Skip to content

🛡️ Sentinel: Fix symlink hijacking in telemetry stream log handlers - #679

Merged
timerloggedout-spec merged 3 commits into
masterfrom
sentinel-telemetry-symlink-protection-17545578022270580346
Sep 21, 2026
Merged

timerloggedout-spec merged 3 commits into
masterfrom
sentinel-telemetry-symlink-protection-17545578022270580346

Conversation

@google-labs-jules

Copy link
Copy Markdown
Contributor

This PR hardens telemetry log stream handling against symlink hijacking across src/telemetry.py, termux-multi-agent/src/telemetry.py, and termux-multi-agent/dashboard.py.

🚨 Severity

HIGH

💡 Vulnerability

TermuxTelemetryLogger.notify opened TELEMETRY_LOG ("agent_telemetry_stream.json") in append mode and applied os.chmod(..., 0o600) without checking if the file was a symbolic link. A local attacker could pre-create a symlink pointing to an arbitrary target file, causing telemetry logging to overwrite or alter permissions on sensitive target files.

🔧 Fix

  1. Validate os.path.islink(TELEMETRY_LOG) in TermuxTelemetryLogger.notify before opening, writing, or changing permissions on the log file.
  2. Validate os.path.islink(TELEMETRY_LOG) in read_latest_telemetry in dashboard.py before reading the log file.
  3. Added unit test test_telemetry_symlink_hijacking_prevention in tests/test_telemetry_optimized.py.

✅ Verification

Ran PYTHONPATH=termux-multi-agent python3 -m pytest tests/test_telemetry_optimized.py and full security test suites. All 38 tests passed.


PR created automatically by Jules for task 17545578022270580346 started by @timerloggedout-spec

Check os.path.islink(TELEMETRY_LOG) before reading, writing, or changing file permissions on telemetry log files to prevent symlink hijacking vulnerabilities. Add unit test coverage in test_telemetry_optimized.py.
@google-labs-jules

Copy link
Copy Markdown
Contributor Author

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@blocksorg

blocksorg Bot commented Sep 20, 2026

Copy link
Copy Markdown

Mention Blocks like a regular teammate with your question or request:

@blocks review this pull request
@blocks make the following changes ...
@blocks create an issue from what was mentioned in the following comment ...
@blocks explain the following code ...
@blocks are there any security or performance concerns?

Run @blocks /help for more information.

Workspace settings | Disable this message

@vercel

vercel Bot commented Sep 20, 2026

Copy link
Copy Markdown

Deployment failed for project help-wanted-dash with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@vercel

vercel Bot commented Sep 20, 2026

Copy link
Copy Markdown

Deployment failed for project help-wanted-oversight with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 6773fb11c5b192089d89ee8b8c6180d3c4be0d7a

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 5 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 20, 2026

Copy link
Copy Markdown

Deployment failed for project mcp-hub with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 6773fb11c5b192089d89ee8b8c6180d3c4be0d7a

PR taxonomy clear (success)

Scanned 5 changed file(s). No taxonomy bucket signals were detected.

Scanned 5 changed file(s).

No PR taxonomy bucket signals were detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 6773fb11c5b192089d89ee8b8c6180d3c4be0d7a

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 5 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 6773fb11c5b192089d89ee8b8c6180d3c4be0d7a

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 5 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 20, 2026

Copy link
Copy Markdown

Deployment failed for project termux-monorepo with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@github-actions

github-actions Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

PR Change Effectiveness Ledger

Measured head: 86bf17aefc2c53ec983ac1cc447bb5b629271502
Measured base: c447216baaa1ecff7e41ea5e37ec51ec5617e228
Merge base: c447216baaa1ecff7e41ea5e37ec51ec5617e228

Signal Value
commits in PR range 3
commits with no file delta 1
commits with file delta 2
no-op commit rate 33%
gross additions across commits 5189
gross deletions across commits 205
final additions vs base 58
final deletions vs base 7
final changed files 5
churn → retained final diff 1%
ahead / behind base 3 / 0

Interpretation: commit count is context, not quality. Empty commits are explicitly measured, not silently treated as productive work. Gross churn describes work performed across history; the final base→head diff describes what remains. Review/comment/check evidence must be evaluated separately and tied to this measured head SHA.

