Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
56 commits
Select commit Hold shift + click to select a range
343371e
RDNET-545 fix vulnerabilities
bmartins-unit Oct 10, 2022
78a6d3f
Rdnet-545-bump-go-version
bmartins-unit Oct 10, 2022
63278dc
Rdnet-545-bump-go-version
bmartins-unit Oct 11, 2022
2803f27
RDNET-798 update chisel from upstream (#5)
bmartins-unit Feb 20, 2023
ced45eb
RDNET-996: bump versions (#6)
bmartins-unit May 2, 2023
4494e35
RDNET-996: test-action (#7)
bmartins-unit May 5, 2023
7192e23
RDNET-996-bump-versions-of-required-libs
bmartins-unit May 10, 2023
b364cdd
RDNET-1213 - bumped go pkg versions (#11)
OS-marcelopereira Jul 3, 2023
187fea3
Upstream sync (#14)
OS-kiranmalsetty Sep 6, 2023
5627867
RDNET-1408: new-libs-version
bmartins-unit Sep 7, 2023
bf0e1ad
fix output (#17)
bmartins-unit Sep 8, 2023
31fe917
feat(RDGRS-336): Create Codeowners file (#18)
guilherme-reis-ops Mar 8, 2024
22e6564
feat(RDGRS-662): build image (#20)
OS-henriquesantos Aug 12, 2024
bd9460b
fix(RDGRS-662): server side keep alive (#19)
OS-henriquesantos Aug 13, 2024
ae34352
chore(RDGRS-662): updating references
OS-kiranmalsetty Aug 14, 2024
4f202ca
chore(RDGRS-662): revert updating references
OS-kiranmalsetty Aug 14, 2024
699d811
chore(RDGRS-662): updating references (#22)
OS-kiranmalsetty Aug 14, 2024
ff5be03
chore(RDGRS-662): Remove reference update and add replace (#23)
OS-kiranmalsetty Aug 16, 2024
1e05934
feat(RDGRS-752): Chisel update (#25)
Dec 3, 2024
e11aa79
fix(RDGRS-942): Update go to 1.22.7
Dec 23, 2024
a6e9745
go version/libs-updated (#27)
samartha-pm Mar 17, 2025
f4adff9
added .gitattributes to ignore ci.yml from upstream (#29)
samartha-pm Mar 24, 2025
9ad986f
Reusing the existing fucntion to implement graceful shutdown logic (#33)
Dilnawaz-khan-ops Jun 11, 2025
1f08271
dependabots update (#34)
samartha-pm Jun 11, 2025
3c52220
feat(RDGRS-1438): minor dependabot bump updates (#35)
samartha-pm Jun 12, 2025
7bbe8ba
dependabots updates and go version bump (#36)
samartha-pm Jul 22, 2025
8f39b91
go version bump,dependabots update and updated CODEOWNERS (#37)
samartha-pm Aug 14, 2025
0b5f870
feat(RDODCP-312): Upstream sync v1.11.3 and dependabots updates (#38)
samartha-pm Oct 8, 2025
6d0ec74
updated codeowners for CES (#39)
samartha-pm Oct 9, 2025
f3137f6
RDODCP-466: Update dependencies (#40)
laurahuysamen Nov 13, 2025
0ff94a3
Security patch and dependabot updates (#41)
samartha-pm Jan 27, 2026
2669204
chore(RDODCP-685): Security patch and dependabot updates (#42)
samartha-pm Jan 29, 2026
de3f5e0
chore(RDODCP-685): Security patch and dependabot updates (#43)
samartha-pm Jan 29, 2026
85b4cd4
chore(RDODCP-685): Security patch and dependabot updates (#44)
samartha-pm Jan 30, 2026
df79e57
chore(RDODCP-685): Security patch and dependabot updates (#45)
samartha-pm Jan 30, 2026
542b9f4
chore(RDODCP-685): Security patch and dependabot updates (#46)
samartha-pm Feb 2, 2026
5c61897
chore(RDODCP-891): Security patch and dependabot updates (#47)
samartha-pm Mar 4, 2026
a09f7f7
Add project documentation (CLAUDE.md, ARCHITECTURE.md, CONTRIBUTING.m…
laurahuysamen Mar 19, 2026
4c14a76
RDODCP-910: Dependency update (#49)
OS-juhitasheth Mar 23, 2026
adec94b
fix-keepalive-timeout (#50)
bmartins-unit Apr 3, 2026
fba25b7
feat: Upstream sync v1.11.5 - Enforce auth ACL on tunnel channels (#51)
samartha-pm Apr 6, 2026
b28e19c
revert base image from distoless to alpine (#52)
samartha-pm Apr 6, 2026
40be4d2
RDODCP-913: Dependency updates (#53)
samartha-pm May 5, 2026
f1a7613
RDODCP-915 Updated packages and dependencies (#55)
anurag-outsystems May 26, 2026
6c2433f
RDODCP-917: Update golang.org/x dependencies to match cloud-connector…
MigueloMadeira Jun 23, 2026
ccbadb4
chore(RDODCP-918): Upstream sync v1.11.7 and dependabots updates (#57)
arshiya-99 Jul 13, 2026
6698a83
Updated versions (#59)
OS-divyasingh Aug 26, 2026
5fb7304
1.12: reliability & security pass (#609)
jpillora Jul 17, 2026
d3500a0
Harden the 1.12 release changes (#614)
jpillora Aug 8, 2026
877d2a0
feat: migrate CLI flags to opts
jpillora Aug 28, 2026
f5c6aa3
chore(deps): use released opts wrapping fix
jpillora Aug 29, 2026
c0839a6
fix(deps): update SSH security dependencies
jpillora Aug 29, 2026
2d5ebd0
RDODCP-914 Library updates for Chisel
anurag-outsystems Sep 3, 2026
e9cfaf1
fix(tunnel): restrict reverse UDP return peers
jpillora Sep 1, 2026
96e3437
fix: exclude promote.yml from upstream merges
anurag-outsystems Sep 3, 2026
faab95c
RDODCP-914 fix(deps): upgrade golang.org/x/crypto to v0.56.0 Fixes 2 …
anurag-outsystems Sep 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .codespellrc
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
[codespell]
skip = go.sum,go.mod,.git,dist,TASKS.md
ignore-words-list = unparseable
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,2 @@
.github/workflows/ci.yml merge=ours
.github/workflows/promote.yml merge=ours
4 changes: 4 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
# https://help.github.com/articles/about-codeowners/

