Skip to content

security: fail-closed cloud TLS verification + safe model-archive extraction#699

Draft
ncylich wants to merge 1 commit into
mainfrom
audit/security-tls-archive
Draft

security: fail-closed cloud TLS verification + safe model-archive extraction#699
ncylich wants to merge 1 commit into
mainfrom
audit/security-tls-archive

Conversation

@ncylich

@ncylich ncylich commented Jun 10, 2026

Copy link
Copy Markdown
Collaborator

cloud.cpp: verify TLS peer/host by default; insecure mode only via explicit CACTUS_CLOUD_INSECURE_SSL=1 opt-out (previously verification was off unless CACTUS_CLOUD_STRICT_SSL was set). qdq.py: reject tar entries that are symlinks/hardlinks or escape the target dir, and use tarfile data filter when available.

Signed-off-by: Noah Cylich noahcylich@gmail.com

…raction

cloud.cpp: verify TLS peer/host by default; insecure mode only via explicit CACTUS_CLOUD_INSECURE_SSL=1 opt-out (previously verification was off unless CACTUS_CLOUD_STRICT_SSL was set). qdq.py: reject tar entries that are symlinks/hardlinks or escape the target dir, and use tarfile data filter when available.

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
ncylich added a commit that referenced this pull request Jun 10, 2026
…ot for direct merge)

Signed-off-by: Noah Cylich <noahcylich@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant