Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
17 commits
Select commit Hold shift + click to select a range
6c6cf19
security: remediate 2026-08-02 audit (33/33 findings), bind bundle en…
beardedeagle Aug 5, 2026
90df6fb
nix: fill cargoLock.outputHashes for the git-pinned ecies dep
beardedeagle Aug 5, 2026
659e548
docs: sweep for statements made stale by the 2026-08-02 audit remedia…
beardedeagle Aug 5, 2026
6fdb5af
docs: remove stale mdbook-build-issue.md scratch note
beardedeagle Aug 5, 2026
5aee321
deps: fold open dependabot PRs — base64 0.23 + minor-patch group
beardedeagle Aug 5, 2026
3004c8b
ci: conform automation to the repo doctrine (just = single source of …
beardedeagle Aug 5, 2026
5e24638
refactor: split over-limit files and group modules by domain
beardedeagle Aug 5, 2026
0d92689
docs: add Unsafe Code section (policy + registry of every unsafe site)
beardedeagle Aug 5, 2026
dae7fa1
lints: adopt multiple_crate_versions (clippy) + deny.toml bans companion
beardedeagle Aug 5, 2026
b011cda
review: address PR #6 review — 18 fixes, 1 rebuttal, 1 documented res…
beardedeagle Aug 5, 2026
776cbd0
docs: move the signal pending/exec race residual to the threat model
beardedeagle Aug 5, 2026
a032262
fix(launcher): close the termination-signal check/exec race (A11 foll…
beardedeagle Aug 5, 2026
2841cfa
fix(launcher): second termination-flag gate immediately before execvp
beardedeagle Aug 6, 2026
613935e
feat(launcher): sibling launch monitor — per-service supervision and …
beardedeagle Aug 6, 2026
7be71fe
test: serialize env-mutating tests on one process-wide ENV_LOCK
beardedeagle Aug 6, 2026
e1f1c21
fix: admit config-required key namings into the key ring
beardedeagle Aug 6, 2026
86e5a6c
docs: single-tenant secrets_dir contract for hand-written configs
beardedeagle Aug 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
91 changes: 91 additions & 0 deletions .github/CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@

# Contributor Covenant 3.0 Code of Conduct

## Our Pledge

We pledge to make our community welcoming, safe, and equitable for all.

We are committed to fostering an environment that respects and promotes the dignity, rights, and contributions of all individuals, regardless of characteristics including race, ethnicity, caste, color, age, physical characteristics, neurodiversity, disability, sex or gender, gender identity or expression, sexual orientation, language, philosophy or religion, national or social origin, socio-economic position, level of education, or other status. The same privileges of participation are extended to everyone who participates in good faith and in accordance with this Covenant.

## Encouraged Behaviors

While acknowledging differences in social norms, we all strive to meet our community's expectations for positive behavior. We also understand that our words and actions may be interpreted differently than we intend based on culture, background, or native language.

With these considerations in mind, we agree to behave mindfully toward each other and act in ways that center our shared values, including:

1. Respecting the **purpose of our community**, our activities, and our ways of gathering.
2. Engaging **kindly and honestly** with others.
3. Respecting **different viewpoints** and experiences.
4. **Taking responsibility** for our actions and contributions.
5. Gracefully giving and accepting **constructive feedback**.
6. Committing to **repairing harm** when it occurs.
7. Behaving in other ways that promote and sustain the **well-being of our community**.


## Restricted Behaviors

We agree to restrict the following behaviors in our community. Instances, threats, and promotion of these behaviors are violations of this Code of Conduct.

1. **Harassment.** Violating explicitly expressed boundaries or engaging in unnecessary personal attention after any clear request to stop.
2. **Character attacks.** Making insulting, demeaning, or pejorative comments directed at a community member or group of people.
3. **Stereotyping or discrimination.** Characterizing anyone’s personality or behavior on the basis of immutable identities or traits.
4. **Sexualization.** Behaving in a way that would generally be considered inappropriately intimate in the context or purpose of the community.
5. **Violating confidentiality**. Sharing or acting on someone's personal or private information without their permission.
6. **Endangerment.** Causing, encouraging, or threatening violence or other harm toward any person or group.
7. Behaving in other ways that **threaten the well-being** of our community.

### Other Restrictions

1. **Misleading identity.** Impersonating someone else for any reason, or pretending to be someone else to evade enforcement actions.
2. **Failing to credit sources.** Not properly crediting the sources of content you contribute.
3. **Promotional materials**. Sharing marketing or other commercial content in a way that is outside the norms of the community.
4. **Irresponsible communication.** Failing to responsibly present content which includes, links or describes any other restricted behaviors.


## Reporting an Issue

Tensions can occur between community members even when they are trying their best to collaborate. Not every conflict represents a code of conduct violation, and this Code of Conduct reinforces encouraged behaviors and norms that can help avoid conflicts and minimize harm.

When an incident does occur, it is important to report it promptly. To report a possible violation, **send an email <randy@heroictek.com>.**

Community Moderators take reports of violations seriously and will make every effort to respond in a timely manner. They will investigate all reports of code of conduct violations, reviewing messages, logs, and recordings, or interviewing witnesses and other participants. Community Moderators will keep investigation and enforcement actions as transparent as possible while prioritizing safety and confidentiality. In order to honor these values, enforcement actions are carried out in private with the involved parties, but communicating to the whole community may be part of a mutually agreed upon resolution.


## Addressing and Repairing Harm

****

If an investigation by the Community Moderators finds that this Code of Conduct has been violated, the following enforcement ladder may be used to determine how best to repair harm, based on the incident's impact on the individuals involved and the community as a whole. Depending on the severity of a violation, lower rungs on the ladder may be skipped.

1) Warning
1) Event: A violation involving a single incident or series of incidents.
2) Consequence: A private, written warning from the Community Moderators.
3) Repair: Examples of repair include a private written apology, acknowledgement of responsibility, and seeking clarification on expectations.
2) Temporarily Limited Activities
1) Event: A repeated incidence of a violation that previously resulted in a warning, or the first incidence of a more serious violation.
2) Consequence: A private, written warning with a time-limited cooldown period designed to underscore the seriousness of the situation and give the community members involved time to process the incident. The cooldown period may be limited to particular communication channels or interactions with particular community members.
3) Repair: Examples of repair may include making an apology, using the cooldown period to reflect on actions and impact, and being thoughtful about re-entering community spaces after the period is over.
3) Temporary Suspension
1) Event: A pattern of repeated violation which the Community Moderators have tried to address with warnings, or a single serious violation.
2) Consequence: A private written warning with conditions for return from suspension. In general, temporary suspensions give the person being suspended time to reflect upon their behavior and possible corrective actions.
3) Repair: Examples of repair include respecting the spirit of the suspension, meeting the specified conditions for return, and being thoughtful about how to reintegrate with the community when the suspension is lifted.
4) Permanent Ban
1) Event: A pattern of repeated code of conduct violations that other steps on the ladder have failed to resolve, or a violation so serious that the Community Moderators determine there is no way to keep the community safe with this person as a member.
2) Consequence: Access to all community spaces, tools, and communication channels is removed. In general, permanent bans should be rarely used, should have strong reasoning behind them, and should only be resorted to if working through other remedies has failed to change the behavior.
3) Repair: There is no possible repair in cases of this severity.

This enforcement ladder is intended as a guideline. It does not limit the ability of Community Managers to use their discretion and judgment, in keeping with the best interests of our community.


## Scope

This Code of Conduct applies within all community spaces, and also applies when an individual is officially representing the community in public or other spaces. Examples of representing our community include using an official email address, posting via an official social media account, or acting as an appointed representative at an online or offline event.


## Attribution

This Code of Conduct is adapted from the Contributor Covenant, version 3.0, permanently available at [https://www.contributor-covenant.org/version/3/0/](https://www.contributor-covenant.org/version/3/0/).

Contributor Covenant is stewarded by the Organization for Ethical Source and licensed under CC BY-SA 4.0. To view a copy of this license, visit [https://creativecommons.org/licenses/by-sa/4.0/](https://creativecommons.org/licenses/by-sa/4.0/)

For answers to common questions about Contributor Covenant, see the FAQ at [https://www.contributor-covenant.org/faq](https://www.contributor-covenant.org/faq). Translations are provided at [https://www.contributor-covenant.org/translations](https://www.contributor-covenant.org/translations). Additional enforcement and community guideline resources can be found at [https://www.contributor-covenant.org/resources](https://www.contributor-covenant.org/resources). The enforcement ladder was inspired by the work of [Mozilla’s code of conduct team](https://github.com/mozilla/inclusion).
4 changes: 2 additions & 2 deletions .github/SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -24,10 +24,10 @@ Preferred channels (either is fine):

1. **GitHub private advisory (recommended).**
Open a report at
https://github.com/beardedeagle/postmaster/security/advisories/new
[security advisories](https://github.com/beardedeagle/postmaster/security/advisories/new).
This keeps the discussion private and allows coordinated disclosure.

