Keep diagnostics strictly local

Discard legacy network allowlists, report the actual loopback-only runtime contract, and return a generic safe error if the final diagnostic reply boundary fails.
This commit is contained in:
Sucukdeluxe
2026-08-13 21:13:34 +02:00
parent 3ced148ee8
commit a7fb3421f1
2 changed files with 16 additions and 5 deletions
+5 -5
View File
@@ -3206,13 +3206,13 @@ function _buildDiagnosticHandler() {
return (msg, _client, reply) => { return (msg, _client, reply) => {
let result; let result;
try { result = agent.handle(msg.op, msg.args); } try { result = agent.handle(msg.op, msg.args); }
catch (e) { result = { ok: false, error: String((e && e.message) || e) }; } catch { result = { ok: false, error: 'diagnostic response could not be safely returned' }; }
reply(result); reply(result);
}; };
} }
function _diagAllowlist(diag) { function _diagAllowlist() {
return Array.isArray(diag && diag.allowlist) ? diag.allowlist.map((x) => String(x).trim()).filter(Boolean) : []; return [];
} }
function _diagBindHost() { function _diagBindHost() {
@@ -3320,10 +3320,10 @@ ipcMain.handle('diagnostics:status', () => {
return { return {
running: !!diagnosticAgent, running: !!diagnosticAgent,
port: diagnosticAgent ? diagnosticAgent.getPort() : (diag.port || 9110), port: diagnosticAgent ? diagnosticAgent.getPort() : (diag.port || 9110),
bindMode: diag.bindMode === 'network' ? 'network' : 'local', bindMode: 'local',
bindAddress: _diagBindHost(diag), bindAddress: _diagBindHost(diag),
publicHost: _diagPublicHost(diag), publicHost: _diagPublicHost(diag),
allowlistCount: _diagAllowlist(diag).length, allowlistCount: 0,
clientCount: diagnosticAgent ? diagnosticAgent.getClientCount() : 0, clientCount: diagnosticAgent ? diagnosticAgent.getClientCount() : 0,
lastAccess: diagnosticAgent ? diagnosticAgent.getLastAccess() : null lastAccess: diagnosticAgent ? diagnosticAgent.getLastAccess() : null
}; };
+11
View File
@@ -1,5 +1,7 @@
const { test } = require('node:test'); const { test } = require('node:test');
const assert = require('node:assert'); const assert = require('node:assert');
const fs = require('node:fs');
const path = require('node:path');
const { createAgent } = require('../lib/diagnostics-agent'); const { createAgent } = require('../lib/diagnostics-agent');
const { valueScrub } = require('../lib/support-bundle'); const { valueScrub } = require('../lib/support-bundle');
@@ -97,3 +99,12 @@ test('agent fails closed when response redaction fails', () => {
assert.deepEqual(result, { ok: false, error: 'diagnostic response could not be safely returned' }); assert.deepEqual(result, { ok: false, error: 'diagnostic response could not be safely returned' });
assert.ok(!JSON.stringify(result).includes('must-not-leak')); assert.ok(!JSON.stringify(result).includes('must-not-leak'));
}); });
test('main process keeps diagnostics local and fails closed at its final reply boundary', () => {
const source = fs.readFileSync(path.join(__dirname, '..', 'main.js'), 'utf8');
assert.match(source, /function _diagBindHost\(\)\s*{\s*return '127\.0\.0\.1'/);
assert.match(source, /function _diagPublicHost\(\)\s*{\s*return '127\.0\.0\.1'/);
assert.match(source, /function _diagAllowlist\(\)\s*{\s*return \[\]/);
assert.match(source, /bindMode: 'local'/);
assert.match(source, /catch\s*{\s*result = { ok: false, error: 'diagnostic response could not be safely returned' }/);
});