package capability import ( "os" "testing" ) // R-861 (agent v0.146.0): the attacks the old globs let through, each as the exact argv a compromised agent would // send. NONE may match any entry of the new sudoers. The same list ran against the REAL sudo 1.9.16 (a throwaway // container, and `sudo -l -U felhom-agent` on both demo boxes after the bundle): audits/hub-safety-2026-10-05/partF/. // // RED-PROOF: run this list against the v0.145.0 sudoers (git show v0.145.0:configs/felhom-agent.sudoers) → most of // these MATCH (recorded in the same evidence folder). var r861Injections = []string{ // a raw host disk for a guest (pct options smuggled through a vmid glob) "/usr/sbin/pct set 9201 --dev0 /dev/sda -onboot 1", "/usr/sbin/pct set 9201 --dev0 /dev/sda -mp8 /mnt/felhom-drives", "/usr/sbin/pct set 9201 --delete mp0 --dev0 /dev/sda", "/usr/sbin/pct set 9201 -mp0 /var/lib/felhom-agent/guests/9201/bootstrap,mp=/x --dev0 /dev/sda", // a bind mount over /etc through traversal "/usr/bin/mount --bind /mnt/../var/lib/felhom-agent/x/felhom-data /mnt/felhom-drives/x", "/usr/bin/mount --bind /mnt/a/felhom-data /mnt/felhom-drives/../../etc/sudoers.d", "/usr/bin/umount /mnt/felhom-drives/x /", "/usr/bin/chown 100000:100000 /mnt/a/felhom-data /etc/shadow", "/usr/bin/mkdir -p /mnt/felhom-drives/x /etc/systemd/system/evil.mount", // root-read files the agent writes: gone as `install` lines "/usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/units/x.mount /etc/systemd/system/etc-sudoers.d.mount", "/usr/bin/install -m 0755 -- /tmp/felhom-guest-hook-1.sh /var/lib/vz/snippets/felhom-guest-hook.sh", "/usr/bin/install -m 0755 -- /tmp/felhom-shared-parent-1.sh /usr/local/sbin/felhom-shared-parent.sh", "/usr/bin/install -m 0644 /tmp/felhom-resolver-1.conf /etc/dnsmasq.d/felhom-x.conf", "/usr/bin/install -o root -g root -m 0600 -- /var/lib/felhom-agent/wg/wg-felhom.conf /etc/wireguard/wg-felhom.conf", "/usr/bin/install -o root -g root -m 0644 -- /var/lib/felhom-agent/felhom-sshd/sshd_config /etc/felhom-sshd/sshd_config", // the unsigned binary flip "/usr/local/sbin/felhom-selfupdate-guarded apply /var/lib/felhom-agent/selfupdate/felhom-agent-9.9.9 0000000000000000000000000000000000000000000000000000000000000000", // enabling or removing anything that is not ours "/usr/bin/systemctl enable --now -- mnt-hdd_1.mount evil.service", "/usr/bin/systemctl enable --now -- etc-sudoers.d.mount", "/usr/bin/rm -f /etc/systemd/system/mnt-felhomx /etc/passwd", "/usr/bin/rm -f /etc/dnsmasq.d/felhom-x.conf /etc/shadow", "/usr/bin/rmdir /mnt/felhom-drives/x /etc", // nftables commands chained after a set element "/usr/sbin/nft add element inet felhom_oob operator_ips { 10.77.0.250 } ; flush ruleset", // extra options to read-only tools "/usr/sbin/smartctl -a -j /dev/sda -s off", "/usr/sbin/lvs --reportformat json --units b -o lv_name,data_percent,metadata_percent -- pve/data --config x", "/usr/sbin/pct exec 9201 --keep-env -- docker inspect -f x felhom-controller", "/usr/sbin/pct unlock 9201 --whatever", // the checker with a path it must never take "/usr/local/sbin/felhom-priv-apply unit ../../etc/x.mount", "/usr/local/sbin/felhom-priv-apply dnsmasq /etc/shadow felhom-x.conf", "/usr/local/sbin/felhom-priv-apply wg /etc/shadow", } func TestSudoersRefusesTheR861Injections(t *testing.T) { data, err := os.ReadFile(sudoersPath) if err != nil { t.Fatal(err) } entries := parseSudoersEntries(t, string(data)) for _, c := range r861Injections { if matchesAny(c, entries) { t.Errorf("the sudoers still allows: %s", c) } } }