Compare commits

...

16 Commits

Author SHA1 Message Date
Laan Tungir
cc5638b6e7 v0.0.21 - Add C reference client library, examples, and integration test migration 2026-05-05 11:44:43 -04:00
Laan Tungir
cc797a16df v0.0.20 - Implement TCP auth envelope verification with signed caller pubkey identity, replay protection, tests, and deferred NIP-46 bunker plan 2026-05-05 11:22:58 -04:00
Laan Tungir
17a1b3f020 v0.0.19 - Publish release with prompt options for verb-only vs all-verbs session approval 2026-05-05 07:39:40 -04:00
Laan Tungir
659aeb934a v0.0.18 - Add prompt options for verb-only session grant vs all-verbs session grant 2026-05-05 07:33:22 -04:00
Laan Tungir
148259040c v0.0.17 - Add n_OS_tr agent migration guide for deny-by-default approval workflow 2026-05-04 19:02:41 -04:00
Laan Tungir
7ffba2b678 v0.0.16 - Implement deny-by-default approval model with on-demand nostr_index derivation and --preapprove CLI flag 2026-05-04 18:44:40 -04:00
Laan Tungir
cfaa8ff637 v0.0.15 - Publish downloadable release assets for selector parsing fix 2026-05-04 08:06:32 -04:00
Laan Tungir
1317de5cbe v0.0.14 - Create downloadable release for selector parsing fix 2026-05-04 08:05:38 -04:00
Laan Tungir
fac0ce6503 v0.0.13 - Fix selector parsing to use last params element for nostr_index options 2026-05-04 08:03:17 -04:00
Laan Tungir
ae95ae6859 v0.0.12 - Fix release flow: always increment version in -r mode; include startup confirmations and latest-version installer behavior 2026-05-04 07:21:30 -04:00
Laan Tungir
3efb0edb61 v0.0.11 - Improve startup UX messaging and installer defaults: show mnemonic acceptance, readiness state, and auto-resolve latest release version 2026-05-04 07:18:27 -04:00
Laan Tungir
c5fdb1a207 v0.0.11 - Improve startup UX: print version, visible mnemonic entry, retry up to 10 attempts, and support q/x quit 2026-05-04 07:02:40 -04:00
Laan Tungir
28f50a750f v0.0.10 - Fix ARM64 static release build via buildx/QEMU and arch-aware nostr_core linking 2026-05-04 05:57:46 -04:00
Laan Tungir
1dd6630311 v0.0.9 - Add timestamped stdout activity logging for TCP mode and show full .fips signer URL in startup helper 2026-05-03 20:37:11 -04:00
Laan Tungir
252d026991 v0.0.8 - Add FIPS npub-aware approval prompt and simplify qube installer to nsigner-only startup flow 2026-05-03 19:50:29 -04:00
Laan Tungir
f9d7b94962 v0.0.7 - Allow TCP non-loopback IPv4/IPv6 binds for FIPS reachability 2026-05-03 11:41:42 -04:00
42 changed files with 4406 additions and 369 deletions

View File

@@ -0,0 +1,7 @@
---
description: "This increments our git tag and version number, along with compiling and uploading a new release to our gitea page."
---
Run increment_and_push.sh -r -p, and supply a good git commit message. For example:
./increment_and_push.sh "Fixed the bug with nip05 implementation"

View File

@@ -46,7 +46,10 @@ RUN cd /tmp && \
# Copy and build nostr_core_lib from project resources
COPY resources/nostr_core_lib /build/nostr_core_lib/
RUN cd /build/nostr_core_lib && \
RUN if [ "$(uname -m)" = "aarch64" ] && ! command -v aarch64-linux-gnu-gcc >/dev/null 2>&1; then \
ln -s "$(command -v gcc)" /usr/local/bin/aarch64-linux-gnu-gcc; \
fi && \
cd /build/nostr_core_lib && \
chmod +x ./build.sh && \
./build.sh --nips=1,4,6,19,44
@@ -54,7 +57,14 @@ RUN cd /build/nostr_core_lib && \
COPY src/ /build/src/
# Build nsigner as a fully static binary
RUN gcc -static -Os -ffunction-sections -fdata-sections -Wl,--gc-sections -s -Wall -Wextra -std=c99 \
RUN ARCH="$(uname -m)"; \
case "$ARCH" in \
aarch64|arm64) NOSTR_LIB="/build/nostr_core_lib/libnostr_core_arm64.a" ;; \
x86_64|amd64) NOSTR_LIB="/build/nostr_core_lib/libnostr_core_x64.a" ;; \
*) echo "Unsupported build arch: $ARCH"; exit 1 ;; \
esac; \
[ -f "$NOSTR_LIB" ] || { echo "Missing nostr core lib: $NOSTR_LIB"; ls -la /build/nostr_core_lib; exit 1; }; \
gcc -static -Os -ffunction-sections -fdata-sections -Wl,--gc-sections -s -Wall -Wextra -std=c99 \
-I/build/nostr_core_lib \
-I/build/nostr_core_lib/nostr_core \
-I/build/nostr_core_lib/cjson \
@@ -70,7 +80,7 @@ RUN gcc -static -Os -ffunction-sections -fdata-sections -Wl,--gc-sections -s -Wa
/build/src/transport_frame.c \
/build/src/key_store.c \
/build/src/socket_name.c \
/build/nostr_core_lib/libnostr_core_x64.a \
"$NOSTR_LIB" \
-o /build/nsigner_static \
$(pkg-config --static --libs libcurl openssl) \
-lsecp256k1 -lsqlite3 -lz -lpthread -lm

View File

@@ -5,6 +5,8 @@ LDFLAGS := -Wl,--gc-sections resources/nostr_core_lib/libnostr_core_x64.a -lz -l
SRC_DIR := src
BUILD_DIR := build
TEST_DIR := tests
CLIENT_DIR := client
EXAMPLES_DIR := examples
TARGET_DEV := $(BUILD_DIR)/nsigner
@@ -20,7 +22,8 @@ SOURCES := \
$(SRC_DIR)/server.c \
$(SRC_DIR)/transport_frame.c \
$(SRC_DIR)/key_store.c \
$(SRC_DIR)/socket_name.c
$(SRC_DIR)/socket_name.c \
$(SRC_DIR)/auth_envelope.c
HEADERS :=
@@ -33,8 +36,11 @@ TEST_DISPATCHER_TARGET := $(BUILD_DIR)/test_dispatcher
TEST_POLICY_TARGET := $(BUILD_DIR)/test_policy
TEST_INTEGRATION_TARGET := $(BUILD_DIR)/test_integration
TEST_SOCKET_NAME_TARGET := $(BUILD_DIR)/test_socket_name
TEST_AUTH_ENVELOPE_TARGET := $(BUILD_DIR)/test_auth_envelope
EXAMPLE_GET_PUBLIC_KEY_TARGET := $(BUILD_DIR)/example_get_public_key_client
EXAMPLE_SIGN_EVENT_TARGET := $(BUILD_DIR)/example_sign_event_client
.PHONY: all lib dev static static-debug static-arm64 test test-integration test-mnemonic test-role test-selector test-enforcement test-dispatcher test-policy test-socket-name clean
.PHONY: all lib dev static static-debug static-arm64 test test-integration test-mnemonic test-role test-selector test-enforcement test-dispatcher test-policy test-socket-name test-auth-envelope examples test-client clean
all: dev
@@ -59,7 +65,7 @@ static-arm64:
chmod +x ./build_static.sh
./build_static.sh --arch arm64
test: lib test-mnemonic test-role test-selector test-enforcement test-dispatcher test-policy test-socket-name
test: lib test-mnemonic test-role test-selector test-enforcement test-dispatcher test-policy test-socket-name test-auth-envelope test-client
test-integration: $(TEST_INTEGRATION_TARGET) $(TARGET_DEV)
./$(TEST_INTEGRATION_TARGET)
@@ -85,6 +91,13 @@ test-policy: $(TEST_POLICY_TARGET)
test-socket-name: $(TEST_SOCKET_NAME_TARGET)
./$(TEST_SOCKET_NAME_TARGET)
test-auth-envelope: $(TEST_AUTH_ENVELOPE_TARGET)
./$(TEST_AUTH_ENVELOPE_TARGET)
test-client: examples
examples: $(EXAMPLE_GET_PUBLIC_KEY_TARGET) $(EXAMPLE_SIGN_EVENT_TARGET)
$(TEST_MNEMONIC_TARGET): $(TEST_DIR)/test_mnemonic.c $(SRC_DIR)/mnemonic.c $(SRC_DIR)/secure_mem.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) $(TEST_DIR)/test_mnemonic.c $(SRC_DIR)/mnemonic.c $(SRC_DIR)/secure_mem.c -o $(TEST_MNEMONIC_TARGET) $(LDFLAGS)
@@ -109,13 +122,25 @@ $(TEST_POLICY_TARGET): $(TEST_DIR)/test_policy.c $(SRC_DIR)/policy.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) $(TEST_DIR)/test_policy.c $(SRC_DIR)/policy.c -o $(TEST_POLICY_TARGET) $(LDFLAGS)
$(TEST_INTEGRATION_TARGET): $(TEST_DIR)/test_integration.c
$(TEST_INTEGRATION_TARGET): $(TEST_DIR)/test_integration.c $(CLIENT_DIR)/nsigner_client.c $(SRC_DIR)/auth_envelope.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) $(TEST_DIR)/test_integration.c -o $(TEST_INTEGRATION_TARGET) $(LDFLAGS)
$(CC) $(CFLAGS) -I$(CLIENT_DIR) $(TEST_DIR)/test_integration.c $(CLIENT_DIR)/nsigner_client.c $(SRC_DIR)/auth_envelope.c -o $(TEST_INTEGRATION_TARGET) $(LDFLAGS)
$(TEST_SOCKET_NAME_TARGET): $(TEST_DIR)/test_socket_name.c $(SRC_DIR)/socket_name.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) $(TEST_DIR)/test_socket_name.c $(SRC_DIR)/socket_name.c -o $(TEST_SOCKET_NAME_TARGET) $(LDFLAGS)
$(TEST_AUTH_ENVELOPE_TARGET): $(TEST_DIR)/test_auth_envelope.c $(SRC_DIR)/auth_envelope.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) $(TEST_DIR)/test_auth_envelope.c $(SRC_DIR)/auth_envelope.c -o $(TEST_AUTH_ENVELOPE_TARGET) $(LDFLAGS)
$(EXAMPLE_GET_PUBLIC_KEY_TARGET): $(EXAMPLES_DIR)/get_public_key_client.c $(CLIENT_DIR)/nsigner_client.c $(SRC_DIR)/auth_envelope.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) -I$(CLIENT_DIR) $(EXAMPLES_DIR)/get_public_key_client.c $(CLIENT_DIR)/nsigner_client.c $(SRC_DIR)/auth_envelope.c -o $(EXAMPLE_GET_PUBLIC_KEY_TARGET) $(LDFLAGS)
$(EXAMPLE_SIGN_EVENT_TARGET): $(EXAMPLES_DIR)/sign_event_client.c $(CLIENT_DIR)/nsigner_client.c $(SRC_DIR)/auth_envelope.c
@mkdir -p $(BUILD_DIR)
$(CC) $(CFLAGS) -I$(CLIENT_DIR) $(EXAMPLES_DIR)/sign_event_client.c $(CLIENT_DIR)/nsigner_client.c $(SRC_DIR)/auth_envelope.c -o $(EXAMPLE_SIGN_EVENT_TARGET) $(LDFLAGS)
clean:
rm -rf $(BUILD_DIR)

View File

@@ -239,7 +239,7 @@ Discovery:
- `nsigner list` enumerates currently bound `nsigner_*` abstract sockets by reading `/proc/net/unix`.
- `nsigner --listen stdio` runs one framed JSON-RPC request/response over stdin/stdout.
- `nsigner --listen qrexec` is the same stdio framing mode, but caller identity can be derived from `QREXEC_REMOTE_DOMAIN` (displayed as `qubes:<source-vm>`).
- `nsigner --listen tcp:127.0.0.1:PORT` (or `tcp:[::1]:PORT`) enables loopback-only TCP listening for non-AF_UNIX clients.
- `nsigner --listen tcp:IPv4:PORT` or `tcp:[IPv6]:PORT` enables TCP listening for non-AF_UNIX clients (for example `tcp:127.0.0.1:8080`, `tcp:[::]:8080`, or `tcp:[fd00::1234]:8080`).
### 7.2 ESP32 MCU: USB-CDC serial
@@ -303,10 +303,10 @@ Generic stdio transport mode (single framed request over stdin/stdout):
nsigner --listen stdio
```
TCP loopback transport mode (no TUI; serves requests until terminated):
TCP transport mode (no TUI; serves requests until terminated):
```bash
nsigner --listen tcp:127.0.0.1:8080
nsigner --listen tcp:[::]:8080
```
### 9.2 Send a request (client mode)

View File

@@ -105,12 +105,29 @@ echo "Platform: $PLATFORM"
echo "Output: $BUILD_DIR/$OUTPUT_NAME"
echo ""
if [ "$ARCH" != "$HOST_ARCH" ]; then
echo "[0/3] Preparing buildx + QEMU for cross-architecture build"
if ! docker buildx inspect >/dev/null 2>&1; then
echo "ERROR: docker buildx is not available"
exit 1
fi
docker run --privileged --rm tonistiigi/binfmt --install all >/dev/null
if ! docker buildx inspect nsigner-builder >/dev/null 2>&1; then
docker buildx create --name nsigner-builder --driver docker-container --use >/dev/null
else
docker buildx use nsigner-builder >/dev/null
fi
docker buildx inspect --bootstrap >/dev/null
fi
echo "[1/3] Building builder stage from project root context"
docker build \
docker buildx build \
--platform "$PLATFORM" \
--target builder \
-f "$DOCKERFILE" \
-t "$IMAGE_TAG" \
--load \
"$SCRIPT_DIR"
echo "[2/3] Extracting static binary"

47
client/README.md Normal file
View File

@@ -0,0 +1,47 @@
# n_signer C Reference Client
This directory provides a minimal copy/paste-friendly C client for `n_signer`.
## Files
- `nsigner_client.h` / `nsigner_client.c`:
- Unix abstract socket connect helper
- length-prefixed frame send/receive
- generic request API
- helpers for `get_public_key` and `sign_event`
- optional TCP auth envelope attachment via `auth_envelope_build_for_request()`
## API at a glance
```c
nsigner_client_t client;
nsigner_client_init(&client);
nsigner_client_connect_unix(&client, "nsigner", 5000);
char *resp = NULL;
nsigner_client_get_public_key(&client, "1", "", &resp);
free(resp);
nsigner_client_close(&client);
```
## Auth envelope usage
If transport requires auth envelopes (for TCP mode), set a private key once:
```c
unsigned char privkey[32] = { /* caller key */ };
nsigner_client_set_auth(&client, privkey, "example-client");
```
Subsequent requests automatically include an `auth` object.
## Ownership rules
- Any `out_response_json` returned by the API must be freed by caller using `free()`.
- `nsigner_client_close()` only closes the socket; it does not free the client struct itself.
## License
Source files in this directory use SPDX `0BSD` headers for permissive reuse in external projects.

369
client/nsigner_client.c Normal file
View File

@@ -0,0 +1,369 @@
/*
* SPDX-License-Identifier: 0BSD
*/
#define _GNU_SOURCE
#include "nsigner_client.h"
#include <arpa/inet.h>
#include <errno.h>
#include <stdarg.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/socket.h>
#include <sys/types.h>
#include <sys/un.h>
#include <time.h>
#include <unistd.h>
#include <cJSON.h>
#include "auth_envelope.h"
#define NSIGNER_CLIENT_MAX_FRAME (65536U)
static void client_set_error(nsigner_client_t *client, const char *fmt, ...) {
va_list ap;
if (client == NULL) {
return;
}
va_start(ap, fmt);
vsnprintf(client->last_error, sizeof(client->last_error), fmt, ap);
va_end(ap);
}
static int write_full(int fd, const void *buf, size_t len) {
const unsigned char *p = (const unsigned char *)buf;
size_t off = 0;
while (off < len) {
ssize_t n = write(fd, p + off, len - off);
if (n < 0) {
if (errno == EINTR) {
continue;
}
return -1;
}
off += (size_t)n;
}
return 0;
}
static int read_full(int fd, void *buf, size_t len) {
unsigned char *p = (unsigned char *)buf;
size_t off = 0;
while (off < len) {
ssize_t n = read(fd, p + off, len - off);
if (n == 0) {
return -1;
}
if (n < 0) {
if (errno == EINTR) {
continue;
}
return -1;
}
off += (size_t)n;
}
return 0;
}
static int send_framed(int fd, const char *payload) {
uint32_t len;
uint32_t be_len;
if (payload == NULL) {
return -1;
}
len = (uint32_t)strlen(payload);
be_len = htonl(len);
if (write_full(fd, &be_len, sizeof(be_len)) != 0) {
return -1;
}
if (write_full(fd, payload, len) != 0) {
return -1;
}
return 0;
}
static int recv_framed(int fd, char **out_payload) {
uint32_t be_len;
uint32_t len;
char *payload;
if (out_payload == NULL) {
return -1;
}
*out_payload = NULL;
if (read_full(fd, &be_len, sizeof(be_len)) != 0) {
return -1;
}
len = ntohl(be_len);
if (len == 0 || len > NSIGNER_CLIENT_MAX_FRAME) {
return -1;
}
payload = (char *)malloc((size_t)len + 1U);
if (payload == NULL) {
return -1;
}
if (read_full(fd, payload, len) != 0) {
free(payload);
return -1;
}
payload[len] = '\0';
*out_payload = payload;
return 0;
}
static int sleep_ms(int ms) {
struct timespec ts;
ts.tv_sec = ms / 1000;
ts.tv_nsec = (long)(ms % 1000) * 1000000L;
return nanosleep(&ts, NULL);
}
void nsigner_client_init(nsigner_client_t *client) {
if (client == NULL) {
return;
}
memset(client, 0, sizeof(*client));
client->fd = -1;
client->timeout_ms = 5000;
}
void nsigner_client_close(nsigner_client_t *client) {
if (client == NULL) {
return;
}
if (client->fd >= 0) {
close(client->fd);
client->fd = -1;
}
}
int nsigner_client_connect_unix(nsigner_client_t *client,
const char *socket_name,
int timeout_ms) {
struct sockaddr_un addr;
socklen_t addr_len;
int elapsed = 0;
if (client == NULL || socket_name == NULL || socket_name[0] == '\0') {
return -1;
}
timeout_ms = (timeout_ms > 0) ? timeout_ms : 5000;
nsigner_client_close(client);
memset(&addr, 0, sizeof(addr));
addr.sun_family = AF_UNIX;
addr.sun_path[0] = '\0';
strncpy(&addr.sun_path[1], socket_name, sizeof(addr.sun_path) - 2);
addr.sun_path[sizeof(addr.sun_path) - 1] = '\0';
addr_len = (socklen_t)(sizeof(sa_family_t) + 1 + strlen(socket_name));
while (elapsed < timeout_ms) {
int fd = socket(AF_UNIX, SOCK_STREAM, 0);
if (fd < 0) {
client_set_error(client, "socket failed: %s", strerror(errno));
return -1;
}
if (connect(fd, (struct sockaddr *)&addr, addr_len) == 0) {
client->fd = fd;
client->timeout_ms = timeout_ms;
client_set_error(client, "ok");
return 0;
}
close(fd);
sleep_ms(100);
elapsed += 100;
}
client_set_error(client, "connect timeout: %s", strerror(errno));
return -1;
}
int nsigner_client_set_auth(nsigner_client_t *client,
const unsigned char privkey[32],
const char *label) {
if (client == NULL || privkey == NULL) {
return -1;
}
memcpy(client->auth_privkey, privkey, 32);
client->auth_enabled = 1;
if (label == NULL) {
label = "";
}
strncpy(client->auth_label, label, sizeof(client->auth_label) - 1);
client->auth_label[sizeof(client->auth_label) - 1] = '\0';
return 0;
}
const char *nsigner_client_last_error(const nsigner_client_t *client) {
if (client == NULL) {
return "invalid_client";
}
return client->last_error;
}
int nsigner_client_request_raw(nsigner_client_t *client,
const char *request_json,
char **out_response_json) {
char *response_json = NULL;
if (client == NULL || request_json == NULL || out_response_json == NULL) {
return -1;
}
if (client->fd < 0) {
client_set_error(client, "not connected");
return -1;
}
*out_response_json = NULL;
if (send_framed(client->fd, request_json) != 0) {
client_set_error(client, "send failed");
return -1;
}
if (recv_framed(client->fd, &response_json) != 0) {
client_set_error(client, "receive failed");
return -1;
}
*out_response_json = response_json;
client_set_error(client, "ok");
return 0;
}
int nsigner_client_request(nsigner_client_t *client,
const char *id,
const char *method,
const cJSON *params,
char **out_response_json) {
cJSON *root = NULL;
cJSON *params_copy = NULL;
cJSON *auth = NULL;
char *request_json = NULL;
int rc = -1;
if (client == NULL || id == NULL || method == NULL || out_response_json == NULL) {
return -1;
}
root = cJSON_CreateObject();
if (root == NULL) {
client_set_error(client, "out of memory");
goto cleanup;
}
cJSON_AddStringToObject(root, "id", id);
cJSON_AddStringToObject(root, "method", method);
if (params != NULL) {
params_copy = cJSON_Duplicate((cJSON *)params, 1);
} else {
params_copy = cJSON_CreateArray();
}
if (params_copy == NULL) {
client_set_error(client, "failed to create params");
goto cleanup;
}
cJSON_AddItemToObject(root, "params", params_copy);
if (client->auth_enabled) {
if (auth_envelope_build_for_request(id,
method,
params_copy,
client->auth_privkey,
client->auth_label,
time(NULL),
&auth) != 0) {
client_set_error(client, "failed to build auth envelope");
goto cleanup;
}
cJSON_AddItemToObject(root, "auth", auth);
auth = NULL;
}
request_json = cJSON_PrintUnformatted(root);
if (request_json == NULL) {
client_set_error(client, "failed to serialize request");
goto cleanup;
}
rc = nsigner_client_request_raw(client, request_json, out_response_json);
cleanup:
cJSON_Delete(root);
cJSON_Delete(auth);
free(request_json);
return rc;
}
int nsigner_client_get_public_key(nsigner_client_t *client,
const char *id,
const char *selector,
char **out_response_json) {
cJSON *params = cJSON_CreateArray();
int rc;
if (params == NULL) {
return -1;
}
cJSON_AddItemToArray(params, cJSON_CreateString((selector != NULL) ? selector : ""));
rc = nsigner_client_request(client, id, "get_public_key", params, out_response_json);
cJSON_Delete(params);
return rc;
}
int nsigner_client_sign_event(nsigner_client_t *client,
const char *id,
const char *event_json,
const char *role,
char **out_response_json) {
cJSON *params = cJSON_CreateArray();
cJSON *opts = cJSON_CreateObject();
int rc;
if (params == NULL || opts == NULL || event_json == NULL) {
cJSON_Delete(params);
cJSON_Delete(opts);
return -1;
}
cJSON_AddItemToArray(params, cJSON_CreateString(event_json));
if (role != NULL && role[0] != '\0') {
cJSON_AddStringToObject(opts, "role", role);
}
cJSON_AddItemToArray(params, opts);
rc = nsigner_client_request(client, id, "sign_event", params, out_response_json);
cJSON_Delete(params);
return rc;
}

56
client/nsigner_client.h Normal file
View File

@@ -0,0 +1,56 @@
/*
* SPDX-License-Identifier: 0BSD
*/
#ifndef NSIGNER_CLIENT_H
#define NSIGNER_CLIENT_H
#include <stddef.h>
#include <stdint.h>
#include <cJSON.h>
typedef struct {
int fd;
int timeout_ms;
unsigned char auth_privkey[32];
int auth_enabled;
char auth_label[64];
char last_error[128];
} nsigner_client_t;
void nsigner_client_init(nsigner_client_t *client);
void nsigner_client_close(nsigner_client_t *client);
int nsigner_client_connect_unix(nsigner_client_t *client,
const char *socket_name,
int timeout_ms);
int nsigner_client_set_auth(nsigner_client_t *client,
const unsigned char privkey[32],
const char *label);
const char *nsigner_client_last_error(const nsigner_client_t *client);
int nsigner_client_request_raw(nsigner_client_t *client,
const char *request_json,
char **out_response_json);
int nsigner_client_request(nsigner_client_t *client,
const char *id,
const char *method,
const cJSON *params,
char **out_response_json);
int nsigner_client_get_public_key(nsigner_client_t *client,
const char *id,
const char *selector,
char **out_response_json);
int nsigner_client_sign_event(nsigner_client_t *client,
const char *id,
const char *event_json,
const char *role,
char **out_response_json);
#endif

View File

@@ -6,14 +6,21 @@ This document is the client-integration spec for `nsigner`.
It is written for agent/tool authors implementing robust request flows against the local signer process.
Reference implementation in this repository:
- Reusable C client library: `client/nsigner_client.h` + `client/nsigner_client.c`
- Minimal usage examples: `examples/get_public_key_client.c` and `examples/sign_event_client.c`
- Auth envelope builder used by the client: `src/auth_envelope.h` (`auth_envelope_build_for_request`)
---
## 2. Discovery and socket targeting
`nsigner` currently supports two transport families:
`nsigner` currently supports three transport families:
- Linux AF_UNIX **abstract namespace** sockets.
- Stdio framed mode (`--listen stdio` and `--listen qrexec`) for one request/response exchange.
- TCP framed mode (`--listen tcp:IPv4:PORT` or `--listen tcp:[IPv6]:PORT`).
For AF_UNIX:
@@ -54,6 +61,14 @@ In server mode:
This mode is server-side only in the current CLI (the `client` subcommand still targets AF_UNIX).
### 2.4 TCP mode authentication (required)
For TCP transport, requests MUST include an `auth` object containing a signed Nostr-style event envelope.
- Missing `auth` returns `{"error":{"code":2014,"message":"auth_envelope_required"}}`.
- Signature verification, method/id/body binding, timestamp skew checks, and replay checks are enforced before policy lookup.
- On success, caller identity is normalized to `pubkey:<hex>` for policy checks.
---
## 3. Transport framing
@@ -147,6 +162,14 @@ Representative error names clients must handle:
- `unauthorized`
- `approval_denied`
- `internal_error`
- `auth_envelope_malformed` (2010)
- `auth_body_mismatch` (2011)
- `auth_signature_invalid` (2012)
- `auth_kind_invalid` (2013)
- `auth_envelope_required` (2014)
- `auth_envelope_mismatch` (2015)
- `auth_envelope_stale` (2016)
- `auth_replay_detected` (2017)
### 5.1 Recovery guidance
@@ -158,6 +181,7 @@ Representative error names clients must handle:
- `unauthorized`: caller identity disallowed by policy; do not blind-retry.
- `approval_denied`: user rejected prompt; treat as final unless user initiates retry.
- `internal_error`: bounded retry with backoff; surface diagnostics.
- `auth_envelope_*` / `auth_*` (2010-2017): fix request signing/auth envelope generation; do not blind-retry unchanged payloads.
---

View File

@@ -2,17 +2,17 @@
## 1. Scope
This runbook covers a practical Tier-1 deployment of `nsigner` over a loopback TCP listener, with connectivity provided by FIPS as the network substrate.
This runbook covers a practical Tier-1 deployment of `nsigner` over a TCP listener, with connectivity provided by FIPS as the network substrate.
Tier-1 objective:
- Keep `nsigner` transport simple (`--listen tcp:127.0.0.1:PORT` or `--listen tcp:[::1]:PORT`).
- Keep `nsigner` transport simple (`--listen tcp:IPv4:PORT` or `--listen tcp:[IPv6]:PORT`).
- Use FIPS to carry traffic between peers.
- Do not add FIPS runtime dependencies into `nsigner`.
Out of scope in this document:
- Remote non-loopback TCP exposure (`--allow-remote`, TLS) planned for later phase.
- Mandatory transport-level TLS/authentication hardening (still planned for a later phase).
- Automatic caller->npub enrichment from FIPS session metadata.
---
@@ -22,17 +22,17 @@ Out of scope in this document:
Two cooperating layers:
1. **Signer process layer** (`nsigner`)
- Listens on loopback TCP only.
- Listens on operator-selected TCP endpoint (IPv4 or IPv6).
- Uses existing 4-byte big-endian framed JSON-RPC protocol.
- Keeps existing policy/prompt behavior.
2. **Network substrate layer** (FIPS)
- Establishes peer connectivity between nodes/qubes.
- Carries application traffic to a local loopback endpoint on each side.
- Carries application traffic to the configured signer TCP endpoint.
Conceptually:
`client app -> local FIPS endpoint -> FIPS mesh -> remote FIPS endpoint -> 127.0.0.1:PORT -> nsigner`
`client app -> local FIPS endpoint -> FIPS mesh -> remote FIPS endpoint -> signer TCP endpoint -> nsigner`
---
@@ -58,21 +58,21 @@ Operational assumptions:
## 4. Start signer in Tier-1 TCP mode
Run `nsigner` in loopback TCP listen mode:
Run `nsigner` in TCP listen mode:
```bash
./build/nsigner --listen tcp:127.0.0.1:8080
./build/nsigner --listen tcp:[::]:8080
```
Or IPv6 loopback:
Or bind to a specific FIPS ULA address:
```bash
./build/nsigner --listen tcp:[::1]:8080
./build/nsigner --listen tcp:[fd00::1234]:8080
```
Behavior notes:
- Non-loopback values are rejected by design.
- Bind target is operator-controlled; pick the narrowest reachable address that satisfies your topology.
- No TUI hotkey loop is required in TCP mode; process serves requests until terminated.
- Caller identity is shown as a TCP endpoint descriptor in activity/prompt context.
@@ -82,14 +82,14 @@ Behavior notes:
Because FIPS deployment topologies vary, use this generic pattern:
1. Bind `nsigner` on loopback in signer environment.
2. Configure FIPS service/forwarding so remote authenticated peer traffic is delivered to that loopback endpoint.
1. Bind `nsigner` on a deliberate signer endpoint (`[::]:PORT` for broad reach, or specific `fd..` for tighter scope).
2. Configure FIPS service/forwarding so remote authenticated peer traffic is delivered to that signer endpoint.
3. On caller side, direct client traffic to the local FIPS ingress endpoint for that remote service.
Validation checklist:
- FIPS session is established between caller and signer nodes.
- Transport path from caller -> signer loopback endpoint succeeds.
- Transport path from caller -> configured signer endpoint succeeds.
- `nsigner` receives framed request and returns framed response.
---
@@ -134,7 +134,7 @@ Trigger a request path that requires prompt/denial and confirm client handles po
## 7. Security guardrails
- Keep listener loopback-only in Tier-1.
- Prefer binding to a specific FIPS IPv6 ULA (`fd..`) rather than wildcard (`[::]`) when possible.
- Do not expose signer port directly on LAN/WAN.
- Keep FIPS peer allowlist tight; avoid broad trust domains.
- Treat FIPS connectivity as transport, not authorization bypass.
@@ -147,20 +147,12 @@ Trigger a request path that requires prompt/denial and confirm client handles po
### 8.1 `invalid tcp listen target`
Cause:
- `--listen` argument does not match `tcp:HOST:PORT` or `tcp:[::1]:PORT`.
- `--listen` argument does not match `tcp:HOST:PORT` or `tcp:[IPv6]:PORT`.
Fix:
- Use explicit loopback host and valid numeric port.
- Use valid numeric port and valid IPv4/IPv6 literal host.
### 8.2 `non-loopback TCP bind denied`
Cause:
- Attempt to bind non-loopback target in Tier-1 mode.
Fix:
- Switch to `127.x.x.x` or `::1` target.
### 8.3 Framing parse failures (`parse_error`)
### 8.2 Framing parse failures (`parse_error`)
Cause:
- Client sent line-delimited/raw JSON instead of framed JSON.
@@ -168,7 +160,7 @@ Cause:
Fix:
- Send 4-byte big-endian length prefix followed by exact UTF-8 JSON payload bytes.
### 8.4 FIPS path up, signer path down
### 8.3 FIPS path up, signer path down
Cause:
- FIPS session exists but forwarding/service mapping to signer loopback endpoint is missing.

View File

@@ -0,0 +1,56 @@
# n_OS_tr Agent Guide: Handling n_signer v0.0.16 Changes
This is a short operational guide for the n_OS_tr agent after the approval-model update in `n_signer`.
## What changed
- `n_signer` is now **deny-by-default**.
- First-time caller/index combinations require approval unless preapproved.
- `nostr_index` values can be auto-derived on approval.
- Policy decisions are visible in activity labels: `:preapprove`, `:session-grant`, `:prompt`, `:no-match`.
## What the agent should do
1. **Always send explicit selector options** in the last `params` item:
- Prefer `{"nostr_index": N}` for service identities.
2. **Expect `policy_denied` on first contact** if caller/index is not preapproved.
3. **Do not retry blindly** on `policy_denied`.
- Surface a clear status: "approval needed".
4. **Treat `unknown_role` as actionable**:
- If using `nostr_index`, request again only after human approval or valid preapprove config.
5. **Use stable caller identity** (service name / VM identity) so preapprove rules match reliably.
## Required startup pattern for n_OS_tr services
Launch `n_signer` with explicit `--preapprove` entries for each boot service that must sign without prompts.
Example:
```ini
ExecStart=/usr/bin/n_signer \
--preapprove caller=qubes:nostr-relay,role=main \
--preapprove caller=qubes:dm-handler,nostr_index=1 \
--preapprove caller=qubes:contacts,nostr_index=2 \
--preapprove caller=qubes:zaps,nostr_index=3
```
## Agent error-handling policy (recommended)
- `policy_denied` → stop, mark as "awaiting approval/preapprove".
- `unknown_role` with `nostr_index` → stop, mark as "identity not yet approved/created".
- `purpose_mismatch` / `curve_mismatch` → configuration bug; fail hard and alert.
- `ambiguous_role_selector` → client bug; send exactly one selector field.
## Observability checks
When troubleshooting, inspect n_signer activity lines:
- `ALLOWED:preapprove` → expected for boot services.
- `ALLOWED:session-grant` → interactive approval happened earlier this session.
- `ALLOWED:prompt` → just approved now.
- `DENIED:no-match` → no policy entry matched caller/index.
## Operational rule of thumb
For n_OS_tr system services, rely on `--preapprove` at startup.
For ad-hoc/manual clients, rely on interactive prompt approvals.

515
documents/SECURITY.md Normal file
View File

@@ -0,0 +1,515 @@
# SECURITY.md
This document explains how `n_signer` enforces security, written so someone new can understand the model end-to-end without reading the source.
If you only read one section, read [§3 The three concepts](#3-the-three-concepts-identity-index-approval) and [§4 The deny-by-default rule](#4-the-deny-by-default-rule).
> This document describes the security model as implemented in the current release. Design rationale is in [`plans/deny_by_default_approvals.md`](../plans/deny_by_default_approvals.md).
---
## 1. What `n_signer` is, in security terms
`n_signer` is a **single foreground program** that holds a BIP-39 mnemonic in locked memory and signs requests on behalf of local clients. It is not a daemon, not a service, and not a key-management database.
The security posture is intentionally minimalist:
- **One process. One terminal. One human.** The terminal is the trust anchor and the only out-of-band approval surface.
- **No persistence.** Nothing about the running session is written to disk: no config, no logs, no PID files, no socket pathnames, no state recovery.
- **Crash equals total wipe.** All sensitive state — mnemonic, derived keys, the policy table, activity buffer — exists only in process RAM (`mlock`'d where applicable) and is unrecoverable after the process ends.
- **Always-attended operation.** Every first request from a previously unknown caller requires an explicit human approval at the terminal, unless the caller was pre-approved at startup by the OS distribution. Human presence is part of the threat model, not an inconvenience.
Authoritative behavior reference: [`README.md`](../README.md). Implementation roadmap: [`plans/nsigner.md`](../plans/nsigner.md). Approval model plan: [`plans/deny_by_default_approvals.md`](../plans/deny_by_default_approvals.md). Wire contract for clients: [`documents/CLIENT_IMPLEMENTATION.md`](CLIENT_IMPLEMENTATION.md).
---
## 2. Threat model
### 2.1 What `n_signer` is designed to defend against
- **Untrusted local clients** asking the signer to perform operations they should not be allowed to perform.
- **Drive-by signing** — an unattended program quietly producing signatures the user did not consent to.
- **Accidental misuse** — a buggy client connecting to the wrong signer instance, or asking for an identity it should not be using.
- **Post-mortem key recovery** — someone obtaining the disk after a crash, kill, or shutdown and recovering signing keys.
### 2.2 What `n_signer` does **not** defend against
- A compromised kernel or hypervisor (`mlock` cannot save you).
- Physical access while the program is running and the terminal is unlocked.
- A malicious user who knows the mnemonic — `n_signer` is a runtime gatekeeper, not a vault.
- Side channels (timing, power, microarchitectural) that target the underlying crypto libraries.
- Network adversaries when transports without authentication are explicitly enabled (e.g. `tcp_local`).
- An OS distribution that ships a malicious `--preapprove` list in its system unit files. The OS is in scope of trust if it pre-approves anything; see [§7](#7-pre-approvals-the-os-distribution-pathway).
### 2.3 Trust anchors
| Anchor | Why it is trusted |
|---|---|
| The terminal `n_signer` is attached to | The user types the mnemonic into it and answers approval prompts on it. If the terminal is compromised, the session is compromised. |
| The kernel and `mlock` / `getrandom` syscalls | Used for in-memory protection and entropy. |
| The static binary itself | Built reproducibly via [`build_static.sh`](../build_static.sh) and shipped as one musl-static artifact. |
| The launcher that started `n_signer` | Whoever ran the process chose the `--preapprove` flags. In interactive use that's the human; in `n_OS_tr` boot it's the OS init system. The launcher's integrity is part of the trust chain. |
Everything else — clients, other processes, other users, remote callers — is **untrusted by default** and must clear an approval check.
---
## 3. The three concepts: identity, index, approval
This is the entire user-facing security model. There are exactly three things to know.
```text
+----------------+ +-----------------------+ +---------------+
| IDENTITY | | INDEX (or PATH) | | APPROVAL |
| who is asking | +---- | which key to use | ----+ | is this OK? |
+----------------+ | +-----------------------+ | +---------------+
| |
| request resolves to |
+-------> (identity, index/path) -----+
|
v
+----------------------------+
| Approved entry exists? |
+----------------------------+
|yes |no
v v
+-----------------+ +----------------+
| Sign / encrypt | | Prompt human |
+-----------------+ +----------------+
|
[y]/[a] | [n]
allow now | deny
/save |
v v
+-----------------+ +----------------+
| Sign / encrypt | | policy_denied |
+-----------------+ +----------------+
```
### Identity — *who is asking*
An identity is a tagged caller record built from the transport. Different transports produce different identity tags; the signer never invents identity, it always reads it from the kernel or framework.
| Kind | What it carries | Source of truth |
|---|---|---|
| `unix_peer` | `uid`, `pid` from `SO_PEERCRED` on an abstract Unix socket. | Kernel — the client cannot forge it. |
| `qubes` | source qube name from `QREXEC_REMOTE_DOMAIN`. | Qubes RPC framework. |
| `tcp_local` | Loopback address of caller. | TCP socket peer address — opt-in transport. |
| `tcp_remote` | Address plus an authenticated pubkey (planned). | Application-layer authentication. |
| `fips` | Peer npub from a NIP-46 style flow (planned). | Application-layer authentication. |
| `usb_serial` | Device path plus an asserted caller (planned). | Trust-on-first-use. |
Identity quality varies. `unix_peer` and `qubes` are vouched for by the kernel or hypervisor — strong. `tcp_local` and `tcp_remote` are transport-asserted only — only as good as the human at the terminal who chose to approve them.
### Index (or path) — *which key*
The signer can derive many keys from one mnemonic. Clients select one in two equivalent ways:
- `nostr_index = N` — shorthand for the Nostr derivation `m/44'/1237'/N'/0/0` per NIP-06.
- `role_path = "<full BIP-32 path>"` — used for non-Nostr key trees (Bitcoin, SSH, etc.). Pre-registered only; see [§9.2](#92-pre-registration-of-role_path).
The three legacy selector words from the wire protocol — `role`, `nostr_index`, `role_path` — all resolve to a single internal record. From the user's perspective, what matters is "which Nostr identity (by index)" or "which advanced derivation (by path)."
### Approval — *is this OK?*
An approval is an in-memory entry that says: *"this identity may use this index/path."* Approvals come from exactly two sources:
1. **The human at the prompt.** When a request arrives that has no matching approval, the signer blocks the request and asks the user. On `[a]` ("allow this caller for this index/path for the rest of the session") the signer adds a session approval. On `[y]` it allows once without saving. On `[n]` it denies.
2. **Pre-approvals.** When the OS distribution starts `n_signer` with `--preapprove caller=...,nostr_index=...` flags, those become approvals that exist before any request arrives. They never trigger prompts. See [§7](#7-pre-approvals-the-os-distribution-pathway).
Approvals are stored in an in-memory table and vanish on process exit. There is no persistent approval database.
---
## 4. The deny-by-default rule
`n_signer` denies any request whose `(identity, index)` pair has no approval. Period.
There is no special case for "same-uid" callers. There is no implicit grant for the user running their own client. Every first request from every caller goes through an approval — either granted by the user at the prompt, or pre-approved by the OS distribution at startup.
This is the single most important property:
- It removes the assumption that "same-uid means trusted" — an assumption that was always more convenience than security.
- It collapses several mechanisms (policy, role pre-registration, the `[a]` flag) into one (the in-memory approval table).
- It makes the audit trail trivial: every signed operation maps to either a pre-approval declaration or a logged human approval.
---
## 5. The two checks every request must pass
Every signing request runs through this short pipeline. Failure at any step returns an error response and is logged.
```text
+----------------------------------------------------------------+
| 1. CLIENT |
| sends length-prefixed JSON-RPC request |
+----------------------------------------------------------------+
|
v
+----------------------------------------------------------------+
| 2. TRANSPORT |
| - reads framed bytes off the socket |
| - builds caller_identity_t (uid / qubes vm / tcp peer / ...)|
+----------------------------------------------------------------+
|
v
+----------------------------------------------------------------+
| 3. RESOLVE INDEX |
| - parse selector options from request |
| - resolve to a specific (index or path) |
| - reject ambiguous selectors |
+----------------------------------------------------------------+
|
v
+----------------------------------------------------------------+
| 4. APPROVAL CHECK |
| - is there an approval for (this identity, this index)? |
| yes -> ALLOW |
| no -> PROMPT human (or DENY if non-interactive) |
| - on [a], append a session approval and continue |
| - on [y], continue this request only |
| - on [n] / EOF, deny |
+----------------------------------------------------------------+
|
v
+----------------------------------------------------------------+
| 5. ENFORCEMENT (verb x purpose x curve) |
| - is this verb compatible with the key's declared purpose? |
| - reject with purpose_mismatch / curve_mismatch otherwise |
+----------------------------------------------------------------+
|
v
+----------------------------------------------------------------+
| 6. KEY DERIVATION + SIGN |
| - derive key from mnemonic at the resolved path |
| - perform crypto operation |
| - return signed result |
+----------------------------------------------------------------+
|
v
+----------------------------------------------------------------+
| 7. RESPONSE FRAMED + SENT |
| - activity log line appended with the approval source label |
+----------------------------------------------------------------+
```
There are two independent gates: the **approval check** (does this caller have permission to use this key?) and the **enforcement check** (is this operation compatible with this key?). Both must pass.
### 5.1 Approval check — *does this caller have permission?*
Implemented as a lookup in the in-memory approval table. First match wins; the catch-all is `*` → deny. No approval entry, no signature.
The approval check answers *who* and *which key*. It does not check what the request will do with the key — that is the enforcement check.
### 5.2 Enforcement check — *is this operation compatible with this key?*
The signer enforces a strict `(verb, purpose, curve)` matrix:
| Verb | Required purpose | Required curve |
|---|---|---|
| `sign_event` | `nostr` | `secp256k1` |
| `get_public_key` | `nostr` | `secp256k1` |
| `nip04_encrypt` / `nip04_decrypt` | `nostr` | `secp256k1` |
| `nip44_encrypt` / `nip44_decrypt` | `nostr` | `secp256k1` |
| Any other verb | rejected | rejected |
A pre-approval to use a Bitcoin-purposed key for `sign_event` does **not** override the enforcement matrix. The approval grants access to the key; enforcement still gates the verb. **Fail-closed**: unknown verbs are rejected, never passed through.
This is the layer that prevents (for example) a `bitcoin/secp256k1` key from being used to sign a Nostr event even if some pre-approval entry mistakenly named it. The key's *purpose* is part of its identity; you cannot reuse it across domains.
Test coverage: [`tests/test_enforcement.c`](../tests/test_enforcement.c).
---
## 6. The interactive approval prompt
When a request has no matching approval and `n_signer` is running attached to a terminal, the signer blocks the request, prints a prompt, and waits for a local keystroke.
Target prompt format:
```
Approval required
caller: qubes:nostr-relay
verb: sign_event
index: nostr_index=0
purpose: nostr / secp256k1
[y] allow once
[a] allow this caller for index 0 for the rest of the session
[n] deny
```
The keys mean:
- `[y]` — Allow this single request. No approval is saved; the next request from the same caller will prompt again.
- `[a]` — Allow, and add a session approval so the same `(caller, index)` pair is silently allowed for the rest of the session.
- `[n]` — Deny this request. Returns `policy_denied` to the client.
- EOF / non-interactive — Treated as deny. There is no implicit "allow when nobody is at the terminal" mode. OS distributions that need silent operation use [`--preapprove`](#7-pre-approvals-the-os-distribution-pathway).
### 6.1 What `[a]` does and does not do
- It approves the **specific caller** (e.g. `qubes:nostr-relay`).
- It approves the **specific index/path** that triggered the prompt.
- It does **not** approve other callers.
- It does **not** approve other indices for the same caller — a different `nostr_index` from the same caller will prompt again.
- It does **not** persist past the process lifetime.
### 6.2 New-identity warning
When a request specifies an unregistered `nostr_index`, the prompt says so plainly:
```
Approval required
caller: qubes:nostr-relay
verb: get_public_key
index: nostr_index=7 (NEW IDENTITY — will be derived if approved)
[y] allow once [a] allow caller for this new identity [n] deny
```
A new identity is just a new derivation of the same mnemonic. It is not a separate key file or a separate seed; it is `m/44'/1237'/7'/0/0` of the existing mnemonic. The user should still see explicitly that they are *creating* a previously-unused identity.
### 6.3 Race-condition behavior
Requests are served one at a time. If a malicious client tries to flood requests during a prompt, only the request being prompted is held; subsequent requests queue or are dropped per the transport's framing. The prompt always names the request being approved. It is not possible for a queued request to "ride along" on an approval intended for an earlier request.
---
## 7. Pre-approvals: the OS distribution pathway
For deployments where multiple system services need keys at boot — `n_OS_tr` and similar — the OS distribution starts `n_signer` with one `--preapprove` flag per service:
```ini
[Service]
ExecStart=/usr/bin/n_signer \
--preapprove caller=qubes:nostr-relay,role=main \
--preapprove caller=qubes:dm-handler,nostr_index=1 \
--preapprove caller=qubes:contacts,nostr_index=2 \
--preapprove caller=qubes:zaps,nostr_index=3
```
At startup, `n_signer`:
1. Parses each flag into an approval entry with prompt mode `NEVER`.
2. Auto-derives any keys those entries depend on (so services don't see "ready" until keys exist).
3. Writes one log line per pre-approval to stderr so the OS unit's journal records what was authorized.
4. Begins listening normally. Pre-approved requests are served silently; everything else still hits the prompt or the catch-all deny.
### 7.1 What pre-approvals can do
- Allow a specific named caller to use a specific named key for any verb that key's purpose/curve permits.
- Auto-create a Nostr identity at a specified `nostr_index` if it does not yet exist.
- Be inspected: anyone reading the systemd unit (or `ps` output) can see exactly what was authorized.
### 7.2 What pre-approvals cannot do
- **Cannot deny.** Pre-approvals only widen authorization, never narrow it. The user at the terminal is always the source of denial. (The plan deliberately rejects "preapprove deny" entries; see [`plans/deny_by_default_approvals.md`](../plans/deny_by_default_approvals.md) §C.3.)
- **Cannot wildcard the caller.** Each entry must name exactly one caller. There is no `qubes:*` rule. The OS distribution must know who its services are.
- **Cannot bypass enforcement.** A pre-approval to use a Nostr key for a hypothetical Bitcoin verb still fails the enforcement matrix in [§5.2](#52-enforcement-check--is-this-operation-compatible-with-this-key).
- **Cannot pre-register `role_path` derivations.** Only `role=<name>` (an existing role) and `nostr_index=<n>` are allowed in pre-approval specs. Free-form `role_path` derivations remain pre-registration-only by code path. See [§9.2](#92-pre-registration-of-role_path).
### 7.3 Trust implications
Pre-approvals shift the trust boundary. Whoever wrote the systemd unit now decides what the signer will allow without asking. Concretely:
- The unit file's integrity matters. If an attacker can rewrite it, they can pre-approve themselves.
- The OS launcher's identity-stamping must be trustworthy. If something else can spoof a `qubes:nostr-relay` tag, it inherits that pre-approval.
- The user retains final authority at the running terminal. Anything *not* pre-approved still goes through the human-approved prompt.
In `n_OS_tr` these properties are part of the OS itself: the unit files are owned by root, the qrexec framework stamps caller identity at the hypervisor level, and the user's terminal is the ultimate arbiter. The trust chain is short and visible.
---
## 8. The audit log
Every served (or denied) request appends a line to the in-memory activity buffer that the running TUI displays. Each line includes the **source label** that explains why the verdict was reached.
Target line format:
```
[2026-05-04 16:03:11] qubes:nostr-relay sign_event(nostr_index=0) ALLOWED:preapprove
[2026-05-04 16:03:14] uid:1000 sign_event(nostr_index=0) ALLOWED:session-grant
[2026-05-04 16:03:18] tcp:[::1]:54122 get_public_key(nostr_index=7) ALLOWED:prompt
[2026-05-04 16:03:21] uid:1001 sign_event(nostr_index=0) DENIED:no-match
```
Source labels:
| Label | Meaning |
|---|---|
| `:preapprove` | Approval came from a `--preapprove` startup flag. |
| `:session-grant` | Approval was added earlier this session by a prompt `[a]`. |
| `:prompt` | Approval was given just now by the user pressing `[y]` or `[a]` at the prompt. |
| `:no-match` | No approval existed and (in non-interactive mode) the request was denied. |
This makes forensic review fast: every signed operation maps to either a pre-approval (audit the unit file), a session grant (audit the session's earlier prompt activity), or a fresh prompt approval (audit human attention at that moment).
---
## 9. The role abstraction (internal plumbing)
Internally `n_signer` uses a structure called a **role** to bundle three things together:
- A derivation path (BIP-32).
- A purpose label (`nostr`, `bitcoin`, `ssh`, `age`).
- A curve label (`secp256k1`, `ed25519`, `x25519`).
Roles are the unit of *enforcement* (the matrix in [§5.2](#52-enforcement-check--is-this-operation-compatible-with-this-key) is keyed on role purpose and curve) and the unit of *audit* (every log line names the role used).
### 9.1 Why roles exist as plumbing rather than user-facing concept
- A future where one mnemonic produces Nostr, Bitcoin, SSH, and age keys requires *something* to track per-key purpose. Roles are that thing. Keeping them in the codebase preserves the option without forcing the user to think about them today.
- Two different identities can use the same role (the same key). The role is the audit unit shared between them, so the activity log is consistent regardless of caller.
- Enforcement against a role's declared purpose/curve is a defense-in-depth: a Nostr key cannot be coerced into producing a Bitcoin signature even if some approval entry mistakenly named it.
A user reading prompts and the activity log will see "index 0" and "index 7" most of the time, not "role main" or "role nostr_idx_7." Roles surface as labels only in advanced views and the source code.
### 9.2 Pre-registration of `role_path`
The `role_path` selector lets a client specify a BIP-32 path directly, including paths outside the Nostr derivation scheme. These remain **pre-registration-only**:
- The signer ships with an empty `role_path` table.
- Operators who want non-Nostr keys must register them at startup (mechanism TBD).
- The interactive prompt does **not** auto-derive `role_path` keys, even with `[a]`. The narrowing in [`plans/deny_by_default_approvals.md`](../plans/deny_by_default_approvals.md) §5 explicitly applies only to `nostr_index`.
The reasoning is that `role_path` is free-form. A malicious or buggy client could request paths that overlap with sensitive domains (bitcoin wallet roots, SSH host keys, age recipients). Auto-derivation in those domains would be a footgun. `nostr_index` is locked to a specific scheme with locked purpose and curve, so auto-derivation there is safe to gate on a single human keystroke.
### 9.3 Role table size limits
`ROLE_TABLE_MAX_ENTRIES` caps the number of distinct roles per session. The plan raises this to 256. Overflow is reported as a clear `role_table_full` error rather than silent truncation or memory unsafety.
---
## 10. Memory safety and zeroization
### 10.1 Locked memory
- The mnemonic and derived private keys live in `mlock`'d allocations managed by [`src/secure_mem.c`](../src/secure_mem.c).
- These pages are pinned in RAM (no swap to disk) for the process lifetime.
- On normal shutdown (`q`, `SIGINT`, `SIGTERM`), buffers are explicitly zeroized before unmap.
### 10.2 Crash semantics
If the process dies abnormally, the kernel reclaims its pages. Anything previously `mlock`'d is not flushed to disk because it never could be. There is no swap residue to scrape, no core dump containing keys (if your environment disables core dumps for setuid-equivalent processes — verify locally), and no recovery path.
This is the meaning of "crash equals total wipe is a security feature" in [`plans/nsigner.md:154`](../plans/nsigner.md:154).
### 10.3 No persistence by design
There is no file under `~/.nsigner`, no `/var/lib/nsigner`, no `~/.config/nsigner`, no approval database. The signer is a process whose authority begins when you type the mnemonic and ends when you quit.
If you want something durable: store the mnemonic on paper or hardware, not in `n_signer`.
The only file inputs are `--preapprove` flags from the launcher's command line, evaluated once at startup and never re-read. There is no live config reload.
---
## 11. Transports and their identity quality
Different transports give different identity quality. The wire format (4-byte length prefix + JSON-RPC) and the security checks ([§5](#5-the-two-checks-every-request-must-pass)) are identical across transports.
### 11.1 Abstract namespace Unix sockets (default)
- Address: `@nsigner_<word1>_<word2>` per [`plans/nsigner.md:96`](../plans/nsigner.md:96).
- Identity: kernel-vouched `uid`, `pid`. Cannot be forged by the client.
- Risk surface: any local process on the same host. Deny-by-default + per-(caller, index) approvals handle this.
### 11.2 Stdio / qrexec mode
- One framed request, one framed response, then exit.
- Identity: `qubes:<vm-name>` from `QREXEC_REMOTE_DOMAIN`, vouched for by Qubes.
- Risk surface: only what Qubes RPC policy permits. See [`packaging/qubes/`](../packaging/qubes/).
### 11.3 TCP (advanced / opt-in)
- Loopback and remote TCP callers must present a valid signed auth envelope.
- Identity is normalized to caller `pubkey:<hex>` after signature verification; TCP peer address is context only.
- The auth gate runs before policy: missing/invalid envelopes are rejected with `2010..2017` auth errors.
- Prompt-driven approval still applies after auth; auth answers "who is calling", policy answers "is this caller allowed".
### 11.4 Future transports
The roadmap ([`plans/nsigner.md:178`](../plans/nsigner.md:178)) describes additional transports (USB serial, FIPS-style relay). The contract is:
- The transport produces a `caller_identity_t`.
- The same approval / enforcement / dispatch stack runs unchanged.
- New transports add new identity *kinds*, not new bypass paths.
---
## 12. Operational guidance
### 12.1 Running interactively (typical desktop use)
- Start `n_signer` only on a terminal you control. No `--preapprove` flags.
- Type or generate the mnemonic. Generated mnemonics are shown once with no confirmation step ([`plans/nsigner.md:84`](../plans/nsigner.md:84)) — write them down before pressing a key.
- Stay near the terminal for the first couple of minutes after launch. New clients will prompt for approval. Press `[a]` to grant for the session.
- Once your usual clients are approved, prompts stop appearing.
### 12.2 Running as a system signer (e.g. `n_OS_tr`)
- Configure pre-approvals in the systemd (or equivalent) unit file. One `--preapprove` flag per service.
- Verify each pre-approval's caller identity exactly matches what the launcher actually produces. Mismatches cause silent deny (`:no-match` in the log).
- Treat the unit file as security-sensitive. Restrict write access to root or its equivalent.
- Keep a terminal attached or piped to where prompts can still be seen. Anything not pre-approved still prompts.
### 12.3 Stopping
- Press `q` for clean shutdown.
- `Ctrl+C` and `SIGTERM` are equivalent — they zeroize and exit.
- Closing the terminal is also equivalent. There is no "detach" mode by design.
### 12.4 Auditing
- The activity buffer in the running TUI is the session log. It does not survive the process.
- For persistent audit, run `n_signer` under a logging supervisor that captures stderr/stdout, knowing the activity buffer reflects post-approval decisions only.
### 12.5 Rotating
- "Rotate" in `n_signer` means: quit, change mnemonic source, restart. There is no in-place rotation because there is no persistent state to migrate.
---
## 13. Relationship to the current codebase
All stages from [`plans/deny_by_default_approvals.md`](../plans/deny_by_default_approvals.md) are implemented in the current codebase. This document therefore describes shipped behavior, not a future target state.
---
## 14. Things that look like bugs but are security features
| Symptom | Reason |
|---|---|
| First request from a new client prompts even though it's the same uid | Deny-by-default. Same-uid trust is gone. Press `[a]` once and you won't see prompts from this client again this session. |
| Killing the process loses all approvals and key derivations | Crash-equals-wipe. Restart with the same mnemonic to rebuild deterministically; re-approve clients. |
| `purpose_mismatch` when calling `sign_event` against a non-Nostr key | Roles are scoped by purpose. Approvals do not bypass enforcement. |
| `unknown_role` for an unregistered `role_path` | `role_path` keys are pre-registration-only by design. Use `nostr_index` for ad-hoc Nostr identities. |
| Pre-approval entry doesn't match incoming requests | Caller identity must match exactly — no wildcards. Verify the launcher tags requests the way the unit file expects. |
| `role=unknown` in the activity log (current code) | Selector did not resolve. Future versions will prompt to create the identity; current code rejects with `unknown_role` after policy passes. |
---
## 15. Quick reference — the security guarantee in one paragraph
`n_signer` will never sign with a key whose use has not been explicitly approved — either by a human keystroke at the running terminal or by a `--preapprove` flag declared at startup. It will never use a key outside its declared `(purpose, curve)` scope. It will never expose a private key to a client. It will never write key material to disk. Every request is checked twice: once for approval, once for enforcement. Default policy is deny. Approvals vanish on process exit.
If any of these statements becomes false in code, that is a security bug worth filing immediately.
---
## 16. References
- [`README.md`](../README.md) — authoritative behavior spec.
- [`plans/nsigner.md`](../plans/nsigner.md) — root design plan and decisions log.
- [`plans/deny_by_default_approvals.md`](../plans/deny_by_default_approvals.md) — the approval model plan this document tracks.
- [`documents/CLIENT_IMPLEMENTATION.md`](CLIENT_IMPLEMENTATION.md) — wire contract for clients.
- [`documents/QUBES_OS.md`](QUBES_OS.md) — Qubes RPC integration.
- [`documents/FIPS_DEPLOYMENT.md`](FIPS_DEPLOYMENT.md) — FIPS-mode deployment notes.
- [`plans/seed_phrase_uses.md`](../plans/seed_phrase_uses.md) — what one mnemonic can become.
- [`src/policy.c`](../src/policy.c), [`src/server.c`](../src/server.c), [`src/dispatcher.c`](../src/dispatcher.c), [`src/role_table.c`](../src/role_table.c), [`src/selector.c`](../src/selector.c), [`src/enforcement.c`](../src/enforcement.c) — the security-related code.

View File

@@ -0,0 +1,32 @@
#include <stdio.h>
#include <stdlib.h>
#include "../client/nsigner_client.h"
int main(int argc, char **argv) {
const char *socket_name = "nsigner";
nsigner_client_t client;
char *response = NULL;
if (argc > 1 && argv[1] != NULL && argv[1][0] != '\0') {
socket_name = argv[1];
}
nsigner_client_init(&client);
if (nsigner_client_connect_unix(&client, socket_name, 5000) != 0) {
fprintf(stderr, "connect failed: %s\n", nsigner_client_last_error(&client));
return 1;
}
if (nsigner_client_get_public_key(&client, "example-1", "", &response) != 0) {
fprintf(stderr, "request failed: %s\n", nsigner_client_last_error(&client));
nsigner_client_close(&client);
return 1;
}
printf("%s\n", response);
free(response);
nsigner_client_close(&client);
return 0;
}

View File

@@ -0,0 +1,33 @@
#include <stdio.h>
#include <stdlib.h>
#include "../client/nsigner_client.h"
int main(int argc, char **argv) {
const char *socket_name = "nsigner";
const char *event_json = "{\"kind\":1,\"content\":\"hello from client example\",\"tags\":[],\"created_at\":1700000000}";
nsigner_client_t client;
char *response = NULL;
if (argc > 1 && argv[1] != NULL && argv[1][0] != '\0') {
socket_name = argv[1];
}
nsigner_client_init(&client);
if (nsigner_client_connect_unix(&client, socket_name, 5000) != 0) {
fprintf(stderr, "connect failed: %s\n", nsigner_client_last_error(&client));
return 1;
}
if (nsigner_client_sign_event(&client, "example-2", event_json, "main", &response) != 0) {
fprintf(stderr, "request failed: %s\n", nsigner_client_last_error(&client));
nsigner_client_close(&client);
return 1;
}
printf("%s\n", response);
free(response);
nsigner_client_close(&client);
return 0;
}

View File

@@ -244,13 +244,7 @@ main() {
check_git_repo
if [[ "$RELEASE_MODE" == true ]]; then
if [[ "$VERSION_INCREMENT_EXPLICIT" == true ]]; then
increment_version "$VERSION_INCREMENT_TYPE"
else
LATEST_TAG=$(git tag -l 'v*.*.*' | sort -V | tail -n 1 || echo "v0.0.1")
NEW_VERSION="$LATEST_TAG"
export NEW_VERSION
fi
if git tag "$NEW_VERSION" > /dev/null 2>&1; then
print_success "Created tag: $NEW_VERSION"

223
install_qube_fips_nsigner.sh Executable file
View File

@@ -0,0 +1,223 @@
#!/usr/bin/env bash
set -euo pipefail
# User-only installer for Qubes AppVM persistence model.
# Nothing is written to /usr, /etc, or other root-owned paths.
#
# Installs into $HOME:
# - nsigner -> ~/.local/bin/nsigner
# - startup helper -> ~/start_nsigner.sh
#
# Usage:
# bash install_qube_fips_nsigner.sh
# bash install_qube_fips_nsigner.sh --help
#
# Optional env vars:
# NSIGNER_VERSION=vX.Y.Z # optional override; default is latest release tag
# NSIGNER_GITEA_TOKEN=<token> # if n_signer release assets are private
# NSIGNER_BINARY_URL=<direct url to nsigner_static_x86_64>
NSIGNER_VERSION="${NSIGNER_VERSION:-}"
PREFIX_BIN="${HOME}/.local/bin"
log() { printf "\033[1;34m[INFO]\033[0m %s\n" "$*"; }
warn() { printf "\033[1;33m[WARN]\033[0m %s\n" "$*"; }
err() { printf "\033[1;31m[ERR ]\033[0m %s\n" "$*"; }
show_help() {
cat <<EOF
Usage: bash install_qube_fips_nsigner.sh [options]
User-only install (Qubes AppVM friendly):
- n_signer ${NSIGNER_VERSION}
- signer startup helper script
Options:
-h, --help Show this help and exit
Optional env vars:
NSIGNER_VERSION=vX.Y.Z # optional override; default is latest release tag
NSIGNER_GITEA_TOKEN=<token> # required if n_signer release assets are private
NSIGNER_BINARY_URL=<direct url to nsigner_static_x86_64>
Install paths:
~/.local/bin/nsigner
~/start_nsigner.sh
EOF
}
require_cmd() {
command -v "$1" >/dev/null 2>&1 || {
err "Missing command: $1"
exit 1
}
}
install_runtime_deps() {
if command -v apt-get >/dev/null 2>&1; then
log "Installing runtime dependencies via apt"
sudo apt-get update
sudo apt-get install -y ca-certificates curl jq
elif command -v dnf >/dev/null 2>&1; then
log "Installing runtime dependencies via dnf"
sudo dnf install -y ca-certificates curl jq
else
err "Unsupported distro: need apt-get or dnf to install runtime dependencies"
exit 1
fi
}
prepare_dirs() {
mkdir -p "${PREFIX_BIN}"
}
resolve_nsigner_version() {
local headers=()
local latest_tag=""
if [[ -n "${NSIGNER_VERSION}" ]]; then
return 0
fi
if [[ -n "${NSIGNER_GITEA_TOKEN:-}" ]]; then
headers=(-H "Authorization: token ${NSIGNER_GITEA_TOKEN}")
fi
latest_tag="$(curl -fsSL "${headers[@]}" "https://git.laantungir.net/api/v1/repos/laantungir/n_signer/releases" \
| jq -r '.[0].tag_name // empty' || true)"
if [[ -z "${latest_tag}" ]]; then
err "Could not resolve latest n_signer release tag from API."
err "Set NSIGNER_VERSION explicitly (e.g. NSIGNER_VERSION=v0.0.11)."
exit 1
fi
NSIGNER_VERSION="${latest_tag}"
}
download_nsigner_asset_url() {
local headers=()
local api_tag_url="https://git.laantungir.net/api/v1/repos/laantungir/n_signer/releases/tags/${NSIGNER_VERSION}"
if [[ -n "${NSIGNER_GITEA_TOKEN:-}" ]]; then
headers=(-H "Authorization: token ${NSIGNER_GITEA_TOKEN}")
fi
curl -fsSL "${headers[@]}" "${api_tag_url}" \
| jq -r '.assets[]?.browser_download_url // empty' \
| grep -E 'nsigner_static_x86_64$' \
| head -n1 || true
}
install_nsigner() {
local release_page=""
resolve_nsigner_version
release_page="https://git.laantungir.net/laantungir/n_signer/releases/tag/${NSIGNER_VERSION}"
log "Installing n_signer ${NSIGNER_VERSION}"
log "Release page: ${release_page}"
local asset_url="${NSIGNER_BINARY_URL:-}"
if [[ -z "${asset_url}" ]]; then
asset_url="$(download_nsigner_asset_url)"
fi
if [[ -z "${asset_url}" ]]; then
err "Could not find downloadable n_signer x86_64 release binary for ${NSIGNER_VERSION}."
err "Provide NSIGNER_BINARY_URL or NSIGNER_GITEA_TOKEN so the release asset can be resolved."
exit 1
fi
log "Using n_signer binary URL: ${asset_url}"
if [[ -n "${NSIGNER_GITEA_TOKEN:-}" ]]; then
curl -fL -H "Authorization: token ${NSIGNER_GITEA_TOKEN}" -o "${PREFIX_BIN}/nsigner" "${asset_url}"
else
curl -fL -o "${PREFIX_BIN}/nsigner" "${asset_url}"
fi
chmod 0755 "${PREFIX_BIN}/nsigner"
log "Installed ${PREFIX_BIN}/nsigner from release binary"
}
write_signer_start_script() {
local script_path="${HOME}/start_nsigner.sh"
cat >"${script_path}" <<'EOF'
#!/usr/bin/env bash
set -euo pipefail
export PATH="$HOME/.local/bin:$PATH"
LISTEN_TARGET="${NSIGNER_LISTEN_TARGET:-tcp:[::]:8080}"
echo "=== n_signer startup ==="
echo "listen target: ${LISTEN_TARGET}"
# Optional: print current FIPS identity info if fipsctl is available.
if command -v fipsctl >/dev/null 2>&1; then
if fipsctl show status >/dev/null 2>&1; then
STATUS_JSON="$(fipsctl show status)"
elif sudo -n fipsctl show status >/dev/null 2>&1; then
STATUS_JSON="$(sudo -n fipsctl show status)"
else
STATUS_JSON=""
fi
if [[ -n "${STATUS_JSON}" ]]; then
FIPS_IPV6="$(printf '%s\n' "${STATUS_JSON}" | sed -n 's/.*"ipv6_addr": "\([^"]*\)".*/\1/p')"
FIPS_NPUB="$(printf '%s\n' "${STATUS_JSON}" | sed -n 's/.*"npub": "\([^"]*\)".*/\1/p')"
LISTEN_PORT="$(printf '%s\n' "${LISTEN_TARGET}" | sed -n 's/.*:\([0-9][0-9]*\)$/\1/p')"
[[ -n "${FIPS_IPV6}" ]] && echo "fips ipv6: ${FIPS_IPV6}"
[[ -n "${FIPS_NPUB}" ]] && echo "fips npub: ${FIPS_NPUB}"
if [[ -n "${FIPS_NPUB}" && -n "${LISTEN_PORT}" ]]; then
echo "fips address: http://${FIPS_NPUB}.fips:${LISTEN_PORT}"
fi
else
echo "fips status: unavailable (run as user in fips group or with sudo)"
fi
fi
echo
echo "Starting signer..."
echo "On first remote request, approve in prompt with [y] or [a]."
exec "$HOME/.local/bin/nsigner" --listen "${LISTEN_TARGET}"
EOF
chmod 0755 "${script_path}"
log "Wrote ${script_path}"
}
post_checks() {
export PATH="${PREFIX_BIN}:${PATH}"
log "Running post-install checks"
require_cmd nsigner
nsigner --version || true
log "User binaries installed in: ${PREFIX_BIN}"
log "If needed, add to shell PATH: export PATH=\"${PREFIX_BIN}:\$PATH\""
}
main() {
if [[ "${1:-}" == "-h" || "${1:-}" == "--help" ]]; then
show_help
exit 0
fi
if [[ $# -gt 0 ]]; then
err "Unknown option: $1"
show_help
exit 1
fi
install_runtime_deps
prepare_dirs
install_nsigner
write_signer_start_script
post_checks
log "Completed user-only install of n_signer"
log "Start signer with: ~/start_nsigner.sh"
}
main "$@"

View File

@@ -0,0 +1,483 @@
# Plan: Caller-pubkey identity with required Schnorr authentication for URL/TCP
Status: **draft v2 — for review**
> **History.** Draft v1 of this document proposed a random 32-byte bearer token persisted to a `0600` file on both ends. That draft was rejected on two grounds: (1) it violated [`documents/SECURITY.md:19`](../documents/SECURITY.md:19) — "Crash equals total wipe" — by writing tokens to disk, and (2) bearer credentials over a transport already chosen as the *least* trusted is the wrong security gradient. v2 replaces the bearer token with a Schnorr-authenticated public key, removes all disk persistence, and requires cryptographic proof-of-possession on every TCP/URL request from day one.
This plan addresses the same originating bug — every TCP reconnect re-fires the approval prompt because `caller_id` is built from the ephemeral `addr:port` pair — but does so by giving the weakest transport the strongest application-layer identity, not the weakest. AF_UNIX and qrexec retain their existing kernel- and hypervisor-vouched identities; TCP/URL gains BIP-340 Schnorr authentication using primitives the signer already links.
---
## 1. Goals
1. **One approval per program-keypair, not per TCP connection.** Two requests carrying the same `caller_pubkey` resolve to the same policy entry regardless of source port, transport jitter, or reconnect.
2. **Cryptographic proof-of-possession on every TCP/URL request.** The wire identity is not just a name; it is backed by a signature that only the holder of the corresponding private key can produce.
3. **Replay-resistant within a bounded window.** A captured request cannot be replayed against the signer indefinitely.
4. **No disk persistence — anywhere.** No tokens on disk, no caller registry on disk, no policy on disk. "Crash equals total wipe" applies to this feature unmodified.
5. **Stronger transports keep their stronger primitives.** AF_UNIX still uses `SO_PEERCRED`; qrexec still uses `QREXEC_REMOTE_DOMAIN`. Neither acquires a new spoofable claim field, and neither is required to send signatures.
6. **Use only `nostr_core_lib` and existing dependencies.** No new crypto libraries. No new hash functions. The auth envelope is a Nostr event, verified by a primitive [`nostr_verify_event_signature`](../resources/nostr_core_lib/nostr_core/nip001.h:20) the signer already trusts.
## 2. Non-goals
- **No transport-level encryption / TLS.** FIPS still provides confidentiality of the substrate. Application-layer auth and transport encryption are separate concerns.
- **No mutual authentication of the signer to the client.** This plan authenticates the client to the signer. The reverse direction is future work and intentionally out of scope.
- **No persistence of any state.** Approvals stay in RAM. A signer restart re-prompts every caller exactly once. A client restart re-prompts itself once if it lost its in-memory keypair, or zero times if the client retains its own identity in its own memory.
- **No new transports.** AF_UNIX, qrexec, stdio, TCP unchanged at the socket layer.
- **No PID-as-identity.** Documented rejection in §10.
- **No bearer tokens.** Explicit reversal of v1.
- **No change to the deny-by-default rule.** A new pubkey shows up exactly once at the prompt; everything in [`plans/deny_by_default_approvals.md`](deny_by_default_approvals.md) applies unchanged.
## 3. The model in one paragraph
For TCP/URL transport, every JSON-RPC request must carry an **auth envelope** — a small Nostr-shaped event signed by the caller's private key. The signer verifies that signature with [`nostr_verify_event_signature`](../resources/nostr_core_lib/nostr_core/nip001.h:20) before any policy logic runs. The verified `pubkey` field becomes the `caller_id` for that request (`pubkey:<hex>` form), feeding straight into the existing policy table that already handles `uid:1000`, `qubes:foo`, `tcp:[addr]:port`. On first contact for a given pubkey, the existing deny-by-default prompt fires; the user sees the npub, an optional client-supplied label, and the verb/role; on `[a]` the pubkey is recorded as an approval entry the same way any other caller is. Subsequent requests from the same pubkey hit the approval and are served silently. AF_UNIX and qrexec are unaffected — they continue to use kernel/hypervisor identity and ignore any auth envelope they receive. Nothing is written to disk on either side at any point.
## 4. Concept additions to the existing model
[`documents/SECURITY.md:57`](../documents/SECURITY.md:57) defines three concepts: identity, index, approval. This plan adds nothing visible to the user beyond an alternate identity *kind*. There is no fourth concept. Specifically:
- A **pubkey-identified caller** is a new identity kind, alongside `unix_peer`, `qubes`, `tcp_local`, `tcp_remote`. Its `caller_id` form is `pubkey:<64 hex chars>`.
- An **auth envelope** is a wire-protocol artifact, not a user-facing concept. The user never sees the word "envelope"; they see "caller: npub1abc…xyz" at the prompt.
- An **approval** is unchanged: the same `(caller_id, role) → PROMPT_NEVER` row in the same in-memory policy table.
The only document-level change is that [`documents/SECURITY.md`](../documents/SECURITY.md) §11's "tcp_remote (planned)" and "fips (planned)" rows ([`documents/SECURITY.md:98-99`](../documents/SECURITY.md:98)) become "implemented; identity = caller pubkey verified by Schnorr signature."
## 5. Per-transport identity primitives — the unified picture
| Transport | Identity primitive | Validation | `caller_id` form | Auth envelope required? |
|---|---|---|---|---|
| AF_UNIX | `SO_PEERCRED.uid` (and `pid` for UX) | Kernel-attested. | `uid:<n>` | **No.** Kernel vouches. |
| qrexec | `QREXEC_REMOTE_DOMAIN` | Hypervisor-attested. | `qubes:<vm>` | **No.** Xen vouches. |
| stdio | inherited environment (qrexec or interactive) | As above. | `qubes:<vm>` or `uid:<n>` | **No.** |
| TCP / FIPS | `caller_pubkey` from auth envelope | BIP-340 Schnorr signature verified by `nostr_verify_event_signature`. | `pubkey:<hex>` | **Yes. Required on every request.** |
A TCP request that arrives **without** a valid auth envelope is rejected before any policy logic runs. There is no fallback to `tcp:[addr]:port` identity; v2 retires that form entirely for the TCP listener. Operators who relied on `--preapprove caller=tcp:...` must migrate to `--preapprove caller=pubkey:<hex>` (see §7.5).
## 6. Wire protocol: the auth envelope
### 6.1 Shape
The auth envelope is a single JSON object placed at the top level of the request, alongside (not inside) `method`/`params`. It is structured exactly like a NIP-01 Nostr event so that [`nostr_verify_event_signature`](../resources/nostr_core_lib/nostr_core/nip001.h:20) verifies it directly with no custom canonicalization code on the signer side:
```json
{
"id": "rpc-42",
"method": "sign_event",
"params": { ... },
"auth": {
"id": "<32-byte event id, hex>",
"pubkey": "<32-byte x-only secp256k1 pubkey, hex>",
"created_at": 1730000000,
"kind": 27235,
"tags": [
["nsigner_rpc", "rpc-42"],
["nsigner_method", "sign_event"],
["nsigner_body_hash", "<sha256(canonical body), hex>"]
],
"content": "<optional client label, e.g. \"nostr_terminal@laptop\">",
"sig": "<64-byte Schnorr signature, hex>"
}
}
```
The `kind` value `27235` is the same kind NIP-42 uses for client authentication to relays. We are explicitly piggybacking on that semantic: this is "client authenticates to a service it wants to use," and reusing the existing kind keeps us inside Nostr conventions rather than inventing a new event kind. The signer accepts kind 27235 events whose tag set marks them as nsigner-bound.
### 6.2 Required tags
Three tags are required on every envelope. The signer rejects envelopes missing any of them with `auth_envelope_malformed` (code 2010).
| Tag name | Value | Purpose |
|---|---|---|
| `nsigner_rpc` | The request's `id` field, copied verbatim. | Binds the signature to this specific request id; a captured envelope cannot be reused with a different request id. |
| `nsigner_method` | The request's `method` field, copied verbatim. | Binds the signature to the verb. A captured `get_public_key` envelope cannot be replayed as `sign_event`. |
| `nsigner_body_hash` | Hex SHA-256 of the canonicalized `params` object — see §6.3. | Binds the signature to the request payload. The signer recomputes this hash and rejects on mismatch with `auth_body_mismatch` (code 2011). |
### 6.3 Canonicalization of `params`
To make `nsigner_body_hash` deterministic across implementations, `params` must be hashed in a single canonical form. To avoid inventing a new canonicalizer, we adopt **JCS** (RFC 8785, JSON Canonicalization Scheme) — the same canonicalization Nostr already uses for event IDs in NIP-01. The body hash is `SHA-256(JCS(params))`, computed by both client and signer using [`nostr_sha256`](../resources/nostr_core_lib/nostr_core/utils.h:46).
If `params` is absent from the request, `nsigner_body_hash` is `SHA-256("null")` (the canonicalization of JSON `null`), which is a fixed 64-char constant the signer can use without per-request hashing for the no-params case.
### 6.4 Signature verification
On receipt of a TCP request, the signer:
1. Extracts the `auth` object. If absent, reject with `auth_envelope_required` (code 2014).
2. Validates the envelope is structurally a NIP-01 event (id is sha256 of canonical event header; `pubkey`, `sig`, `created_at`, `kind`, `tags`, `content` present and well-typed). Library function [`nostr_validate_event_structure`](../resources/nostr_core_lib/nostr_core/nip001.h:19) handles this.
3. Verifies the Schnorr signature: [`nostr_verify_event_signature(auth_event)`](../resources/nostr_core_lib/nostr_core/nip001.h:20). Reject with `auth_signature_invalid` (code 2012) on failure.
4. Checks `kind == 27235`. Reject with `auth_kind_invalid` (code 2013) otherwise.
5. Confirms `nsigner_rpc` tag matches request `id` and `nsigner_method` tag matches request `method`. Reject with `auth_envelope_mismatch` (code 2015) on either mismatch.
6. Computes `SHA-256(JCS(params))` and confirms it matches `nsigner_body_hash`. Reject with `auth_body_mismatch` (code 2011) on mismatch.
7. Applies replay protection — see §6.5.
8. On success, sets `caller.caller_id = "pubkey:" + hex(pubkey)`. Policy lookup proceeds against this caller_id.
### 6.5 Replay protection
Two layered defenses, neither requiring disk:
#### 6.5.1 Timestamp window
`auth.created_at` must satisfy `|now - created_at| <= AUTH_CLOCK_SKEW_SEC`. Default `AUTH_CLOCK_SKEW_SEC = 30`. Configurable via `--auth-skew-seconds` at startup. Reject with `auth_envelope_stale` (code 2016) if outside the window.
The 30-second window is small enough that a captured envelope is a poor reuse target and large enough to tolerate ordinary clock drift in the FIPS-mediated path. Operators with looser requirements can widen it; operators with NTP-locked deployments can narrow it.
#### 6.5.2 Nonce / id cache
The signer maintains an in-memory ring buffer of recently-seen `auth.id` values:
```c
#define AUTH_NONCE_CACHE_SIZE 1024
typedef struct {
uint8_t id[32];
uint64_t seen_at; /* monotonic seconds */
} auth_nonce_entry_t;
typedef struct {
auth_nonce_entry_t entries[AUTH_NONCE_CACHE_SIZE];
int head;
int count;
} auth_nonce_cache_t;
```
On verified envelope, the signer linearly scans the cache for `auth.id`. If found, reject with `auth_replay_detected` (code 2017). If not, insert at head, evicting the tail if full.
The cache size of 1024 paired with the 30-second window means at sustained 33+ requests/second from any caller would push older entries out before they expire — at which point the timestamp window catches the replay anyway. The two defenses overlap intentionally: the cache catches fast replays inside the window; the timestamp catches slow replays outside it.
The cache is purely in-memory. On signer restart it starts empty, which is safe because the timestamp window also resets the universe of acceptable envelopes — any envelope created before the restart is now outside the window and would be rejected on `created_at` grounds before reaching the nonce check.
### 6.6 Error codes added
| Code | Symbolic name | Meaning |
|---|---|---|
| 2010 | `auth_envelope_malformed` | Required field or tag missing / wrong type. |
| 2011 | `auth_body_mismatch` | `nsigner_body_hash` did not match recomputed hash of `params`. |
| 2012 | `auth_signature_invalid` | Schnorr verification failed. |
| 2013 | `auth_kind_invalid` | Auth event kind ≠ 27235. |
| 2014 | `auth_envelope_required` | TCP request arrived with no `auth` object. |
| 2015 | `auth_envelope_mismatch` | `nsigner_rpc` or `nsigner_method` tag did not match request envelope. |
| 2016 | `auth_envelope_stale` | `created_at` outside skew window. |
| 2017 | `auth_replay_detected` | `auth.id` already seen in nonce cache. |
These are placed in their own contiguous range so client code can identify "auth-layer error → bug in my signing code" vs "policy-layer error → user denied."
## 7. Signer-side data model and code changes
### 7.1 Extension to `caller_identity_t`
[`src/server.c:404`](../src/server.c:404) currently has:
```c
typedef struct {
int kind;
char caller_id[64];
char source_qube[64];
} caller_identity_t;
```
Becomes:
```c
typedef struct {
int kind;
char caller_id[80]; /* widened: "pubkey:" + 64 hex + NUL fits */
char source_qube[64];
/* Filled in only when an auth envelope was verified on this request. */
int auth_present; /* 0 or 1 */
uint8_t auth_pubkey[32]; /* present iff auth_present */
char auth_label[64]; /* envelope `content` field, sanitized */
/* UX context, never used as policy key. */
pid_t peer_pid; /* SO_PEERCRED.pid for AF_UNIX, else 0 */
char peer_addr[64]; /* tcp:[...]:port, used in prompt context */
} caller_identity_t;
```
The widened `caller_id` ripples through every translation unit's headerless declaration block. Mechanical change.
### 7.2 New translation unit: `src/auth_envelope.c`
A new file owns auth-envelope parsing, verification, and the nonce cache. Public surface:
```c
typedef enum {
AUTH_OK = 0,
AUTH_ERR_MALFORMED,
AUTH_ERR_BODY_MISMATCH,
AUTH_ERR_SIG_INVALID,
AUTH_ERR_KIND_INVALID,
AUTH_ERR_REQUIRED,
AUTH_ERR_TAG_MISMATCH,
AUTH_ERR_STALE,
AUTH_ERR_REPLAY
} auth_result_t;
/* Verify the auth envelope embedded in `request_root` against the request's
* id, method, and params. On AUTH_OK, fills caller->auth_pubkey and
* caller->auth_label. Does not touch caller_id. */
auth_result_t auth_envelope_verify(cJSON *request_root,
auth_nonce_cache_t *nonce_cache,
int skew_seconds,
uint64_t now_unix,
caller_identity_t *caller);
void auth_nonce_cache_init(auth_nonce_cache_t *cache);
```
The implementation is thin: extract `auth` cJSON object, run library validations, run our tag/body/replay checks, return. All the heavy crypto lifting is `nostr_verify_event_signature`.
A corresponding [`tests/test_auth_envelope.c`](../tests/test_auth_envelope.c) covers the eight error paths with hand-crafted envelopes (using a fixed test keypair) and the happy path.
### 7.3 Ordering in `server_handle_one`
[`src/server.c:1192`](../src/server.c:1192) gains an auth gate between framed-receive and selector-resolve, but only on TCP. Pseudocode for the revised flow:
```
1. accept(); server_get_caller(fd, &caller); /* unchanged: kind, peer_addr */
2. transport_recv_framed(fd, &request);
3. if (caller.kind == NSIGNER_LISTEN_TCP) {
parse request as cJSON;
auth_result = auth_envelope_verify(root, &ctx->nonce_cache,
ctx->auth_skew, now, &caller);
if (auth_result != AUTH_OK) { send error 2010-2017; close; return; }
snprintf(caller.caller_id, ..., "pubkey:%s", hex(caller.auth_pubkey));
}
/* AF_UNIX/qrexec: caller.caller_id already set; auth envelope, if any,
is silently ignored. */
4. extract method + selector; /* unchanged */
5. resolve role; /* unchanged */
6. policy_check(caller.caller_id, ...); /* unchanged */
7. prompt if PROMPT; /* unchanged */
8. dispatch; /* unchanged */
```
The auth gate is a single function call. Existing code paths are touched only at the point where `caller.caller_id` is overwritten on success.
### 7.4 Server context additions
[`server_ctx_t`](../src/server.c) gains:
```c
auth_nonce_cache_t nonce_cache; /* in-memory, zeroed at startup, never persisted */
int auth_skew_seconds; /* default 30, settable via --auth-skew-seconds */
```
### 7.5 `--preapprove` extension
[`parse_preapprove_spec`](../src/policy.c:553) gains a new caller form:
```
--preapprove caller=pubkey:<64 hex>,role=main
--preapprove caller=pubkey:<64 hex>,nostr_index=1
```
The pubkey is the **client's** caller pubkey — a 32-byte x-only secp256k1 hex value. No file reference; the operator has the pubkey directly. There is no `pubkey_file` form because the pubkey is not secret and embedding it in the unit file is fine.
The `tcp:` caller form is **deprecated** for the TCP listener (not removed; AF_UNIX and qrexec preapprovals are unaffected — they never used `tcp:`). On a `--preapprove caller=tcp:...` for a TCP listener, the signer prints a deprecation warning at startup explaining that TCP requests now require auth envelopes and the entry will never match. This is documented in [`documents/N_OS_TR_AGENT_CHANGES.md`](../documents/N_OS_TR_AGENT_CHANGES.md).
### 7.6 No persistence — confirmed property
This plan introduces:
- An in-memory `caller_identity_t` per request (already exists; widened).
- An in-memory `auth_nonce_cache_t` per server context (new, ring buffer, RAM only).
- New entries in the existing in-memory `policy_table_t` keyed on `pubkey:<hex>` (no schema change).
It does **not** introduce:
- Any file written by the signer.
- Any file required at startup by the signer (beyond the already-required mnemonic input).
- Any state that survives `server_stop`.
"Crash equals total wipe" remains literally true.
## 8. Client-side requirements (e.g. nostr_terminal)
### 8.1 Caller keypair
The client needs a secp256k1 keypair for the purpose of authenticating to n_signer. Three sourcing strategies are supported, and the choice is the client's:
1. **Reuse the program's existing Nostr identity.** A program like nostr_terminal that already has a published Nostr pubkey can use that same keypair as its caller identity. The user sees a familiar npub at the prompt and recognizes "yes, that's nostr_terminal's pubkey."
2. **Derive a dedicated caller identity from the program's seed.** A program with a stored seed can derive a separate `m/44'/1237'/<n>'/0/<m>` key as a stable "RPC client identity" distinct from its public posting key. The user sees a unique-to-the-program-installation npub.
3. **Generate ephemerally per session.** A program that has no persistent identity at all generates a fresh secp256k1 key in memory at startup. Each client restart yields a new key, and the user re-prompts once per restart. This is the slowest UX but the simplest implementation.
n_signer does not know or care which strategy a client uses. The pubkey on the wire is the only thing the signer sees.
### 8.2 Signing each request
For every TCP request, the client:
1. Builds the regular JSON-RPC envelope (`id`, `method`, `params`).
2. Computes `body_hash = SHA-256(JCS(params))`.
3. Constructs an auth event with kind 27235, the three required tags, optional `content` label, current `created_at`.
4. Signs the event with its private key (BIP-340 Schnorr — for nostr_terminal this is the same `nostr_schnorr_sign`-style call it already uses for kind-1 events, just with a different kind and tag set).
5. Embeds the signed event under an `auth` field in the request.
6. Sends the framed bytes.
The signing operation is bounded — one Schnorr sign per RPC. Modern hardware does this in microseconds. Implementations should not cache or skip signing; the per-request `created_at` is what makes the nonce defense meaningful.
### 8.3 Reconnect behavior — the bug being fixed
- TCP socket drops mid-session → client reconnects → next RPC carries a fresh auth envelope (different `id`, different `created_at`) signed by the same pubkey.
- Signer verifies envelope, computes the same `caller_id = "pubkey:<hex>"`, finds the existing approval entry, serves silently. **No prompt.**
- Signer process restart → policy table empties → next RPC's envelope verifies fine but the policy entry is gone → user re-prompts once per pubkey, picks `[a]`, future requests served silently. **One prompt per signer restart, exactly as for any other caller kind.**
- Client process restart → if the client persisted its keypair (its own choice), zero prompts. If the client used an ephemeral keypair, one prompt for the new pubkey.
### 8.4 Replay-window awareness
Clients must keep their clock synced within `AUTH_CLOCK_SKEW_SEC` (default 30s). This is normally trivial via NTP. The signer's response on stale-clock errors (`auth_envelope_stale`, code 2016) tells the client to fix its clock; clients should surface this clearly rather than retrying.
### 8.5 No on-disk requirement
The client is **not required** to store anything on disk. Whether it does is the client's policy. n_signer's plan imposes no client-side filesystem state.
## 9. Mermaid: TCP request decision tree
```mermaid
flowchart TD
A[TCP request arrives] --> B[parse JSON, extract auth]
B --> C{auth present?}
C -- no --> D[reject 2014 auth_envelope_required]
C -- yes --> E[validate event structure]
E -- bad --> F[reject 2010 auth_envelope_malformed]
E -- ok --> G[verify Schnorr signature]
G -- bad --> H[reject 2012 auth_signature_invalid]
G -- ok --> I{kind == 27235?}
I -- no --> J[reject 2013 auth_kind_invalid]
I -- yes --> K{tags match request id and method?}
K -- no --> L[reject 2015 auth_envelope_mismatch]
K -- yes --> M{body hash matches?}
M -- no --> N[reject 2011 auth_body_mismatch]
M -- yes --> O{within skew window?}
O -- no --> P[reject 2016 auth_envelope_stale]
O -- yes --> Q{auth.id in nonce cache?}
Q -- yes --> R[reject 2017 auth_replay_detected]
Q -- no --> S[insert nonce, set caller_id pubkey:hex]
S --> T[normal policy_check pipeline]
T --> U{verdict}
U -- ALLOW --> V[dispatch RPC]
U -- DENY --> W[2001 policy_denied]
U -- PROMPT --> X[user approves with a, registers caller]
X --> V
```
## 10. Identity primitives compared
| Primitive | Stable across reconnects | Forgeable on TCP/FIPS | Survives client restart | Replay-resistant | n_signer dependency added |
|---|---|---|---|---|---|
| `tcp:[addr]:port` (today) | **No** | n/a (it is the address) | n/a | n/a | none |
| PID claimed in JSON | Yes | **Yes** — any client claims any int | n/a | No | none |
| 32-byte random bearer token (v1 of this plan) | Yes | Yes if leaked from disk or wire | Only if disk-persisted (rejected) | No | none |
| **Caller pubkey + Schnorr signature (this plan)** | **Yes** | **No** — signature attests possession | Yes if client retains key (its choice) | Yes (nonce + skew window) | none — `nostr_core_lib` already linked |
The bottom row is the only one that satisfies all four columns and adds zero new transitive dependencies. PID and the v1 token are kept in the table as documentation of why we are not doing them.
PID retains a single legitimate use: **prompt UX context for AF_UNIX**. When the signer can read PID via `SO_PEERCRED`, it is displayed in the approval prompt as `pid=18437 (exe=/usr/local/bin/nostr_terminal)` so the user can `ps -p 18437` and verify. PID is never the policy key.
## 11. Threats addressed and not addressed
### Addressed
- **Connection-churn re-prompting.** The originating bug. One pubkey, one approval.
- **Same-IP, different-program ambiguity.** Two programs from the same FIPS endpoint hold different keypairs and produce distinct, verified `pubkey:` caller_ids.
- **Drive-by signing from a process that lacks the privkey.** A network adversary or local-but-unauthorized process cannot forge envelopes. Wire knowledge of the pubkey is non-sensitive; the privkey never leaves the legitimate client's memory.
- **Replay of captured envelopes.** Bounded by `AUTH_CLOCK_SKEW_SEC` and the in-memory nonce cache.
- **Tampered request bodies.** `nsigner_body_hash` covers `params`, so a man-in-the-middle who flips a kind-1 request to a kind-30000 request invalidates the signature and is rejected.
- **Tampered request methods or ids.** Covered by required tags `nsigner_method` and `nsigner_rpc`.
### Not addressed (explicit)
- **A local attacker who reads the client's privkey out of process memory.** They become the registered caller. This is the same threat as today's same-uid trust model and is handled by the OS, not by n_signer.
- **A network attacker who can both passively observe AND inject AND has compromised the FIPS substrate.** Without TLS at the n_signer layer, transport encryption is FIPS's job. If FIPS confidentiality is broken, the attacker can read envelopes — but they still cannot forge them (no privkey) and they cannot replay them outside the skew window. Confidentiality of `params` is a separate concern from auth.
- **Signer authenticating to the client.** This plan does the client → signer direction. Signer → client auth is future work; today the client trusts whichever endpoint the operator pointed it at.
- **Long-term key rotation policy.** Operators rotate by removing the old approval entry (TUI hotkey, future) and prompting the new pubkey. There is no automatic rotation.
## 12. Implementation order (suggested)
Each step is independently testable.
1. **`src/auth_envelope.c` and `tests/test_auth_envelope.c`.** Pure data-structure and crypto wrapper around `nostr_validate_event_structure` + `nostr_verify_event_signature` + tag/body/timestamp/nonce checks. No transport coupling. Test with hand-crafted JSON and fixed test keypairs.
2. **Nonce cache primitive.** Ring buffer; trivial unit tests for insert / lookup / eviction.
3. **`caller_identity_t` widening.** Mechanical change across all `NSIGNER_HEADERLESS_DECLS_BEGIN` blocks. Compile-only step; existing tests should still pass.
4. **Auth gate in `server_handle_one`.** Hook (1) into the request flow at TCP transport. Add the eight new error code responses. Integration test: fire a TCP request without `auth` and confirm rejection with code 2014; fire one with a valid envelope and confirm normal flow.
5. **`--preapprove caller=pubkey:<hex>` parsing.** Extension to [`parse_preapprove_spec`](../src/policy.c:553).
6. **`--auth-skew-seconds` flag.** Plumbing.
7. **Documentation.**
- [`documents/SECURITY.md`](../documents/SECURITY.md): replace `tcp_remote (planned)` and `fips (planned)` rows in §11 with the verified-pubkey description; add a section on the auth envelope.
- [`documents/CLIENT_IMPLEMENTATION.md`](../documents/CLIENT_IMPLEMENTATION.md): full chapter on the auth envelope, JCS canonicalization rule, the eight error codes, a concrete signing example.
- [`documents/FIPS_DEPLOYMENT.md`](../documents/FIPS_DEPLOYMENT.md): note that TCP requests now require auth envelopes; update the deployment checklist; remove the "remote TCP mode only with mandatory TLS + authenticated caller key flow" future-work note since this plan delivers the second half.
- [`documents/N_OS_TR_AGENT_CHANGES.md`](../documents/N_OS_TR_AGENT_CHANGES.md): example with `--preapprove caller=pubkey:<hex>`.
8. **Deprecation handling for `--preapprove caller=tcp:...` on TCP listeners.** Warning at startup; entries effectively dead.
9. **TUI revocation hotkey.** UX-side, can land later.
## 13. Open questions for review
These are the judgment calls left in v2. None of them block the v2 → implementation move; defaults are stated for each.
1. **Skew window default.** This plan says 30 seconds. Confirm. Tighter (5s) means fewer replay opportunities but more clock-drift errors; looser (120s) the reverse.
2. **Nonce cache size.** This plan says 1024. With a 30s window that handles ~33 RPS sustained per signer, far above realistic load. Confirm the size is fine.
3. **Should the auth envelope's `content` field carry a label?** This plan says yes, displayed at prompt as a hint, max 63 bytes UTF-8. Alternative: leave `content` empty and force the operator to recognize the npub. The label is purely UX; the npub is the truth. Default = label allowed, but ignored by policy.
4. **JCS as canonicalization vs. a simpler rule.** JCS is the right answer (RFC standard, used by NIP-01) but not all client languages have a JCS library. Alternative: define a small subset rule ("sort keys lexicographically, no whitespace, JSON-stringify each value"). Default = JCS; revisit if a target client language lacks support.
5. **Should AF_UNIX accept an `auth` envelope as an *additional* identity claim?** Today this plan says no — AF_UNIX uses `SO_PEERCRED` and ignores `auth`. Alternative: allow a client over AF_UNIX to ALSO send an envelope and have the signer record both `uid:1000` AND `pubkey:<hex>` as identities for the same caller. Adds complexity for a use case nobody has asked for. Default = AF_UNIX ignores `auth`.
---
## Appendix A — Diff against existing plans and docs
- [`plans/deny_by_default_approvals.md`](deny_by_default_approvals.md): unchanged. The deny-by-default rule, prompt outcomes, on-demand role derivation, and `--preapprove` mechanics all continue. Only the *form* of `caller_id` for one transport changes.
- [`plans/nsigner.md`](nsigner.md): the future-work item "remote TCP mode only with mandatory TLS + authenticated caller key flow" ([`documents/FIPS_DEPLOYMENT.md:177`](../documents/FIPS_DEPLOYMENT.md:177)) is half answered: the auth side is done; TLS at the n_signer layer remains future work.
- [`documents/SECURITY.md`](../documents/SECURITY.md):
- §11 rows for `tcp_remote` and `fips` move from "planned" to "implemented; identity = caller pubkey verified by Schnorr signature."
- New subsection in §5 ("the two checks") inserts an auth check ahead of the approval check, applicable only to TCP transport.
- [`documents/CLIENT_IMPLEMENTATION.md`](../documents/CLIENT_IMPLEMENTATION.md): new chapter "Authenticating over TCP/URL transport" defining the auth envelope, JCS rule, and error codes 20102017.
- [`documents/N_OS_TR_AGENT_CHANGES.md`](../documents/N_OS_TR_AGENT_CHANGES.md): adds a `--preapprove caller=pubkey:<hex>` example for system services that have a stable identity keypair; notes that `--preapprove caller=tcp:...` is deprecated for TCP listeners.
## Appendix B — Why kind 27235 specifically
NIP-42 already defines kind 22242 for "client authentication to relays" with HTTP-Auth-style semantics. Reusing 22242 verbatim would be wrong because the tag schema (`relay`, `challenge`) is relay-specific. Choosing a fresh kind in the parameterized-replaceable range used for HTTP/RPC auth (27235 is used elsewhere for HTTP request auth in some Nostr ecosystems — verify before locking in) lets us define our own tag schema (`nsigner_rpc`, `nsigner_method`, `nsigner_body_hash`) without colliding with relay-auth conventions.
If 27235 turns out to be already claimed by a NIP we do not want to inherit semantics from, the plan can pick a different kind in the same range. The kind is a constant in [`src/auth_envelope.c`](../src/auth_envelope.c) and changing it is a one-line edit in both signer and client.
## Appendix C — Pseudocode: client signing one request
```c
/* Pseudocode, illustrative only. */
cJSON *params = build_params_for_method(method);
/* 1. Compute body hash. */
char *params_jcs = jcs_canonicalize(params);
unsigned char body_hash[32];
nostr_sha256((const unsigned char *)params_jcs, strlen(params_jcs), body_hash);
char body_hash_hex[65];
nostr_bytes_to_hex(body_hash, 32, body_hash_hex);
/* 2. Build the auth event JSON. */
cJSON *auth = cJSON_CreateObject();
cJSON_AddStringToObject(auth, "pubkey", caller_pubkey_hex);
cJSON_AddNumberToObject(auth, "created_at", (double)time(NULL));
cJSON_AddNumberToObject(auth, "kind", 27235);
cJSON *tags = cJSON_CreateArray();
add_tag(tags, "nsigner_rpc", request_id);
add_tag(tags, "nsigner_method", method);
add_tag(tags, "nsigner_body_hash", body_hash_hex);
cJSON_AddItemToObject(auth, "tags", tags);
cJSON_AddStringToObject(auth, "content", optional_label_or_empty);
/* 3. Compute event id (sha256 of canonical event header) and sign. */
unsigned char event_id[32], sig[64];
compute_nostr_event_id(auth, event_id); /* helper from nostr_core_lib usage */
nostr_schnorr_sign(caller_privkey, event_id, sig);
char id_hex[65], sig_hex[129];
nostr_bytes_to_hex(event_id, 32, id_hex);
nostr_bytes_to_hex(sig, 64, sig_hex);
cJSON_AddStringToObject(auth, "id", id_hex);
cJSON_AddStringToObject(auth, "sig", sig_hex);
/* 4. Embed in the request and send. */
cJSON *root = cJSON_CreateObject();
cJSON_AddStringToObject(root, "id", request_id);
cJSON_AddStringToObject(root, "method", method);
cJSON_AddItemToObject(root, "params", params);
cJSON_AddItemToObject(root, "auth", auth);
send_framed(cJSON_PrintUnformatted(root));
```
The signer side is the same flow in reverse, replacing `nostr_schnorr_sign` with `nostr_verify_event_signature` on the embedded `auth` event.

View File

@@ -0,0 +1,357 @@
# Plan: Deny-by-default approvals + on-demand role derivation
Status: **implemented**
This plan replaces several entangled mechanisms (same-uid auto-allow, role pre-registration as a hard rule, global `[a]` flag) with a single, coherent approval model. It also addresses the `n_OS_tr` system-services-at-boot scenario.
If implemented, this plan supersedes:
- The same-uid auto-allow rule in [`policy_init_default()`](../src/policy.c:551).
- The "role_path / nostr_index must be pre-registered" rule recorded in [`plans/nsigner.md:159`](nsigner.md:159) (the rule is *narrowed*, not removed — see §5).
- The global `g_prompt_always_allow` flag in [`src/server.c:469`](../src/server.c:469) as the meaning of prompt-`[a]`. The running-TUI `[a]` hotkey is unaffected (or removed; see §11).
---
## 1. Goals
1. **Deny-by-default.** No client can sign or get a public key without an explicit human approval at the terminal **or** an explicit pre-approval declared at startup.
2. **One approval mechanism.** Both the runtime prompt (human approves a request) and the boot-time pre-approval (OS-level config) populate the **same** in-memory policy table. There is exactly one path through the dispatcher that determines whether to sign.
3. **On-demand role creation.** When a request specifies an unregistered `nostr_index`, the prompt path may auto-derive a fresh role at that index *only after* the human (or a startup pre-approval) consents. Pre-registration of `role_path` keys remains required.
4. **Boot-time ergonomics for `n_OS_tr`.** OS-level system services that need keys at boot can be pre-approved by the OS distribution via CLI flags, with no prompts and no on-disk runtime config files.
5. **Auditable approval source.** The activity log distinguishes between approvals granted at runtime by the user, approvals loaded from startup pre-approvals, and approvals already in place from prior session activity.
## 2. Non-goals
- This plan does **not** add per-verb scoping at the prompt. `[a]` means "this caller may use this role for all verbs the role's purpose/curve permits." Per-verb scoping is a future iteration.
- This plan does **not** add persistent (across-restart) policy storage. Approvals still vanish on process exit.
- This plan does **not** introduce capability tokens or any new authentication primitive. Identity remains transport-derived.
- This plan does **not** change the wire protocol. Clients see the same JSON-RPC request/response shape.
## 3. The new model in one paragraph
The signer maintains an in-memory policy table whose entries are tuples of `(caller_id, role, prompt_mode)`. At startup, the table is empty except for entries declared via `--preapprove` CLI flags (set by `n_OS_tr` system unit files for boot-required services). Every request without a matching policy entry triggers an interactive prompt at the terminal. If the user picks `[a]`, a new policy entry for `(this caller, this role)` is appended to the table and any future request matching that tuple is served silently. If the request specifies an unregistered `nostr_index`, the consent path also derives a fresh role at that index. The `*` catch-all is `PROMPT_DENY` for any caller that hasn't been explicitly added.
## 4. Concept renaming and positioning
The user-facing language collapses to three concepts:
| User-facing term | Internal mapping |
|---|---|
| **Identity** | `caller_identity_t` (uid, qubes vm name, tcp peer, etc.) |
| **Index / Path** | `nostr_index` shorthand or full `role_path` for advanced use |
| **Approval** | A policy table entry with `prompt_mode = PROMPT_NEVER` |
The word **role** is retained internally (the role table, the [`role_entry_t`](../src/role_table.c:103) struct, derivation paths) but de-emphasized in user-facing prompts and docs. A user reading a prompt sees:
```
Approval required
caller: qubes:nostr-relay
verb: sign_event
index: nostr_index=0 (resolves to the default identity)
```
instead of `role: main`. Internally the resolved role is still recorded for audit.
## 5. The narrowed pre-registration rule
The original rule was: **all** selectors must resolve to a pre-registered role.
The new rule is:
> Pre-registration is required for **`role_path`** selectors. For **`nostr_index`** selectors, an unregistered index is a valid prompt trigger, and the role for that index is derived on the fly **after** explicit consent (prompt or `--preapprove`).
Rationale:
- `nostr_index` paths follow a fixed scheme (`m/44'/1237'/<n>'/0/0`) with locked purpose (`nostr`) and curve (`secp256k1`). Auto-derivation cannot accidentally produce a key that mixes purposes. The risk is solely "this is a fresh nostr identity"; the human at the prompt can answer that.
- `role_path` is free-form and can address any BIP-32 path, including paths that overlap with bitcoin/SSH/age domains. Auto-derivation here would let a malicious or buggy client coerce the signer into producing keys whose purpose the human can't easily verify. We keep that locked.
- This narrowing is the smallest crack we can open in the original rule that still solves the user's `nostr_index: 1` use case.
[`plans/nsigner.md:159`](nsigner.md:159) ("`role_path` must be pre-registered") remains true. The `nostr_index` clause becomes new and explicit.
## 6. The four pieces of work
### Piece A — Deny-by-default policy
#### A.1 Default policy table
[`policy_init_default()`](../src/policy.c:551) currently inserts two entries:
1. `caller = "uid:<owner>"``PROMPT_NEVER` (auto-allow same-uid)
2. `caller = "*"``PROMPT_DENY`
The new default inserts only:
1. `caller = "*"``PROMPT_PROMPT`
There is no same-uid special case. Even the user's own client triggers a prompt the first time it connects.
If `--preapprove` flags were given at startup, those entries are appended **before** the catch-all `*` so they win first-match. See §C.
#### A.2 Removal of `g_prompt_always_allow` as a *prompt outcome*
The flag is currently set to 1 by both:
- The interactive prompt's `[a]` outcome ([`src/server.c:684`](../src/server.c:684))
- The running-TUI `[a]` hotkey ([`src/main.c:974`](../src/main.c:974), [`src/main.c:1239`](../src/main.c:1239))
The prompt's `[a]` no longer flips the flag. Instead it appends a per-`(caller, role)` policy entry. See §B.
The running-TUI `[a]` hotkey can either be:
- Removed, since it is now redundant with explicit per-caller entries, **or**
- Retained as a debugging/panic mode under a non-default name, e.g. `[A]` (capital) for "auto-approve everything regardless of caller; for development only."
The plan recommends retaining it as a deliberately ugly, capital-letter hotkey so its destructive scope is visible. Default-off; activates only on explicit press.
#### A.3 Wire-level effect
A previously-unknown caller making a first request observes:
1. Length-prefixed request lands.
2. Selector resolves (or fails — see §B).
3. Policy lookup returns `POLICY_PROMPT` because no matching entry exists.
4. Server blocks the request, prints the prompt to the controlling terminal, waits for keystroke.
5. On `[a]`, server appends `(caller, role) → PROMPT_NEVER` and serves the request.
6. On `[y]`, server serves once without appending.
7. On `[n]`, server returns `policy_denied` without appending.
8. On EOF / non-interactive: server returns `policy_denied`. There is no implicit allow path for non-interactive sessions; OS distributions must use `--preapprove`.
### Piece B — On-demand role derivation at the prompt
#### B.1 Failure path today
When `selector_resolve()` returns `SELECTOR_ERR_NOT_FOUND` for an unregistered `nostr_index`, the request currently dies in the dispatcher with `unknown_role` (error 1002). The user observes nothing in the terminal.
#### B.2 New failure path
The server's request-handling loop checks selector resolution **before** invoking the dispatcher. The new control flow:
```
1. Receive request, parse method + selector.
2. Try selector_resolve():
a. SELECTOR_OK -> proceed to step 3 with the resolved role.
b. SELECTOR_ERR_NOT_FOUND on nostr_index -> proceed to step 3 with
a PENDING_DERIVATION marker holding the requested index.
c. SELECTOR_ERR_NOT_FOUND on role_path -> reject with unknown_role.
d. SELECTOR_ERR_AMBIGUOUS -> reject with ambiguous_role_selector.
e. SELECTOR_ERR_NO_DEFAULT -> reject with internal_error
(this should never happen if main role is always present).
3. Determine policy: ALLOW / DENY / PROMPT.
- For PENDING_DERIVATION cases, the prompt displays the requested
index and clearly states "this will create a new identity."
4. On PROMPT, ask human; on [a] or [y], proceed; on [n], reject.
5. On approval to proceed:
a. If PENDING_DERIVATION, register a role for that index in the
role_table now. Synthesize a name like nostr_idx_7. Trigger
key derivation for the new role.
b. If [a] (not [y]), append a session policy entry for
(caller, resolved-role-name) with PROMPT_NEVER.
6. Invoke the dispatcher with the resolved role.
7. Send response, append activity log line including approval source.
```
#### B.3 Auto-registered role naming
A role auto-registered for `nostr_index = N` is named `nostr_idx_N` by the signer.
- Predictable, so humans reading the activity log can correlate.
- Will not collide with the built-in `main` (which is `nostr_idx_0` by index but `main` by name; the role table allows lookups by either).
- Does not require user input at the prompt. Naming UX is a future iteration.
#### B.4 Role-table sizing
[`ROLE_TABLE_MAX_ENTRIES`](../src/role_table.c) is currently small. With on-demand derivation a single session might accumulate dozens of `nostr_idx_*` entries. Bump the constant to an explicit budget (suggest 256). On overflow, return a clear error like `role_table_full` rather than crashing.
