolated offline read-only Linux arm64 component tests: 454 RUN/PASS, zero skips/failures; source/compiler/script/binary manifests unchanged and owned container removed. CGO-disabled component testing, not Linux race coverage.
  • Old negative logs are preserved; no timeout/build failure substituted for a behavioral negative.

Boundaries

Absolute symlinks, even back into the site, now require migration to confined relative links or copied assets. Mounts, hard links, public aliases to hidden targets and device files are not isolated; keep the site tree public-only and the configured directory/parent trusted. No release/tag/deployment/SSH, browser traffic comparison or canceled corpus was performed. This is file confidentiality/website compatibility evidence, not passive-fingerprint certification.

Final head: a12c5fc2c6d42c5b0df1a74263774cf4e2cb6ad3; final selected Go/docs/workflow/module/README manifest (221 paths): 000ab56157d4ef37f31aa908ef112e172c62215d7997f91de1a5fb3e107b7e34.

GitHub final-head verification: CI (11/11 successful jobs), CodeQL, native netem control. Actual Windows logs show four exact selected top-level tests each passed once with no skips (30 total RUN/PASS); actual OCI logs show integration passed and both architecture builds plus OCI export completed. PR runner checkout b64a85bd2b91f148c3c804d0455a29e633057d9b was independently verified to have the exact final-head tree and base/head parents. No reruns were needed.

Independent source/test reviews found no blocker. Fresh GitHub review read: one Copilot COMMENTED overview with no findings, not an APPROVED review; zero inline review threads.

Merged into main as 236bfc2335ec3c8a6fba834eb4248ae5f2384b6f, with the identical tested tree. Main-push CI (11/11 successful jobs), CodeQL, and native netem control all completed successfully on that exact main SHA. Actual main Windows tests, OCI integration/build/export, and native netem completion were verified from their fresh job logs. Local main is synchronized and clean; same-source post-merge focused race ×3 passed (423 RUN/PASS, zero skips/failures). No release/tag/deployment was made.

Copilot AI balanced review requested due to automatic review settings October 2, 2026 21:11

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The confinement policy is consistently implemented, documented, and covered across supported protocols and platforms.

Review effort: Balanced
Findings: None

What changed in this PR

Confines static cover serving to trusted roots while preserving standard HTTP behavior.

Changes:

  • Adds request-scoped os.Root confinement and hidden-path filtering.
  • Adds comprehensive unit, protocol, and Windows CI coverage.
  • Documents security boundaries and migration requirements.
File Description
internal/​cover/​static.go Implements confined static serving.
internal/​cover/​handler.go Removes the previous static handler.
internal/​cover/​static_security_test.go Tests security and HTTP compatibility.
internal/​cover/​static_filesystem_test.go Tests filesystem wrapper contracts.
internal/​tunnel/​web_cover_static_security_test.go Tests H1/H2/H3 behavior.
.github/​workflows/​ci.yml Adds fail-closed Windows tests.
docs/​WEB_COVER.md Documents static-cover policy.
docs/​DEPLOYMENT.md Adds deployment and migration guidance.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cppla
cppla merged commit 236bfc2 into main Oct 2, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants