audit: record refused writes; make the log tamper-evident #275

closed cmc opened this on 2026-09-28 04:33 UTC · admin security

Discussion

cmc 2026-09-28 04:33 UTC

The audit log records every successful mutating command, authentication failures and admin actions. Two gaps:

  • Refused commands (exit 4, and not-found on write paths) are not recorded, so probing leaves no trace except SSH auth failures. Dispatch audits only ExitOK writes (internal/control/control.go).
  • audit_log lives in the same database the daemon writes, so a compromised daemon or host can edit it.

Changes: audit refusals of mutating commands (rate-limited per actor); ship audit rows to an append-only sink (journal, syslog, or a hash chain checked by gitbayd admin).

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

closed by cmc in commit 0666c9f622: audit: refused pushes, journal copy, admin audit verify

2026-09-28 21:50 UTC

referenced in commit 607ba55d8f by cmc: control: audit refused mutating commands, rate-limited per actor

2026-09-28 21:50 UTC

referenced in commit 5a1b72b671 by cmc: store: hash-chained audit rows, journal copy, chain verification

2026-09-28 21:50 UTC

referenced in commit 77ff123033 by cmc: wiki: unkeyed audit chain, stall kill, enforced limits, pack-limit gaps

2026-09-28 23:13 UTC

referenced in commit ead6796abe by cmc: hookd: audit refused hook requests and refused pushes

2026-09-28 23:13 UTC