State: 🟢 EFFECTIVE_DIFF_PRESENT; ⚠️ 1 empty/no-op commit(s) observed.

Generated: 2026-09-21T01:22:42Z

@timerloggedout-spec

Copy link
Copy Markdown
Owner

ECC App activity — dual-gate merges; review skills/hooks before merge.

@google-labs-jules

Copy link
Copy Markdown
Contributor Author

ECC App activity — dual-gate merges; review skills/hooks before merge.

Acknowledged.

Check os.path.islink(TELEMETRY_LOG) before reading, writing, or changing file permissions on telemetry log files to prevent symlink hijacking vulnerabilities. Add unit test coverage in test_telemetry_optimized.py.
@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 6749853615796ae9337beea342c14aeef759e2c7

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 5 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 6749853615796ae9337beea342c14aeef759e2c7

PR taxonomy clear (success)

Scanned 5 changed file(s). No taxonomy bucket signals were detected.

Scanned 5 changed file(s).

No PR taxonomy bucket signals were detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 6749853615796ae9337beea342c14aeef759e2c7

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 5 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
help-wanted-oversight Ready Ready Preview Sep 20, 2026 7:36am UTC

@vercel

vercel Bot commented Sep 20, 2026

Copy link
Copy Markdown

Deployment failed for project termux-monorepo with the following error:

Resource is limited - try again in 1 day (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 20, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 6749853615796ae9337beea342c14aeef759e2c7

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 5 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

Copy link
Copy Markdown
Owner

OPERATOR HOLD/WAIT: mergeable_state=unstable; base SHA lag vs live master 6b0fd29f. Dual-gate not confirmed on current HEAD. Observe Jules; do not squash until termux-smoke + hygiene SUCCESS on rebased tip. Symlink check is a valid extract-only slice after rebase.

@google-labs-jules

Copy link
Copy Markdown
Contributor Author

OPERATOR HOLD/WAIT: mergeable_state=unstable; base SHA lag vs live master 6b0fd29f. Dual-gate not confirmed on current HEAD. Observe Jules; do not squash until termux-smoke + hygiene SUCCESS on rebased tip. Symlink check is a valid extract-only slice after rebase.

Acknowledged operator hold/wait notice.

@ecc-tools

ecc-tools Bot commented Sep 21, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 86bf17aefc2c53ec983ac1cc447bb5b629271502

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 5 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 21, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 86bf17aefc2c53ec983ac1cc447bb5b629271502

PR taxonomy clear (success)

Scanned 5 changed file(s). No taxonomy bucket signals were detected.

Scanned 5 changed file(s).

No PR taxonomy bucket signals were detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 21, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 86bf17aefc2c53ec983ac1cc447bb5b629271502

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 5 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 21, 2026

Copy link
Copy Markdown

Deployment failed for project help-wanted-dash with the following error:

Resource is limited - try again in 1 day (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 21, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 86bf17aefc2c53ec983ac1cc447bb5b629271502

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 5 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@timerloggedout-spec
timerloggedout-spec merged commit 3be3601 into master Sep 21, 2026
22 of 29 checks passed
timerloggedout-spec added a commit that referenced this pull request Sep 21, 2026
Master tip 3be3601. Dual-gate contract unchanged. #682 rebase in flight. Vercel non-gate. Agent-Identity: Grok (Administrator)
timerloggedout-spec added a commit that referenced this pull request Sep 21, 2026
Living SSOT rewrite. Dual-gate: hygiene+portability SUCCESS, agentic termux smoke SUCCESS. Vercel non-gate. Copilot advisory. Closes session pulse for Issue #175.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant