- xdp: CString for if_nametoindex (was UB), real detach via prog fd (fabricated borrow_raw(-1) silently never detached), SAFETY comments, saturating expiry math; +5 unit tests - redis: real pubsub reconnect with exponential backoff (was sleep+return); KEYS -> SCAN in heartbeat sweep - ci: cargo test --all-features, repo-gates job — module size gate (scripts/check_module_size.sh, ratchet baseline) + default-secrets grep - refactor src/ to <=250 LOC/file, <=4 .rs/dir without behavior change; thin bins (rampart.rs 330 -> 6 LOC), new app/, subnet/, intel/, profile/, prefix/, challenge/, filter/, probe/, inventory/, metrics/, node/ - docs: TODO v5.0 (status refresh, new rules, findings backlog), README quickstart now matches real binaries - verify: fmt/clippy -D warnings/test --all-features (164 tests)/clang XDP green
63 lines
2.2 KiB
Bash
Executable file
63 lines
2.2 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
#
|
|
# check_default_secrets.sh — reject the placeholder secret "changeme"
|
|
# committed as a real value in code, deploy configs, or docs.
|
|
#
|
|
# Intentional occurrences are whitelisted in two layers:
|
|
# 1. File level — the validation code itself:
|
|
# src/bin/rampart-manager.rs (startup guard rejecting the default)
|
|
# src/manager/api/auth.rs (test constant)
|
|
# 2. Line level — only lines that *use* "changeme" as a value are reported.
|
|
# A matching line is skipped when it contains "must not be" or "test"
|
|
# (case-insensitive), states the prohibition ("запр" root: запрет /
|
|
# запрещено / запрещён — the project docs are partly Russian), or is a
|
|
# comment / markdown table row (starts with '#', '//', '*', '|', '--').
|
|
#
|
|
# Any remaining occurrence is an offender -> exit 1, offending lines listed.
|
|
|
|
set -u
|
|
|
|
PATTERN="changeme"
|
|
SCAN_DIRS="src deploy docs"
|
|
FILE_WHITELIST="src/bin/rampart-manager.rs src/manager/api/auth.rs"
|
|
|
|
cd "$(CDPATH= cd -- "$(dirname -- "$0")/.." && pwd)" || exit 1
|
|
|
|
found=0
|
|
for dir in $SCAN_DIRS; do
|
|
[ -d "$dir" ] || continue
|
|
while IFS= read -r match; do
|
|
file="${match%%:*}"
|
|
rest="${match#*:}"
|
|
lineno="${rest%%:*}"
|
|
content="${rest#*:}"
|
|
|
|
skip=0
|
|
for whitelisted in $FILE_WHITELIST; do
|
|
[ "$file" = "$whitelisted" ] && skip=1
|
|
done
|
|
if printf '%s' "$content" | grep -qiE 'must not be|test|запр'; then
|
|
skip=1
|
|
fi
|
|
trimmed="${content#"${content%%[![:space:]]*}"}"
|
|
if [ "${trimmed:0:2}" = "//" ] || [ "${trimmed:0:2}" = "--" ]; then
|
|
skip=1
|
|
fi
|
|
case "${trimmed:0:1}" in
|
|
'#'|'*'|'|') skip=1 ;;
|
|
esac
|
|
|
|
if [ "$skip" -eq 0 ]; then
|
|
found=1
|
|
printf 'FAIL %s:%s: %s\n' "$file" "$lineno" "$trimmed" >&2
|
|
fi
|
|
done < <(grep -rn --binary-files=without-match "$PATTERN" "$dir" 2>/dev/null)
|
|
done
|
|
|
|
if [ "$found" -ne 0 ]; then
|
|
echo "secrets gate: FAIL — 'changeme' used as a value (see lines above)" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "secrets gate: PASS — no unexpected '$PATTERN' occurrences in: $SCAN_DIRS"
|
|
exit 0
|