Skip to content

[FIX] Native audit hardening (v0.9.1) - #2

Merged
francoios merged 1 commit into
mainfrom
fix/native-audit-hardening
Jul 20, 2026
Merged

francoios merged 1 commit into
mainfrom
fix/native-audit-hardening

Conversation

@francoios

Copy link
Copy Markdown
Contributor

Production-audit hardening, no API/ABI change: ELF NOTE bounds check (OOB read), atomic_flag re-entry guard, explicit TLS verify, breadcrumb slot scrub, version string 0.8.0->0.9.1. 3-OS CI is the build gate.

…, TLS verify, breadcrumb scrub, version

Production-audit findings (no API/ABI change):
- read_build_id: bounds-check name+descriptor vs segment end + forward-progress guard (OOB read on a truncated/hostile PT_NOTE at install).
- signal re-entry guard: std::atomic_flag::test_and_set (async-signal-safe + cross-thread) replacing a non-atomic volatile sig_atomic_t (dual-thread fault could corrupt the dump).
- transport_curl: set CURLOPT_SSL_VERIFYPEER/VERIFYHOST explicitly (don't inherit host defaults).
- BreadcrumbRing::clear(): scrub slot strings on consent-revoke/GDPR reset.
- tombstone_version() 0.8.0 -> 0.9.1; header docblock now describes the shipped opt-in handler. v0.9.1.
@francoios
francoios merged commit b10b2f3 into main Jul 20, 2026
3 checks passed
@francoios
francoios deleted the fix/native-audit-hardening branch July 20, 2026 16:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant