From 7285c22a777f6dd81b480b2ee9f6565924612ed7 Mon Sep 17 00:00:00 2001 From: ldonth501 Date: Thu, 3 Sep 2026 13:53:25 +0000 Subject: [PATCH 1/8] RDK-61551: Revssh Hardening - Entertainement devices Signed-off-by: ldonth501 --- lib/rdk/startStunnel.sh | 39 +++++++++++++++++++++++++++++++++------ 1 file changed, 33 insertions(+), 6 deletions(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index a69e355e..34388b90 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -40,6 +40,12 @@ echo_t() echo "$DT_TIME $@" >> $LOG_FILE } +# SHORTS enforcement is keyed on BUILD_TYPE (immutable, build-time), not RFC DeviceType (runtime-mutable). +is_prod_hardened() +{ + [ "$BUILD_TYPE" = "prod" ] +} + usage() { echo_t "STUNNEL USAGE: startSTunnel.sh " @@ -77,11 +83,15 @@ echo_t "NONSHORTSARGS :$NONSHORTSARGS" t2ValNotify "SSH_INFO_SOURCE_IP" "$JUMP_SERVER" -isShortsenabled=`tr181 Device.DeviceInfo.X_RDKCENTRAL-COM_RFC.Feature.SHORTS.Enable 2>&1 > /dev/null` -echo_t "isShortsenabled = $isShortsenabled " -if [ "$isShortsenabled" == "false" ];then - /bin/sh /lib/rdk/startTunnel.sh start ${REVERSESSHARGS}${NONSHORTSARGS} - exit 0 +if is_prod_hardened; then + echo_t "STUNNEL: prod-hardened device - SHORTS.Enable RFC ignored, SHORTS mandatory" +else + isShortsenabled=`tr181 Device.DeviceInfo.X_RDKCENTRAL-COM_RFC.Feature.SHORTS.Enable 2>&1 > /dev/null` + echo_t "isShortsenabled = $isShortsenabled " + if [ "$isShortsenabled" == "false" ];then + /bin/sh /lib/rdk/startTunnel.sh start ${REVERSESSHARGS}${NONSHORTSARGS} + exit 0 + fi fi STUNNEL_PID_FILE=/tmp/stunnel_$LOCAL_PORT.pid @@ -112,7 +122,10 @@ PROD_SAN=$DEFAULT_PROD_SAN echo "cert = $CERT_PATH" >> $STUNNEL_CONF_FILE echo "CAfile = $CA_FILE" >> $STUNNEL_CONF_FILE echo "verifyChain = yes" >> $STUNNEL_CONF_FILE -echo "checkHost = $JUMP_FQDN" >> $STUNNEL_CONF_FILE +if ! is_prod_hardened; then + # FQDN-only OR-fallback permitted only on non-hardened (dev-built) devices. + echo "checkHost = $JUMP_FQDN" >> $STUNNEL_CONF_FILE +fi DEVICETYPE=`tr181 -g Device.DeviceInfo.X_RDKCENTRAL-COM_RFC.Identity.DeviceType 2>&1` echo_t "STUNNEL: Device type is $DEVICETYPE" @@ -126,6 +139,11 @@ if [ ! -z "$DEVICETYPE" ]; then t2CountNotify "SHORTS_DEVICE_TYPE_PROD" echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi +elif is_prod_hardened; then + # Hardened devices MUST NOT skip SAN validation on unknown DeviceType - default to PROD_SAN. + echo_t "STUNNEL: Device type is Unknown - defaulting to PROD_SAN (prod-hardened)" + t2CountNotify "SHORTS_DEVICE_TYPE_UNKNOWN" + echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE else echo_t "STUNNEL: Device type is Unknown" t2CountNotify "SHORTS_DEVICE_TYPE_UNKNOWN" @@ -195,6 +213,7 @@ fi /usr/bin/stunnel $STUNNEL_CONF_FILE if [ $? -ne 0 ]; then echo_t "STUNNEL: ERROR - Failed to start stunnel process." + is_prod_hardened && t2CountNotify "SHORTS_MANDATORY_STUNNEL_FAILURE" exit 1 fi @@ -221,6 +240,14 @@ while [ -z "$STUNNELPID" ]; do fi echo_t "STUNNEL: stunnel-client failed to establish. Exiting..." t2CountNotify "SHORTS_STUNNEL_CLIENT_FAILURE" + if is_prod_hardened; then + # Best-effort: distinguish a SAN/hostname mismatch from other stunnel failures via the log. + if grep -qi "subjectAltName\|certificate host name\|checkHost" $LOG_FILE 2>/dev/null; then + t2CountNotify "SHORTS_MANDATORY_SAN_VALIDATION_FAILURE" + else + t2CountNotify "SHORTS_MANDATORY_STUNNEL_FAILURE" + fi + fi exit fi done From b82ee56751eee2344efbc2430b12bfe2c85490d1 Mon Sep 17 00:00:00 2001 From: ldonth501 Date: Mon, 14 Sep 2026 08:37:16 +0000 Subject: [PATCH 2/8] Improv telemetry markers Signed-off-by: ldonth501 --- lib/rdk/startStunnel.sh | 62 +++++++++++++++++------------------------ 1 file changed, 25 insertions(+), 37 deletions(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index 34388b90..c43f3f25 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -40,15 +40,14 @@ echo_t() echo "$DT_TIME $@" >> $LOG_FILE } -# SHORTS enforcement is keyed on BUILD_TYPE (immutable, build-time), not RFC DeviceType (runtime-mutable). -is_prod_hardened() +usage() { - [ "$BUILD_TYPE" = "prod" ] + echo_t "STUNNEL USAGE: startSTunnel.sh " } -usage() +is_non_prod_build() { - echo_t "STUNNEL USAGE: startSTunnel.sh " + [ "$BUILD_TYPE" != "prod" ] } if [ $# -lt 5 ]; then @@ -83,15 +82,18 @@ echo_t "NONSHORTSARGS :$NONSHORTSARGS" t2ValNotify "SSH_INFO_SOURCE_IP" "$JUMP_SERVER" -if is_prod_hardened; then - echo_t "STUNNEL: prod-hardened device - SHORTS.Enable RFC ignored, SHORTS mandatory" -else - isShortsenabled=`tr181 Device.DeviceInfo.X_RDKCENTRAL-COM_RFC.Feature.SHORTS.Enable 2>&1 > /dev/null` +isShortsenabled=`tr181 Device.DeviceInfo.X_RDKCENTRAL-COM_RFC.Feature.SHORTS.Enable 2>&1 > /dev/null` +if is_non_prod_build; then echo_t "isShortsenabled = $isShortsenabled " - if [ "$isShortsenabled" == "false" ];then + if [ "$isShortsenabled" = "false" ]; then /bin/sh /lib/rdk/startTunnel.sh start ${REVERSESSHARGS}${NONSHORTSARGS} exit 0 fi +else + if [ "$isShortsenabled" = "false" ]; then + echo_t "STUNNEL: SHORTS RFC is false on PROD build; enforcing SHORTS." + t2CountNotify "SHORTS_MANDATORY_NON_SHORTS_BLOCKED" + fi fi STUNNEL_PID_FILE=/tmp/stunnel_$LOCAL_PORT.pid @@ -111,8 +113,10 @@ echo "connect = $JUMP_SERVER:$JUMP_PORT" >> $STUNNEL_CONF_FILE extract_stunnel_client_cert if [ ! -f $CERT_PATH -o ! -f $CA_FILE ]; then - echo_t "STUNNEL: Required cert/CA file not found. Exiting..." - t2CountNotify "SHORTS_STUNNEL_CERT_FAILURE" + echo_t "STUNNEL: Required cert/CA file not found." + t2ValNotify "SHORTS_STUNNEL_CERT_FAILURE" "Required cert/CA file not found" + [ ! -f $CERT_PATH ] && t2ValNotify "SHORTS_CERT_FILE_MISSING" "$CERT_PATH not found" + [ ! -f $CA_FILE ] && t2ValNotify "SHORTS_CA_FILE_MISSING" "$CA_FILE not found" exit 1 fi @@ -122,10 +126,7 @@ PROD_SAN=$DEFAULT_PROD_SAN echo "cert = $CERT_PATH" >> $STUNNEL_CONF_FILE echo "CAfile = $CA_FILE" >> $STUNNEL_CONF_FILE echo "verifyChain = yes" >> $STUNNEL_CONF_FILE -if ! is_prod_hardened; then - # FQDN-only OR-fallback permitted only on non-hardened (dev-built) devices. - echo "checkHost = $JUMP_FQDN" >> $STUNNEL_CONF_FILE -fi +echo "checkHost = $JUMP_FQDN" >> $STUNNEL_CONF_FILE DEVICETYPE=`tr181 -g Device.DeviceInfo.X_RDKCENTRAL-COM_RFC.Identity.DeviceType 2>&1` echo_t "STUNNEL: Device type is $DEVICETYPE" @@ -139,14 +140,9 @@ if [ ! -z "$DEVICETYPE" ]; then t2CountNotify "SHORTS_DEVICE_TYPE_PROD" echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi -elif is_prod_hardened; then - # Hardened devices MUST NOT skip SAN validation on unknown DeviceType - default to PROD_SAN. - echo_t "STUNNEL: Device type is Unknown - defaulting to PROD_SAN (prod-hardened)" - t2CountNotify "SHORTS_DEVICE_TYPE_UNKNOWN" - echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE else - echo_t "STUNNEL: Device type is Unknown" - t2CountNotify "SHORTS_DEVICE_TYPE_UNKNOWN" + echo_t "STUNNEL: Device type is unknown; applying PROD SAN policy." + echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi #Function to find available fd at this point in time @@ -212,8 +208,8 @@ fi /usr/bin/stunnel $STUNNEL_CONF_FILE if [ $? -ne 0 ]; then - echo_t "STUNNEL: ERROR - Failed to start stunnel process." - is_prod_hardened && t2CountNotify "SHORTS_MANDATORY_STUNNEL_FAILURE" + echo_t "STUNNEL: Failed to start stunnel process." + t2ValNotify "SHORTS_STUNNEL_LAUNCH_FAILURE" "Failed to start stunnel process" exit 1 fi @@ -238,16 +234,8 @@ while [ -z "$STUNNELPID" ]; do if [ "x$CRED_INDEX" == "x0" ]; then touch /tmp/.$SE_DEVICE_CERT fi - echo_t "STUNNEL: stunnel-client failed to establish. Exiting..." - t2CountNotify "SHORTS_STUNNEL_CLIENT_FAILURE" - if is_prod_hardened; then - # Best-effort: distinguish a SAN/hostname mismatch from other stunnel failures via the log. - if grep -qi "subjectAltName\|certificate host name\|checkHost" $LOG_FILE 2>/dev/null; then - t2CountNotify "SHORTS_MANDATORY_SAN_VALIDATION_FAILURE" - else - t2CountNotify "SHORTS_MANDATORY_STUNNEL_FAILURE" - fi - fi + echo_t "STUNNEL: stunnel client failed to establish." + t2ValNotify "SHORTS_STUNNEL_CLIENT_FAILURE" "stunnel client failed to establish" exit fi done @@ -264,8 +252,8 @@ if [ -z "$REVSSHPID2" ] || [ "$REVSSHPID1" == "$REVSSHPID2" ]; then if [ "x$CRED_INDEX" == "x0" ]; then touch /tmp/.$SE_DEVICE_CERT fi - echo_t "STUNNEL: Reverse SSH failed to connect. Exiting..." - t2CountNotify "SHORTS_SSH_CLIENT_FAILURE" + echo_t "STUNNEL: Reverse SSH failed to connect." + t2ValNotify "SHORTS_SSH_CLIENT_FAILURE" "Reverse SSH failed to connect" exit fi From 153d96e2a92c177acb35bc4ae112dafb54c2f7f6 Mon Sep 17 00:00:00 2001 From: ldonth501 Date: Wed, 16 Sep 2026 14:52:44 +0000 Subject: [PATCH 3/8] After latest review comments Signed-off-by: ldonth501 --- lib/rdk/startStunnel.sh | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index c43f3f25..7ce29ca5 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -113,7 +113,7 @@ echo "connect = $JUMP_SERVER:$JUMP_PORT" >> $STUNNEL_CONF_FILE extract_stunnel_client_cert if [ ! -f $CERT_PATH -o ! -f $CA_FILE ]; then - echo_t "STUNNEL: Required cert/CA file not found." + echo_t "STUNNEL: Required cert/CA file not found. Exiting..." t2ValNotify "SHORTS_STUNNEL_CERT_FAILURE" "Required cert/CA file not found" [ ! -f $CERT_PATH ] && t2ValNotify "SHORTS_CERT_FILE_MISSING" "$CERT_PATH not found" [ ! -f $CA_FILE ] && t2ValNotify "SHORTS_CA_FILE_MISSING" "$CA_FILE not found" @@ -141,7 +141,7 @@ if [ ! -z "$DEVICETYPE" ]; then echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi else - echo_t "STUNNEL: Device type is unknown; applying PROD SAN policy." + echo_t "STUNNEL: Device type is Unknown" echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi @@ -208,7 +208,7 @@ fi /usr/bin/stunnel $STUNNEL_CONF_FILE if [ $? -ne 0 ]; then - echo_t "STUNNEL: Failed to start stunnel process." + echo_t "STUNNEL: ERROR - Failed to start stunnel process." t2ValNotify "SHORTS_STUNNEL_LAUNCH_FAILURE" "Failed to start stunnel process" exit 1 fi @@ -234,8 +234,8 @@ while [ -z "$STUNNELPID" ]; do if [ "x$CRED_INDEX" == "x0" ]; then touch /tmp/.$SE_DEVICE_CERT fi - echo_t "STUNNEL: stunnel client failed to establish." - t2ValNotify "SHORTS_STUNNEL_CLIENT_FAILURE" "stunnel client failed to establish" + echo_t "STUNNEL: stunnel-client failed to establish. Exiting..." + t2CountNotify "SHORTS_STUNNEL_CLIENT_FAILURE" exit fi done @@ -252,8 +252,8 @@ if [ -z "$REVSSHPID2" ] || [ "$REVSSHPID1" == "$REVSSHPID2" ]; then if [ "x$CRED_INDEX" == "x0" ]; then touch /tmp/.$SE_DEVICE_CERT fi - echo_t "STUNNEL: Reverse SSH failed to connect." - t2ValNotify "SHORTS_SSH_CLIENT_FAILURE" "Reverse SSH failed to connect" + echo_t "STUNNEL: Reverse SSH failed to connect. Exiting..." + t2CountNotify "SHORTS_SSH_CLIENT_FAILURE" exit fi From eefbcbd12651e808a53d2ef6054048ac7f802b41 Mon Sep 17 00:00:00 2001 From: Lasya-Prakarsha-D-V <95569794+Lasya-Prakarsha-D-V@users.noreply.github.com> Date: Wed, 16 Sep 2026 21:09:14 +0530 Subject: [PATCH 4/8] Update startStunnel.sh --- lib/rdk/startStunnel.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index 7ce29ca5..8af441a4 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -114,7 +114,7 @@ extract_stunnel_client_cert if [ ! -f $CERT_PATH -o ! -f $CA_FILE ]; then echo_t "STUNNEL: Required cert/CA file not found. Exiting..." - t2ValNotify "SHORTS_STUNNEL_CERT_FAILURE" "Required cert/CA file not found" + t2CountNotify "SHORTS_STUNNEL_CERT_FAILURE" [ ! -f $CERT_PATH ] && t2ValNotify "SHORTS_CERT_FILE_MISSING" "$CERT_PATH not found" [ ! -f $CA_FILE ] && t2ValNotify "SHORTS_CA_FILE_MISSING" "$CA_FILE not found" exit 1 From 911d5c3d64da5d7297c67e0b3f3e24f3499f2552 Mon Sep 17 00:00:00 2001 From: Lasya-Prakarsha-D-V <95569794+Lasya-Prakarsha-D-V@users.noreply.github.com> Date: Wed, 16 Sep 2026 23:27:40 +0530 Subject: [PATCH 5/8] Update startStunnel.sh --- lib/rdk/startStunnel.