Co-Authored-By: Gerald KERMA <devel@cybermind.fr>
66 KiB
TODO — SecuBox-DEB Backlog
Mis à jour : 2026-07-25
🧅 Transparent .onion / proxypac — follow-ups fallback WPAD/PAC (2026-07-25, non-bloquant)
Le mécanisme transparent (primaire, wg-toolbox+LAN) est déployé et couvre le cas réel. Ces items ne concernent que le fallback PAC/WPAD (clients non force-routés) — pas urgents.
- Route HAProxy pour
wpad.gk2.secubox.in: le vhostwpad-vhost.confalisten 80, mais sur gk2 nginx sert sur:9080derrière HAProxy (qui possède:80) →/wpad.datrenvoie 421. Câbler une route HAProxywpad.gk2→ nginx:9080 (patron public-vhost project_sbxwaf_live_routing) +listen 9080dans le vhost. La résolution DNSwpad.gk2→ box marche déjà (record tier2 Unbound). - MIME strict
/proxy.pacsur le vhost admin : renvoietext/htmlcarwebui.conf(vhost admin réel) n'inclut passecubox.d/. Ajouter lalocation = /proxy.pac(MIMEapplication/x-ns-proxy-autoconfig) àwebui.conf, OU router via le vhost wpad ci-dessus. - Backport source : la board a l'
api.pyproxypac patchée + le bind Unbound LAN + la règle onion repointée en live ; vérifier que le rebuild depuis la branche mergée (#900) réconcilie tout (aggregator.toml registration incluse).
🎚️ R-level par peer — follow-ups (2026-07-25, non-bloquant)
- Réconcilier le drift .deb : la live api.py toolbox est patchée A' (ctl
sans sudo, NNP=true préservé) mais le
.deb 2.8.7installé prédate. Rebuildersecubox-toolbox2.8.8 depuis master (#901 mergée) + redéployer pour durabilité (un reinstall du 2.8.7 régresserait vers le chemin sudo qui ne marche pas). - Enforcement
reel— ban/rewrite temps réel : v1 honore le block existant ; les hooks ban/rewrite par-peer restent à étoffer (hors périmètre v1).
📺 Intégration webui LXC — frigate + hexo (2026-07-24)
Motif validé (réf. secubox-picobrew) : service à webui complète → sous-domaine
<mod>.gk2LAN-confiné (patron lyrion : snippet exposure allow-privé/deny-all, nginx:9080 → LXC:port, TLS par HAProxy, route dans haproxy-routes.json, upgrade WebSocket) + page admin = COCKPIT (contrôle + statut + accès + logs), PAS une iframe pleine page. Le fix WebSocket sbxmitm (déployé) profite à tous.
- frigate — BLOQUÉ au provisionnement. LXC provisionné (10.100.0.140,
systemd PID 1 OK) mais
frigate.serviceéchoue :Failed to locate executable /usr/bin/podman— frigate tourne en conteneur podman DANS le LXC, podman absent.frigatectla déjàPUBLIC_HOSTNAME=frigate.gk2+HTTP_PORT=5000(prêt pour le sous-domaine). À TRANCHER d'abord (systematic-debugging) : installer podman+pull l'image frigate DANS le LXC, OU réécrire frigate en natif (cf. feedback_lxc_native_over_docker_package : le dépôt préfère natif). Une fois frigate qui SERT sur :5000 → appliquer sous-domaine + cockpit comme picobrew. Nécessitera aussi une config caméras pour être utile. NB race frigatectl :svc startjuste après lxc-start échoue (systemd du conteneur pas encore booté) — attendre. LXC laissé STOPPED (état antérieur restauré). - hexo — cas DIFFÉRENT (pas un LXC). secubox-hexo = api/ + www/ + nginx dropin secubox.d (aggregator-served, générateur de blog host). Le patron « sous-domaine iframe LXC » ne s'applique pas tel quel : évaluer d'abord ce qu'est la « webui complète » de hexo (admin blog ? blog généré ?) et l'intégrer en conséquence.