#### B.5 Persistence
Same as everything else in n_signer: derived roles vanish on process exit. The next session re-derives `nostr_idx_7` from the same mnemonic, getting the same key. This is normal and intentional.
### Piece C — `--preapprove` CLI flag
#### C.1 Flag syntax
```
--preapprove <SPEC>
```
`SPEC` is a comma-separated list of `key=value` pairs. Required keys:
- `caller=<id>` — exact caller identity to match. Format depends on transport:
- `uid:1000`
- `qubes:work-vm`
- `tcp:[fdb8::1]:0` (port 0 means "any port")
- `qubes:*` is **not** supported. Wildcards are intentionally restricted to the catch-all entry only.
- One of:
- `role=<name>` — match the role by name. Useful when the OS knows it wants `main`.
- `nostr_index=<n>` — match by index. Equivalent to `role=nostr_idx_<n>` after auto-derivation.
Optional keys (deferred for now, but reserved):
- `verbs=<list>` — comma-separated verb list. Default is `*`.
- `purposes=<list>` — comma-separated purpose list. Default is `*`.
Multiple `--preapprove` flags are allowed; each becomes a separate policy entry.
#### C.2 Example: `n_OS_tr` boot
`n_OS_tr`'s systemd unit file:
```ini
[Service]
ExecStart=/usr/bin/n_signer \
--preapprove caller=qubes:nostr-relay,role=main \
--preapprove caller=qubes:dm-handler,nostr_index=1 \
--preapprove caller=qubes:contacts,nostr_index=2 \
--preapprove caller=qubes:zaps,nostr_index=3
```
At startup, n_signer:
1. Parses each `--preapprove` flag into a `policy_entry_t` with `prompt = PROMPT_NEVER`.
2. For each entry that references an unregistered `nostr_index`, auto-derives the role *immediately at startup* (not lazily — we want all key derivation to happen before services start signaling readiness).
3. Inserts each policy entry into the table **before** the catch-all `*` deny.
4. Logs each pre-approval to stderr at boot so the systemd unit's journal records what was preapproved.
When `qubes:nostr-relay` connects and asks for `sign_event` against `role=main`, `policy_check()` matches the preapprove entry, returns `POLICY_ALLOW`, and the request is served with no prompt.
When some other caller (say, a misconfigured systemd service) connects, the catch-all matches and the request is denied (or prompts, in interactive mode — see §C.4).
#### C.3 What `--preapprove` cannot do
- **Cannot deny.** Deny entries can only come from defaults or the prompt's `[n]` (if we ever add caller-deny). Pre-approve only widens.
- **Cannot match wildcards on caller.** Each entry must specify exactly one caller_id. The OS distribution is responsible for knowing exactly who its services are.
- **Cannot bypass purpose/curve enforcement.** A pre-approval to use `role=main` for `verb=sign_btc_tx` (a hypothetical bitcoin verb) still fails enforcement because `main`'s purpose is `nostr`. The pre-approval grants access to the role; enforcement still gates the verb.
#### C.4 Interaction with interactive mode
The same binary supports both:
- `n_signer` with no `--preapprove` flags → pure deny-by-default, every first request prompts.
- `n_signer --preapprove ...` → starts with the listed entries already in the policy table.
Both modes use exactly the same code path. There is no separate "system mode" toggle.
#### C.5 Auditability
When a pre-approval matches, the activity log line includes the source:
```
qubes:nostr-relay sign_event(role=main) ALLOWED:preapprove
```
So an operator reviewing the log can tell which decisions came from boot config vs. runtime user approvals.
#### C.6 Validation
Bad `--preapprove` syntax fails fast at startup with a clear error message. n_signer refuses to start. This avoids the "I thought I configured this but typoed it" silent-degrade problem.
### Piece D — Audit-log labeling of approval source
#### D.1 The four label values
| Label | Meaning |
|---|---|
| `:preapprove` | Matched a policy entry installed via `--preapprove` at startup. |
| `:session-grant` | Matched a policy entry created earlier in this session by a prompt `[a]`. |
| `:prompt` | Just-now approved by the user pressing `[y]` or `[a]` at the prompt. |
| `:auto-allow` | Matched the running-TUI `[a]` panic mode (if retained). |
A line in the activity log under the new model:
```
[2026-05-04 16:03:11] qubes:nostr-relay sign_event(role=main) ALLOWED:preapprove
[2026-05-04 16:03:14] uid:1000 sign_event(role=main) ALLOWED:session-grant
[2026-05-04 16:03:18] tcp:[::1]:54122 get_public_key(role=nostr_idx_7) ALLOWED:prompt
[2026-05-04 16:03:21] uid:1001 sign_event(role=main) DENIED:no-match
```
#### D.2 Implementation
The label is a small enum threaded from `policy_check()` (which returns the matching entry's source tag) and from `prompt_for_policy_decision()` (which returns `:prompt`). `server_handle_one()` includes the label in the activity-log line.
#### D.3 Visibility
The label appears in:
- The TUI's running activity buffer.
- The structured activity event passed to the `server_activity_cb` callback (so external observers — e.g. a future syslog feeder — can also see the source).
#### D.4 No on-disk persistence
The activity buffer remains in-memory only. If `n_OS_tr` wants persistent audit, it forwards the activity callback to its own logging subsystem outside of n_signer's process.
## 7. Code change inventory
| Module | Change |
|---|---|
| [`src/policy.c`](../src/policy.c) | `policy_init_default()` collapses to one entry. `policy_check()` extends to return the matching entry's source label. New helper `policy_table_add_at_position()` to insert before the catch-all. |
| [`src/server.c`](../src/server.c) | `prompt_for_policy_decision()` rewritten: appends a policy entry on `[a]`, no longer flips the global flag. New pre-derivation control flow in `server_handle_one()`. New CLI parser for `--preapprove`. |
| [`src/role_table.c`](../src/role_table.c) | Bump `ROLE_TABLE_MAX_ENTRIES` to 256. New `role_table_register_nostr_index(int n)` helper that creates a `nostr_idx_<n>` entry and triggers derivation. |
| [`src/key_store.c`](../src/key_store.c) | Add a one-role derivation path so newly-registered roles can be derived without re-deriving the whole table. |
| [`src/dispatcher.c`](../src/dispatcher.c) | No semantic change — dispatcher continues to assume the role exists. The server makes that true before invoking. |
| [`src/main.c`](../src/main.c) | CLI parsing for `--preapprove`. Remove or restrict the running-TUI `[a]` hotkey. Log preapproves to stderr at boot. |
| [`tests/test_policy.c`](../tests/test_policy.c) | New tests: deny-by-default, prompt-`[a]` appends entry, preapprove flag parsing, source-label propagation. |
| [`tests/test_dispatcher.c`](../tests/test_dispatcher.c) | New tests: unregistered nostr_index path with consent-required gating. |
| [`tests/test_integration.c`](../tests/test_integration.c) | New scenario: `--preapprove` allows scripted client; without it, scripted client gets denied. |
| [`documents/SECURITY.md`](../documents/SECURITY.md) | Rewritten in identity / index / approval terms (separate task after this plan ships). |
| [`documents/CLIENT_IMPLEMENTATION.md`](../documents/CLIENT_IMPLEMENTATION.md) | Add a note about possible `policy_denied` on first contact in interactive mode; pointer to `--preapprove` for system services. |
| [`plans/nsigner.md`](nsigner.md) | Decisions log entry referencing this plan. The `role_path` pre-registration rule remains; the `nostr_index` clause becomes new. |
## 8. Test plan
Tests must cover at minimum:
1. **Default deny.** A startup with no `--preapprove` flags receives a request from any caller and (in non-interactive mode) returns `policy_denied`.
2. **Prompt `[a]` appends entry.** Inject a non-interactive prompt-default of `ALLOW`, observe a policy entry added, verify a second matching request is served without re-prompting.
3. **Prompt `[y]` does not append entry.** Same fixture, second request still triggers the prompt path.
4. **`--preapprove` with `role=main`.** Request from named caller succeeds without prompt; request from any other caller is denied.
5. **`--preapprove` with `nostr_index=N` for unregistered N.** Role is auto-derived at startup; request succeeds; activity log shows `:preapprove`.
6. **`--preapprove` cannot bypass enforcement.** Pre-approve `(caller=X, role=main)` and request a verb that violates purpose/curve. Response is `purpose_mismatch` or `curve_mismatch`.
7. **Unknown `role_path` still rejected.** Even with consent, an unregistered `role_path` returns `unknown_role`. (The narrowing is `nostr_index`-only.)
8. **Audit-log labels.** Each path produces the expected source tag.
9. **Multi-instance isolation.** Two n_signers with different `--preapprove` lists serve different requests; cross-instance requests are denied as expected.
10. **Role table overflow.** Force more than `ROLE_TABLE_MAX_ENTRIES` derivations and observe `role_table_full` instead of corruption.
## 9. Backwards-compatibility implications
- **Existing scripts that rely on same-uid auto-allow break.** They now hit the prompt (interactive) or get denied (non-interactive). Migration path: add `--preapprove caller=uid:1000,role=main` to the startup invocation. We document this prominently.
- **Interactive desktop users see a prompt the first time their client connects, where today they don't.** This is the intended behavior change. We document it in the README.
- **Wire protocol unchanged.** No client-side changes required.
- **Existing `[a]` running-TUI hotkey may change semantics or disappear.** This is the most disruptive UI change for someone who actually uses the panic-allow today. Document the change in the release notes.
## 10. Rollout staging
This is too much to land in one commit. Suggested order:
1. **Stage 1 — deny-by-default + prompt `[a]` appends entry.** Removes the same-uid auto-allow, makes the prompt the source of session-grants. No CLI flag yet. Headless scripts break; we accept that for now and document the workaround as "use stage 2."
2. **Stage 2 — `--preapprove` CLI flag.** Restores headless ergonomics for OS distributions like `n_OS_tr`.
3. **Stage 3 — on-demand role derivation at the prompt.** Closes the user-visible `(unknown)` failure mode.
4. **Stage 4 — audit-log labels and structured activity output.** Forensics + observability.
5. **Stage 5 — `documents/SECURITY.md` rewrite.** After the code is settled.
Each stage is a self-contained release.
## 11. Open decisions to confirm before coding
- **Q1.** Keep the running-TUI `[a]` hotkey as a panic-allow under a different visual treatment, or remove it entirely? Plan recommends keep, capitalized, default-off.
- **Q2.** Is `nostr_idx_<n>` an acceptable auto-naming convention, or do we want to ask the user for a name in the prompt? Plan recommends auto-name now, prompt-name later as iteration.
- **Q3.** Should the prompt's "this will create a new identity" warning differ visually from a normal approval prompt? Plan recommends a clearly distinct extra line in the prompt body.
- **Q4.** What is the ceiling for `ROLE_TABLE_MAX_ENTRIES`? Plan recommends 256 with a fail-loud overflow.
- **Q5.** Do we want a TUI panel showing the active session approvals (helpful for the user to see what they've granted)? Plan recommends yes, smallest possible: caller + role + source label. Could be deferred to a later stage.
## 12. After this plan lands: deferred work
- Per-verb scoping at the prompt (the user wants `[a]` to mean "all verbs for this role" but a future `[c]` to mean "let me pick"). Deferred per the user's instruction.
- Approval revocation hotkeys (`[k]` to clear all session-grants, `[K]` to clear one).
- Approvals visible-and-editable as a TUI panel.
- Persistent (cross-restart) approvals — explicitly out of scope; n_signer remains memory-only.
- `role_path` auto-derivation under prompt — explicitly out of scope; the security argument in §5 stands.
- Capability tokens for cross-machine transports (FIPS, USB serial) — separate plan, separate threat model.
## 13. References
- [`README.md`](../README.md) — authoritative behavior spec.
- [`plans/nsigner.md`](nsigner.md) — root design plan; pre-registration rule at line 159.
- [`documents/CLIENT_IMPLEMENTATION.md`](../documents/CLIENT_IMPLEMENTATION.md) — wire contract.
- [`documents/SECURITY.md`](../documents/SECURITY.md) — security model document; will be rewritten when this plan lands.
- [`src/policy.c`](../src/policy.c), [`src/server.c`](../src/server.c), [`src/dispatcher.c`](../src/dispatcher.c), [`src/role_table.c`](../src/role_table.c), [`src/selector.c`](../src/selector.c) — code that changes.

View File

@@ -0,0 +1,98 @@
# Plan: Deferred NIP-46 bunker transport mode
Status: **deferred (design only, not in current implementation scope)**
This document records a future transport mode where `n_signer` can operate as a NIP-46-compatible bunker over relays, while keeping the current local/TCP framed JSON-RPC path intact.
Current implementation priority remains [`plans/caller_token_identity.md`](caller_token_identity.md): required per-request caller authentication for TCP/URL using signed auth envelopes and existing `n_signer` request flow.
---
## 1. Why this is deferred
NIP-46 adds more than caller authentication:
- Relay session lifecycle and routing
- NIP-44 encrypted request/response payloads
- `connect` ceremony and secret verification
- Signer service identity (`remote-signer-pubkey`) management
- Compatibility behavior for `nostrconnect://` and `bunker://`
That is a separate subsystem from the immediate bugfix (stable, authenticated caller identity over TCP reconnects). Combining both now would increase risk and delay rollout.
---
## 2. Future objective
Add an optional mode (example: `--listen nip46`) that accepts NIP-46 `kind:24133` requests and returns NIP-46 `kind:24133` responses as defined in [`resources/nips/46.md`](../resources/nips/46.md).
This mode should:
1. Authenticate client requests using NIP-46 client keypairs and encrypted content.
2. Map NIP-46 caller identity to the same deny-by-default approval model already used by current transports.
3. Reuse existing dispatcher/enforcement/policy machinery after transport decoding.
---
## 3. Compatibility stance (future)
- Keep current framed JSON-RPC transports (`AF_UNIX`, `qrexec`, `tcp`) as first-class for local deployments.
- Add NIP-46 as **additional** transport, not replacement.
- Shared internal core: once a request is decoded into `(caller_id, method, params, selector)`, the same policy and enforcement pipeline runs.
---
## 4. Planned phases
### Phase A — Transport shell
- Add `nip46` listen mode and relay I/O loop.
- Parse and validate incoming `kind:24133` envelope.
- Decrypt NIP-44 payload and extract JSON-RPC-like `method` + `params`.
### Phase B — Identity + approval binding
- Derive caller identity from NIP-46 `client-pubkey`.
- Represent as `caller_id = pubkey:<hex>` to align with the current TCP auth direction in [`plans/caller_token_identity.md`](caller_token_identity.md).
- Route to existing policy checks and prompt behavior.
### Phase C — Response path
- Convert dispatcher results into NIP-46 response payloads.
- Encrypt via NIP-44 and emit `kind:24133` response event.
- Preserve request `id` correlation and error mapping.
### Phase D — Connect / secret / perms polish
- Implement full `connect` handshake semantics from [`resources/nips/46.md`](../resources/nips/46.md:100).
- Validate optional secret behavior.
- Support requested permissions metadata and signer-side policy translation.
### Phase E — Operational hardening
- Relay switching behavior (`switch_relays`), lifecycle recovery.
- Rate limits and replay protections specific to relay transport.
- Audit/event logs for NIP-46 connections and requests.
---
## 5. Open design questions (for later)
1. Should NIP-46 mode require a dedicated signer identity key, or may it reuse the user signing identity?
2. How should `connect` permissions map to `n_signer` role/selector approvals?
3. Should NIP-46 callers and TCP-auth callers share the same `pubkey:<hex>` approval namespace by default?
4. Do we support both relay-initiated and direct-client initiation flows from day one?
5. What minimum relay trust assumptions are required in `documents/SECURITY.md`?
---
## 6. Out of scope for current code work
The current implementation task does **not** include:
- Adding relay networking
- NIP-44 tunnel encryption for requests
- NIP-46 `connect` handshake
- `nostrconnect://` URI flow
Those remain deferred to this plan.

View File

@@ -214,22 +214,22 @@ Use Qubes' native inter-qube primitive instead of inventing one.
- Tests: a unit test that injects fake qrexec env vars and a stdio framing harness; an integration script that documents end-to-end install in a Qubes VM (manual, not in CI).
- Docs: add a "Qubes deployment" section to [`README.md`](../README.md) and to [`CLIENT_IMPLEMENTATION.md`](../CLIENT_IMPLEMENTATION.md).
### 7.2 Phase T2 — TCP loopback transport
### 7.2 Phase T2 — TCP transport
Smallest IP-based step; on-ramp for non-Linux clients and for FIPS later.
- New CLI: `nsigner --listen tcp:127.0.0.1:PORT`.
- Default-deny non-loopback binds (reject `0.0.0.0` / non-`127.x` / non-`::1` unless `--allow-remote`, see T3).
- Caller identity for loopback: `tcp_local { addr }`. Approval prompt still mandatory.
- New CLI: `nsigner --listen tcp:HOST:PORT` (IPv4 literal) or `nsigner --listen tcp:[IPv6]:PORT`.
- Current behavior: accepts operator-selected local/remote bind addresses (including `[::]` and `fd..`), pending later transport hardening.
- Caller identity for TCP: endpoint address/port in caller descriptor. Approval prompt still mandatory.
- `nsigner list` extended to enumerate active TCP listeners (from internal registry; not from `/proc/net/tcp`).
- Same framing as AF_UNIX path; no protocol changes.
- Tests: integration coverage that spawns a child signer with `--listen tcp:127.0.0.1:0`, captures the bound port, runs the same NIP-04/NIP-44/sign_event matrix as AF_UNIX.
- Tests: integration coverage that spawns a child signer with `--listen tcp:127.0.0.1:0` (and one IPv6 case), captures the bound port, runs the same NIP-04/NIP-44/sign_event matrix as AF_UNIX.
- Docs: extend [`documents/CLIENT_IMPLEMENTATION.md`](../documents/CLIENT_IMPLEMENTATION.md) section 2 with `tcp:` discovery rules and section 3 confirming framing parity.
Implementation checklist (Tier-1 delivery):
- [x] Parse `--listen tcp:HOST:PORT` in [`src/main.c`](../src/main.c).
- [x] Reject invalid/non-loopback listen targets in [`src/server.c`](../src/server.c).
- [x] Parse and validate literal IPv4/IPv6 listen targets in [`src/server.c`](../src/server.c).
- [x] Bind/listen non-blocking TCP sockets and run server loop without TUI dependence.
- [x] Keep existing framed JSON-RPC protocol unchanged via shared [`src/transport_frame.c`](../src/transport_frame.c).
- [ ] Add integration test coverage for `tcp:127.0.0.1:PORT` request flow.
@@ -250,7 +250,7 @@ Only after T2 is solid.
FIPS is a *substrate* for an existing TCP listener, not a new transport in nsigner code.
- Deployment topology: nsigner binds TCP loopback inside the FIPS network namespace (or on a host where `fips0` is up); peers reach it via `fd00::/8` IPv6 derived from the signer's npub.
- Deployment topology: nsigner binds a chosen TCP endpoint inside the FIPS network namespace (or on a host where `fips0` is up); peers reach it via `fd00::/8` IPv6 derived from the signer's npub.
- Optional `caller_kind=fips` enrichment: a small sidecar query (`fipsctl show sessions` style) maps the connecting IPv6 address to a peer npub and feeds it into `caller_identity_t.fips { peer_npub }`. If unavailable, fall back to `tcp_remote` identity.
- nsigner does not embed FIPS, does not depend on libfips, and does not require Rust.
- New optional flag: `--peer-id-source fips:/var/run/fips/fips.sock` (path/method TBD per FIPS API).
@@ -259,7 +259,7 @@ FIPS is a *substrate* for an existing TCP listener, not a new transport in nsign
Execution tasks for initial FIPS trial:
- [x] Deliver T2 TCP loopback listener as FIPS substrate prerequisite.
- [x] Deliver T2 TCP listener as FIPS substrate prerequisite.
- [x] Document signer/caller qube deployment flow in [`documents/FIPS_DEPLOYMENT.md`](../documents/FIPS_DEPLOYMENT.md).
- [ ] Add two-node operator validation script (manual) using `fipsctl` + framed JSON-RPC client.
- [ ] Evaluate optional caller identity enrichment from FIPS session metadata.

409
src/auth_envelope.c Normal file
View File

@@ -0,0 +1,409 @@
#define _GNU_SOURCE
#include "auth_envelope.h"
#include <ctype.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <time.h>
#include <cJSON.h>
#include <nostr_core/nip001.h>
#include <nostr_core/utils.h>
static int set_error(int *out_code,
const char **out_message,
int code,
const char *message) {
if (out_code != NULL) {
*out_code = code;
}
if (out_message != NULL) {
*out_message = message;
}
return -1;
}
void auth_nonce_cache_init(auth_nonce_cache_t *cache) {
if (cache == NULL) {
return;
}
memset(cache, 0, sizeof(*cache));
}
static int auth_nonce_cache_contains(const auth_nonce_cache_t *cache, const uint8_t id[32]) {
int i;
if (cache == NULL || id == NULL) {
return 0;
}
for (i = 0; i < cache->count; ++i) {
if (memcmp(cache->ids[i], id, 32) == 0) {
return 1;
}
}
return 0;
}
static void auth_nonce_cache_insert(auth_nonce_cache_t *cache, const uint8_t id[32]) {
if (cache == NULL || id == NULL) {
return;
}
if (cache->count < AUTH_NONCE_CACHE_SIZE) {
memcpy(cache->ids[cache->count], id, 32);
cache->count++;
return;
}
memcpy(cache->ids[cache->next], id, 32);
cache->next = (cache->next + 1) % AUTH_NONCE_CACHE_SIZE;
}
static int json_item_to_compact_string(const cJSON *item, char *out, size_t out_sz) {
char *printed;
if (out == NULL || out_sz == 0 || item == NULL) {
return -1;
}
if (cJSON_IsString(item) && item->valuestring != NULL) {
strncpy(out, item->valuestring, out_sz - 1);
out[out_sz - 1] = '\0';
return 0;
}
printed = cJSON_PrintUnformatted((cJSON *)item);
if (printed == NULL) {
return -1;
}
strncpy(out, printed, out_sz - 1);
out[out_sz - 1] = '\0';
free(printed);
return 0;
}
static int compute_hash_hex_for_json_item(const cJSON *item, char *out_hex, size_t out_hex_sz) {
unsigned char hash[32];
char *compact = NULL;
if (out_hex == NULL || out_hex_sz < 65) {
return -1;
}
if (item == NULL) {
compact = strdup("null");
} else {
compact = cJSON_PrintUnformatted((cJSON *)item);
}
if (compact == NULL) {
return -1;
}
if (nostr_sha256((const unsigned char *)compact, strlen(compact), hash) != 0) {
free(compact);
return -1;
}
nostr_bytes_to_hex(hash, sizeof(hash), out_hex);
out_hex[64] = '\0';
free(compact);
return 0;
}
static int compute_params_hash_hex(cJSON *root, char *out_hex, size_t out_hex_sz) {
cJSON *params = cJSON_GetObjectItemCaseSensitive(root, "params");
return compute_hash_hex_for_json_item(params, out_hex, out_hex_sz);
}
static cJSON *find_tag_value(cJSON *tags, const char *name) {
int i;
if (!cJSON_IsArray(tags) || name == NULL) {
return NULL;
}
for (i = 0; i < cJSON_GetArraySize(tags); ++i) {
cJSON *tag = cJSON_GetArrayItem(tags, i);
cJSON *tag_name;
cJSON *tag_value;
if (!cJSON_IsArray(tag) || cJSON_GetArraySize(tag) < 2) {
continue;
}
tag_name = cJSON_GetArrayItem(tag, 0);
tag_value = cJSON_GetArrayItem(tag, 1);
if (!cJSON_IsString(tag_name) || tag_name->valuestring == NULL) {
continue;
}
if (strcmp(tag_name->valuestring, name) != 0) {
continue;
}
return tag_value;
}
return NULL;
}
static cJSON *build_tag_pair(const char *name, const char *value) {
cJSON *pair;
if (name == NULL || value == NULL) {
return NULL;
}
pair = cJSON_CreateArray();
if (pair == NULL) {
return NULL;
}
cJSON_AddItemToArray(pair, cJSON_CreateString(name));
cJSON_AddItemToArray(pair, cJSON_CreateString(value));
return pair;
}
int auth_envelope_build_for_request(const char *request_id,
const char *method,
const cJSON *params,
const unsigned char privkey[32],
const char *label,
time_t created_at,
cJSON **out_auth) {
cJSON *tags = NULL;
cJSON *auth = NULL;
char body_hash_hex[65];
if (out_auth == NULL || request_id == NULL || method == NULL ||
privkey == NULL || request_id[0] == '\0' || method[0] == '\0') {
return -1;
}
*out_auth = NULL;
if (compute_hash_hex_for_json_item(params, body_hash_hex, sizeof(body_hash_hex)) != 0) {
return -1;
}
tags = cJSON_CreateArray();
if (tags == NULL) {
return -1;
}
cJSON_AddItemToArray(tags, build_tag_pair("nsigner_rpc", request_id));
cJSON_AddItemToArray(tags, build_tag_pair("nsigner_method", method));
cJSON_AddItemToArray(tags, build_tag_pair("nsigner_body_hash", body_hash_hex));
if (created_at <= 0) {
created_at = time(NULL);
}
auth = nostr_create_and_sign_event(AUTH_EVENT_KIND,
(label != NULL) ? label : "",
tags,
privkey,
created_at);
if (auth == NULL) {
cJSON_Delete(tags);
return -1;
}
*out_auth = auth;
return 0;
}
int auth_envelope_verify_request(const char *request_json,
auth_nonce_cache_t *cache,
int skew_seconds,
char *out_pubkey_hex,
size_t out_pubkey_hex_sz,
char *out_label,
size_t out_label_sz,
int *out_error_code,
const char **out_error_message) {
cJSON *root = NULL;
cJSON *auth = NULL;
cJSON *method_item;
cJSON *id_item;
cJSON *kind_item;
cJSON *created_item;
cJSON *pubkey_item;
cJSON *content_item;
cJSON *id_hex_item;
cJSON *tags_item;
cJSON *tag_rpc;
cJSON *tag_method;
cJSON *tag_body_hash;
char request_id[128];
char body_hash_hex[65];
uint8_t nonce_bytes[32];
time_t now;
long long created;
if (out_error_code != NULL) {
*out_error_code = 0;
}
if (out_error_message != NULL) {
*out_error_message = NULL;
}
if (out_pubkey_hex == NULL || out_pubkey_hex_sz < 65 ||
out_label == NULL || out_label_sz == 0 ||
request_json == NULL || cache == NULL) {
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
out_pubkey_hex[0] = '\0';
out_label[0] = '\0';
root = cJSON_Parse(request_json);
if (root == NULL) {
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
method_item = cJSON_GetObjectItemCaseSensitive(root, "method");
id_item = cJSON_GetObjectItemCaseSensitive(root, "id");
if (!cJSON_IsString(method_item) || method_item->valuestring == NULL ||
json_item_to_compact_string(id_item, request_id, sizeof(request_id)) != 0) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
auth = cJSON_GetObjectItemCaseSensitive(root, "auth");
if (!cJSON_IsObject(auth)) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_REQUIRED,
"auth_envelope_required");
}
if (nostr_validate_event_structure(auth) != 0) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
if (nostr_verify_event_signature(auth) != 0) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_SIGNATURE_INVALID,
"auth_signature_invalid");
}
kind_item = cJSON_GetObjectItemCaseSensitive(auth, "kind");
if (!cJSON_IsNumber(kind_item) || kind_item->valueint != AUTH_EVENT_KIND) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_KIND_INVALID,
"auth_kind_invalid");
}
tags_item = cJSON_GetObjectItemCaseSensitive(auth, "tags");
tag_rpc = find_tag_value(tags_item, "nsigner_rpc");
tag_method = find_tag_value(tags_item, "nsigner_method");
tag_body_hash = find_tag_value(tags_item, "nsigner_body_hash");
if (!cJSON_IsString(tag_rpc) || tag_rpc->valuestring == NULL ||
!cJSON_IsString(tag_method) || tag_method->valuestring == NULL ||
!cJSON_IsString(tag_body_hash) || tag_body_hash->valuestring == NULL) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
if (strcmp(tag_rpc->valuestring, request_id) != 0 ||
strcmp(tag_method->valuestring, method_item->valuestring) != 0) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MISMATCH,
"auth_envelope_mismatch");
}
if (compute_params_hash_hex(root, body_hash_hex, sizeof(body_hash_hex)) != 0 ||
strcasecmp(tag_body_hash->valuestring, body_hash_hex) != 0) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_BODY_MISMATCH,
"auth_body_mismatch");
}
created_item = cJSON_GetObjectItemCaseSensitive(auth, "created_at");
if (!cJSON_IsNumber(created_item)) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
if (skew_seconds <= 0) {
skew_seconds = AUTH_DEFAULT_SKEW_SECONDS;
}
now = time(NULL);
created = (long long)created_item->valuedouble;
if (llabs((long long)now - created) > (long long)skew_seconds) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_STALE,
"auth_envelope_stale");
}
id_hex_item = cJSON_GetObjectItemCaseSensitive(auth, "id");
if (!cJSON_IsString(id_hex_item) || id_hex_item->valuestring == NULL ||
strlen(id_hex_item->valuestring) != 64 ||
nostr_hex_to_bytes(id_hex_item->valuestring, nonce_bytes, sizeof(nonce_bytes)) != 0) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
if (auth_nonce_cache_contains(cache, nonce_bytes)) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_REPLAY_DETECTED,
"auth_replay_detected");
}
auth_nonce_cache_insert(cache, nonce_bytes);
pubkey_item = cJSON_GetObjectItemCaseSensitive(auth, "pubkey");
if (!cJSON_IsString(pubkey_item) || pubkey_item->valuestring == NULL ||
strlen(pubkey_item->valuestring) != 64) {
cJSON_Delete(root);
return set_error(out_error_code, out_error_message,
AUTH_ERR_ENVELOPE_MALFORMED,
"auth_envelope_malformed");
}
strncpy(out_pubkey_hex, pubkey_item->valuestring, out_pubkey_hex_sz - 1);
out_pubkey_hex[out_pubkey_hex_sz - 1] = '\0';
content_item = cJSON_GetObjectItemCaseSensitive(auth, "content");
if (cJSON_IsString(content_item) && content_item->valuestring != NULL) {
size_t i;
for (i = 0; content_item->valuestring[i] != '\0' && i + 1 < out_label_sz; ++i) {
unsigned char ch = (unsigned char)content_item->valuestring[i];
out_label[i] = (char)((isprint(ch) && ch != '\n' && ch != '\r' && ch != '\t') ? ch : ' ');
}
out_label[i] = '\0';
} else {
out_label[0] = '\0';
}
cJSON_Delete(root);
return 0;
}

49
src/auth_envelope.h Normal file
View File

@@ -0,0 +1,49 @@
#ifndef NSIGNER_AUTH_ENVELOPE_H
#define NSIGNER_AUTH_ENVELOPE_H
#include <stddef.h>
#include <stdint.h>
#include <time.h>
#include <cJSON.h>
#define AUTH_NONCE_CACHE_SIZE 1024
#define AUTH_DEFAULT_SKEW_SECONDS 30
#define AUTH_EVENT_KIND 27235
#define AUTH_ERR_ENVELOPE_MALFORMED 2010
#define AUTH_ERR_BODY_MISMATCH 2011
#define AUTH_ERR_SIGNATURE_INVALID 2012
#define AUTH_ERR_KIND_INVALID 2013
#define AUTH_ERR_ENVELOPE_REQUIRED 2014
#define AUTH_ERR_ENVELOPE_MISMATCH 2015
#define AUTH_ERR_ENVELOPE_STALE 2016
#define AUTH_ERR_REPLAY_DETECTED 2017
typedef struct {
uint8_t ids[AUTH_NONCE_CACHE_SIZE][32];
int count;
int next;
} auth_nonce_cache_t;
void auth_nonce_cache_init(auth_nonce_cache_t *cache);
int auth_envelope_verify_request(const char *request_json,
auth_nonce_cache_t *cache,
int skew_seconds,
char *out_pubkey_hex,
size_t out_pubkey_hex_sz,
char *out_label,
size_t out_label_sz,
int *out_error_code,
const char **out_error_message);
int auth_envelope_build_for_request(const char *request_id,
const char *method,
const cJSON *params,
const unsigned char privkey[32],
const char *label,
time_t created_at,
cJSON **out_auth);
#endif

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -388,7 +396,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -584,7 +592,10 @@ char *dispatcher_handle_request(dispatcher_ctx_t *ctx, const char *json_request)
selector_request_init(&selector_req);
options_item = cJSON_GetArrayItem(params_item, 1);
{
int params_count = cJSON_GetArraySize(params_item);
options_item = (params_count > 0) ? cJSON_GetArrayItem(params_item, params_count - 1) : NULL;
}
if (cJSON_IsObject(options_item)) {
tmp = cJSON_GetObjectItemCaseSensitive(options_item, "role");
if (tmp != NULL) {

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -75,7 +75,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -231,7 +231,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -241,6 +241,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -251,6 +257,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -279,7 +286,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -312,6 +320,9 @@ typedef struct {
* Returns number of keys derived, or -1 on error. */
int crypto_derive_all(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic);
/* Derive key for exactly one role index. Returns 0 on success, -1 on error. */
int crypto_derive_one(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic, int role_index);
/* Get the derived private key for a role (by table index). Returns NULL if not derived. */
const unsigned char *crypto_get_private_key(const key_store_t *store, int role_index);
@@ -378,7 +389,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -520,6 +531,74 @@ int crypto_derive_all(key_store_t *store, role_table_t *table, const mnemonic_st
return derived_count;
}
int crypto_derive_one(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic, int role_index) {
role_entry_t *role;
derived_key_t *dst;
unsigned char priv[32];
unsigned char pub[32];
if (store == NULL || table == NULL || mnemonic == NULL) {
return -1;
}
if (!mnemonic_is_loaded(mnemonic)) {
return -1;
}
if (role_index < 0 || role_index >= table->count || role_index >= ROLE_TABLE_MAX_ENTRIES) {
return -1;
}
role = &table->entries[role_index];
dst = &store->keys[role_index];
role->derived = 0;
role->pubkey_hex[0] = '\0';
secure_buf_free(&dst->private_key);
secure_memzero(dst->public_key, sizeof(dst->public_key));
secure_memzero(dst->pubkey_hex, sizeof(dst->pubkey_hex));
secure_memzero(dst->npub, sizeof(dst->npub));
dst->valid = 0;
if (role->purpose != PURPOSE_NOSTR ||
role->curve != CURVE_SECP256K1 ||
role->selector_type != SELECTOR_NOSTR_INDEX) {
return -1;
}
if (secure_buf_alloc(&dst->private_key, 32) != 0) {
return -1;
}
if (nostr_derive_keys_from_mnemonic(mnemonic_get_phrase(mnemonic), role->nostr_index, priv, pub) != 0) {
secure_memzero(priv, sizeof(priv));
secure_memzero(pub, sizeof(pub));
secure_buf_free(&dst->private_key);
return -1;
}
memcpy(dst->private_key.data, priv, 32);
memcpy(dst->public_key, pub, 32);
nostr_bytes_to_hex(pub, 32, dst->pubkey_hex);
dst->npub[0] = '\0';
(void)nostr_key_to_bech32(pub, "npub", dst->npub);
strncpy(role->pubkey_hex, dst->pubkey_hex, sizeof(role->pubkey_hex) - 1);
role->pubkey_hex[sizeof(role->pubkey_hex) - 1] = '\0';
role->derived = 1;
dst->valid = 1;
if (store->count < table->count) {
store->count = table->count;
}
secure_memzero(priv, sizeof(priv));
secure_memzero(pub, sizeof(pub));
return 0;
}
const unsigned char *crypto_get_private_key(const key_store_t *store, int role_index) {
if (store == NULL || role_index < 0 || role_index >= ROLE_TABLE_MAX_ENTRIES) {
return NULL;

View File

@@ -75,7 +75,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -151,6 +151,9 @@ const char *role_purpose_to_str(role_purpose_t p);
/* Curve enum to string */
const char *role_curve_to_str(role_curve_t c);
/* Register a nostr-index role if missing. Returns 0 on success, -1 on error. */
int role_table_register_nostr_index(role_table_t *table, int nostr_index);
/* from selector.h */
@@ -231,7 +234,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -241,6 +244,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -251,6 +260,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -274,12 +284,19 @@ void policy_init_default(policy_table_t *table, uid_t owner_uid);
/* Add a policy entry. Returns 0 on success, -1 if full. */
int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
/* Insert an entry before the final catch-all rule. */
int policy_table_insert_before_last(policy_table_t *table, const policy_entry_t *entry);
/* Parse a --preapprove spec into a policy entry. */
int parse_preapprove_spec(const char *spec, policy_entry_t *out_entry, int *out_nostr_index);
/*
* Check whether caller_id is allowed to invoke `verb` on `role_name` with given `purpose`.
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -384,7 +401,7 @@ typedef struct {
gid_t gid;
pid_t pid;
int kind;
char caller_id[64]; /* "uid:<n>" or "qubes:<vm>" */
char caller_id[80]; /* "uid:<n>" or "qubes:<vm>" */
char source_qube[64];
} caller_identity_t;
@@ -451,8 +468,8 @@ int socket_name_random(char *out, size_t out_len);
/* Version information (auto-updated by build/version tooling) */
#define NSIGNER_VERSION_MAJOR 0
#define NSIGNER_VERSION_MINOR 0
#define NSIGNER_VERSION_PATCH 6
#define NSIGNER_VERSION "v0.0.6"
#define NSIGNER_VERSION_PATCH 21
#define NSIGNER_VERSION "v0.0.21"
/* NSIGNER_HEADERLESS_DECLS_END */
@@ -549,12 +566,16 @@ static void print_usage(const char *program_name) {
printf("nsigner - single-binary signer program\n");
printf("Usage:\n");
printf(" %s [--socket-name|--name|-n <name>] [--listen <unix|stdio|qrexec|tcp:HOST:PORT>]\n", program_name);
printf(" [--preapprove <SPEC>]...\n");
printf(" Run signer server (unix mode has TUI)\n");
printf(" %s [--socket-name|--name|-n <name>] client '<json>' Send JSON-RPC request\n", program_name);
printf(" %s [--socket-name|--name|-n <name>] client - Read JSON-RPC request from stdin\n", program_name);
printf(" %s list List running nsigner abstract sockets\n", program_name);
printf(" %s --help\n", program_name);
printf(" %s --version\n", program_name);
printf("\nOptions:\n");
printf(" --preapprove SPEC Pre-approve a caller for a role (repeatable)\n");
printf(" SPEC: caller=<id>,role=<name> or caller=<id>,nostr_index=<n>\n");
}
static int extract_nsigner_socket_from_proc_line(const char *line,
@@ -746,6 +767,28 @@ static void activity_log_cb(const char *message, void *user_data) {
g_activity_log.count++;
}
static void tcp_activity_stdout_cb(const char *message, void *user_data) {
time_t now;
struct tm tm_now;
char ts[32];
(void)user_data;
if (message == NULL) {
return;
}
now = time(NULL);
if (localtime_r(&now, &tm_now) != NULL) {
(void)strftime(ts, sizeof(ts), "%Y-%m-%d %H:%M:%S", &tm_now);
} else {
strncpy(ts, "0000-00-00 00:00:00", sizeof(ts) - 1);
ts[sizeof(ts) - 1] = '\0';
}
printf("[%s] %s\n", ts, message);
fflush(stdout);
}
static void render_status(const role_table_t *role_table,
const mnemonic_state_t *mnemonic,
int derived_count,
@@ -785,7 +828,7 @@ static void render_status(const role_table_t *role_table,
}
printf("\nHotkeys\n-------\n");
printf("q quit l lock/reunlock r refresh a toggle auto-approve(prompt): %s\n",
printf("q/x quit l lock/reunlock r refresh A toggle auto-approve(prompt): %s\n",
g_auto_approve ? "ON" : "OFF");
fflush(stdout);
}
@@ -814,14 +857,14 @@ static int prompt_load_mnemonic(mnemonic_state_t *mnemonic) {
char phrase[MNEMONIC_MAX_LEN];
char phrase_copy[MNEMONIC_MAX_LEN];
char mode[MNEMONIC_MAX_LEN];
struct termios old_term;
struct termios new_term;
int have_term = 0;
int invalid_attempts = 0;
const int max_invalid_attempts = 10;
if (mnemonic == NULL) {
return -1;
}
while (invalid_attempts < max_invalid_attempts) {
printf("Mnemonic source: [E]nter existing or [G]enerate new (default E; you can also paste mnemonic here): ");
fflush(stdout);
if (read_line_stdin(mode, sizeof(mode)) != 0) {
@@ -829,14 +872,25 @@ static int prompt_load_mnemonic(mnemonic_state_t *mnemonic) {
return -1;
}
if (strchr(mode, ' ') != NULL && mode[0] != 'g' && mode[0] != 'G') {
if (mnemonic_load(mnemonic, mode) != 0) {
fprintf(stderr, "Invalid mnemonic (must be 12/15/18/21/24 words)\n");
if ((mode[0] == 'q' || mode[0] == 'Q' || mode[0] == 'x' || mode[0] == 'X') && mode[1] == '\0') {
fprintf(stderr, "User requested exit.\n");
return -1;
}
if (strchr(mode, ' ') != NULL && mode[0] != 'g' && mode[0] != 'G') {
if (mnemonic_load(mnemonic, mode) == 0) {
printf("Seed phrase is valid and accepted.\n");
return 0;
}
invalid_attempts++;
fprintf(stderr,
"Invalid mnemonic (must be 12/15/18/21/24 words). Attempts: %d/%d\n",
invalid_attempts,
max_invalid_attempts);
continue;
}
if (mode[0] == 'g' || mode[0] == 'G') {
int idx = 1;
char *ctx = NULL;
@@ -865,6 +919,7 @@ static int prompt_load_mnemonic(mnemonic_state_t *mnemonic) {
return -1;
}
printf("Seed phrase is valid and accepted.\n");
memset(phrase, 0, sizeof(phrase));
memset(phrase_copy, 0, sizeof(phrase_copy));
return 0;
@@ -873,37 +928,35 @@ static int prompt_load_mnemonic(mnemonic_state_t *mnemonic) {
printf("Enter mnemonic (12/15/18/21/24 words): ");
fflush(stdout);
if (isatty(STDIN_FILENO) && tcgetattr(STDIN_FILENO, &old_term) == 0) {
new_term = old_term;
new_term.c_lflag &= (tcflag_t)~ECHO;
if (tcsetattr(STDIN_FILENO, TCSANOW, &new_term) == 0) {
have_term = 1;
}
}
if (read_line_stdin(phrase, sizeof(phrase)) != 0) {
if (have_term) {
(void)tcsetattr(STDIN_FILENO, TCSANOW, &old_term);
}
fprintf(stderr, "Failed to read mnemonic\n");
return -1;
}
if (have_term) {
(void)tcsetattr(STDIN_FILENO, TCSANOW, &old_term);
printf("\n");
}
if (mnemonic_load(mnemonic, phrase) != 0) {
if ((phrase[0] == 'q' || phrase[0] == 'Q' || phrase[0] == 'x' || phrase[0] == 'X') && phrase[1] == '\0') {
memset(phrase, 0, sizeof(phrase));
fprintf(stderr, "Invalid mnemonic (must be 12/15/18/21/24 words)\n");
fprintf(stderr, "User requested exit.\n");
return -1;
}
if (mnemonic_load(mnemonic, phrase) == 0) {
printf("Seed phrase is valid and accepted.\n");
memset(phrase, 0, sizeof(phrase));
return 0;
}
memset(phrase, 0, sizeof(phrase));
invalid_attempts++;
fprintf(stderr,
"Invalid mnemonic (must be 12/15/18/21/24 words). Attempts: %d/%d\n",
invalid_attempts,
max_invalid_attempts);
}
fprintf(stderr, "Too many invalid mnemonic attempts (%d). Exiting.\n", max_invalid_attempts);
return -1;
}
static void apply_test_overrides(policy_table_t *policy) {
const char *force_prompt;
const char *noninteractive_prompt;
@@ -937,8 +990,8 @@ static void apply_test_overrides(policy_table_t *policy) {
if (hotkeys != NULL) {
const char *p = hotkeys;
while (*p != '\0') {
char ch = (char)tolower((unsigned char)*p);
if (ch == 'a') {
char ch = *p;
if (ch == 'A') {
g_auto_approve = g_auto_approve ? 0 : 1;
server_set_prompt_always_allow(g_auto_approve);
}
@@ -963,6 +1016,8 @@ int main(int argc, char *argv[]) {
int listen_mode = NSIGNER_LISTEN_UNIX;
const char *listen_target = NSIGNER_DEFAULT_SOCKET_NAME;
int argi = 1;
const char *preapprove_specs[POLICY_MAX_ENTRIES];
int preapprove_count = 0;
while (argi < argc) {
if (strcmp(argv[argi], "--socket-name") == 0 ||
@@ -998,6 +1053,19 @@ int main(int argc, char *argv[]) {
argi += 2;
continue;
}
if (strcmp(argv[argi], "--preapprove") == 0) {
if (argi + 1 >= argc) {
fprintf(stderr, "Missing value for %s\n", argv[argi]);
return 1;
}
if (preapprove_count >= POLICY_MAX_ENTRIES) {
fprintf(stderr, "Too many --preapprove entries (max %d)\n", POLICY_MAX_ENTRIES);
return 1;
}
preapprove_specs[preapprove_count++] = argv[argi + 1];
argi += 2;
continue;
}
break;
}
@@ -1033,6 +1101,9 @@ int main(int argc, char *argv[]) {
return 1;
}
printf("nsigner %s\n", NSIGNER_VERSION);
fflush(stdout);
mnemonic_init(&mnemonic);
if (prompt_load_mnemonic(&mnemonic) != 0) {
mnemonic_unload(&mnemonic);
@@ -1048,6 +1119,41 @@ int main(int argc, char *argv[]) {
memset(&key_store, 0, sizeof(key_store));
owner_uid = getuid();
policy_init_default(&policy, owner_uid);
for (int i = 0; i < preapprove_count; ++i) {
policy_entry_t entry;
int parsed_nostr_index = -1;
if (parse_preapprove_spec(preapprove_specs[i], &entry, &parsed_nostr_index) != 0) {
mnemonic_unload(&mnemonic);
return 1;
}
entry.source = POLICY_SOURCE_PREAPPROVE;
if (parsed_nostr_index >= 0 && role_table_find_by_nostr_index(&role_table, parsed_nostr_index) == NULL) {
if (role_table_register_nostr_index(&role_table, parsed_nostr_index) != 0) {
fprintf(stderr,
"ERROR: failed to register role for --preapprove nostr_index=%d\n",
parsed_nostr_index);
mnemonic_unload(&mnemonic);
return 1;
}
}
if (policy_table_insert_before_last(&policy, &entry) != 0) {
fprintf(stderr, "ERROR: failed to insert --preapprove policy entry (table full): %s\n", preapprove_specs[i]);
mnemonic_unload(&mnemonic);
return 1;
}
fprintf(stderr, "[PREAPPROVE] caller=%s role=%s\n", entry.caller, entry.roles[0]);
}
apply_test_overrides(&policy);
if (nostr_init() != 0) {
fprintf(stderr, "Failed to initialize crypto subsystem\n");
mnemonic_unload(&mnemonic);
@@ -1064,20 +1170,6 @@ int main(int argc, char *argv[]) {
dispatcher_init(&dispatcher, &role_table, &mnemonic, &key_store);
owner_uid = getuid();
if (listen_mode == NSIGNER_LISTEN_QREXEC || listen_mode == NSIGNER_LISTEN_TCP) {
policy_entry_t e;
policy_table_init(&policy);
memset(&e, 0, sizeof(e));
strncpy(e.caller, "*", sizeof(e.caller) - 1);
e.prompt = PROMPT_EVERY_REQUEST;
(void)policy_table_add(&policy, &e);
} else {
policy_init_default(&policy, owner_uid);
}
apply_test_overrides(&policy);
if (listen_mode == NSIGNER_LISTEN_UNIX && !socket_name_explicit) {
if (socket_name_random(generated_socket_name, sizeof(generated_socket_name)) != 0) {
fprintf(stderr, "Failed to generate random socket name\n");
@@ -1119,6 +1211,17 @@ int main(int argc, char *argv[]) {
(void)signal(SIGINT, handle_signal);
(void)signal(SIGTERM, handle_signal);
if (listen_mode == NSIGNER_LISTEN_UNIX) {
printf("System is ready and waiting for connections on @%s.\n", socket_name);
} else if (listen_mode == NSIGNER_LISTEN_TCP) {
printf("System is ready and waiting for connections on %s.\n", listen_target);
} else if (listen_mode == NSIGNER_LISTEN_QREXEC) {
printf("System is ready and waiting for a qrexec request.\n");
} else {
printf("System is ready and waiting for a stdio request.\n");
}
fflush(stdout);
if (listen_mode == NSIGNER_LISTEN_STDIO || listen_mode == NSIGNER_LISTEN_QREXEC) {
int hrc = server_handle_one(&server, NULL, NULL);
server_stop(&server);
@@ -1141,7 +1244,7 @@ int main(int argc, char *argv[]) {
break;
}
if (prc > 0 && (pfds[0].revents & POLLIN)) {
if (server_handle_one(&server, NULL, NULL) < 0) {
if (server_handle_one(&server, tcp_activity_stdout_cb, NULL) < 0) {
break;
}
}
@@ -1184,16 +1287,16 @@ int main(int argc, char *argv[]) {
if (prc > 0 && (pfds[1].revents & POLLIN)) {
char ch = '\0';
if (read(STDIN_FILENO, &ch, 1) > 0) {
ch = (char)tolower((unsigned char)ch);
if (ch == 'q') {
char lower = (char)tolower((unsigned char)ch);
if (lower == 'q' || lower == 'x') {
g_running = 0;
} else if (ch == 'r') {
} else if (lower == 'r') {
render_status(&role_table, &mnemonic, derived_count, socket_name);
} else if (ch == 'a') {
} else if (ch == 'A') {
g_auto_approve = g_auto_approve ? 0 : 1;
server_set_prompt_always_allow(g_auto_approve);
render_status(&role_table, &mnemonic, derived_count, socket_name);
} else if (ch == 'l') {
} else if (lower == 'l') {
printf("\n[lock] Session locked. Re-enter mnemonic to unlock.\n");
fflush(stdout);
crypto_wipe(&key_store);

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -440,7 +448,9 @@ int socket_name_random(char *out, size_t out_len);
/* NSIGNER_HEADERLESS_DECLS_END */
#include <errno.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
static void copy_str(char *dst, size_t dst_sz, const char *src) {
@@ -540,6 +550,112 @@ const char *prompt_mode_to_str(prompt_mode_t m) {
}
}
int parse_preapprove_spec(const char *spec, policy_entry_t *out_entry, int *out_nostr_index) {
char *spec_copy;
char *token;
const char *caller = NULL;
const char *role = NULL;
int nostr_index = -1;
int has_role = 0;
int has_nostr_index = 0;
if (out_nostr_index != NULL) {
*out_nostr_index = -1;
}
if (spec == NULL || out_entry == NULL) {
fprintf(stderr, "ERROR: invalid --preapprove arguments\n");
return -1;
}
spec_copy = (char *)malloc(strlen(spec) + 1);
if (spec_copy == NULL) {
fprintf(stderr, "ERROR: out of memory parsing --preapprove spec: %s\n", spec);
return -1;
}
memcpy(spec_copy, spec, strlen(spec) + 1);
token = strtok(spec_copy, ",");
while (token != NULL) {
char *eq = strchr(token, '=');
if (eq == NULL || eq == token || eq[1] == '\0') {
fprintf(stderr, "ERROR: invalid --preapprove key=value field: %s\n", spec);
free(spec_copy);
return -1;
}
*eq = '\0';
if (strcmp(token, "caller") == 0) {
caller = eq + 1;
} else if (strcmp(token, "role") == 0) {
role = eq + 1;
has_role = 1;
} else if (strcmp(token, "nostr_index") == 0) {
char *endptr = NULL;
long val;
errno = 0;
val = strtol(eq + 1, &endptr, 10);
if (errno != 0 || endptr == (eq + 1) || *endptr != '\0' || val < 0) {
fprintf(stderr, "ERROR: --preapprove spec has invalid nostr_index= value: %s\n", spec);
free(spec_copy);
return -1;
}
nostr_index = (int)val;
has_nostr_index = 1;
} else {
fprintf(stderr, "ERROR: unknown --preapprove field '%s' in spec: %s\n", token, spec);
free(spec_copy);
return -1;
}
token = strtok(NULL, ",");
}
if (caller == NULL) {
fprintf(stderr, "ERROR: --preapprove spec missing 'caller=' field: %s\n", spec);
free(spec_copy);
return -1;
}
if (!has_role && !has_nostr_index) {
fprintf(stderr, "ERROR: --preapprove spec must include 'role=' or 'nostr_index=': %s\n", spec);
free(spec_copy);
return -1;
}
if (has_role && has_nostr_index) {
fprintf(stderr, "ERROR: --preapprove spec has both 'role=' and 'nostr_index=' (use one): %s\n", spec);
free(spec_copy);
return -1;
}
memset(out_entry, 0, sizeof(*out_entry));
strncpy(out_entry->caller, caller, sizeof(out_entry->caller) - 1);
out_entry->caller[sizeof(out_entry->caller) - 1] = '\0';
if (has_role) {
strncpy(out_entry->roles[0], role, sizeof(out_entry->roles[0]) - 1);
out_entry->roles[0][sizeof(out_entry->roles[0]) - 1] = '\0';
} else {
if (nostr_index == 0) {
strncpy(out_entry->roles[0], "main", sizeof(out_entry->roles[0]) - 1);
out_entry->roles[0][sizeof(out_entry->roles[0]) - 1] = '\0';
} else {
(void)snprintf(out_entry->roles[0], sizeof(out_entry->roles[0]), "nostr_idx_%d", nostr_index);
}
if (out_nostr_index != NULL) {
*out_nostr_index = nostr_index;
}
}
out_entry->role_count = 1;
out_entry->prompt = PROMPT_NEVER;
free(spec_copy);
return 0;
}
void policy_table_init(policy_table_t *table) {
if (table == NULL) {
return;
@@ -549,8 +665,9 @@ void policy_table_init(policy_table_t *table) {
}
void policy_init_default(policy_table_t *table, uid_t owner_uid) {
policy_entry_t allow_owner;
policy_entry_t deny_all;
policy_entry_t prompt_all;
(void)owner_uid;
if (table == NULL) {
return;
@@ -558,15 +675,11 @@ void policy_init_default(policy_table_t *table, uid_t owner_uid) {
policy_table_init(table);
memset(&allow_owner, 0, sizeof(allow_owner));
(void)snprintf(allow_owner.caller, sizeof(allow_owner.caller), "uid:%u", (unsigned int)owner_uid);
allow_owner.prompt = PROMPT_NEVER;
(void)policy_table_add(table, &allow_owner);
memset(&deny_all, 0, sizeof(deny_all));
copy_str(deny_all.caller, sizeof(deny_all.caller), "*");
deny_all.prompt = PROMPT_DENY;
(void)policy_table_add(table, &deny_all);
memset(&prompt_all, 0, sizeof(prompt_all));
copy_str(prompt_all.caller, sizeof(prompt_all.caller), "*");
prompt_all.prompt = PROMPT_EVERY_REQUEST;
prompt_all.source = POLICY_SOURCE_DEFAULT;
(void)policy_table_add(table, &prompt_all);
}
int policy_table_add(policy_table_t *table, const policy_entry_t *entry) {
@@ -583,10 +696,34 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry) {
return 0;
}
int policy_table_insert_before_last(policy_table_t *table, const policy_entry_t *entry) {
if (table == NULL || entry == NULL) {
return -1;
}
if (table->count >= POLICY_MAX_ENTRIES) {
return -1;
}
if (table->count == 0) {
return policy_table_add(table, entry);
}
table->entries[table->count] = table->entries[table->count - 1];
table->entries[table->count - 1] = *entry;
table->count++;
return 0;
}
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose) {
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source) {
int i;
if (out_source != NULL) {
*out_source = POLICY_SOURCE_DEFAULT;
}
if (table == NULL || caller_id == NULL || verb == NULL || role_name == NULL || purpose == NULL) {
return POLICY_NO_MATCH;
}
@@ -618,12 +755,20 @@ int policy_check(const policy_table_t *table, const char *caller_id,
continue;
}
if (out_source != NULL) {
*out_source = entry->source;
}
if (entry->prompt == PROMPT_DENY) {
return POLICY_DENY;
}
if (entry->prompt == PROMPT_NEVER) {
return POLICY_ALLOW;
}
if (out_source != NULL) {
*out_source = POLICY_SOURCE_DEFAULT;
}
return POLICY_PROMPT;
}

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -149,6 +149,9 @@ const char *role_purpose_to_str(role_purpose_t p);
/* Curve enum to string */
const char *role_curve_to_str(role_curve_t c);
/* Register a nostr-index role if missing. Returns 0 on success, -1 on error. */
int role_table_register_nostr_index(role_table_t *table, int nostr_index);
/* from selector.h */
@@ -229,7 +232,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +242,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +258,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +287,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +387,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -440,6 +451,7 @@ int socket_name_random(char *out, size_t out_len);
/* NSIGNER_HEADERLESS_DECLS_END */
#include <stdio.h>
#include <string.h>
static int str_eq(const char *a, const char *b) {
@@ -533,6 +545,36 @@ role_entry_t *role_table_get_default(role_table_t *table) {
return role_table_find_by_name(table, "main");
}
int role_table_register_nostr_index(role_table_t *table, int nostr_index) {
role_entry_t role;
if (table == NULL || nostr_index < 0) {
return -1;
}
if (role_table_find_by_nostr_index(table, nostr_index) != NULL) {
return 0;
}
memset(&role, 0, sizeof(role));
if (nostr_index == 0) {
strncpy(role.name, "main", sizeof(role.name) - 1);
} else {
(void)snprintf(role.name, sizeof(role.name), "nostr_idx_%d", nostr_index);
}
strncpy(role.purpose_str, "nostr", sizeof(role.purpose_str) - 1);
strncpy(role.curve_str, "secp256k1", sizeof(role.curve_str) - 1);
role.purpose = role_purpose_from_str(role.purpose_str);
role.curve = role_curve_from_str(role.curve_str);
role.selector_type = SELECTOR_NOSTR_INDEX;
role.nostr_index = nostr_index;
role.derived = 0;
return role_table_add(table, &role);
}
role_purpose_t role_purpose_from_str(const char *s) {
if (str_eq(s, "nostr")) {
return PURPOSE_NOSTR;

View File

@@ -75,7 +75,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -231,7 +231,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -241,6 +241,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -251,6 +257,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -279,7 +286,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -378,7 +386,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -75,7 +75,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -151,6 +151,9 @@ const char *role_purpose_to_str(role_purpose_t p);
/* Curve enum to string */
const char *role_curve_to_str(role_curve_t c);
/* Register a nostr-index role if missing. Returns 0 on success, -1 on error. */
int role_table_register_nostr_index(role_table_t *table, int nostr_index);
/* from selector.h */
@@ -231,7 +234,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -241,6 +244,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -251,6 +260,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -261,6 +271,8 @@ typedef struct {
/* Policy check result */
#define POLICY_ALLOW 0
#define POLICY_ALLOW_SESSION_VERB 3 /* allow + save session grant for this caller+role+verb */
#define POLICY_ALLOW_SESSION_ALL 4 /* allow + save session grant for this caller+role (all verbs) */
#define POLICY_DENY -1
#define POLICY_PROMPT -2 /* would need user confirmation */
#define POLICY_NO_MATCH -3 /* no policy entry matched (fail-closed = deny) */
@@ -274,12 +286,16 @@ void policy_init_default(policy_table_t *table, uid_t owner_uid);
/* Add a policy entry. Returns 0 on success, -1 if full. */
int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
/* Insert an entry before the final catch-all rule. */
int policy_table_insert_before_last(policy_table_t *table, const policy_entry_t *entry);
/*
* Check whether caller_id is allowed to invoke `verb` on `role_name` with given `purpose`.
