Skip to content

Home 2.1: real SSH/SMB decoys, macOS recovery, and control fixes - #49

Merged
chrissyrocket merged 7 commits into
mainfrom
feature/deception-depth-2.1.0-current
Sep 28, 2026
Merged

chrissyrocket merged 7 commits into
mainfrom
feature/deception-depth-2.1.0-current

Conversation

@mattmacrocket

@mattmacrocket mattmacrocket commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Home 2.1: real SSH/SMB decoys, macOS recovery, and control fixes

Scope

  • Add a disposable, isolated OpenSSH/Samba guest with a shared Studio Build Mac
    persona, file operations, and per-service evidence.
  • Improve macOS 27 installer/startup recovery, desktop interaction and
    accessibility, including pull-to-refresh feedback.
  • Add LAN ownership/PF recovery controls and fix pairing, relay descriptor
    lifetime, half-close, malformed control messages, alert deduplication, AI
    result validation, and telemetry-drain recovery.
  • Pin chrissyrocket (User ID 333806721) as the sole release-environment
    reviewer in a separate commit. The prior verified Write grant and reviewer
    configuration are unchanged by this follow-up, as are the main/tag rulesets,
    self-review prohibition, disabled admin bypass, and signing secrets.

Chrissy review follow-up

  • M2: 300-second idle and 30-second half-closed-idle cleanup. Byte progress
    renews deadlines; active transfers have no absolute duration limit. Workers
    retain descriptors/admission until both exit, and bounded nonblocking I/O
    avoids depending on shutdown alone to wake a blocked Darwin read.
  • VZ connection setup has a 10-second deadline. Expiry invalidates the VM's
    connector, resumes pending callers, refuses new requests, closes late
    callbacks, and stops the unhealthy guest. Uncancellable callbacks cannot
    accumulate through repeated timeout/retry cycles.
  • N1: exempt only the shared 127.0.0.1/32 SSH relay source from penalties;
    align MaxStartups 16 with the existing host ceiling. No new rate limit,
    authentication rule, forwarding restriction, or guest quota.
  • N2, qualified: every received attempt remains evidence, including capacity
    rejections. One protocol-qualified outcome distinguishes guest connection,
    rejection, failure, and timeout in telemetry and the alert timeline. Legacy
    records stay ambiguous; guest-connected is not an authentication claim.
  • Fix Xcode 16.2 test traversal and LAN-dependent lifecycle fixtures without
    weakening production fail-closed binding. Repetition also found a test that
    inspected closed descriptor numbers; it now observes its owned peer instead.
  • Run app, helper, and guest tests in separate CI invocations. The first pushed
    run compiled all 538 tests but timed out in one sub-second socket deadline test
    during combined execution. The same complete targets passed locally in
    isolation; no tests were removed and product sources are unchanged.
  • Extend test-only LAN isolation to directly constructed lifecycle orchestrators,
    fixing the remaining Linux CI resume/profile-limit failure without changing
    production binding.

The timing/refusal changes have an explicit deception review in
docs/testing/2026-09-26-availability-review-fixes.md. No SSH/SMB content parser
or banner change was introduced.

Verification

  • Source and final extracted-package sensor code: each passed 2,321 tests, with
    one opt-in VM skip. The extracted run uses test-environment Python; embedded
    Python is independently checked below.
  • App: 394 passed. Helper: 121 passed. Guest runtime: 23 passed, plus 50 complete
    suite repetitions (1,150 executions) after the cancellation fix.
  • Disposable real guest: scanner-style banner grabs, wrong passwords followed
    by valid login, full 16-slot pool, one capacity-rejection event, recovery after
    the production half-close deadline, SSH/SFTP/SMB transfers, authenticated
    reconnects, isolation, telemetry, and shutdown passed with the final debug
    runtime and rebuilt guest.
  • Exact extracted release-mode runtime acceptance passed on September 27 in
    60.78 seconds, using packaged sensor code and approved temporary root-owned
    guest copies. Ownership was restored afterward; the same executable then
    correctly rejected the user-owned copy before boot. Installer bytes are
    unchanged. See the packaged-runtime report.
  • The September 28 documentation follow-up passed 132 release/package checks,
    relative-link checks, and whitespace validation.
  • Both guest architectures rebuilt from the pinned Alpine image and unchanged
    package inventory. 132 release/package contract tests passed. Ruff, dependency
    lock, and whitespace checks passed. Pyright reported zero errors, 29 warnings.
  • Final local ARM64 installer extracted and verified: exact app/Python/script/
    lock parity, guest digests, ad-hoc signatures, virtualization entitlement,
    embedded-Python dependency check and 19 isolated imports.
  • All five CI jobs passed at documentation head
    0c9ce026adfad24be0f0fe40dfeadbbfe6936eb3:
    App CI
    build and tests;
    Sensor CI
    lint, type checking, tests, and Docker build;
    Supply Chain CI
    Linux release controls and macOS package-lifecycle checks.

The local package is unsigned and not notarized. It was not installed. SHA-256:
cc285b1c0061c1d424b602d43b1dc7e9a5573851a40e4a6a81f445eed32855e7.

Remaining gates

  • A5 live PF ownership/replacement/state-cleanup/failure-injection acceptance.
  • Installed upgrade and second-machine virtual-IP protocol acceptance.
  • Remaining review findings, Intel execution, independent PR approval, and
    Developer ID signing/notarization.

See docs/testing/2026-09-26-availability-review-fixes.md for the current
artifact, evidence, and limitations; prior relay/control and release-preparation
reports remain historical evidence. Chrissy should re-review the availability,
outcome, and CI fixes while keeping these gates open. PR approval does not
authorize merge, tag creation, workflow dispatch, or publication. Linux
publication remains blocked.

mattmacrocket and others added 4 commits September 4, 2026 07:35
Add the isolated Studio Mini guest, coherent synthetic persona, and agent-facing decoy services with containment and packaging checks.

Expose folded connection totals, per-service counts, and recent activity in the app. Document installation, authorized penetration tests, and telemetry limits.
Add native refresh feedback and accessibility improvements, repair macOS 27 installer and LAN recovery, and cover pairing, connection ownership, guest admission, and PF guard regressions. Record local verification and remaining live acceptance gates.

@chrissyrocket chrissyrocket left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

updates applied, code is approved

@chrissyrocket
chrissyrocket merged commit 6db225c into main Sep 28, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants