Skip to content

Reject unsafe Linux app users centrally - #155

Merged
samo-agent merged 2 commits into
mainfrom
agent/appuser-validation
Jul 14, 2026
Merged

Reject unsafe Linux app users centrally#155
samo-agent merged 2 commits into
mainfrom
agent/appuser-validation

Conversation

@samo-agent

Copy link
Copy Markdown
Collaborator

Summary

  • define one strict Linux appUser policy for manifests, CLI, registration, and persisted state
  • fail closed before bootstrap, host-prep, preview-create, or secrets-rotation scripts interpolate an account name
  • reject reserved system accounts and injection-shaped values without echoing hostile input

Scope

This is the validation-only PR-B split from #153. It intentionally does not change routing, root-helper design, firewall source wiring, or deployment behavior.

Verification

  • RED: 3a88324
  • GREEN: 41be194
  • focused + adjacent: 601 pass
  • full suite: 1850 pass
  • bunx tsc --noEmit
  • git diff --check

@samo-agent

Copy link
Copy Markdown
Collaborator Author

samorev Code Review Report

Pipeline Coverage
PASS Not reported

BLOCKING ISSUES (1)

HIGH MR/PR state - Review target is draft

The review target is still marked as draft.
Fix: Mark it ready for review before merge.


Summary

Area Findings Potential Filtered
CI/Pipeline 0 0 0
Security 0 0 0
Bugs 0 0 0
Tests 0 0 0
Guidelines 0 0 0
Docs 0 0 0
Metadata 1 0 0

Note:

  • Findings: High-confidence issues (8-10/10) - blocking or non-blocking per severity
  • Potential: Medium-confidence issues (4-7/10) - review manually
  • Filtered: Low-confidence issues (0-3/10) - excluded as likely false positives
Review metadata
provider=github
kind=pr
project=NikolayS/samohost
number=155
target=github:NikolayS/samohost#155
state=OPEN
draft=true
diff_lines=437
diff_added=295
diff_removed=1
diff_bytes=15084
comments_count=0
commits_count=2
ci_status=success
ci_summary=total=1 success=1 failure=0 pending=0 other=0
prompt=.claude/commands/review-mr.md
blocking=true
posted_by=gh
no_comment=false
live_posting=posted

samorev-assisted review (AI analysis by Tanya301/samorev)

@samo-agent
samo-agent marked this pull request as ready for review July 14, 2026 04:13
@samo-agent

Copy link
Copy Markdown
Collaborator Author

samorev Code Review Report

Pipeline Coverage
PASS Not reported

No issues found. Reviewed for security, bugs, tests, guidelines, and documentation.

Result: PASSED


Summary

Area Findings Potential Filtered
CI/Pipeline 0 0 0
Security 0 0 0
Bugs 0 0 0
Tests 0 0 0
Guidelines 0 0 0
Docs 0 0 0
Metadata 0 0 0

Note:

  • Findings: High-confidence issues (8-10/10) - blocking or non-blocking per severity
  • Potential: Medium-confidence issues (4-7/10) - review manually
  • Filtered: Low-confidence issues (0-3/10) - excluded as likely false positives
Review metadata
provider=github
kind=pr
project=NikolayS/samohost
number=155
target=github:NikolayS/samohost#155
state=OPEN
draft=false
diff_lines=437
diff_added=295
diff_removed=1
diff_bytes=15084
comments_count=1
commits_count=2
ci_status=success
ci_summary=total=1 success=1 failure=0 pending=0 other=0
prompt=.claude/commands/review-mr.md
blocking=true
posted_by=gh
no_comment=false
live_posting=posted

samorev-assisted review (AI analysis by Tanya301/samorev)

@samo-agent
samo-agent merged commit 59c430d into main Jul 14, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant