cfdb1c418c
docs: Anti-Track v2 Plan 2c bypass-seed design (ref #633 )
2026-06-17 13:33:56 +02:00
41fb5e6102
feat(toolbox): per-IP audit for pure-tracker drops (CSPN forensics) (ref #633 )
...
Replace aggregate-count audit with individual IP list in the audit line so
each enforcement decision is independently traceable. Add CDN-allowlist
fail-open comment. Test now asserts the dropped IP appears in the audit entry.
2026-06-17 13:14:07 +02:00
d8c34b2811
chore(toolbox): changelog for Anti-Track v2 Plan 2b IP-drop (ref #633 )
2026-06-17 13:10:10 +02:00
10565ad4e9
chore(toolbox): escalate gated block uses relative import, drop dead sys.path (ref #633 )
2026-06-17 13:09:09 +02:00
cb21023e4d
feat(toolbox): escalate drops exclusive pure-tracker IPs (dark-gated, CDN-safe) (ref #633 )
2026-06-17 13:05:39 +02:00
833905a1dd
feat(toolbox): ship CDN/cloud allowlist for exclusive-IP gate (ref #633 )
2026-06-17 13:01:15 +02:00
64c547aeea
feat(toolbox): ip_dns exclusive-tracker-IP computation (CDN-gated) (ref #633 )
2026-06-17 12:58:30 +02:00
f3dc9e9bb2
chore(toolbox): warn when CDN allowlist missing (fail-open visibility) (ref #633 )
2026-06-17 12:57:29 +02:00
80dc9e6c06
feat(toolbox): ip_dns CDN allowlist parsing + membership (ref #633 )
2026-06-17 12:55:42 +02:00
78a049c4b2
docs: Anti-Track v2 Plan 2b IP-drop implementation plan (ref #633 )
2026-06-17 12:52:41 +02:00
ee3a9aee4d
docs: Anti-Track v2 Plan 2b enforcement design (DNS-refuse + exclusive-IP nft-drop) (ref #633 )
2026-06-17 12:49:21 +02:00
8323db2690
chore(toolbox): changelog for Anti-Track v2 Plan 2a (ref #633 )
2026-06-17 12:24:14 +02:00
b3e842838f
fix(toolbox): autolearn must not zero pure-trackers.txt when learn import fails (ref #633 )
2026-06-17 12:23:10 +02:00
2235c63986
feat(toolbox): autolearn writes learned-trackers (incl. cookie-xsite) + pure-trackers (ref #633 )
2026-06-17 12:20:15 +02:00
61224031e2
chore(toolbox): log DB errors in learn signals for offline-job debuggability (ref #633 )
2026-06-17 12:17:59 +02:00
c0e3ff5858
feat(toolbox): pure-trackers promotion (curated seed + conservative auto-promote) (ref #633 )
2026-06-17 12:15:01 +02:00
c078f66d8f
feat(toolbox): autolearn cookie-xsite signal (top-N capped) (ref #633 )
2026-06-17 12:11:06 +02:00
01715363aa
docs: Anti-Track v2 Plan 2a implementation plan (ref #633 )
2026-06-17 12:08:03 +02:00
76cc96eff5
docs: Anti-Track v2 Plan 2a learning design (cookie-xsite + pure-promote) (ref #633 )
2026-06-17 12:04:41 +02:00
4caf79be55
feat(toolbox): register privacy_guard on R3 mitm-wg fanout workers (ref #633 )
2026-06-17 11:52:42 +02:00
a560f626d0
chore(toolbox): remove stale unused debian/secubox-toolbox-mitm.service (drift hazard; authoritative unit is systemd/) (ref #633 )
2026-06-17 11:47:59 +02:00
11d589c19b
feat(toolbox): provision privacy-jar.key + register privacy_guard addon (ref #633 )
2026-06-17 11:43:50 +02:00
b71a815cc4
refactor(toolbox): protective_mode delegates tracker detection to privacy brain (ref #633 )
2026-06-17 11:37:22 +02:00
c89c632caa
fix(toolbox): privacy_guard — drop duplicate hook, fail-private cookie drop, doc referer fallback (ref #633 )
2026-06-17 11:35:30 +02:00
f5fcc2f9aa
feat(toolbox): privacy_guard hot-path addon (block/poison/anonymize) (ref #633 )
2026-06-17 11:29:30 +02:00
110f060446
feat(toolbox): Anti-Track filter toggles (privacy_*/fortknox), ship dark (ref #633 )
2026-06-17 11:24:26 +02:00
47773a63ab
harden(toolbox): same_site empty-host guard + fail-safe tests (ref #633 )
2026-06-17 11:23:00 +02:00
9315a01a4f
feat(toolbox): privacy brain — layered verdict + Fort-Knox (ref #633 )
2026-06-17 11:20:59 +02:00
931c936d9b
style(toolbox): drop dead _ga condition, document best-effort shaping (ref #633 )
2026-06-17 11:19:38 +02:00
0b1d139e40
feat(toolbox): privacy brain — deterministic fake-identity jar (ref #633 )
2026-06-17 11:17:01 +02:00
83d3f136a3
fix(toolbox): drop dead imports, add learned-list test, clarify _TRACKER provenance (ref #633 )
2026-06-17 11:15:13 +02:00
e2dcce4e9f
feat(toolbox): privacy brain — registrable + tracker classification (ref #633 )
2026-06-17 10:59:56 +02:00
2e2ab3995f
docs: Anti-Track v2 core implementation plan (ref #633 )
2026-06-17 10:57:26 +02:00
CyberMind
c9397e3008
Merge pull request #631 from CyberMind-FR/feature/630-make-live-ops-fixes-permanent-package-di
...
License Headers / check (push) Waiting to run
Make live ops fixes permanent: core traversal fix + dirs-guard timer + toolbox stream_inject default (closes #630 )
2026-06-17 10:00:37 +02:00
CyberMind
206157047e
Merge pull request #629 from CyberMind-FR/feature/628-hub-health-monitor-page-vital-common-ser
...
hub: Health Monitor page (vital + common services, live) (closes #628 )
2026-06-17 10:00:26 +02:00
CyberMind
bed4c1c6d3
Merge pull request #627 from CyberMind-FR/feature/626-haproxy-smart-self-healing-error-pages-5
...
haproxy: smart self-healing error pages + wire errorfile in generator (closes #626 )
2026-06-17 10:00:16 +02:00
CyberMind
9ba49e3bf7
Merge pull request #625 from CyberMind-FR/feature/624-waf-robustness-package-self-healing-insp
...
WAF robustness: package self-healing inspector watchdog + HAProxy redispatch (durable)
2026-06-17 10:00:04 +02:00
ebf714f123
fix(core): stop clobbering /var/lib+/usr/share/secubox to 0750 + ship secubox-dirs-guard timer; toolbox: stream_inject default on ( closes #630 )
2026-06-17 09:33:26 +02:00
5763aa3a73
fix(hub): health monitor reads nested health-batch .modules (ref #628 )
2026-06-17 08:59:40 +02:00
2a8c1b33de
feat(hub): Health Monitor page — vital + common service status, live ( closes #628 )
2026-06-17 08:55:44 +02:00
9d1b0abade
docs: spec for HAProxy complete dynamic vhost auto-discovery (landed for later)
2026-06-17 08:49:29 +02:00
41d78ef455
docs(haproxy): tidy 1.3.1 changelog (secubox-errors path, drift guard, traversal fix)
2026-06-17 08:47:11 +02:00
fbd474b2c3
fix(haproxy): postinst set shared /run|/var/lib/secubox to 0750, breaking traversal (kbin/toolbox 500) -> 0755 parents, 0750 leaves (ref #626 )
2026-06-17 08:46:26 +02:00
c47e454532
fix(haproxy): ship error pages to /etc/haproxy/secubox-errors (avoid file conflict with haproxy pkg) (ref #626 )
2026-06-17 08:44:06 +02:00
e12790efbd
fix(haproxy): repair broken generate (set -e abort + dup backend) + drift guard (ref #626 )
...
haproxyctl generate exited 1 producing no backends: set -e + && {} vhost-loop
chains aborted on the first non-SSL vhost, and a duplicate mitmproxy_inspector
(auto + user TOML) was fatal. Converted chains to if/then/fi, dedup user
backends. Added a drift guard: refuse to install a cfg with fewer vhosts/
backends than live, so a successful regen can't silently drop hand-maintained
vhosts (kbin/gitea/matrix/...) absent from haproxy.toml.
2026-06-17 08:36:27 +02:00
ce636273a6
feat(haproxy): smart self-healing error pages + wire errorfile in generator ( closes #626 )
...
502/503/504 poll the URL and auto-reload on backend recovery (live status +
manual retry); 400/403/408/500 branded static. haproxyctl now emits errorfile
directives (durable across regen) + retries/redispatch in defaults. Pages shipped
to /etc/haproxy/errors/.
2026-06-17 07:46:43 +02:00
4dd87eae2f
fix(mitmproxy): ExecStartPost chmod raced socket creation -> wait+non-fatal (ref #624 )
2026-06-17 07:36:33 +02:00
af02a9731c
fix(mitmproxy): service used absent /usr/bin/uvicorn (203/EXEC crash-loop) -> python3 -m uvicorn + stale-socket unlink (ref #624 )
2026-06-17 07:34:01 +02:00
663715af0f
feat(mitmproxy): package self-healing WAF inspector watchdog ( closes #624 )
...
secubox-waf-watchdog timer checks inspector :8080 every 60s and auto-recovers
the mitmproxy LXC after 3 consecutive failures (rate-limited once/10min) — an
inspector crash becomes a ~3min auto-recovery instead of a multi-hour 503.
Shipped in secubox-mitmproxy; enabled in postinst, disabled in prerm. Makes the
live hotfix from the #624 incident durable across reflash.
2026-06-17 07:31:29 +02:00
CyberMind
05d6135e53
Merge pull request #622 from CyberMind-FR/fix/619-hub-dashboard-services-cache-never-warms
...
License Headers / check (push) Waiting to run
hub: dashboard/services cache never warms under aggregator → blocking systemctl stalls shared event loop (504s, empty widgets)
2026-06-17 07:08:16 +02:00