Paste a secret, get a link, send it. The first person to open it and press
Reveal sees the secret; the link dies at that moment. The recipient needs a
browser and nothing else — no account, no client, no installed tooling.
The server cannot read what it stores. AES-256-GCM happens in the browser and
the key lives in the URL fragment, which browsers never transmit, so hushd
holds ciphertext and no key material. That is a property of where the key sits
rather than a promise about our conduct, which is why there is deliberately no
endpoint accepting a plaintext secret and no server-side-encryption fallback:
two guarantees behind one URL would be worse than one honest guarantee.
Three decisions carry the design:
* GET /s/{id} touches NO storage, not even to check existence. Slack, Teams,
WhatsApp, iMessage and Outlook Safe Links all fetch a URL before a human
sees it, so destroying on GET would destroy most secrets in transit and the
recipient's "already used" would be indistinguishable from interception.
Only POST /reveal consumes. Bot user-agent detection is an arms race;
removing the side effect from GET is not. Pinned by
TestGettingTheRevealPageNeverConsumesTheSecret.
* Destruction is one Redis GETDEL, which is atomic. GET-then-DEL has a window
where two simultaneous readers both win, and for a one-time secret that
window is the product. The store contract demands atomicity and the same
concurrency test runs against both implementations.
* Missing, already-revealed, expired and evicted are ONE indistinguishable
410. Separating them would confirm to a prober that a given link was real.
The secret id IS the capability, so secret.ID is a struct whose every
accidental path — %v, %s, String(), slog, json.Marshal — emits a redacted
handle or refuses, and the raw value needs an explicit Value(). The first
version tried to prevent leaks by implementing no String() at all; its own test
caught that Go's fmt prints unexported fields anyway, so forbidding the method
had removed the control rather than the leak.
Operationally: structured JSON on stdout in the fleet's wire format, which
Vector already collects with no annotation; six hush_* metrics on the chassis
registry with no id, IP or path in any label; five alert rules wired into
vmalert. The public Ingress enumerates /, /s/ and /api/ so /metrics, /healthz
and /readyz share the port but are unreachable from the internet — no
basic-auth middleware to maintain and get wrong.
Dependencies are vendored because go-chassis is private: the Woodpecker test
step and the in-cluster Kaniko build both run -mod=vendor with GOPROXY=off and
hold no git credential.
cmd/hush-mcp is a stdio MCP server doing the same client-side crypto locally,
so using hush from an agent preserves the same guarantee as using it from a
browser.
249 lines
7.6 KiB
Go
249 lines
7.6 KiB
Go
// Copyright The Prometheus Authors
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package procfs
|
|
|
|
import (
|
|
"bufio"
|
|
"encoding/hex"
|
|
"fmt"
|
|
"io"
|
|
"net"
|
|
"os"
|
|
"strconv"
|
|
"strings"
|
|
)
|
|
|
|
const (
|
|
// Maximum size limit used by io.LimitReader while reading the content of the
|
|
// /proc/net/udp{,6} files. The number of lines inside such a file is dynamic
|
|
// as each line represents a single used socket.
|
|
// In theory, the number of available sockets is 65535 (2^16 - 1) per IP.
|
|
// With e.g. 150 Byte per line and the maximum number of 65535,
|
|
// the reader needs to handle 150 Byte * 65535 =~ 10 MB for a single IP.
|
|
readLimit = 4294967296 // Byte -> 4 GiB
|
|
)
|
|
|
|
// This contains generic data structures for both udp and tcp sockets.
|
|
type (
|
|
// NetIPSocket represents the contents of /proc/net/{t,u}dp{,6} file without the header.
|
|
NetIPSocket []*netIPSocketLine
|
|
|
|
// NetIPSocketSummary provides already computed values like the total queue lengths or
|
|
// the total number of used sockets. In contrast to NetIPSocket it does not collect
|
|
// the parsed lines into a slice.
|
|
NetIPSocketSummary struct {
|
|
// TxQueueLength shows the total queue length of all parsed tx_queue lengths.
|
|
TxQueueLength uint64
|
|
// RxQueueLength shows the total queue length of all parsed rx_queue lengths.
|
|
RxQueueLength uint64
|
|
// UsedSockets shows the total number of parsed lines representing the
|
|
// number of used sockets.
|
|
UsedSockets uint64
|
|
// Drops shows the total number of dropped packets of all UDP sockets.
|
|
Drops *uint64
|
|
}
|
|
|
|
// A single line parser for fields from /proc/net/{t,u}dp{,6}.
|
|
// Fields which are not used by IPSocket are skipped.
|
|
// Drops is non-nil for udp{,6}, but nil for tcp{,6}.
|
|
// For the proc file format details, see https://linux.die.net/man/5/proc.
|
|
netIPSocketLine struct {
|
|
Sl uint64
|
|
LocalAddr net.IP
|
|
LocalPort uint64
|
|
RemAddr net.IP
|
|
RemPort uint64
|
|
St uint64
|
|
TxQueue uint64
|
|
RxQueue uint64
|
|
UID uint64
|
|
Inode uint64
|
|
Drops *uint64
|
|
}
|
|
)
|
|
|
|
func newNetIPSocket(file string) (NetIPSocket, error) {
|
|
f, err := os.Open(file)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
defer f.Close()
|
|
|
|
var netIPSocket NetIPSocket
|
|
isUDP := strings.Contains(file, "udp")
|
|
|
|
lr := io.LimitReader(f, readLimit)
|
|
s := bufio.NewScanner(lr)
|
|
s.Scan() // skip first line with headers
|
|
for s.Scan() {
|
|
fields := strings.Fields(s.Text())
|
|
line, err := parseNetIPSocketLine(fields, isUDP)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
netIPSocket = append(netIPSocket, line)
|
|
}
|
|
if err := s.Err(); err != nil {
|
|
return nil, err
|
|
}
|
|
return netIPSocket, nil
|
|
}
|
|
|
|
// newNetIPSocketSummary creates a new NetIPSocket{,6} from the contents of the given file.
|
|
func newNetIPSocketSummary(file string) (*NetIPSocketSummary, error) {
|
|
f, err := os.Open(file)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
defer f.Close()
|
|
|
|
var netIPSocketSummary NetIPSocketSummary
|
|
var udpPacketDrops uint64
|
|
isUDP := strings.Contains(file, "udp")
|
|
|
|
lr := io.LimitReader(f, readLimit)
|
|
s := bufio.NewScanner(lr)
|
|
s.Scan() // skip first line with headers
|
|
for s.Scan() {
|
|
fields := strings.Fields(s.Text())
|
|
line, err := parseNetIPSocketLine(fields, isUDP)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
netIPSocketSummary.TxQueueLength += line.TxQueue
|
|
netIPSocketSummary.RxQueueLength += line.RxQueue
|
|
netIPSocketSummary.UsedSockets++
|
|
if isUDP {
|
|
udpPacketDrops += *line.Drops
|
|
netIPSocketSummary.Drops = &udpPacketDrops
|
|
}
|
|
}
|
|
if err := s.Err(); err != nil {
|
|
return nil, err
|
|
}
|
|
return &netIPSocketSummary, nil
|
|
}
|
|
|
|
// the /proc/net/{t,u}dp{,6} files are network byte order for ipv4 and for ipv6 the address is four words consisting of four bytes each. In each of those four words the four bytes are written in reverse order.
|
|
|
|
func parseIP(hexIP string) (net.IP, error) {
|
|
var byteIP []byte
|
|
byteIP, err := hex.DecodeString(hexIP)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse socket field in %q: %w", ErrFileParse, hexIP, err)
|
|
}
|
|
switch len(byteIP) {
|
|
case 4:
|
|
return net.IP{byteIP[3], byteIP[2], byteIP[1], byteIP[0]}, nil
|
|
case 16:
|
|
i := net.IP{
|
|
byteIP[3], byteIP[2], byteIP[1], byteIP[0],
|
|
byteIP[7], byteIP[6], byteIP[5], byteIP[4],
|
|
byteIP[11], byteIP[10], byteIP[9], byteIP[8],
|
|
byteIP[15], byteIP[14], byteIP[13], byteIP[12],
|
|
}
|
|
return i, nil
|
|
default:
|
|
return nil, fmt.Errorf("%w: Unable to parse IP %s: %v", ErrFileParse, hexIP, nil)
|
|
}
|
|
}
|
|
|
|
// parseNetIPSocketLine parses a single line, represented by a list of fields.