2. **Email.** Write to randy@heroictek.com.
2. **Email.** Write to <randy@heroictek.com>.

Please include as much of the following as you can:

Expand Down
55 changes: 55 additions & 0 deletions .github/actions/setup-nix/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
name: Setup Nix
description: >-
Install Nix via the official installer, integrity-verified against a
pinned sha256 before execution, enable flakes, and put nix on PATH for
later steps. In-repo composite: no third-party actions, no unverified
remote code.

inputs:
installer-version:
description: Nix release version to install.
required: false
default: "2.34.7"
installer-sha256:
description: sha256 of the official install script for installer-version.
required: false
default: "e9d447ce3d2ff62d7ff9cb6ef401de6fa8acb148839dd00f7271945d7b638b14"

runs:
using: composite
steps:
- name: Install Nix (integrity-verified)
shell: bash
env:
NIX_VERSION: ${{ inputs.installer-version }}
INSTALLER_SHA256: ${{ inputs.installer-sha256 }}
run: |
set -euo pipefail
if command -v nix >/dev/null 2>&1; then
echo "nix already available: $(command -v nix) -> $(nix --version)"
else
url="https://releases.nixos.org/nix/nix-${NIX_VERSION}/install"
tmp="$(mktemp -t nix-install)"
# Verify the pinned digest BEFORE executing: a substituted or
# corrupted installer fails closed here, never runs.
curl -sSfL "$url" -o "$tmp"
if command -v sha256sum >/dev/null 2>&1; then
echo "${INSTALLER_SHA256} ${tmp}" | sha256sum -c -
else
echo "${INSTALLER_SHA256} ${tmp}" | shasum -a 256 -c -
fi
sh "$tmp" --daemon --yes --no-modify-profile
fi
# The installer does not put nix on PATH for subsequent GHA steps.
if [[ -n "${GITHUB_PATH:-}" ]]; then
echo "/nix/var/nix/profiles/default/bin" >> "$GITHUB_PATH"
fi

- name: Enable nix-command and flakes
shell: bash
run: |
set -euo pipefail
mkdir -p "$HOME/.config/nix"
if ! grep -q 'experimental-features' "$HOME/.config/nix/nix.conf" 2>/dev/null; then
echo 'experimental-features = nix-command flakes' >> "$HOME/.config/nix/nix.conf"
fi
107 changes: 107 additions & 0 deletions .github/actions/setup-rust/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
name: Setup Rust and just
description: Install the pinned Rust toolchain (from rust-toolchain.toml), just, and optional cargo tools.

inputs:
targets:
description: Optional space-separated list of additional Rust targets to install.
required: false
default: ""
install-just:
description: Whether to install the pinned just command runner.
required: false
default: "true"
just-version:
description: just runner version to install (not the Rust compiler version).
required: false
default: "1.51.0"
install-cargo-deny:
description: Whether to install cargo-deny.
required: false
default: "false"
install-cargo-audit:
description: Whether to install cargo-audit.
required: false
default: "false"
install-target-dir:
description: Cargo target directory for tool installation builds.
required: false
default: target/cargo-install

runs:
using: composite
steps:
- name: Install pinned Rust toolchain
shell: bash
env:
RUST_TARGETS: ${{ inputs.targets }}
run: |
set -euo pipefail
if ! command -v rustup >/dev/null 2>&1; then
echo "rustup must be preinstalled; refusing to run an unpinned remote installer" >&2
exit 1
fi
if [[ -n "${GITHUB_PATH:-}" ]]; then
echo "$HOME/.cargo/bin" >> "$GITHUB_PATH"
fi
# Installs the toolchain and components pinned in rust-toolchain.toml.
rustup show
if [[ -n "$RUST_TARGETS" ]]; then
rustup target add $RUST_TARGETS
fi

- name: Install just
if: ${{ inputs.install-just == 'true' }}
shell: bash
env:
JUST_VERSION: ${{ inputs.just-version }}
CARGO_INSTALL_TARGET_DIR: ${{ inputs.install-target-dir }}
run: |
set -euo pipefail
# Probe by actually running `just`, not `command -v just`: a mise/asdf
# shim on PATH satisfies `command -v` but fails at call time with
# "No version is set for shim: just" when no version is pinned. If it
# does not run, or runs but reports a version other than the pin, install
# the pinned just and prepend ~/.cargo/bin so the real binary shadows
# any lingering shim for the rest of the job.
install_pinned_just() {
cargo install just --version "$JUST_VERSION" --locked --target-dir "$CARGO_INSTALL_TARGET_DIR"
if [[ -n "${GITHUB_PATH:-}" ]]; then
echo "$HOME/.cargo/bin" >> "$GITHUB_PATH"
fi
"$HOME/.cargo/bin/just" --version
}
if found="$(just --version 2>/dev/null)"; then
# `just --version` reports "just X.Y.Z"
found_version="${found#just }"
if [[ "$found_version" == "$JUST_VERSION" ]]; then
echo "just already available at pinned version: $(command -v just) -> $found"
else
echo "just version mismatch: found '$found', pinned is 'just $JUST_VERSION'; installing pinned version"
install_pinned_just
fi
else
echo "no runnable just found; installing pinned just $JUST_VERSION"
install_pinned_just
fi

- name: Install cargo-deny
if: ${{ inputs.install-cargo-deny == 'true' }}
shell: bash
env:
CARGO_INSTALL_TARGET_DIR: ${{ inputs.install-target-dir }}
run: |
set -euo pipefail
if ! command -v cargo-deny >/dev/null 2>&1; then
cargo install cargo-deny --locked --target-dir "$CARGO_INSTALL_TARGET_DIR"
fi

- name: Install cargo-audit
if: ${{ inputs.install-cargo-audit == 'true' }}
shell: bash
env:
CARGO_INSTALL_TARGET_DIR: ${{ inputs.install-target-dir }}
run: |
set -euo pipefail
if ! command -v cargo-audit >/dev/null 2>&1; then
cargo install cargo-audit --locked --target-dir "$CARGO_INSTALL_TARGET_DIR"
fi
35 changes: 12 additions & 23 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -32,29 +32,15 @@ jobs:
- macos-latest
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false

- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy

- name: Cache Cargo
uses: Swatinem/rust-cache@v2

- name: Check formatting
run: cargo fmt --all --check
- name: Setup Rust and just
uses: ./.github/actions/setup-rust

- name: Run Clippy
run: cargo clippy --all-targets -- -D warnings

- name: Build
run: cargo build --locked

- name: Test
run: cargo test --locked
- name: Quality gate (fmt, clippy, build, test)
run: just ci-rust

deny:
name: Dependency policy
Expand All @@ -63,11 +49,14 @@ jobs:
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false

- name: Dependency policy (cargo-deny)
uses: EmbarkStudios/cargo-deny-action@v2
- name: Setup Rust, just, and cargo-deny
uses: ./.github/actions/setup-rust
with:
manifest-path: Cargo.toml
install-cargo-deny: "true"

- name: Dependency policy
run: just deny
12 changes: 6 additions & 6 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,15 +29,15 @@ jobs:
timeout-minutes: 15
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false

- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v16
with:
extra-conf: |
experimental-features = nix-command flakes
uses: ./.github/actions/setup-nix

- name: Install just
uses: ./.github/actions/setup-rust

- name: Build book
run: nix run nixpkgs#mdbook -- build docs
run: just docs
15 changes: 9 additions & 6 deletions .github/workflows/nix.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,18 +29,21 @@ jobs:
- macos-latest
steps:
- name: Checkout
uses: actions/checkout@v5
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1
with:
persist-credentials: false

- name: Install Nix
uses: DeterminateSystems/nix-installer-action@v16
uses: ./.github/actions/setup-nix

- name: Install just
uses: ./.github/actions/setup-rust
with:
extra-conf: |
experimental-features = nix-command flakes
install-cargo-deny: "false"
install-cargo-audit: "false"

- name: nix flake check
run: nix flake check
run: just flake-check

- name: nix flake check (eval-only, all systems)
run: nix flake check --all-systems --no-build
run: just flake-check-eval-all
Loading