security: protect local data at rest (issue #146) #172
Open
jabber.developer2
wants to merge 1 commits from
fix/data-at-rest-hardening into master
pull from: fix/data-at-rest-hardening
merge into: devs:master
devs:master
devs:fix/untrusted-input-148
devs:fix/e2ee-transport-147
devs:feat/cons-show-warning-87
devs:fix/disco-info-null-from
devs:fix/editor-terminal-size
devs:fix/omemo-prosody-bootstrap
devs:feat/ai-api-type
devs:ci/docker-hub-publishing
devs:feat/disco-ac
devs:feat/privacy-enhancements
devs:fix/clientid-regression
devs:fix/ai-chat-completions-followup
devs:feat/ai-custom
devs:fix/unencrypted-send
devs:rollback/pre-upstream-merge
devs:fix/autoping-warning-null-domain
devs:fix/pad-dead-space-reclaim
devs:feat/autoping-warning
devs:chore/untrack-gitversion
devs:fix/multiline-pad-clip
devs:fix/issue-112-followups
devs:fix/issue-128-migrate-v3-dedup
devs:fix/delay-timestamp-validation
devs:ref/light-cleanup
devs:fix/history-scroll-pad-redraw-storm
devs:fix/plugin-post-display-incoming-only
devs:merge/upstream-full
devs:merge-improve
devs:chore/remove-chatlog-stage-1
devs:fix/ai-json-encoding
devs:feat/no-db-backlog-114
devs:fix/scroll-non-chat-windows
devs:fix/paged-non-chat-windows
devs:fix/ai-leaks
devs:feat/ai
devs:fix/ai-followups
devs:test/ai-coverage-unit-only
devs:test/ai-coverage
devs:refactor/scroll-mechanism
devs:fix/verify-per-contact-context
devs:feat/no-db-mode
devs:feat/ai-json
devs:feat/pikaur-parity-arch
devs:fix-pikaur-build
devs:feat/upstream-sync
devs:feat/functest-speedup
devs:fix/cwe-134-format-string-audit
devs:ci/separate-build-step
devs:test/autoping-functional-tests
devs:test/db-functional-tests
devs:fix/arch-build
devs:fix/xep-0030-disco-items-error-handling
devs:fix/xep-0030-empty-disco-items
devs:playground/fix/src_refactoring
devs:tests/disco
devs:fix/test-CI-stability
devs:feat/parallel-tests-clean
devs:feat/parallel-functional-tests
devs:fix/functional_tests_v2
devs:fix/functional_tests
devs:fix/connect_max_args
devs:feat/extended_debug_info
devs:playground/fix/scroll-stuck
devs:build/multicore
devs:build/reenable-fedora
devs:build/autoupdate
1 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
b63a9d29f8
|
security: protect local data at rest (issue #146)
All checks were successful
CI Code / Check spelling (pull_request) Successful in 15s
CI Code / Check coding style (pull_request) Successful in 26s
CI Code / Linux (debian) (pull_request) Successful in 5m3s
CI Code / Linux (arch) (pull_request) Successful in 6m25s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m1s
CI Code / Code Coverage (pull_request) Successful in 9m27s
T03 — keep secrets out of profanity.log: - new redact_secrets() helper (common.c) masks the content of SASL auth/response/challenge/success and <password> elements; applied in the libstrophe logger (_xmpp_file_logger) and the stderr-to-log bridge (REQ-DAR-03, REQ-LOG-06) - _add_to_db() no longer logs decrypted message bodies or the full INSERT statement (REQ-DAR-03) T07 — owner-only permissions on key material and history (REQ-AUTH-01): - chmod 0600 on chatlog.db after open (journal/WAL files inherit) - chmod 0600 on OTR keys.txt and fingerprints.txt after every write - parent dirs are already 0700 (create_dir); this is defense in depth T08 — integrity before trust: - PRAGMA quick_check(1) gates every chatlog.db open; on failure the DB stays closed, the user is warned once in the console and the session continues without history (REQ-RES-02) - OMEMO aesgcm downloads decrypt into a 0600 tempfile next to the target and rename it into place only after the GCM tag verifies; the open-command hook no longer runs on failed decryption (REQ-CRY-06) Tests: redact_secrets unit tests; AES-256-GCM roundtrip and tampered-tag/ciphertext unit tests (crypto.c now linked into unittests under BUILD_OMEMO); functional test planting a corrupt chatlog.db and asserting graceful degradation. Closes #146 |