Skip to content

fix(snap): require mTLS for the snap gateway - #3725

Closed
drew wants to merge 2 commits into
mainfrom
fix/installer-snap-opt-in
Closed

drew wants to merge 2 commits into
mainfrom
fix/installer-snap-opt-in

Conversation

@drew

@drew drew commented Sep 25, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

The snap gateway ran as root on plaintext 127.0.0.1:17670 with unauthenticated local access, so any local user could operate it. This PR makes the snap gateway serve TLS and require client certificates, matching the Debian/RPM packages, for both install.sh and direct snap install installs.

Related Issue

No issue required: localized hardening of the snap packaging default.

Changes

  • snap-gateway-wrapper.sh: stop forcing OPENSHELL_DISABLE_TLS=true. The gateway now serves TLS from the bundle the wrapper already generates in $SNAP_COMMON/tls.
  • snap/hooks/install: the default config enables [openshell.gateway.mtls_auth] instead of allow_unauthenticated_users = true. It also replaces the exact legacy default config; operator-edited configs, symlinks, and directories are still left untouched.
  • snap/hooks/post-refresh (new): runs the install hook so existing installs migrate on refresh. The change takes effect when the gateway restarts (refresh-mode: endure).
  • install.sh: waits for the gateway before registering, probes HTTPS then HTTP to detect the snap revision, copies the client bundle (root reads, target user writes, 0600/0700) into ~/snap/openshell/common/.local/state/openshell/tls, and registers https://127.0.0.1:17670 --local. Older plaintext revisions still register over HTTP with a warning.
  • snapcraft.yaml: description shows the manual client-cert copy and HTTPS registration for direct snap install users.
  • Release canary: the snap lane asserts mTLS user authentication enabled in the gateway journal and an HTTPS registration.

The earlier commits on this branch (installer opt-in) are superseded; the net diff contains only the mTLS change. Published docs (docs/about/installation.mdx) still describe the plaintext snap and will be updated in a follow-up.

Upgrade impact: after refresh and gateway restart, existing CLI registrations pointing at http://127.0.0.1:17670 stop working. Rerunning install.sh re-registers over HTTPS. Sandboxes created under the plaintext gateway may need to be recreated.

Testing

  • mise run pre-commit passes
  • Unit tests added/updated: test-install-sh.sh (flow order, HTTPS vs legacy HTTP registration, bundle copy perms), test-snap-install-hook.sh (new default, legacy migration, edited-legacy preserved, post-refresh), test-snap-gateway-wrapper.sh, test-packaging-assets.sh
  • E2E tests added/updated (if applicable): canary snap lane updated; not yet run against a built snap

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable): deferred to follow-up

🤖 Generated with Claude Code

The snap gateway runs as root on plaintext loopback without client
authentication, so any local user can operate it. Stop selecting the snap
automatically when the snap command is available; Linux installs now default
to the Debian or RPM package with the per-user mTLS gateway.

The snap path remains available with OPENSHELL_INSTALL_SNAP=1, and hosts that
already have the OpenShell snap keep refreshing it rather than gaining a
second gateway on the same port. The snap path now warns about unauthenticated
local access.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
@drew
drew force-pushed the fix/installer-snap-opt-in branch from 701fe44 to e0786bb Compare September 25, 2026 23:16
@drew drew closed this Sep 25, 2026
@drew drew changed the title fix(install): make the snap install opt-in fix(snap): require mTLS for the snap gateway Sep 25, 2026
@drew

drew commented Sep 25, 2026

Copy link
Copy Markdown
Collaborator Author

Superseded by #3726 (branch renamed to fix/snap-gateway-mtls and history squashed).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant