Apply what it diagnoses: sshd enforce, firewall enable parity - #12
Merged
Merged
Conversation
Five of the eight probes could name a problem and then hand the reader
somewhere else for a one-line change. That gap is what this closes: a
posture tool that measures a weak sshd keyword, a stopped firewalld and a
service listening on the network, and then offers nothing for any of them,
is asking its reader to go and do by hand exactly what it has just proved
needs doing.
The rule for what may be offered has not moved. A change is a command this
tool will run only when it can be previewed in full, read at a glance and
undone the same way. What is new:
- sshd:<keyword> sets one of six keywords through
/etc/ssh/sshd_config.d/50-tui-secure.conf, a file this tool owns and
regenerates whole from what it held before. The plan is three commands
and the check comes first, so a file sshd refuses never reaches /etc.
- firewalld and nftables get the enable action ufw already had, with the
same warning about the session it can end. nftables refuses without a
ruleset file, or with one nft will not parse: a loader service enabled
with nothing to load is a green row on an open machine.
- port:<n> stops the unit behind a listening socket, found in
/proc/<pid>/cgroup rather than by asking systemd a second time. The ssh
server is never offered.
The refusals are the part worth reading. Turning passwords off is refused
when no account on the machine holds an authorized key — and when the only
one that does is root while PermitRootLogin is going to no in the same
change. A home directory that could not be read is not an account without a
key: those are named on the dialog instead, because guessing in either
direction is worse than saying which homes could not be looked into.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MCypLQF5AD8JD831Ea9S9q
The README and the manifest still said "three fixes", which was true until the commit before this one. They now name the whole set, and give the refusals a section of their own: a reader deciding whether to trust this tool with sshd deserves to know, before running it, that turning passwords off on a machine with no key anywhere is a thing it will not do. The smoke test now checks both drop-ins are absent after a read-only run, not just the sysctl one. The main and sshd screenshots are re-rendered: the sshd probe grades PermitEmptyPasswords now, so the frame was stale. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MCypLQF5AD8JD831Ea9S9q
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Five of the eight probes could name a problem and then hand the reader
somewhere else for a one-line change.
ufw-enable,timer:<unit>andsysctl:<key>were the only things this tool would run; everything else —a weak sshd keyword, a stopped firewalld, an empty nftables ruleset, a
service listening on the network — ended at a status-line hint saying it
belonged to another tool.
The rule for what may be offered has not moved. A change is a command this
tool runs only when it can be previewed in full, read at a glance and
undone the same way.
What is new
sshd:<keyword>sshd -t -f <staged>,install -m 600 <it> /etc/ssh/sshd_config.d/50-tui-secure.conf,systemctl reload sshdfirewalld-enablesystemctl enable --now firewalldnftables-enablesystemctl enable --now nftablesport:<n>systemctl disable --now <the unit behind the socket>Six sshd keywords are owned:
PermitRootLogin,PasswordAuthentication,PermitEmptyPasswords,PubkeyAuthentication,MaxAuthTries,X11Forwarding. The drop-in is regenerated whole from what it held before,so a keyword agreed to earlier survives and one this tool does not own is
not carried forward — which is what makes the file shown on the dialog the
whole file that will exist. The check runs first, so a file sshd refuses
never reaches
/etc. The unit name is the one the probe detected (sshd,or
sshon Debian), mirroring tui-ssh.The probe also grades
PermitEmptyPasswordsnow, which it read and ignoredbefore.
What it refuses
/etc/passwdis walked for anauthorized_keyswith something in it. None, or only root's whilePermitRootLogingoes tonoin the same change, is refused with thereason. A home that could not be read is not an account without a key:
those are named on the dialog instead.
nftables.servicewith no ruleset, or onenft -c -fwill notparse. A loader service enabled with nothing to load is a green row on an
open machine.
--demohas parity: the sample machine offers the sshd and port actions,and applying them turns the rows green the way the real ones would.
Checked
make check(gofmt,go vet,check-exec.sh, golangci-lint with gosecand errcheck, tests) green.
injection guards on every argument, the lockout matrix, the include-order
warning, and both fake-parity paths.
FuzzRenderSSHDDropIn(the file this tool wrote last time is input to thenext preview),
FuzzParseCgroupUnit(its output goes into asystemctl disableargv) andFuzzParsePasswdLoginAccounts.test/smoke.shon Fedora 42: 22 passed, 4 failed — the same four--reportfailuresmainhas today, untouched by this branch.Co-Authored-By: Claude Fable 5.1 noreply@anthropic.com
🤖 Generated with Claude Code