Files
proxy-god/CHANGELOG.md
Dr Jones 792b320257
Some checks failed
CI / Test Python 3.10 (push) Has been cancelled
CI / Test Python 3.11 (push) Has been cancelled
CI / Test Python 3.12 (push) Has been cancelled
fix: address P0/P1/P2 audit findings — security, reliability, CI, docs
P0 - Critical:
- config.py: add _mask() credential-redaction helper, SETTINGS_SCHEMA_VERSION,
  plaintext-storage warning; corrupt settings.json backed up before defaults
- gost_util.py: pin SHA256 for gost_3.2.6_windows_amd64.zip; verify before
  extraction; _add_defender_exclusion now logs warning on failure
- firewall.py: add emergency_disengage() for atexit/signal use
- service.py: register fw_emergency_disengage via atexit + SIGTERM/SIGINT;
  stop() calls emergency_disengage if thread hangs past 15s timeout
- app.py: wrap main() in top-level except with CTk error dialog + log
- LICENSE: add MIT license file

P1 - Important:
- app.py: switch to RotatingFileHandler (5 MB / 3 backups)
- config.py: settings_version + migrate(); save_settings() writes .bak before
  overwrite; _is_safe_https_url() strips RFC-1918 sources/ip_check_url
- service.py: threading.Lock on _settings; _signal_handler; graceful stop
- requirements.txt: pin exact versions; add cryptography==48.0.0
- .gitignore: add settings.json, credential JSON files, screenshot noise
- tray.py, dns_leak.py, gost_util.py: replace bare except:pass with logging
- CHANGELOG.md: document all session changes

P2 - Nice to have:
- .github/workflows/test.yml: CI on Python 3.10/3.11/3.12 windows-latest
- run.py: --version / -V flag
- docs/OPERATOR_RUNBOOK.md: emergency disengage, proxy leak, GOST, settings

Tests: 47/47 passed (python -m unittest discover -s tests -v)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-21 23:49:02 -07:00

2.7 KiB

Changelog

All meaningful changes to this repository should be recorded here.

Unreleased — 2026-05-21 (Audit remediation P0/P1/P2)

Security (P0)

  • Secrets at rest: Added _mask() helper in config.py to redact credentials from any debug log output. Added SETTINGS_SCHEMA_VERSION and prominent plaintext-storage warning.
  • GOST integrity: gost_util.py now verifies the downloaded release zip against a pinned SHA256 (GOST_RELEASE_ZIP_SHA256) before extraction. Supply-chain swap raises RuntimeError.
  • Kill-switch recovery: firewall.py exposes emergency_disengage(). service.py registers it via atexit and signal.SIGTERM/SIGINT so a crash cannot leave outbound traffic permanently blocked.

Reliability (P0/P1)

  • Top-level exception handler: app.py main() now catches unhandled exceptions, shows a tkinter.messagebox error dialog, logs to file, and re-raises.
  • Log rotation: app.py switches from bare FileHandler to RotatingFileHandler (5 MB max, 3 backups).
  • Settings migration: config.py gains settings_version field, migrate() function, and safe corrupt-file backup (settings.json.corrupt) on parse failure.
  • Settings backup: save_settings() copies settings.json → settings.json.bak before overwriting.
  • Graceful shutdown: service.py stop() calls fw_emergency_disengage() if the thread does not exit within 15 s.
  • Thread safety: ChainService._settings reads/writes guarded by threading.Lock.
  • Input / URL validation: sanitize_settings() now validates sources and ip_check_url against an RFC-1918 / link-local block-list; unsafe entries are removed with a warning.

CI / Distribution (P0/P1/P2)

  • GitHub Actions CI added: .github/workflows/test.yml runs compileall + unittest discover on Python 3.10 / 3.11 / 3.12 on windows-latest.
  • LICENSE: MIT license added to repo root.
  • requirements.txt: All four runtime dependencies pinned to exact versions; cryptography added for future Fernet-based secret storage.
  • .gitignore: Added settings.json, *.json credential files, and screenshot noise.
  • --version flag: run.py now supports --version / -V.

Documentation (P1/P2)

  • docs/OPERATOR_RUNBOOK.md: Emergency firewall disengage, proxy leak, empty pool, GOST quarantine, and settings-restore instructions.
  • Bare except: pass cleanup: Key silent-failure sites in tray.py, dns_leak.py, and gost_util.py now log a warning or debug message instead of swallowing errors.

2026-05-20 - Gitea Stewardship Import

  • Verified README and wiki coverage.
  • Added standard stewardship documentation where missing.
  • Established security, contribution, release, and provenance expectations.