Automated security review (HIGH) caught a jail-escape my own review
missed: copy_recursive used fs::metadata (follows symlinks). A symlink
inside the jail pointing to e.g. /etc, then a 'copy' of its parent dir,
would dereference it and pull external content INTO the jail where it
could be read — a read-escape exfiltration. jail() validates only the
top-level src/dest; the recursive walk reintroduced the escape.
Fix: copy_recursive uses symlink_metadata and refuses any symlink
('symlinks are not followed across the jail boundary'). list() likewise
switched to symlink_metadata so it reports the link, never the
dereferenced target's size/type (info leak). Two regression tests added:
copy-symlink-exfil (asserts no external content lands inside) and
list-no-deref. 44/44 tests green. Rolled forward to alpha.4 (vulnerable
alpha.3 superseded).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Corrosion Host Agent
Rust rewrite of the Go companion agent (companion-agent/, retained as the
behavior reference until parity). One agent per machine supervises every game
instance on that host — Rust, Conan Exiles, Soulmask, Dune: Awakening.
- Wire protocol: see PROTOCOL.md (v2, instance-scoped subjects)
- Config: see agent.example.toml
Status — Phase 0
- Multi-instance TOML config + env overrides (
CORROSION_LICENSE_ID,CORROSION_NATS_URL,CORROSION_NATS_TOKEN) - NATS connection (infinite reconnect, capped backoff, 30s ping, offline send-buffering,
tls://support) - Host heartbeat with real telemetry (sysinfo: CPU, memory, disks) — no fabricated values
- Connectivity prober (outbound TCP, periodic + on-demand)
- Host command channel (
ping,probe,sysinfo) - Graceful shutdown (cancellation token, going-offline beacon, NATS flush)
- Phase 1a: process supervision — per-instance start/stop/restart/status over
{instance}.cmdrequest-reply, push state events on{instance}.status, crash detection with exit codes, live state in heartbeats (integration-tested with real processes + live-NATS contract test) - Phase 1b: RCON trait (WebRCON rust / TCP conan+soulmask), SteamCMD, jailed file manager
- Phase 2: Dune Docker adapter (compose lifecycle, RabbitMQ bus, Postgres admin)
- Phase 3: signed self-update (enforced ed25519 — release gate), service install, supervisor split
Build
cargo build --release # native
cargo build --release --target x86_64-unknown-linux-gnu # linux deploy target
cargo build --release --target x86_64-pc-windows-msvc # windows (cargo-xwin on non-Windows)
Run
corrosion-host-agent --config ./agent.toml # foreground
corrosion-host-agent --config ./agent.toml check # validate config only
corrosion-host-agent version # semver + git hash + build ts