Repository navigation
rustup names every file it installs, and the ladder still read the toolchain's cargo as a stranger - #67
Merged
opencdlee-dotcom merged 1 commit intoSep 24, 2026
Conversation
…olchain's cargo as a stranger #539 and #540 are HIGH "Suspicious running process" on the toolchain's own `cargo` and `rustc`. Both are ad-hoc signed and got no rung. rustup keeps `lib/rustlib/components` in every toolchain, plus a `manifest-<component>` that lists each file the component wrote (`file:bin/cargo`). The format was read from the real install on this Mac. - `_rustup_receipt`: when a path resolves inside `<RUSTUP_HOME or ~/.rustup>/toolchains/<tc>/`, it answers `rustup:<tc>:<component>` only if an installed component's manifest has a `file:` line for it. A `dir:` line vouches for nothing beneath it, a manifest that `components` does not name is not read, and a listed file swapped for a link out of the toolchain answers nothing. - `_cargo_install_receipt`: `<CARGO_HOME>/.crates2.json` is cargo's own record of `cargo install`. A binary it lists in `<CARGO_HOME>/bin` answers `cargo-install:<crate>@<version>`. A link at the listed path is not followed (`_listed_file_key`). - The rustup proxies in `~/.cargo/bin` stay uncovered. They are links to or copies of rustup, and rustup-init leaves no receipt for rustup itself. settings.toml and update-hashes record the toolchain, not rustup's bytes. - `_PACKAGE_RECEIPTS` now carries a roster of the installers on the reference Mac, each marked covered or not. Both new receipts are package-managed (vouched tier). They are same-uid-forgeable like the Homebrew receipt: one step, never to LOW, risk weight 0.25, and never consulted for attack-defined evidence. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
opencdlee-dotcom
merged commit Sep 24, 2026
6549d91
into
agent/fable-precision/assembly
6 of 9 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to P2b (#63). Base:
agent/fable-precision/assembly.Why
#539 and #540 are open HIGH "Suspicious running process" incidents on the rustup toolchain's own
cargoandrustc. Both binaries are ad-hoc signed and got no custody rung. rustup records every file it installs, and the format below was read from the real install on this Mac before anything was written:~/.rustup/toolchains/<tc>/lib/rustlib/componentslists the installed components, one per line (e.g.cargo-aarch64-apple-darwin).lib/rustlib/manifest-<component>lists what each component wrote, asfile:bin/cargoordir:share/doc/rust/html, relative to the toolchain root.What
_rustup_receipt: when the resolved path is inside<RUSTUP_HOME or ~/.rustup>/toolchains/<tc>/, it answersrustup:<tc>:<component>, but only if an installed component's manifest has afile:line for that path.dir:lines vouch for nothing beneath them.componentsdoes not name is not read._cargo_install_receipt:<CARGO_HOME or ~/.cargo>/.crates2.jsonis cargo's own record ofcargo install. A binary it lists in<CARGO_HOME>/binanswerscargo-install:<crate>@<version>._listed_file_keydoes not follow a link at the listed path.~/.cargo/bin/cargo,rustc, ...): left uncovered. On this Mac they are symlinks to~/.cargo/bin/rustup, and rustup-init leaves no receipt for rustup itself.settings.tomlnames the default toolchain andupdate-hashes/<tc>holds a 20-character channel-manifest hash. Neither records rustup's own bytes._PACKAGE_RECEIPTScomment now carries the roster of installers on this Mac, each marked covered or not._reset_custody_probes.Both receipts can be forged by anything running as the operator's user, like the Homebrew receipt, so both answer only
package-managed, which is in the vouched tier: one step, never to LOW, a 0.25 risk weight, and never for attack-defined evidence.AnInstallerReceiptIsVouchedTierOnlypins this.Live answers on the reference Mac
.crates2.jsonexists here, but the two binaries it lists (gws,watchdog) are no longer in~/.cargo/bin, so there is no live cargo-install answer. That live test skips.Backtest replay (
--days 30 --reobserve), assembly tip c6bda80 vs this branchTo check that the two cases that closed are cargo and rustc, a wrapper recorded every answer
_package_receiptgave during the replay. The rustup answers were only on~/.rustup/.../bin/cargo(2 findings) and.../bin/rustc(6 findings), and open process cases went from 6 to 4. The noise list is unchanged because #539 and #540 have no noise label yet.Tests
tests/test_installer_receipts.py: 48 passed, 1 skipped (the live cargo-install check; no listed binary is present on this Mac).-k "receipt or package or custody": 203 passed, 1 skipped.test_backtest_replay_persistence.py::AnAgentExecTargetIsRegradedAgainstItsRecordedBytes::test_a_target_now_proven_committed_is_demoted(custody_changed1 != 0). It is pre-existing: it fails identically on a cleangit archiveof the assembly tip c6bda80.Not covered
CARGO_INSTALL_ROOTandcargo install --rootare not read; onlyCARGO_HOMEand~/.cargoare..crates2.jsonbin naming (with or without.exe) is unverified.🤖 Generated with Claude Code