Conversation
drew
requested review from
a team,
derekwaynecarr,
mrunalp and
sjenning
as code owners
September 25, 2026 23:10
The snap gateway runs as root on plaintext loopback without client authentication, so any local user can operate it. Stop selecting the snap automatically when the snap command is available; Linux installs now default to the Debian or RPM package with the per-user mTLS gateway. The snap path remains available with OPENSHELL_INSTALL_SNAP=1, and hosts that already have the OpenShell snap keep refreshing it rather than gaining a second gateway on the same port. The snap path now warns about unauthenticated local access. Signed-off-by: Drew Newberry <anewberry@nvidia.com>
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
drew
force-pushed
the
fix/installer-snap-opt-in
branch
from
September 25, 2026 23:16
701fe44 to
e0786bb
Compare
Collaborator
Author
|
Superseded by #3726 (branch renamed to |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The snap gateway ran as root on plaintext
127.0.0.1:17670with unauthenticated local access, so any local user could operate it. This PR makes the snap gateway serve TLS and require client certificates, matching the Debian/RPM packages, for bothinstall.shand directsnap installinstalls.Related Issue
No issue required: localized hardening of the snap packaging default.
Changes
snap-gateway-wrapper.sh: stop forcingOPENSHELL_DISABLE_TLS=true. The gateway now serves TLS from the bundle the wrapper already generates in$SNAP_COMMON/tls.snap/hooks/install: the default config enables[openshell.gateway.mtls_auth]instead ofallow_unauthenticated_users = true. It also replaces the exact legacy default config; operator-edited configs, symlinks, and directories are still left untouched.snap/hooks/post-refresh(new): runs the install hook so existing installs migrate on refresh. The change takes effect when the gateway restarts (refresh-mode: endure).install.sh: waits for the gateway before registering, probes HTTPS then HTTP to detect the snap revision, copies the client bundle (root reads, target user writes,0600/0700) into~/snap/openshell/common/.local/state/openshell/tls, and registershttps://127.0.0.1:17670 --local. Older plaintext revisions still register over HTTP with a warning.snapcraft.yaml: description shows the manual client-cert copy and HTTPS registration for directsnap installusers.mTLS user authentication enabledin the gateway journal and an HTTPS registration.The earlier commits on this branch (installer opt-in) are superseded; the net diff contains only the mTLS change. Published docs (
docs/about/installation.mdx) still describe the plaintext snap and will be updated in a follow-up.Upgrade impact: after refresh and gateway restart, existing CLI registrations pointing at
http://127.0.0.1:17670stop working. Rerunninginstall.shre-registers over HTTPS. Sandboxes created under the plaintext gateway may need to be recreated.Testing
mise run pre-commitpassestest-install-sh.sh(flow order, HTTPS vs legacy HTTP registration, bundle copy perms),test-snap-install-hook.sh(new default, legacy migration, edited-legacy preserved, post-refresh),test-snap-gateway-wrapper.sh,test-packaging-assets.shChecklist
🤖 Generated with Claude Code