📧 Vie privée mail & traceurs (en pause, 2026-07-23)
- Pixels de suivi email — plan d'implémentation. Spec validé et commité :
docs/superpowers/specs/2026-07-23-email-tracking-pixel-detection-design.md(fc8e0f9d). Reste à faire : ouvrir l'issue GitHub, puis dérouler writing-plans. Aucun code écrit. Rappel des décisions :data:URI 1×1 inline (zéro requête émise), archive du brut DKIM-intact, heuristique conservatrice, intégrité du courrier non négociable (exception ⇒ original intact). Cœur =pixelscan.py, fonction pure testable sur de vrais.emlsans Postfix ni LXC. - ⚠ rspamd ne filtre rien (anomalie constatée 2026-07-23, hors périmètre du spec) :
rspamdestactivedans le LXCmailmaissmtpd_miltersest vide → aucun milter Postfix ne l'appelle. L'antispam est vraisemblablement inopérant depuis un moment. Issue à ouvrir. - Suivi #ads : vérifier après quelques heures d'usage réel via wg-toolbox que
total_candidatesprogresse et quecandidates_cumulativerepasse àfalse. Si rien ne bouge, un filtre subsiste en amont → reprendre l'enquête depuis cette preuve.
🖥️ Afficheurs & appliances (en pause, 2026-07-23)
Trois sujets suspendus explicitement par l'utilisateur. Contexte complet : HISTORY/WIP 07-22→23.
- rpi400 — pas de réseau (bloquant). L'image kiosk boote sur une console mais n'a pas de
réseau utilisable : IP affichée, aucun ping. Piste n°1 : l'IP visible est probablement celle
du bridge isolé
eye-br0(10.55.0.1/24,secubox-eye-remote) alors qu'eth0n'a jamais obtenu de bail DHCP — trancher en console (root/secubox) avecip -br a; ip r.10-eth.networkest pourtant correct (Match eth* en*,DHCP=yes, non bridgé). Piste n°2 (kiosk qui ne s'affiche pas) :config.txtportegpu_mem=64et aucundtoverlay=vc4-kms-v3d→ X n'a peut-être pas de driver d'affichage exploitable. - rpi400 — restaurer
cmdline.txt.baksur la partition boot de la carte (j'y ai retiréquiet splashet ajoutéloglevel=7pour diagnostiquer). À faire avant toute mise en service. - Propager le fix postinst mediaflow (
#DEBHELPER#dans un commentaire,~bookworm3) vers apt.secubox.in et gk2 : le bug cassait leconfigurede toutes les installs, pas seulement l'image rpi. - Round eye gadget — à reflasher (« bugge dernièrement »). ⚠ Ne pas reflasher à l'aveugle :
identifier d'abord le symptôme (écran figé ? plus de données ? gadget USB non détecté ? boucle de
reboot ?), sinon on re-livre proprement le même défaut — leçon du rpi400. Outillage :
remote-ui/round/build-eye-remote-image.sh,deploy.sh, CI.github/workflows/build-eye-remote.yml. - Console double écran carré (Pepper's ghost) — brainstorming suspendu au choix des dalles. Acté : 2 écrans = 2 couches de profondeur (pas maître/détail) ; composition optique par demi-miroir 45° ; rôle = console de contrôle SecuBox (fond = santé globale, avant = module en focus + actions) ; commande au geste sans contact (ToF/IR) car aucun écran n'est touchable en Pepper's ghost. Contrainte de design à honorer : les actions destructives (restart/ban) exigent une confirmation explicite, le capteur étant imprécis. Point de reprise : échelle des dalles + SBC (l'utilisateur penche « small » ; ⚠ le demi-miroir divise la luminosité par ~2, ce qui est le critère décisif contre du petit SPI).
🕸️ MIND — metalogue OSINT suite (#845, suivis 2026-07-12)
Maigret + SpiderFoot live/installés sur gk2 ; OpenCTI différé. Voir Metalogue wiki + HISTORY 07-12.
- P3 — OpenCTI (hub graphe Maltego) sur nœud amd64 (192.168.1.9) ou hardware dédié : LXC OpenCTI (ES+Redis+RabbitMQ+MinIO), connecteurs depuis Maigret/SpiderFoot/openclaw, route WAF cross-mesh vers la navbar gk2. Migrer le rôle hub de SpiderFoot → OpenCTI. Trop lourd pour gk2 (~1.5 Go libre).
