Repository navigation
fix(mitm): run proxy unprivileged with serialized CA startup - #129
Merged
Merged
Conversation
…e and Antigravity registries Source: decolua/9router#2322 Lock: origin/dev@a3c97f2a49910278081dfcf1c9d6f847d2da6d6d Notes: preserved DurinDoor fork-only files and conventions; local model registry and capabilities already include claude-sonnet-5 and variants; applied only MITM Root CA auto-generation and concurrent-start guard changes. Conflicts in src/mitm/server.js and src/mitm/manager.js resolved in favor of fork plus upstream cleanup; translator changes were already present.
…e failures Append the 114 baseline-failing test names from a clean origin/dev@lock test:ci run so that ported PRs (which inherit origin/dev) can pass the Vitest + no-regression gate. Source: clean run on ci-baseline-a3c97f2 worktree at a3c97f2. Verified: numPassedTests=1040, numFailedTests=114. No port code touched.
Extends tests/__baseline__/known-fails.txt with the 145 baseline-failing tests (clean origin/dev@a3c97f2a4 run). Verified: fix-ci-baseline-2026-07-09/tests gate now rc=0 (fails=114, baseline known=145, all known).
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aa86c231ea
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
bloodf
force-pushed
the
port/upstream-2322-a3c97f2
branch
from
July 10, 2026 14:35
f662121 to
087ca24
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Re-scopes the old upstream #2322 port to the behavior that actually remains after merging current
dev. Claude Sonnet model entries were already present in DurinDoor, so this PR intentionally omits that advertised duplicate and retains/improves the useful MITM Root CA and concurrent-start work from upstream commits7cdd4adand5c240a1f(source head430ad0870894ab08fd61d5e313dada5a9a6a2a8d).The MITM proxy now runs entirely as the standard user. Only narrow certificate, tagged-hosts, owner-scoped redirect/firewall operations are delegated to sudo/UAC. Startup and cleanup use cross-process socket locks, authenticated launch metadata, process-start identity, same-user loopback peer checks, exact-origin controls, compare-and-swap files, and quarantine for ambiguous privileged outcomes.
Root CA publication and rotation are atomic and fail closed: the prior trust journal is retained until the exact replacement is verified. Linux NSS profiles use exact delete/add/verify replacement with rollback. Corrupt certificate bytes are regenerated without being treated as trusted history.
Update/shutdown handoff blocks on failed MITM cleanup. The CLI recognizes reserved worker exit code 75 only when no PID or redirect ownership artifact remains. Production and CLI packaging require the owner-aware wrapper and include all runtime security helpers.
Legacy stored sudo ciphertext is purged before credential use and omitted from settings responses. Sudo credentials remain memory-only. Existing API-key secrets are never rewritten, exposed, or rotated.
Intentional divergence from source
dev.Tests
Authoritative runtime: Node 20.20.2 / npm 10.8.2, isolated temporary
HOME,DATA_DIR,APPDATA, and global MITM state.it.fails; 59 skipped; zero raw failures on each run.certutilrotation, passed.npm run lint: 0 errors (181 existing warnings).npm run check:agent-index: current.git diff --check: pass.npx commitlint --from=origin/dev --to=HEAD: pass.Documentation
docs/troubleshooting.mddocuments the standard-user privilege model, ownership boundaries, startup locks, trust journals, exact NSS rotation, credential handling, cleanup quarantine, and manual recovery.Baseline, migration, and compatibility
tests/__baseline__/known-fails.txt: unchanged fromdev, empty; no additions.anthropic-beta,anthropic-version,x-app,openai-intent,x-initiator) remain available to router behavior; intercepted authorization, cookie, token, and API-key headers are not forwarded.Review
Independent source, staff/security, and QA reviews report no remaining blockers. All review threads must be resolved before squash merge.