|
|
func parseNetIPSocketLine(fields []string, isUDP bool) (*netIPSocketLine, error) {
|
|
line := &netIPSocketLine{}
|
|
if len(fields) < 10 {
|
|
return nil, fmt.Errorf(
|
|
"%w: Less than 10 columns found %q",
|
|
ErrFileParse,
|
|
strings.Join(fields, " "),
|
|
)
|
|
}
|
|
var err error // parse error
|
|
|
|
// sl
|
|
s := strings.Split(fields[0], ":")
|
|
if len(s) != 2 {
|
|
return nil, fmt.Errorf("%w: Unable to parse sl field in line %q", ErrFileParse, fields[0])
|
|
}
|
|
|
|
if line.Sl, err = strconv.ParseUint(s[0], 0, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Unable to parse sl field in %q: %w", ErrFileParse, line.Sl, err)
|
|
}
|
|
// local_address
|
|
l := strings.Split(fields[1], ":")
|
|
if len(l) != 2 {
|
|
return nil, fmt.Errorf("%w: Unable to parse local_address field in %q", ErrFileParse, fields[1])
|
|
}
|
|
if line.LocalAddr, err = parseIP(l[0]); err != nil {
|
|
return nil, err
|
|
}
|
|
if line.LocalPort, err = strconv.ParseUint(l[1], 16, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Unable to parse local_address port value line %q: %w", ErrFileParse, line.LocalPort, err)
|
|
}
|
|
|
|
// remote_address
|
|
r := strings.Split(fields[2], ":")
|
|
if len(r) != 2 {
|
|
return nil, fmt.Errorf("%w: Unable to parse rem_address field in %q", ErrFileParse, fields[1])
|
|
}
|
|
if line.RemAddr, err = parseIP(r[0]); err != nil {
|
|
return nil, err
|
|
}
|
|
if line.RemPort, err = strconv.ParseUint(r[1], 16, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse rem_address port value in %q: %w", ErrFileParse, line.RemPort, err)
|
|
}
|
|
|
|
// st
|
|
if line.St, err = strconv.ParseUint(fields[3], 16, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse st value in %q: %w", ErrFileParse, line.St, err)
|
|
}
|
|
|
|
// tx_queue and rx_queue
|
|
q := strings.Split(fields[4], ":")
|
|
if len(q) != 2 {
|
|
return nil, fmt.Errorf(
|
|
"%w: Missing colon for tx/rx queues in socket line %q",
|
|
ErrFileParse,
|
|
fields[4],
|
|
)
|
|
}
|
|
if line.TxQueue, err = strconv.ParseUint(q[0], 16, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse tx_queue value in %q: %w", ErrFileParse, line.TxQueue, err)
|
|
}
|
|
if line.RxQueue, err = strconv.ParseUint(q[1], 16, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse trx_queue value in %q: %w", ErrFileParse, line.RxQueue, err)
|
|
}
|
|
|
|
// uid
|
|
if line.UID, err = strconv.ParseUint(fields[7], 0, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse UID value in %q: %w", ErrFileParse, line.UID, err)
|
|
}
|
|
|
|
// inode
|
|
if line.Inode, err = strconv.ParseUint(fields[9], 0, 64); err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse inode value in %q: %w", ErrFileParse, line.Inode, err)
|
|
}
|
|
|
|
// drops
|
|
if isUDP {
|
|
drops, err := strconv.ParseUint(fields[12], 0, 64)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("%w: Cannot parse drops value in %q: %w", ErrFileParse, drops, err)
|
|
}
|
|
line.Drops = &drops
|
|
}
|
|
|
|
return line, nil
|
|
}
|