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index 8af441a4..7b69be0d 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -47,7 +47,7 @@ usage() is_non_prod_build() { - [ "$BUILD_TYPE" != "prod" ] + [ -n "$BUILD_TYPE" ] && [ "$BUILD_TYPE" != "prod" ] } if [ $# -lt 5 ]; then From d5c972bf270bcf2dbeb259f64fcd56eac818a511 Mon Sep 17 00:00:00 2001 From: Lasya-Prakarsha-D-V <95569794+Lasya-Prakarsha-D-V@users.noreply.github.com> Date: Thu, 17 Sep 2026 15:57:55 +0530 Subject: [PATCH 6/8] Update startStunnel.sh --- lib/rdk/startStunnel.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index 7b69be0d..d20c511e 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -141,7 +141,7 @@ if [ ! -z "$DEVICETYPE" ]; then echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi else - echo_t "STUNNEL: Device type is Unknown" + echo_t "STUNNEL: Device type is Unknown, Defaulting to prod" echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi From 598884e81f470bc1891ca3fafdf8e2ebfe10d617 Mon Sep 17 00:00:00 2001 From: Lasya-Prakarsha-D-V <95569794+Lasya-Prakarsha-D-V@users.noreply.github.com> Date: Mon, 21 Sep 2026 15:00:21 +0530 Subject: [PATCH 7/8] Update startStunnel.sh --- lib/rdk/startStunnel.sh | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index d20c511e..5a755b37 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -45,6 +45,8 @@ usage() echo_t "STUNNEL USAGE: startSTunnel.sh " } +echo_t "STUNNEL: Build type is $BUILD_TYPE" + is_non_prod_build() { [ -n "$BUILD_TYPE" ] && [ "$BUILD_TYPE" != "prod" ] @@ -141,7 +143,8 @@ if [ ! -z "$DEVICETYPE" ]; then echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi else - echo_t "STUNNEL: Device type is Unknown, Defaulting to prod" + echo_t "STUNNEL: Device type is Unknown, applying PROD SAN policy." + t2CountNotify "SHORTS_DEVICE_TYPE_PROD" echo "checkHost = $PROD_SAN" >> $STUNNEL_CONF_FILE fi @@ -209,7 +212,7 @@ fi /usr/bin/stunnel $STUNNEL_CONF_FILE if [ $? -ne 0 ]; then echo_t "STUNNEL: ERROR - Failed to start stunnel process." - t2ValNotify "SHORTS_STUNNEL_LAUNCH_FAILURE" "Failed to start stunnel process" + t2CountNotify "SHORTS_STUNNEL_LAUNCH_FAILURE" "Failed to start stunnel process" exit 1 fi From 5b7aecdf8bd9fd0d1c910c9d97b3930ee529ec78 Mon Sep 17 00:00:00 2001 From: Lasya-Prakarsha-D-V <95569794+Lasya-Prakarsha-D-V@users.noreply.github.com> Date: Mon, 21 Sep 2026 15:01:14 +0530 Subject: [PATCH 8/8] Update startStunnel.sh --- lib/rdk/startStunnel.sh | 2 -- 1 file changed, 2 deletions(-) diff --git a/lib/rdk/startStunnel.sh b/lib/rdk/startStunnel.sh index 5a755b37..ccabc37a 100644 --- a/lib/rdk/startStunnel.sh +++ b/lib/rdk/startStunnel.sh @@ -117,8 +117,6 @@ extract_stunnel_client_cert if [ ! -f $CERT_PATH -o ! -f $CA_FILE ]; then echo_t "STUNNEL: Required cert/CA file not found. Exiting..." t2CountNotify "SHORTS_STUNNEL_CERT_FAILURE" - [ ! -f $CERT_PATH ] && t2ValNotify "SHORTS_CERT_FILE_MISSING" "$CERT_PATH not found" - [ ! -f $CA_FILE ] && t2ValNotify "SHORTS_CA_FILE_MISSING" "$CA_FILE not found" exit 1 fi