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -312,6 +328,9 @@ typedef struct {
* Returns number of keys derived, or -1 on error. */
int crypto_derive_all(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic);
/* Derive key for exactly one role index. Returns 0 on success, -1 on error. */
int crypto_derive_one(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic, int role_index);
/* Get the derived private key for a role (by table index). Returns NULL if not derived. */
const unsigned char *crypto_get_private_key(const key_store_t *store, int role_index);
@@ -384,8 +403,11 @@ typedef struct {
gid_t gid;
pid_t pid;
int kind;
char caller_id[64]; /* "uid:<n>" or "qubes:<vm>" */
char caller_id[80]; /* "uid:<n>", "qubes:<vm>", or "pubkey:<hex>" */
char source_qube[64];
int auth_present;
char auth_pubkey_hex[65];
char auth_label[64];
} caller_identity_t;
/* Server context */
@@ -455,6 +477,8 @@ int socket_name_random(char *out, size_t out_len);
int transport_send_framed(int fd, const char *payload);
int transport_recv_framed(int fd, char **out_payload, size_t max_size);
#include "auth_envelope.h"
#include <arpa/inet.h>
#include <ctype.h>
#include <errno.h>
@@ -468,6 +492,159 @@ int transport_recv_framed(int fd, char **out_payload, size_t max_size);
static int g_prompt_always_allow = 0;
static int g_noninteractive_prompt_default = -1;
static auth_nonce_cache_t g_auth_nonce_cache;
static int g_auth_nonce_cache_inited = 0;
static int caller_id_extract_ipv6(const char *caller_id, char *out_ipv6, size_t out_sz) {
const char *start;
const char *end;
size_t len;
if (caller_id == NULL || out_ipv6 == NULL || out_sz == 0) {
return -1;
}
if (strncmp(caller_id, "tcp:[", 5) != 0) {
return -1;
}
start = caller_id + 5;
end = strchr(start, ']');
if (end == NULL || end[1] != ':') {
return -1;
}
len = (size_t)(end - start);
if (len == 0 || len >= out_sz) {
return -1;
}
memcpy(out_ipv6, start, len);
out_ipv6[len] = '\0';
return 0;
}
static int read_cmd_output(const char *cmd, char **out_buf) {
FILE *fp;
char chunk[512];
char *buf = NULL;
size_t used = 0;
size_t cap = 0;
if (cmd == NULL || out_buf == NULL) {
return -1;
}
*out_buf = NULL;
fp = popen(cmd, "r");
if (fp == NULL) {
return -1;
}
while (fgets(chunk, sizeof(chunk), fp) != NULL) {
size_t n = strlen(chunk);
if (used + n + 1 > cap) {
size_t new_cap = (cap == 0) ? 2048 : cap * 2;
while (new_cap < used + n + 1) {
new_cap *= 2;
}
{
char *tmp = (char *)realloc(buf, new_cap);
if (tmp == NULL) {
free(buf);
(void)pclose(fp);
return -1;
}
buf = tmp;
cap = new_cap;
}
}
memcpy(buf + used, chunk, n);
used += n;
}
(void)pclose(fp);
if (buf == NULL) {
return -1;
}
buf[used] = '\0';
*out_buf = buf;
return 0;
}
static int lookup_fips_peer_for_ipv6(const char *ipv6,
char *out_npub,
size_t out_npub_sz,
char *out_name,
size_t out_name_sz) {
char *json = NULL;
cJSON *root = NULL;
cJSON *peers = NULL;
int i;
if (ipv6 == NULL || out_npub == NULL || out_npub_sz == 0 || out_name == NULL || out_name_sz == 0) {
return -1;
}
out_npub[0] = '\0';
out_name[0] = '\0';
if (read_cmd_output("fipsctl show peers 2>/dev/null", &json) != 0) {
return -1;
}
root = cJSON_Parse(json);
free(json);
if (root == NULL) {
return -1;
}
peers = cJSON_GetObjectItemCaseSensitive(root, "peers");
if (!cJSON_IsArray(peers)) {
cJSON_Delete(root);
return -1;
}
for (i = 0; i < cJSON_GetArraySize(peers); ++i) {
cJSON *peer = cJSON_GetArrayItem(peers, i);
cJSON *peer_ip;
cJSON *peer_npub;
cJSON *peer_name;
if (!cJSON_IsObject(peer)) {
continue;
}
peer_ip = cJSON_GetObjectItemCaseSensitive(peer, "ipv6_addr");
if (!cJSON_IsString(peer_ip) || peer_ip->valuestring == NULL) {
continue;
}
if (strcmp(peer_ip->valuestring, ipv6) != 0) {
continue;
}
peer_npub = cJSON_GetObjectItemCaseSensitive(peer, "npub");
peer_name = cJSON_GetObjectItemCaseSensitive(peer, "display_name");
if (cJSON_IsString(peer_npub) && peer_npub->valuestring != NULL) {
strncpy(out_npub, peer_npub->valuestring, out_npub_sz - 1);
out_npub[out_npub_sz - 1] = '\0';
}
if (cJSON_IsString(peer_name) && peer_name->valuestring != NULL) {
strncpy(out_name, peer_name->valuestring, out_name_sz - 1);
out_name[out_name_sz - 1] = '\0';
}
cJSON_Delete(root);
return (out_npub[0] != '\0') ? 0 : -1;
}
cJSON_Delete(root);
return -1;
}
void server_set_prompt_always_allow(int enabled) {
g_prompt_always_allow = enabled ? 1 : 0;
@@ -484,7 +661,8 @@ void server_set_noninteractive_prompt_default(int decision) {
static int prompt_for_policy_decision(const caller_identity_t *caller,
const char *method,
const char *role_name,
const char *purpose) {
const char *purpose,
int pending_derivation) {
int ch;
if (g_prompt_always_allow) {
@@ -501,10 +679,28 @@ static int prompt_for_policy_decision(const caller_identity_t *caller,
printf("\nApproval required\n");
printf("caller: %s\n", (caller != NULL) ? caller->caller_id : "unknown");
if (caller != NULL && caller->kind == NSIGNER_LISTEN_TCP) {
char ipv6[INET6_ADDRSTRLEN];
char npub[128];
char display_name[128];
if (caller_id_extract_ipv6(caller->caller_id, ipv6, sizeof(ipv6)) == 0 &&
lookup_fips_peer_for_ipv6(ipv6, npub, sizeof(npub), display_name, sizeof(display_name)) == 0) {
if (display_name[0] != '\0') {
printf("fips peer: %s (%s)\n", npub, display_name);
} else {
printf("fips peer: %s\n", npub);
}
}
}
printf("method: %s\n", (method != NULL) ? method : "unknown");
printf("role: %s\n", (role_name != NULL) ? role_name : "unknown");
printf("purpose: %s\n", (purpose != NULL) ? purpose : "unknown");
printf("[y] allow once [n] deny [a] always allow this session\n> ");
if (pending_derivation) {
printf(" ** NEW IDENTITY — will be derived if approved **\n");
}
printf("[y] allow once [n] deny [e] allow this caller+role+verb for session\n");
printf("[a] allow this caller+role for session (all verbs)\n> ");
fflush(stdout);
ch = getchar();
@@ -517,8 +713,10 @@ static int prompt_for_policy_decision(const caller_identity_t *caller,
ch = tolower(ch);
if (ch == 'a') {
g_prompt_always_allow = 1;
return POLICY_ALLOW;
return POLICY_ALLOW_SESSION_ALL;
}
if (ch == 'e') {
return POLICY_ALLOW_SESSION_VERB;
}
if (ch == 'y') {
return POLICY_ALLOW;
@@ -601,17 +799,17 @@ static int parse_tcp_target(const char *target,
return -1;
}
if (strcmp(out_host, "::1") == 0) {
*out_family = AF_INET6;
} else {
{
struct in6_addr addr6;
struct in_addr addr4;
if (inet_pton(AF_INET, out_host, &addr4) != 1) {
if (inet_pton(AF_INET6, out_host, &addr6) == 1) {
*out_family = AF_INET6;
} else if (inet_pton(AF_INET, out_host, &addr4) == 1) {
*out_family = AF_INET;
} else {
return -1;
}
if ((ntohl(addr4.s_addr) & 0xff000000U) != 0x7f000000U) {
return -2;
}
*out_family = AF_INET;
}
*out_port = (uint16_t)port_long;
@@ -634,6 +832,45 @@ static void json_copy_string(char *dst, size_t dst_sz, const char *src, const ch
dst[dst_sz - 1] = '\0';
}
static int extract_request_id_compact(const char *json, char *out_id, size_t out_id_sz) {
cJSON *root;
cJSON *id_item;
char *printed = NULL;
if (json == NULL || out_id == NULL || out_id_sz == 0) {
return -1;
}
out_id[0] = '\0';
root = cJSON_Parse(json);
if (root == NULL) {
return -1;
}
id_item = cJSON_GetObjectItemCaseSensitive(root, "id");
if (id_item == NULL) {
cJSON_Delete(root);
return -1;
}
if (cJSON_IsString(id_item) && id_item->valuestring != NULL) {
json_copy_string(out_id, out_id_sz, id_item->valuestring, "null");
cJSON_Delete(root);
return 0;
}
printed = cJSON_PrintUnformatted(id_item);
if (printed != NULL) {
json_copy_string(out_id, out_id_sz, printed, "null");
free(printed);
cJSON_Delete(root);
return 0;
}
cJSON_Delete(root);
return -1;
}
static int extract_method_and_selector(const char *json,
char *method,
size_t method_sz,
@@ -666,7 +903,10 @@ static int extract_method_and_selector(const char *json,
params_item = cJSON_GetObjectItemCaseSensitive(root, "params");
if (cJSON_IsArray(params_item)) {
options_item = cJSON_GetArrayItem(params_item, 1);
{
int params_count = cJSON_GetArraySize(params_item);
options_item = (params_count > 0) ? cJSON_GetArrayItem(params_item, params_count - 1) : NULL;
}
if (cJSON_IsObject(options_item)) {
tmp = cJSON_GetObjectItemCaseSensitive(options_item, "role");
if (cJSON_IsString(tmp) && tmp->valuestring != NULL) {
@@ -711,6 +951,10 @@ void server_init(server_ctx_t *ctx, const char *socket_name, int socket_name_exp
ctx->dispatcher = dispatcher;
ctx->policy = policy;
ctx->socket_name_explicit = socket_name_explicit ? 1 : 0;
if (!g_auth_nonce_cache_inited) {
auth_nonce_cache_init(&g_auth_nonce_cache);
g_auth_nonce_cache_inited = 1;
}
}
int server_start(server_ctx_t *ctx) {
@@ -746,17 +990,10 @@ int server_start(server_ctx_t *ctx) {
int one = 1;
int prc = parse_tcp_target(ctx->socket_name, &family, host, sizeof(host), &port);
if (prc == -2) {
(void)snprintf(ctx->last_error,
sizeof(ctx->last_error),
"non-loopback TCP bind denied: %s (use 127.x.x.x or ::1)",
ctx->socket_name);
return -1;
}
if (prc != 0) {
(void)snprintf(ctx->last_error,
sizeof(ctx->last_error),
"invalid tcp listen target: %s (expected tcp:127.0.0.1:PORT or tcp:[::1]:PORT)",
"invalid tcp listen target: %s (expected tcp:IPv4:PORT or tcp:[IPv6]:PORT)",
ctx->socket_name);
return -1;
}
@@ -1008,13 +1245,24 @@ int server_handle_one(server_ctx_t *ctx, server_activity_cb cb, void *cb_data) {
char *request = NULL;
char *response = NULL;
char method[64];
char request_id[128];
char auth_pubkey[65];
char auth_label[64];
char role_name[ROLE_NAME_MAX];
char purpose[ROLE_PURPOSE_MAX];
selector_request_t selector_req;
role_entry_t *role = NULL;
int selector_rc;
int pchk;
policy_source_t policy_src = POLICY_SOURCE_DEFAULT;
int pending_derivation = 0;
int hard_selector_error = 0;
int derivation_error = 0;
char activity[256];
const char *verdict = "DENIED";
const char *source_label = "no-match";
int auth_err_code = 0;
const char *auth_err_msg = NULL;
if (ctx == NULL || ctx->listen_fd < 0 || ctx->dispatcher == NULL || ctx->policy == NULL) {
return -1;
@@ -1058,43 +1306,183 @@ int server_handle_one(server_ctx_t *ctx, server_activity_cb cb, void *cb_data) {
json_copy_string(method, sizeof(method), "unknown", "unknown");
json_copy_string(role_name, sizeof(role_name), "unknown", "unknown");
json_copy_string(purpose, sizeof(purpose), "unknown", "unknown");
json_copy_string(request_id, sizeof(request_id), "null", "null");
auth_pubkey[0] = '\0';
auth_label[0] = '\0';
if (caller.kind == NSIGNER_LISTEN_TCP) {
if (auth_envelope_verify_request(request,
&g_auth_nonce_cache,
AUTH_DEFAULT_SKEW_SECONDS,
auth_pubkey,
sizeof(auth_pubkey),
auth_label,
sizeof(auth_label),
&auth_err_code,
&auth_err_msg) != 0) {
(void)extract_request_id_compact(request, request_id, sizeof(request_id));
if (auth_err_msg == NULL) {
auth_err_msg = "auth_envelope_malformed";
}
{
char errbuf[256];
(void)snprintf(errbuf,
sizeof(errbuf),
"{\"id\":\"%s\",\"error\":{\"code\":%d,\"message\":\"%s\"}}",
request_id,
(auth_err_code != 0) ? auth_err_code : AUTH_ERR_ENVELOPE_MALFORMED,
auth_err_msg);
response = strdup(errbuf);
}
if (response != NULL) {
(void)transport_send_framed((client_fd == STDIN_FILENO) ? STDOUT_FILENO : client_fd, response);
free(response);
}
free(request);
if (client_fd != STDIN_FILENO) {
close(client_fd);
}
return 1;
}
caller.auth_present = 1;
json_copy_string(caller.auth_pubkey_hex,
sizeof(caller.auth_pubkey_hex),
auth_pubkey,
"");
json_copy_string(caller.auth_label,
sizeof(caller.auth_label),
auth_label,
"");
(void)snprintf(caller.caller_id, sizeof(caller.caller_id), "pubkey:%s", auth_pubkey);
}
if (extract_method_and_selector(request, method, sizeof(method), &selector_req) == 0) {
if (ctx->dispatcher->role_table != NULL &&
selector_resolve(&selector_req, ctx->dispatcher->role_table, &role) == SELECTOR_OK &&
role != NULL) {
if (ctx->dispatcher->role_table != NULL) {
selector_rc = selector_resolve(&selector_req, ctx->dispatcher->role_table, &role);
if (selector_rc == SELECTOR_OK && role != NULL) {
json_copy_string(role_name, sizeof(role_name), role->name, "main");
json_copy_string(purpose, sizeof(purpose), role_purpose_to_str(role->purpose), "nostr");
} else if (selector_rc == SELECTOR_ERR_NOT_FOUND && selector_req.has_nostr_index) {
pending_derivation = 1;
if (selector_req.nostr_index == 0) {
json_copy_string(role_name, sizeof(role_name), "main", "main");
} else {
(void)snprintf(role_name, sizeof(role_name), "nostr_idx_%d", selector_req.nostr_index);
}
json_copy_string(purpose, sizeof(purpose), "nostr", "nostr");
} else if (selector_rc == SELECTOR_ERR_AMBIGUOUS ||
selector_rc == SELECTOR_ERR_NOT_FOUND ||
selector_rc == SELECTOR_ERR_NO_DEFAULT) {
hard_selector_error = selector_rc;
}
}
}
pchk = policy_check(ctx->policy, caller.caller_id, method, role_name, purpose);
if (hard_selector_error == SELECTOR_ERR_AMBIGUOUS) {
response = strdup("{\"id\":\"null\",\"error\":{\"code\":1001,\"message\":\"ambiguous_role_selector\"}}");
pchk = POLICY_DENY;
} else if (hard_selector_error == SELECTOR_ERR_NO_DEFAULT) {
response = strdup("{\"id\":\"null\",\"error\":{\"code\":1003,\"message\":\"no_default_role\"}}");
pchk = POLICY_DENY;
} else if (hard_selector_error == SELECTOR_ERR_NOT_FOUND) {
response = strdup("{\"id\":\"null\",\"error\":{\"code\":1002,\"message\":\"unknown_role\"}}");
pchk = POLICY_DENY;
} else {
pchk = policy_check(ctx->policy, caller.caller_id, method, role_name, purpose, &policy_src);
}
if (pchk == POLICY_PROMPT) {
pchk = prompt_for_policy_decision(&caller, method, role_name, purpose);
pchk = prompt_for_policy_decision(&caller, method, role_name, purpose, pending_derivation);
if (pchk == POLICY_ALLOW_SESSION_VERB || pchk == POLICY_ALLOW_SESSION_ALL) {
policy_entry_t grant;
memset(&grant, 0, sizeof(grant));
strncpy(grant.caller, caller.caller_id, sizeof(grant.caller) - 1);
strncpy(grant.roles[0], role_name, ROLE_NAME_MAX - 1);
grant.role_count = 1;
if (pchk == POLICY_ALLOW_SESSION_VERB) {
strncpy(grant.verbs[0], method, POLICY_VERB_MAX_LEN - 1);
grant.verb_count = 1;
}
grant.prompt = PROMPT_NEVER;
grant.source = POLICY_SOURCE_SESSION_GRANT;
if (policy_table_insert_before_last(ctx->policy, &grant) != 0) {
pchk = POLICY_DENY;
} else {
pchk = POLICY_ALLOW;
}
}
}
if (pchk == POLICY_ALLOW) {
if (pchk == POLICY_ALLOW && pending_derivation) {
role_entry_t *new_role;
int role_index;
if (ctx->dispatcher == NULL ||
ctx->dispatcher->role_table == NULL ||
ctx->dispatcher->key_store == NULL ||
ctx->dispatcher->mnemonic == NULL ||
role_table_register_nostr_index(ctx->dispatcher->role_table, selector_req.nostr_index) != 0) {
derivation_error = 1;
} else {
new_role = role_table_find_by_nostr_index(ctx->dispatcher->role_table, selector_req.nostr_index);
if (new_role == NULL) {
derivation_error = 1;
} else {
role_index = (int)(new_role - &ctx->dispatcher->role_table->entries[0]);
if (role_index < 0 || role_index >= ctx->dispatcher->role_table->count ||
crypto_derive_one(ctx->dispatcher->key_store,
ctx->dispatcher->role_table,
ctx->dispatcher->mnemonic,
role_index) != 0) {
derivation_error = 1;
} else {
json_copy_string(role_name, sizeof(role_name), new_role->name, role_name);
json_copy_string(purpose, sizeof(purpose), role_purpose_to_str(new_role->purpose), "nostr");
}
}
}
}
if (pchk == POLICY_ALLOW && !derivation_error) {
verdict = "ALLOWED";
response = dispatcher_handle_request(ctx->dispatcher, request);
if (response == NULL) {
response = strdup("{\"id\":\"null\",\"error\":{\"code\":-32603,\"message\":\"internal_error\"}}");
}
} else if (pchk == POLICY_ALLOW && derivation_error) {
verdict = "DENIED";
response = strdup("{\"id\":\"null\",\"error\":{\"code\":-32603,\"message\":\"internal_error\"}}");
} else {
verdict = "DENIED";
if (response == NULL) {
response = strdup("{\"id\":\"null\",\"error\":{\"code\":2001,\"message\":\"policy_denied\"}}");
}
}
if (response != NULL) {
(void)transport_send_framed((client_fd == STDIN_FILENO) ? STDOUT_FILENO : client_fd, response);
}
if (pchk == POLICY_ALLOW && policy_src == POLICY_SOURCE_PREAPPROVE) {
source_label = "preapprove";
} else if (pchk == POLICY_ALLOW && policy_src == POLICY_SOURCE_SESSION_GRANT) {
source_label = "session-grant";
} else if (pchk == POLICY_ALLOW) {
source_label = "prompt";
} else {
source_label = "no-match";
}
(void)snprintf(activity,
sizeof(activity),
"%s %s(%s) %s",
"%s %s(%s) %s:%s",
caller.caller_id,
method,
role_name,
verdict);
verdict,
source_label);
if (cb != NULL) {
cb(activity, cb_data);

View File

@@ -75,7 +75,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -231,7 +231,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -241,6 +241,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -251,6 +257,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -279,7 +286,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -378,7 +386,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

227
tests/test_auth_envelope.c Normal file
View File

@@ -0,0 +1,227 @@
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <time.h>
#include <cJSON.h>
#include <nostr_core/nip001.h>
#include <nostr_core/utils.h>
#include "../src/auth_envelope.h"
static int g_failures = 0;
static void check_condition(const char *name, int ok) {
if (ok) {
printf("[PASS] %s\n", name);
} else {
printf("[FAIL] %s\n", name);
g_failures++;
}
}
static int compute_params_hash_hex(cJSON *params, char out_hex[65]) {
char *compact;
unsigned char hash[32];
if (params == NULL || out_hex == NULL) {
return -1;
}
compact = cJSON_PrintUnformatted(params);
if (compact == NULL) {
return -1;
}
if (nostr_sha256((const unsigned char *)compact, strlen(compact), hash) != 0) {
free(compact);
return -1;
}
nostr_bytes_to_hex(hash, 32, out_hex);
out_hex[64] = '\0';
free(compact);
return 0;
}
static cJSON *tag_pair(const char *k, const char *v) {
cJSON *arr = cJSON_CreateArray();
cJSON_AddItemToArray(arr, cJSON_CreateString(k));
cJSON_AddItemToArray(arr, cJSON_CreateString(v));
return arr;
}
static char *make_request_json(const unsigned char privkey[32],
const char *req_id,
const char *method,
int created_at) {
cJSON *params = cJSON_CreateArray();
cJSON *options = cJSON_CreateObject();
cJSON *tags = cJSON_CreateArray();
cJSON *auth;
cJSON *root;
char body_hash[65];
char *out;
cJSON_AddItemToArray(params, cJSON_CreateString("{\"kind\":1,\"content\":\"x\",\"tags\":[],\"created_at\":1700000000}"));
cJSON_AddStringToObject(options, "role", "main");
cJSON_AddItemToArray(params, options);
if (compute_params_hash_hex(params, body_hash) != 0) {
cJSON_Delete(params);
return NULL;
}
cJSON_AddItemToArray(tags, tag_pair("nsigner_rpc", req_id));
cJSON_AddItemToArray(tags, tag_pair("nsigner_method", method));
cJSON_AddItemToArray(tags, tag_pair("nsigner_body_hash", body_hash));
auth = nostr_create_and_sign_event(AUTH_EVENT_KIND, "test-client", tags, privkey, (time_t)created_at);
if (auth == NULL) {
cJSON_Delete(params);
return NULL;
}
root = cJSON_CreateObject();
cJSON_AddStringToObject(root, "id", req_id);
cJSON_AddStringToObject(root, "method", method);
cJSON_AddItemToObject(root, "params", params);
cJSON_AddItemToObject(root, "auth", auth);
out = cJSON_PrintUnformatted(root);
cJSON_Delete(root);
return out;
}
int main(void) {
auth_nonce_cache_t cache;
unsigned char privkey[32] = {
0x01,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00,
0x00,0x00,0x00,0x00,0x00,0x00,0x00,0x00
};
char pubkey_hex[65];
char label[64];
const char *err_msg = NULL;
int err_code = 0;
char *req;
check_condition("nostr_crypto_init", nostr_crypto_init() == 0);
auth_nonce_cache_init(&cache);
req = make_request_json(privkey, "req-1", "sign_event", (int)time(NULL));
check_condition("build valid request", req != NULL);
if (req != NULL) {
check_condition("valid auth envelope accepted",
auth_envelope_verify_request(req,
&cache,
AUTH_DEFAULT_SKEW_SECONDS,
pubkey_hex,
sizeof(pubkey_hex),
label,
sizeof(label),
&err_code,
&err_msg) == 0);
check_condition("pubkey output length 64", strlen(pubkey_hex) == 64);
free(req);
}
check_condition("missing auth rejected with required code",
auth_envelope_verify_request("{\"id\":\"x\",\"method\":\"get_public_key\",\"params\":[]}",
&cache,
AUTH_DEFAULT_SKEW_SECONDS,
pubkey_hex,
sizeof(pubkey_hex),
label,
sizeof(label),
&err_code,
&err_msg) != 0 &&
err_code == AUTH_ERR_ENVELOPE_REQUIRED);
req = make_request_json(privkey, "req-2", "get_public_key", (int)time(NULL));
check_condition("build second request", req != NULL);
if (req != NULL) {
cJSON *root = cJSON_Parse(req);
cJSON *method_item;
char *tampered;
check_condition("parse second request", root != NULL);
method_item = (root != NULL) ? cJSON_GetObjectItemCaseSensitive(root, "method") : NULL;
if (method_item != NULL) {
cJSON_SetValuestring(method_item, "sign_event");
}
tampered = (root != NULL) ? cJSON_PrintUnformatted(root) : NULL;
cJSON_Delete(root);
check_condition("tamper method mismatch rejected",
tampered != NULL &&
auth_envelope_verify_request(tampered,
&cache,
AUTH_DEFAULT_SKEW_SECONDS,
pubkey_hex,
sizeof(pubkey_hex),
label,
sizeof(label),
&err_code,
&err_msg) != 0 &&
err_code == AUTH_ERR_ENVELOPE_MISMATCH);
free(tampered);
free(req);
}
req = make_request_json(privkey, "req-3", "sign_event", (int)time(NULL));
check_condition("build replay request", req != NULL);
if (req != NULL) {
int first_ok = auth_envelope_verify_request(req,
&cache,
AUTH_DEFAULT_SKEW_SECONDS,
pubkey_hex,
sizeof(pubkey_hex),
label,
sizeof(label),
&err_code,
&err_msg);
int second_ok = auth_envelope_verify_request(req,
&cache,
AUTH_DEFAULT_SKEW_SECONDS,
pubkey_hex,
sizeof(pubkey_hex),
label,
sizeof(label),
&err_code,
&err_msg);
check_condition("first replay request accepted", first_ok == 0);
check_condition("second replay request rejected", second_ok != 0 && err_code == AUTH_ERR_REPLAY_DETECTED);
free(req);
}
req = make_request_json(privkey, "req-4", "sign_event", (int)time(NULL) - 1000);
check_condition("build stale request", req != NULL);
if (req != NULL) {
check_condition("stale request rejected",
auth_envelope_verify_request(req,
&cache,
AUTH_DEFAULT_SKEW_SECONDS,
pubkey_hex,
sizeof(pubkey_hex),
label,
sizeof(label),
&err_code,
&err_msg) != 0 &&
err_code == AUTH_ERR_ENVELOPE_STALE);
free(req);
}
nostr_crypto_cleanup();
if (g_failures == 0) {
printf("ALL TESTS PASSED\n");
return 0;
}
printf("TESTS FAILED: %d\n", g_failures);
return 1;
}

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -149,6 +149,9 @@ const char *role_purpose_to_str(role_purpose_t p);
/* Curve enum to string */
const char *role_curve_to_str(role_curve_t c);
/* Register a nostr-index role if missing. Returns 0 on success, -1 on error. */
int role_table_register_nostr_index(role_table_t *table, int nostr_index);
/* from selector.h */
@@ -229,7 +232,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +242,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +258,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +287,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -310,6 +321,9 @@ typedef struct {
* Returns number of keys derived, or -1 on error. */
int crypto_derive_all(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic);
/* Derive key for exactly one role index. Returns 0 on success, -1 on error. */