# Global reviewers
* @OutSystems/cloud-enablement-services
10 changes: 10 additions & 0 deletions .github/Dockerfile
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# goreleaser builds the binary and provides it in the build context
FROM alpine:3 AS certs
RUN apk add --no-cache ca-certificates

FROM scratch
LABEL maintainer="dev@jpillora.com"
COPY --from=certs /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
WORKDIR /app
COPY chisel /app/bin
ENTRYPOINT ["/app/bin"]
8 changes: 7 additions & 1 deletion .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,10 @@ updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
interval: "monthly"

# Dependencies listed in go.mod
- package-ecosystem: "gomod"
directory: "/" # Location of package manifests
schedule:
interval: "monthly"
7 changes: 0 additions & 7 deletions .github/gocompare.sh

This file was deleted.

29 changes: 25 additions & 4 deletions .github/goreleaser.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# test this goreleaser config with:
# - cd chisel
# - goreleaser --skip-publish --rm-dist --config .github/goreleaser.yml
# test this file with
# goreleaser release --config goreleaser.yml --clean --snapshot
version: 2
builds:
- env:
- CGO_ENABLED=0
Expand All @@ -12,6 +12,7 @@ builds:
- linux
- darwin
- windows
- openbsd
goarch:
- 386
- amd64
Expand All @@ -25,20 +26,40 @@ builds:
- mips64le
- s390x
goarm:
- 5
- 6
- 7
gomips:
- hardfloat
- softfloat
nfpms:
- maintainer: "https://github.com/{{ .Env.GITHUB_USER }}"
formats:
- deb
- rpm
- apk
archives:
- format: gz
files:
- none*
checksum:
# The publishing workflow stages preflight-verified archives outside dist,
# then sets this glob so the real release checksums those exact files.
# Empty by default so normal local/snapshot releases keep standard behavior.
extra_files:
- glob: '{{ envOrDefault "RELEASE_ARCHIVES_GLOB" "" }}'
release:
draft: true
replace_existing_draft: true
prerelease: auto
# In CI, these are the archives produced and checked by the non-publishing
# preflight. The publishing run uses --skip=archive, so it cannot replace
# them with rebuilt, unvalidated archives.
extra_files:
- glob: '{{ envOrDefault "RELEASE_ARCHIVES_GLOB" "" }}'
changelog:
sort: asc
filters:
exclude:
- "^docs:"
- "^test:"
- "^test:"
81 changes: 0 additions & 81 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -1,81 +0,0 @@
on: [push, pull_request]
name: CI
jobs:
# ================
# TEST JOB
# runs on every push and PR
# runs 2x3 times (see matrix)
# ================
test:
name: Test
strategy:
matrix:
go-version: [1.13.x, 1.14.x, 1.15.x]
platform: [ubuntu-latest, macos-latest, windows-latest]
runs-on: ${{ matrix.platform }}
steps:
- name: Install Go
uses: actions/setup-go@v1
with:
go-version: ${{ matrix.go-version }}
- name: Checkout code
uses: actions/checkout@v2
- name: Build
run: go build -v .
- name: Test
run: go test -v ./...
env:
GODEBUG: x509ignoreCN=0
# ================
# RELEASE JOB
# runs after a success test
# only runs on push "v*" tag
# ================
release:
name: Release
needs: test
if: startsWith(github.ref, 'refs/tags/v')
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v2
- name: goreleaser
if: success()
uses: docker://goreleaser/goreleaser:latest
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
args: release --config .github/goreleaser.yml
- name: Set up QEMU
uses: docker/setup-qemu-action@v1
- name: Set up Docker Buildx
id: buildx
uses: docker/setup-buildx-action@v1
- name: Login to DockerHub
uses: docker/login-action@v1
with:
username: ${{ secrets.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}
- name: Docker meta
id: docker_meta
uses: crazy-max/ghaction-docker-meta@v1
with:
images: jpillora/chisel
tag-latest: true
# Outputs:
# jpillora/chisel:1.2.3
# jpillora/chisel:1.2
# jpillora/chisel:1
# jpillora/chisel:latest
tag-semver: |
{{version}}
{{major}}.{{minor}}
{{major}}
- name: Build and push
uses: docker/build-push-action@v2
with:
context: .
platforms: linux/amd64,linux/arm64,linux/ppc64le,linux/386,linux/arm/v7,linux/arm/v6
push: true
tags: ${{ steps.docker_meta.outputs.tags }}
labels: ${{ steps.docker_meta.outputs.labels }}
Empty file added .github/workflows/promote.yml
Empty file.
101 changes: 101 additions & 0 deletions 1.12-changes.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,101 @@
# Chisel 1.12 — UX & Compatibility Review

**Scope:** user-facing changes on branch `ai-incoming` (the unreleased 1.12 line, HEAD `e0b639d`) compared to `master` (`310eec3` — released v1.11.7 `927abde` plus one dependency bump, no UX impact).
**Date:** 2026-07-02, revised 2026-07-17.
**Method:** three parallel code reviews (client surface, server/operator surface, tunnel/wire surface) plus manual verification of every load-bearing claim against the code. This revision re-verified each changed claim against current code.
**Status:** all four recommendations below were implemented on `ai-incoming` (commits `3c66f9b` and `c4038c3`) — the §5 gaps are closed. The branch has since been rebased onto current `master`, with its Go-module and CI-action dependencies brought fully up to date (§7).

---

## Verdict

The branch is a large but well-behaved surface change. Measured against master, there are only **three genuinely breaking changes for existing users, and the branch documents all of them** — plus it retroactively documents the SOCKS ACL break that master *already shipped* in v1.11.7 with zero README coverage. The one remaining rough edge is a silent automation-facing change (exit codes), which the changelog calls out. The diagnosability gap flagged in the original review — ACL denials logging only at debug level — has since been fixed (they now log at info).

---

## 1. Breaking changes for existing users

### a. SOCKS + `--authfile` — *already on master, branch adds the missing docs*

Enforcement (`UserAddr()` → `"socks"`, channel-level ACL gate) shipped in v1.11.7 (`927abde`), so branch-vs-master this is **not a new break** — but today's released chisel has an *undocumented* breaking change: its README/`--help` say nothing about the `socks` token. The branch fixes that in five places (server help, client help, README auth section, SOCKS guide, 1.12 changelog) including the migration line "existing authfiles which should allow SOCKS5 must add an entry matching `socks`". This documentation is arguably the most valuable UX content on the branch.

The original review flagged a diagnosability gap here: a denied user's server-side trace was `Debugf("Denied connection to socks (ACL)")`, invisible without `-v`, making "socks stopped working after upgrade" the #1 anticipated support ticket. **This is now fixed** — commit `3c66f9b` raised it to `Infof("Denied connection to %s (ACL)", hostPort)` (`share/tunnel/tunnel_out_ssh.go:57`), so operators see socks ACL denials at the default log level.

### b. Truncated legacy MD5 fingerprints rejected — *branch-new, loud*

Master's `verifyLegacyFingerprint` used `strings.HasPrefix`, so `--fingerprint a5:b3` matched any key with that MD5 prefix (~1-in-65k spoof risk). The branch requires the full 16-octet colon form (`client/client.go:248`). Affected users fail **loudly** at connect with `Invalid fingerprint (...)`, and the preceding info line helpfully prints the correct SHA256 fingerprint to migrate to. SHA256 fingerprints were always exact-match — only MD5 stragglers with shorthand configs are affected. Documented in README Security, and the 1.12 changelog now lists it as breaking (added in `c4038c3`).

### c. `--auth` without a colon is now a fatal startup error — *branch-new, loud*

On master, `--auth nocolon` silently degraded (server: user never registered → effectively no auth; client: empty credentials). That's a security footgun, and the branch turns it into `invalid auth string, expected <user>:<pass>` at startup on both sides. Anyone hit by this was already running something other than what they believed. Documented in README, and the 1.12 changelog now lists it as breaking (added in `c4038c3`).

### d. Exit code on `--max-retry-count` exhaustion: 0 → non-zero — *branch-new, silent for automation*

`client_connect.go` now returns `connection attempts exhausted` on give-up (ctx-cancel/Ctrl-C still exits 0). Correct behavior, but it's the one change scripts and `Restart=on-failure` units experience with **no error message to notice** — the semantics of `$?` just flip. It *is* in the 1.12 changelog, which is the right mitigation.

---

## 2. Quiet behavior changes (non-breaking, but observable)

- **Reconnect pacing:** backoff floor moves 100ms → 1s (new `--min-retry-interval`). Softer thundering-herd on server restarts; individual reconnects marginally slower.
- **Dead connections actually die:** pings now time out (`CHISEL_PING_TIMEOUT`, default = keepalive interval, so ~50s at defaults vs 15–60 min of kernel retransmit limbo on master). Sleep/wake and NAT-timeout hangs become visible reconnects in logs. Old peers reply to pings, so mixed versions are fine.
- **Honest connect failures:** exit-side dial now happens *before* channel accept (`CHISEL_DIAL_TIMEOUT` 30s). Apps see "connection refused/timeout" instead of master's instant-success-then-EOF. Strictly better UX, but tools that measured "connect success" will notice.
- **Half-close propagation:** `shutdown(SHUT_WR)` traverses the tunnel (`share/cio/pipe.go`), fixing netcat-style pipelines and rsync. Falls back to full-close against old peers — no hangs, just old behavior.
- **SIGTERM is graceful:** first signal drains (HTTP drain `CHISEL_SHUTDOWN_GRACE` 5s, under docker's 10s default), second forces exit. Master died instantly on SIGTERM.
- **New info-level logs:** session `Open (user=… addr=… remotes=…)` / `Close (… duration=…)` and `Login failed for user "X" (ip)` — failed logins are finally fail2ban-able. The username is quoted and escaped, so an attacker-supplied name cannot forge a second log line. Two side effects: log parsers keyed on the old debug `Closed connection` need updating, and tunnel endpoints now appear in default-level logs (mild privacy consideration for shipped logs).
- **Authfile reloads actually work:** the watcher survives vim renames, truncation, and k8s ConfigMap symlink swaps, with 100ms debounce; ACLs re-resolve per new channel; the `--auth` user is pinned across reloads and wins name clashes; removed users lose *new* tunnels but established ones aren't cut (documented). Operators who habitually restart after edits will find edits now apply live.
- **Unanchored ACL patterns warn** at every load, per pattern, unsuppressible. Common `.*`-style files keep working but get noisy — the warning is doing its job, since unanchored patterns really do over-match.
- **WS read cap 512 KiB pre-auth** (`CHISEL_WS_READ_LIMIT`, only 0 disables; negative values use the default) on both sides. The pinned `x/crypto/ssh` accepts transport packets up to 256 KiB; the doubled ceiling clears that with room to spare, so no valid SSH packet is rejected, while retaining a finite pre-auth bound. Custom positive limits remain available through the env knob.
- **UDP at the flow cap:** master permanently blackholed flows past 100; branch sweeps idle over-cap flows (`CHISEL_UDP_DEADLINE` 15s), so DNS-heavy exit nodes recover instead of wedging.
- **Nicer failure edges:** partial `BindRemotes` failure now unbinds earlier listeners (no zombie ports); bad `--keyfile` errors no longer echo raw key material into logs; `go install` builds report real versions; `3000/UDP` uppercase now parses.

