Files
proxy-god/CHANGELOG.md
Dr Jones 792b320257
Some checks failed
CI / Test Python 3.10 (push) Has been cancelled
CI / Test Python 3.11 (push) Has been cancelled
CI / Test Python 3.12 (push) Has been cancelled
fix: address P0/P1/P2 audit findings — security, reliability, CI, docs
P0 - Critical:
- config.py: add _mask() credential-redaction helper, SETTINGS_SCHEMA_VERSION,
  plaintext-storage warning; corrupt settings.json backed up before defaults
- gost_util.py: pin SHA256 for gost_3.2.6_windows_amd64.zip; verify before
  extraction; _add_defender_exclusion now logs warning on failure
- firewall.py: add emergency_disengage() for atexit/signal use
- service.py: register fw_emergency_disengage via atexit + SIGTERM/SIGINT;
  stop() calls emergency_disengage if thread hangs past 15s timeout
- app.py: wrap main() in top-level except with CTk error dialog + log
- LICENSE: add MIT license file

P1 - Important:
- app.py: switch to RotatingFileHandler (5 MB / 3 backups)
- config.py: settings_version + migrate(); save_settings() writes .bak before
  overwrite; _is_safe_https_url() strips RFC-1918 sources/ip_check_url
- service.py: threading.Lock on _settings; _signal_handler; graceful stop
- requirements.txt: pin exact versions; add cryptography==48.0.0
- .gitignore: add settings.json, credential JSON files, screenshot noise
- tray.py, dns_leak.py, gost_util.py: replace bare except:pass with logging
- CHANGELOG.md: document all session changes

P2 - Nice to have:
- .github/workflows/test.yml: CI on Python 3.10/3.11/3.12 windows-latest
- run.py: --version / -V flag
- docs/OPERATOR_RUNBOOK.md: emergency disengage, proxy leak, GOST, settings

Tests: 47/47 passed (python -m unittest discover -s tests -v)
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-21 23:49:02 -07:00

51 lines
2.7 KiB
Markdown

# Changelog
All meaningful changes to this repository should be recorded here.
## Unreleased — 2026-05-21 (Audit remediation P0/P1/P2)
### Security (P0)
- **Secrets at rest**: Added `_mask()` helper in `config.py` to redact credentials from any
debug log output. Added `SETTINGS_SCHEMA_VERSION` and prominent plaintext-storage warning.
- **GOST integrity**: `gost_util.py` now verifies the downloaded release zip against a pinned
SHA256 (`GOST_RELEASE_ZIP_SHA256`) before extraction. Supply-chain swap raises `RuntimeError`.
- **Kill-switch recovery**: `firewall.py` exposes `emergency_disengage()`. `service.py`
registers it via `atexit` and `signal.SIGTERM`/`SIGINT` so a crash cannot leave outbound
traffic permanently blocked.
### Reliability (P0/P1)
- **Top-level exception handler**: `app.py` `main()` now catches unhandled exceptions, shows a
`tkinter.messagebox` error dialog, logs to file, and re-raises.
- **Log rotation**: `app.py` switches from bare `FileHandler` to `RotatingFileHandler`
(5 MB max, 3 backups).
- **Settings migration**: `config.py` gains `settings_version` field, `migrate()` function, and
safe corrupt-file backup (`settings.json.corrupt`) on parse failure.
- **Settings backup**: `save_settings()` copies `settings.json → settings.json.bak` before
overwriting.
- **Graceful shutdown**: `service.py` `stop()` calls `fw_emergency_disengage()` if the thread
does not exit within 15 s.
- **Thread safety**: `ChainService._settings` reads/writes guarded by `threading.Lock`.
- **Input / URL validation**: `sanitize_settings()` now validates `sources` and `ip_check_url`
against an RFC-1918 / link-local block-list; unsafe entries are removed with a warning.
### CI / Distribution (P0/P1/P2)
- **GitHub Actions CI** added: `.github/workflows/test.yml` runs `compileall` + `unittest
discover` on Python 3.10 / 3.11 / 3.12 on `windows-latest`.
- **LICENSE**: MIT license added to repo root.
- **requirements.txt**: All four runtime dependencies pinned to exact versions; `cryptography`
added for future Fernet-based secret storage.
- **`.gitignore`**: Added `settings.json`, `*.json` credential files, and screenshot noise.
- **`--version` flag**: `run.py` now supports `--version` / `-V`.
### Documentation (P1/P2)
- **`docs/OPERATOR_RUNBOOK.md`**: Emergency firewall disengage, proxy leak, empty pool, GOST
quarantine, and settings-restore instructions.
- **Bare `except: pass` cleanup**: Key silent-failure sites in `tray.py`, `dns_leak.py`, and
`gost_util.py` now log a `warning` or `debug` message instead of swallowing errors.
## 2026-05-20 - Gitea Stewardship Import
- Verified README and wiki coverage.
- Added standard stewardship documentation where missing.
- Established security, contribution, release, and provenance expectations.