int crypto_derive_one(key_store_t *store, role_table_t *table, const mnemonic_state_t *mnemonic, int role_index);
/* Get the derived private key for a role (by table index). Returns NULL if not derived. */
const unsigned char *crypto_get_private_key(const key_store_t *store, int role_index);
@@ -376,7 +390,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -515,6 +529,9 @@ int main(void) {
role_table_add(&table, &main_role);
role_table_add(&table, &ssh_role);
check_condition("role_table_register_nostr_index adds index 9",
role_table_register_nostr_index(&table, 9) == 0 && role_table_find_by_nostr_index(&table, 9) != NULL);
mnemonic_init(&mnemonic);
mnemonic_load(&mnemonic, valid_12);
@@ -527,6 +544,19 @@ int main(void) {
derived = crypto_derive_all(&key_store, &table, &mnemonic);
check_condition("crypto_derive_all derives at least one key", derived >= 1);
{
role_entry_t *r9 = role_table_find_by_nostr_index(&table, 9);
int idx9 = (r9 != NULL) ? (int)(r9 - &table.entries[0]) : -1;
check_condition("new role idx9 exists before derive_one", idx9 >= 0);
if (idx9 >= 0) {
check_condition("crypto_derive_one derives newly registered role",
crypto_derive_one(&key_store, &table, &mnemonic, idx9) == 0 &&
table.entries[idx9].derived == 1 &&
crypto_get_pubkey_hex(&key_store, idx9) != NULL);
}
}
/* 1. Valid get_public_key no selector -> default main, real pubkey */
resp = dispatcher_handle_request(&dispatcher,
"{\"id\":\"1\",\"method\":\"get_public_key\",\"params\":[\"\"]}");
@@ -603,7 +633,7 @@ int main(void) {
crypto_wipe(&key_store);
nostr_cleanup();
printf("%d/12 tests passed\n", g_passes);
printf("%d/%d tests passed\n", g_passes, g_total);
return (g_passes == 12 && g_total == 12) ? 0 : 1;
return (g_passes == g_total) ? 0 : 1;
}

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -75,7 +75,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -231,7 +231,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -241,6 +241,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -251,6 +257,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -279,7 +286,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -378,7 +386,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -456,6 +464,8 @@ int socket_name_random(char *out, size_t out_len);
#include <time.h>
#include <unistd.h>
#include "nsigner_client.h"
#define SOCKET_NAME_A "nsigner_test_run_a"
#define SOCKET_NAME_B "nsigner_test_run_b"
#define MAX_MSG_SIZE 65536
@@ -622,6 +632,8 @@ int main(void) {
char *resp = NULL;
int status;
(void)signal(SIGPIPE, SIG_IGN);
if (pipe(stdin_pipe) != 0) {
perror("pipe");
return 1;
@@ -696,7 +708,11 @@ int main(void) {
sleep_ms(1000);
if (request_roundtrip_to(SOCKET_NAME_A, "{\"id\":\"1\",\"method\":\"get_public_key\",\"params\":[\"\"]}", &resp) == 0) {
{
nsigner_client_t client;
nsigner_client_init(&client);
if (nsigner_client_connect_unix(&client, SOCKET_NAME_A, 5000) == 0) {
if (nsigner_client_get_public_key(&client, "1", "", &resp) == 0) {
check_condition("get_public_key response id", strstr(resp, "\"id\":\"1\"") != NULL);
check_condition("get_public_key has result", strstr(resp, "\"result\":") != NULL);
} else {
@@ -704,34 +720,45 @@ int main(void) {
}
free(resp);
resp = NULL;
nsigner_client_close(&client);
} else {
check_condition("connect signer socket for client library", 0);
}
if (request_roundtrip_to(SOCKET_NAME_A, "{\"id\":\"2\",\"method\":\"sign_event\",\"params\":[\"{\\\"kind\\\":1,\\\"content\\\":\\\"hello\\\",\\\"tags\\\":[],\\\"created_at\\\":1700000000}\",{\"role\":\"main\"}]}", &resp) == 0) {
nsigner_client_init(&client);
if (nsigner_client_connect_unix(&client, SOCKET_NAME_A, 5000) == 0) {
if (nsigner_client_sign_event(&client,
"2",
"{\"kind\":1,\"content\":\"hello\",\"tags\":[],\"created_at\":1700000000}",
"main",
&resp) == 0) {
check_condition("sign_event response id", strstr(resp, "\"id\":\"2\"") != NULL);
check_condition("sign_event has result", strstr(resp, "\"result\":") != NULL);
} else {
check_condition("sign_event request roundtrip", 0);
}
free(resp);
resp = NULL;
} else {
check_condition("connect signer socket for sign_event", 0);
}
nsigner_client_close(&client);
}
{
char *resp_a = NULL;
char *resp_b = NULL;
char pub_a[65] = {0};
char pub_b[65] = {0};
char cipher[2048] = {0};
char req[4096];
const char *p;
if (request_roundtrip_to(SOCKET_NAME_A, "{\"id\":\"3\",\"method\":\"get_public_key\",\"params\":[\"\"]}", &resp_a) == 0 &&
request_roundtrip_to(SOCKET_NAME_B, "{\"id\":\"4\",\"method\":\"get_public_key\",\"params\":[\"\"]}", &resp_b) == 0) {
if (request_roundtrip_to(SOCKET_NAME_A, "{\"id\":\"3\",\"method\":\"get_public_key\",\"params\":[\"\"]}", &resp_a) == 0) {
p = strstr(resp_a, "\"result\":\"");
if (p) { p += 10; strncpy(pub_a, p, 64); pub_a[64]='\0'; }
p = strstr(resp_b, "\"result\":\"");
if (p) { p += 10; strncpy(pub_b, p, 64); pub_b[64]='\0'; }
check_condition("multi-instance distinct sockets respond", pub_a[0] && pub_b[0]);
check_condition("single-instance public key request", pub_a[0] != '\0');
snprintf(req, sizeof(req), "{\"id\":\"5\",\"method\":\"nip04_encrypt\",\"params\":[\"%s\",\"hello_nip04\"]}", pub_b);
snprintf(req, sizeof(req), "{\"id\":\"5\",\"method\":\"nip04_encrypt\",\"params\":[\"%s\",\"hello_nip04\"]}", pub_a);
free(resp_a); resp_a = NULL;
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
p = strstr(resp_a, "\"result\":\"");
@@ -742,9 +769,9 @@ int main(void) {
cipher[i]='\0';
}
snprintf(req, sizeof(req), "{\"id\":\"6\",\"method\":\"nip04_decrypt\",\"params\":[\"%s\",\"%s\"]}", pub_a, cipher);
free(resp_b); resp_b = NULL;
if (request_roundtrip_to(SOCKET_NAME_B, req, &resp_b) == 0) {
check_condition("nip04 round-trip plaintext recovered", strstr(resp_b, "hello_nip04") != NULL);
free(resp_a); resp_a = NULL;
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
check_condition("nip04 round-trip plaintext recovered", strstr(resp_a, "hello_nip04") != NULL);
} else {
check_condition("nip04 decrypt request roundtrip", 0);
}
@@ -753,7 +780,7 @@ int main(void) {
}
memset(cipher, 0, sizeof(cipher));
snprintf(req, sizeof(req), "{\"id\":\"7\",\"method\":\"nip44_encrypt\",\"params\":[\"%s\",\"hello_nip44\"]}", pub_b);
snprintf(req, sizeof(req), "{\"id\":\"7\",\"method\":\"nip44_encrypt\",\"params\":[\"%s\",\"hello_nip44\"]}", pub_a);
free(resp_a); resp_a = NULL;
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
p = strstr(resp_a, "\"result\":\"");
@@ -764,9 +791,9 @@ int main(void) {
cipher[i]='\0';
}
snprintf(req, sizeof(req), "{\"id\":\"8\",\"method\":\"nip44_decrypt\",\"params\":[\"%s\",\"%s\"]}", pub_a, cipher);
free(resp_b); resp_b = NULL;
if (request_roundtrip_to(SOCKET_NAME_B, req, &resp_b) == 0) {
check_condition("nip44 round-trip plaintext recovered", strstr(resp_b, "hello_nip44") != NULL);
free(resp_a); resp_a = NULL;
if (request_roundtrip_to(SOCKET_NAME_A, req, &resp_a) == 0) {
check_condition("nip44 round-trip plaintext recovered", strstr(resp_a, "hello_nip44") != NULL);
} else {
check_condition("nip44 decrypt request roundtrip", 0);
}
@@ -774,10 +801,9 @@ int main(void) {
check_condition("nip44 encrypt request roundtrip", 0);
}
} else {
check_condition("multi-instance public key requests", 0);
check_condition("single-instance public key request", 0);
}
free(resp_a);
free(resp_b);
}
if (kill(child, SIGTERM) == 0) {

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -266,18 +273,25 @@ typedef struct {
/* Initialize policy table */
void policy_table_init(policy_table_t *table);
/* Initialize default policy: allow same-uid, deny others */
/* Initialize default policy table entries. */
void policy_init_default(policy_table_t *table, uid_t owner_uid);
/* Add a policy entry. Returns 0 on success, -1 if full. */
int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
/* Insert an entry before the final catch-all rule. */
int policy_table_insert_before_last(policy_table_t *table, const policy_entry_t *entry);
/* Parse a --preapprove spec into a policy entry. */
int parse_preapprove_spec(const char *spec, policy_entry_t *out_entry, int *out_nostr_index);
/*
* Check whether caller_id is allowed to invoke `verb` on `role_name` with given `purpose`.
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +390,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -486,7 +500,9 @@ static void add_single_entry(policy_table_t *table,
int main(void) {
policy_table_t table;
policy_entry_t parsed;
int rc;
int parsed_nostr_index;
uid_t uid = getuid();
char same_uid[64];
char other_uid[64];
@@ -494,74 +510,177 @@ int main(void) {
(void)snprintf(same_uid, sizeof(same_uid), "uid:%u", (unsigned int)uid);
(void)snprintf(other_uid, sizeof(other_uid), "uid:%u", (unsigned int)(uid + 1U));
policy_init_default(&table, uid);
rc = policy_check(&table, same_uid, "sign_event", "main", "nostr");
check_condition("policy_init_default allows same uid", rc == POLICY_ALLOW);
rc = parse_preapprove_spec("caller=uid:1000,role=main", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec accepts caller+role", rc == 0);
check_condition("parse_preapprove_spec caller set", strcmp(parsed.caller, "uid:1000") == 0);
check_condition("parse_preapprove_spec role set", strcmp(parsed.roles[0], "main") == 0);
check_condition("parse_preapprove_spec role_count=1", parsed.role_count == 1);
check_condition("parse_preapprove_spec prompt=never", parsed.prompt == PROMPT_NEVER);
check_condition("parse_preapprove_spec nostr_index unchanged for role", parsed_nostr_index == -1);
rc = policy_check(&table, other_uid, "sign_event", "main", "nostr");
check_condition("policy_init_default denies different uid", rc == POLICY_DENY);
rc = parse_preapprove_spec("caller=uid:1000,nostr_index=0", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec accepts caller+nostr_index", rc == 0);
check_condition("parse_preapprove_spec nostr_index=0 maps to main", strcmp(parsed.roles[0], "main") == 0);
check_condition("parse_preapprove_spec returns parsed nostr_index", parsed_nostr_index == 0);
rc = parse_preapprove_spec("caller=uid:1000,nostr_index=2", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec maps nonzero nostr_index role", strcmp(parsed.roles[0], "nostr_idx_2") == 0);
check_condition("parse_preapprove_spec stores nonzero nostr_index", parsed_nostr_index == 2);
rc = parse_preapprove_spec("role=main", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec rejects missing caller", rc == -1);
rc = parse_preapprove_spec("caller=uid:1000", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec rejects missing role and nostr_index", rc == -1);
rc = parse_preapprove_spec("caller=uid:1000,role=main,nostr_index=0", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec rejects both role and nostr_index", rc == -1);
rc = parse_preapprove_spec("caller=uid:1000,nostr_index=-1", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec rejects negative nostr_index", rc == -1);
rc = parse_preapprove_spec("caller=uid:1000,nostr_index=abc", &parsed, &parsed_nostr_index);
check_condition("parse_preapprove_spec rejects non-numeric nostr_index", rc == -1);
policy_init_default(&table, uid);
rc = policy_check(&table, same_uid, "sign_event", "main", "nostr", NULL);
check_condition("policy_init_default prompts same uid", rc == POLICY_PROMPT);
rc = policy_check(&table, other_uid, "sign_event", "main", "nostr", NULL);
check_condition("policy_init_default prompts different uid", rc == POLICY_PROMPT);
/* Insert before catch-all: matching caller allowed, non-matching still prompted */
policy_table_init(&table);
add_single_entry(&table, "*", NULL, NULL, NULL, PROMPT_EVERY_REQUEST);
{
policy_entry_t grant;
memset(&grant, 0, sizeof(grant));
strncpy(grant.caller, "uid:1000", sizeof(grant.caller) - 1);
strncpy(grant.roles[0], "main", sizeof(grant.roles[0]) - 1);
grant.role_count = 1;
grant.prompt = PROMPT_NEVER;
rc = policy_table_insert_before_last(&table, &grant);
check_condition("policy_table_insert_before_last succeeds", rc == 0);
}
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("insert_before_last matching caller returns POLICY_ALLOW", rc == POLICY_ALLOW);
rc = policy_check(&table, "uid:2000", "sign_event", "main", "nostr", NULL);
check_condition("insert_before_last non-matching caller returns POLICY_PROMPT", rc == POLICY_PROMPT);
/* Preapprove parse + insert: matching caller allowed, non-matching prompted */
policy_init_default(&table, uid);
rc = parse_preapprove_spec("caller=uid:1000,role=main", &parsed, &parsed_nostr_index);
check_condition("preapprove parse for policy insert succeeds", rc == 0);
rc = policy_table_insert_before_last(&table, &parsed);
check_condition("preapprove insert_before_last succeeds", rc == 0);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("preapprove allows matching caller+role", rc == POLICY_ALLOW);
rc = policy_check(&table, "uid:2000", "sign_event", "main", "nostr", NULL);
check_condition("preapprove leaves non-matching caller at POLICY_PROMPT", rc == POLICY_PROMPT);
/* Exact caller, verb, role, purpose + never => allow */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "main", "nostr", PROMPT_NEVER);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("exact match returns POLICY_ALLOW", rc == POLICY_ALLOW);
/* Wildcard caller + deny => deny */
policy_table_init(&table);
add_single_entry(&table, "*", "sign_event", "main", "nostr", PROMPT_DENY);
rc = policy_check(&table, "uid:2000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:2000", "sign_event", "main", "nostr", NULL);
check_condition("wildcard caller with deny returns POLICY_DENY", rc == POLICY_DENY);
/* Caller no match => POLICY_NO_MATCH */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "main", "nostr", PROMPT_NEVER);
rc = policy_check(&table, "uid:9999", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:9999", "sign_event", "main", "nostr", NULL);
check_condition("caller mismatch returns POLICY_NO_MATCH", rc == POLICY_NO_MATCH);
/* Verb not in list => no match */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "get_public_key", "main", "nostr", PROMPT_NEVER);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("verb mismatch returns POLICY_NO_MATCH", rc == POLICY_NO_MATCH);
/* Role not in list => no match */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "throwaway", "nostr", PROMPT_NEVER);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("role mismatch returns POLICY_NO_MATCH", rc == POLICY_NO_MATCH);
/* Purpose not in list => no match */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "main", "bitcoin", PROMPT_NEVER);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("purpose mismatch returns POLICY_NO_MATCH", rc == POLICY_NO_MATCH);
/* Empty verbs list means all verbs */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", NULL, "main", "nostr", PROMPT_NEVER);
rc = policy_check(&table, "uid:1000", "nip44_encrypt", "main", "nostr");
rc = policy_check(&table, "uid:1000", "nip44_encrypt", "main", "nostr", NULL);
check_condition("empty verbs list matches any verb", rc == POLICY_ALLOW);
/* prompt=first_per_boot => POLICY_PROMPT */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "main", "nostr", PROMPT_FIRST_PER_BOOT);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("first_per_boot returns POLICY_PROMPT", rc == POLICY_PROMPT);
/* prompt=every_request => POLICY_PROMPT */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "main", "nostr", PROMPT_EVERY_REQUEST);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("every_request returns POLICY_PROMPT", rc == POLICY_PROMPT);
/* First matching entry wins */
policy_table_init(&table);
add_single_entry(&table, "uid:1000", "sign_event", "main", "nostr", PROMPT_DENY);
add_single_entry(&table, "uid:1000", "sign_event", "main", "nostr", PROMPT_NEVER);
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr");
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", NULL);
check_condition("first matching entry wins", rc == POLICY_DENY);
/* Verify out_source for preapprove, session-grant, and default catch-all */
policy_table_init(&table);
{
policy_entry_t pre;
policy_entry_t sess;
policy_entry_t prompt_all;
policy_source_t src = POLICY_SOURCE_DEFAULT;
memset(&pre, 0, sizeof(pre));
strncpy(pre.caller, "uid:1000", sizeof(pre.caller) - 1);
strncpy(pre.roles[0], "main", sizeof(pre.roles[0]) - 1);
pre.role_count = 1;
pre.prompt = PROMPT_NEVER;
pre.source = POLICY_SOURCE_PREAPPROVE;
rc = policy_table_add(&table, &pre);
check_condition("source test preapprove entry add", rc == 0);
memset(&sess, 0, sizeof(sess));
strncpy(sess.caller, "uid:1001", sizeof(sess.caller) - 1);
strncpy(sess.roles[0], "main", sizeof(sess.roles[0]) - 1);
sess.role_count = 1;
sess.prompt = PROMPT_NEVER;
sess.source = POLICY_SOURCE_SESSION_GRANT;
rc = policy_table_add(&table, &sess);
check_condition("source test session entry add", rc == 0);
memset(&prompt_all, 0, sizeof(prompt_all));
strncpy(prompt_all.caller, "*", sizeof(prompt_all.caller) - 1);
prompt_all.prompt = PROMPT_EVERY_REQUEST;
prompt_all.source = POLICY_SOURCE_DEFAULT;
rc = policy_table_add(&table, &prompt_all);
check_condition("source test default catch-all add", rc == 0);
src = POLICY_SOURCE_DEFAULT;
rc = policy_check(&table, "uid:1000", "sign_event", "main", "nostr", &src);
check_condition("policy_check reports preapprove source", rc == POLICY_ALLOW && src == POLICY_SOURCE_PREAPPROVE);
src = POLICY_SOURCE_DEFAULT;
rc = policy_check(&table, "uid:1001", "sign_event", "main", "nostr", &src);
check_condition("policy_check reports session-grant source", rc == POLICY_ALLOW && src == POLICY_SOURCE_SESSION_GRANT);
src = POLICY_SOURCE_PREAPPROVE;
rc = policy_check(&table, "uid:9999", "sign_event", "main", "nostr", &src);
check_condition("policy_check resets source for prompt/default", rc == POLICY_PROMPT && src == POLICY_SOURCE_DEFAULT);
}
printf("%d/%d tests passed\n", g_passes, g_total);
return (g_passes == g_total) ? 0 : 1;
}

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -149,6 +149,9 @@ const char *role_purpose_to_str(role_purpose_t p);
/* Curve enum to string */
const char *role_curve_to_str(role_curve_t c);
/* Register a nostr-index role if missing. Returns 0 on success, -1 on error. */
int role_table_register_nostr_index(role_table_t *table, int nostr_index);
/* from selector.h */
@@ -229,7 +232,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +242,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +258,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +287,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +387,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */
@@ -530,40 +541,28 @@ int main(void) {
rc = role_table_add(&table, &e_main);
check_condition("duplicate name rejection returns -2", rc == -2);
role_table_init(&table);
rc = role_table_register_nostr_index(&table, 7);
check_condition("register nostr_index=7 returns 0", rc == 0);
found = role_table_find_by_nostr_index(&table, 7);
check_condition("register nostr_index=7 creates role", found != NULL);
check_condition("registered role name is nostr_idx_7", found != NULL && strcmp(found->name, "nostr_idx_7") == 0);
check_condition("registered role purpose nostr", found != NULL && found->purpose == PURPOSE_NOSTR);
check_condition("registered role curve secp256k1", found != NULL && found->curve == CURVE_SECP256K1);
check_condition("registered role selector type nostr_index", found != NULL && found->selector_type == SELECTOR_NOSTR_INDEX);
rc = role_table_register_nostr_index(&table, 7);
check_condition("register nostr_index=7 idempotent second call", rc == 0);
check_condition("register nostr_index=7 idempotent no duplicate", table.count == 1);
role_table_init(&table);
for (i = 0; i < ROLE_TABLE_MAX_ENTRIES; ++i) {
role_entry_t e;
char name_buf[ROLE_NAME_MAX];
memset(&e, 0, sizeof(e));
snprintf(name_buf, sizeof(name_buf), "role_%d", i);
strncpy(e.name, name_buf, sizeof(e.name) - 1);
strncpy(e.purpose_str, "nostr", sizeof(e.purpose_str) - 1);
strncpy(e.curve_str, "secp256k1", sizeof(e.curve_str) - 1);
e.purpose = PURPOSE_NOSTR;
e.curve = CURVE_SECP256K1;
e.selector_type = SELECTOR_NOSTR_INDEX;
e.nostr_index = i;
rc = role_table_add(&table, &e);
check_condition("fill table role add returns 0", rc == 0);
rc = role_table_register_nostr_index(&table, i);
check_condition("fill table via register_nostr_index returns 0", rc == 0);
}
{
role_entry_t overflow;
memset(&overflow, 0, sizeof(overflow));
strncpy(overflow.name, "overflow", sizeof(overflow.name) - 1);
strncpy(overflow.purpose_str, "nostr", sizeof(overflow.purpose_str) - 1);
strncpy(overflow.curve_str, "secp256k1", sizeof(overflow.curve_str) - 1);
overflow.purpose = PURPOSE_NOSTR;
overflow.curve = CURVE_SECP256K1;
overflow.selector_type = SELECTOR_NOSTR_INDEX;
overflow.nostr_index = 999;
rc = role_table_add(&table, &overflow);
check_condition("table full rejection returns -1", rc == -1);
}
rc = role_table_register_nostr_index(&table, ROLE_TABLE_MAX_ENTRIES + 7);
check_condition("register_nostr_index table full returns -1", rc == -1);
if (g_failures == 0) {
printf("ALL TESTS PASSED\n");

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */

View File

@@ -73,7 +73,7 @@ int mnemonic_generate(int word_count, char *out, size_t out_len);
#define ROLE_PURPOSE_MAX 32
#define ROLE_CURVE_MAX 16
#define ROLE_PUBKEY_HEX_MAX 66 /* 64 hex chars + null + pad */
#define ROLE_TABLE_MAX_ENTRIES 64
#define ROLE_TABLE_MAX_ENTRIES 256
/* Purpose enum for fast comparison (string form kept for config/display) */
typedef enum {
@@ -229,7 +229,7 @@ const char *enforce_strerror(int err);
#define POLICY_MAX_ROLES 16
#define POLICY_MAX_PURPOSES 8
#define POLICY_VERB_MAX_LEN 32
#define POLICY_CALLER_MAX_LEN 64
#define POLICY_CALLER_MAX_LEN 80
/* Prompt behavior */
typedef enum {
@@ -239,6 +239,12 @@ typedef enum {
PROMPT_DENY
} prompt_mode_t;
typedef enum {
POLICY_SOURCE_DEFAULT = 0, /* the catch-all entry */
POLICY_SOURCE_PREAPPROVE, /* from --preapprove CLI flag */
POLICY_SOURCE_SESSION_GRANT /* from prompt [a] during session */
} policy_source_t;
/* A single policy entry */
typedef struct {
char caller[POLICY_CALLER_MAX_LEN]; /* e.g. "uid:1000" or "*" for any */
@@ -249,6 +255,7 @@ typedef struct {
char purposes[POLICY_MAX_PURPOSES][ROLE_PURPOSE_MAX];
int purpose_count;
prompt_mode_t prompt;
policy_source_t source;
} policy_entry_t;
/* Policy table */
@@ -277,7 +284,8 @@ int policy_table_add(policy_table_t *table, const policy_entry_t *entry);
* Returns POLICY_ALLOW, POLICY_DENY, POLICY_PROMPT, or POLICY_NO_MATCH.
*/
int policy_check(const policy_table_t *table, const char *caller_id,
const char *verb, const char *role_name, const char *purpose);
const char *verb, const char *role_name, const char *purpose,
policy_source_t *out_source);
/* Parse prompt mode from string */
prompt_mode_t prompt_mode_from_str(const char *s);
@@ -376,7 +384,7 @@ typedef struct {
uid_t uid;
gid_t gid;
pid_t pid;
char caller_id[64]; /* "uid:<n>" */
char caller_id[80]; /* "uid:<n>" */
} caller_identity_t;
/* Server context */