---

## 3. Library consumers (Go API)

No compile-breaking signature changes in `client`, `server`, or `share/...`. Additive: `client.Config.MinRetryInterval`, `Client.Ready(ctx)`, `Tunnel.Ready`, `UserIndex.PinUser`. Behavioral: `NewServer` returns errors where master called `log.Fatal` inside (a win for embedders), `Remote.UserAddr()` returns `"socks"` for forward-socks, `L4Proto` lowercases — only code depending on those exact outputs would notice.

---

## 4. Mixed-version deployments

Protocol string is unchanged (`chisel-v3`), and no handshake changes were found.

- **v1.11.x client ↔ 1.12 server:** works. Socks ACL is server-side and already live since v1.11.7; WS cap and ping timeout are old-peer-safe.
- **1.12 client ↔ v1.11.x server:** works, degrading gracefully — no half-close benefit, no dial propagation, no server-side changes; `socks5://` proxy scheme is client-local.

---

## 5. README review

**Strengths:** breaking changes are stated *as* breaking, in the places users actually look (flag help, auth section, changelog); the env-var table surfaces a dozen previously undiscoverable knobs with sides and defaults (all verified against the code — `PING_TIMEOUT`, `WS_READ_LIMIT`, `UDP_*`, `SHUTDOWN_GRACE`, `DIAL_TIMEOUT`); the dead Heroku demo is replaced with a working fly.io recipe (linked `example/fly.toml` and `example/reverse-tunneling-authenticated.md` both exist); new TLS, CDN, and reverse-SOCKS-with-authfile guides fill real gaps; version-history typo (`akp`→`apk`) fixed. Several master help-text errors are corrected without behavior changes — verified that `remote-host` already defaulted to `127.0.0.1` in code (master's "0.0.0.0" doc was wrong) and `--backend`/`--proxy` were already aliases on master.

**Gaps found at review time** (all four have since been fixed — see §6):

1. The 1.12 changelog listed only the socks break; the MD5-fingerprint and auth-colon breaks were absent (only covered in prose sections). Changelogs are what people skim before upgrading.
2. Server-side ACL denials log at debug only — invisible to operators diagnosing post-upgrade socks failures without `-v`.
3. Client `--fingerprint` help said fingerprints "must be 44 characters containing a trailing equals" — contradicting the still-supported legacy MD5 colon form described in the Security section.
4. `PING_TIMEOUT` "default: keepalive interval" didn't state what happens with `--keepalive 0`.

---

## 6. Recommendations — all implemented ✅

1. ✅ **Raise ACL denials to info level**: converts the one undocumented-feeling break into a self-diagnosing one. Implemented in `3c66f9b` (`tunnel_out_ssh.go` — denials now log `Denied connection to <dest> (ACL)` without `-v`).
2. ✅ **Add the two missing breaking bullets to the 1.12 changelog** (fingerprint exact-match, auth-colon fatal). Implemented in `c4038c3`.
3. ✅ **Reconcile the `--fingerprint` help text** with the legacy-MD5 reality — help now states legacy MD5 fingerprints are accepted only in full 16-octet form. Implemented in `c4038c3` (main.go + README help copy).
4. ✅ **"Upgrading to 1.12"** README subsection consolidating the four migration items (socks grant, full fingerprints, auth colon, exit codes), placed under the changelog. Implemented in `c4038c3`. The `PING_TIMEOUT` env-table row also now notes it is inert with `--keepalive 0` (verified: the keepalive loop is skipped entirely at `tunnel.go:93`).

---

## 7. Dependency & supply-chain posture

Since the original review the branch was rebased onto current `master` (`310eec3`) and its dependencies brought fully current. These carry **no user-facing behavior change** — they matter for the security and compatibility posture:

- **Go modules:** `golang.org/x/crypto 0.54.0`, `golang.org/x/net 0.57.0`, `golang.org/x/sync 0.22.0`, `github.com/fsnotify/fsnotify 1.10.1` (indirect `x/sys 0.47.0`, `x/text 0.40.0`). `go build ./...`, `go vet ./...`, and `go mod verify` all pass.
- **CI actions:** `actions/checkout v7`, `docker/setup-qemu-action v4`, `docker/setup-buildx-action v4`, `docker/login-action v4`; `docker/build-push-action` was dropped by the goreleaser rework.
- **Dependabot coverage:** every open Dependabot PR (#597–#607) is now covered or superseded on the branch, and master's own crypto bump (#606) was absorbed by the rebase. Bringing master onto these versions should resolve the moderate Dependabot alert currently open on its default branch, if it stems from one of these modules.

---

*Comparison basis: `ai-incoming@e0b639d` vs `master@310eec3` (released v1.11.7). Produced 2026-07-02, revised 2026-07-17.*
Loading