- ip_forward reset au runtime : la valeur dérive à
0après boot malgré99-secubox-zz-lxc-forward.conf(=1) → coupe la sortie internet de TOUS les LXC. Trouver le service/script qui remetip_forward=0et le neutraliser (récurrent). - Self-registration
aggregator.toml: maigret/spiderfoot ajoutés à la main dansmodules=[](comme openclaw). Un postinst devrait s'auto-enregistrer (idempotent, sans race sur le fichier partagé) — sinon une image neuve perd les modules. - Re-enable SpiderFoot public sur image neuve : l'expo
spiderfoot.gk2(vhost + route sbxwaf + ACL HAProxy + nft :9043 + snippet exposure) a été câblée live. Idéalement viasecubox-exposure emancipate spiderfoot 5001 spiderfoot.gk2.secubox.in(le tool documenté). - Bridge collecteurs → hub : pousser les findings Maigret/openclaw dans SpiderFoot (import
API) en attendant OpenCTI ; stub
metalogue-bridgepour le connecteur OpenCTI P3.
🟣 MIND — ToolBox rapport vie privée (suivis #785/#790, ajouts 2026-07-04)
Contexte : rapport kbin fidèle PDF↔web (donut-grids, media types, fiche de personnage, Quêtes réelles) mergé (#785 #787 · #790 #794 · #792). Voir ToolBox wiki + HISTORY 07-04.
- #786 — double-caching de l'agrégation media-catch (non bloquant, dormant hors R3/R4).
/media_types(secubox-dpi) +_media_stats(toolbox) agrègent/run/secubox/media-catch.jsonlpar requête (borné mémoire par tail-read, mais pas de cache 60 s comme la règle double-caching CLAUDE.md). Option préférée : sbxmitm émet unmedia-stats.jsonpré-roulé (pattern producteur→static→lecture, comme/exfil) ; sinon cache asyncio 60 s dans chaque process consommateur. Fichiers :common/secubox_core/media_catch.py,secubox-dpi/api/main.py,secubox-toolbox/.../api.py. - Cosmétique HTML Quêtes : double-espace quand une menace a un
detailmais pas deservice/dst(report-live.html.j2, garde{% if _dest or q.detail %}). - Nettoyage post-
.deb: le board gk2 a un drop-in MPLCONFIGDIR manuel/etc/systemd/system/secubox-toolbox.service.d/50-mplconfigdir.conf; le paquet livre l'équivalent30-mplcache.conf→ retirer le/etcmanuel au prochain install du.deb.
🟢 P2P — Roadmap post-DHT/Federation/Master-link (#774 · PR #775)
Socle livré & live sur le mesh 3 nœuds (voir HISTORY 2026-07-02 +
docs/P2P-EVOLUTIONS-POSTER-PROMPT.md). Suites, par priorité :
🔜 Pont bans mesh → moteur sbxwaf
- Alimenter sbxwaf (bouncer CrowdSec) avec les bans fédérés threatmesh (#768) :
cscli decisions add --ip <IP> -R "secubox-mesh" -d 4hen plus du nftinet secubox_meshbanactuel. - Anti-boucle : dans
secubox-threatmesh-bridge, filtrer les décisions de reasonsecubox-meshpour ne pas re-fédérer une décision déjà reçue par le mesh. - Vérifier que sbxwaf applique bien (403 +
X-SecuBox-WAF: banned) sur une IP reçue uniquement via le mesh (0 décision crowdsec locale).
🔜 macroctl sur satellites (chemin privilégié)
secubox-p2pstandalone tourneNoNewPrivileges=yes→sudo macroctl activaterefusé (« NNP flag is set »). OK sur gk2 (p2p dans l'aggregator NNP=no).- Fixer sans affaiblir le durcissement satellite : drop-in ciblé ou helper vetté
(pas de
NoNewPrivileges=noglobal sur l'unité durcie).
🔜 Fenêtre transitoire du socket p2p
- Restart de
secubox-p2p→ webui satellite 502/504 le temps de recréerp2p.sock. Lisser via socket-wait /RuntimeDirectoryPreserve=yespour supprimer les erreursapiGetvisibles.
🌀 Horizon (conçu, non construit)
- Mesh phases 2–4 (
project_mesh_gk2_c3box). - Liaison NIZK/PSI GK·HAM : remplacer les stubs
ZKP-HAM-v1parzkp-hamiltoniancffi. - Nouveaux kinds macro (
wg-relay,dns-resolver,http-mirror). - Macros en mode
pending(fédération cross-nœud des Subscription/APPROVE). - Mesh master→satellite (nft c3box) + Freebox forward UDP 51822 pour le remote.
⚪ T5 — Images / OS variants / Hardware (ajouts 2026-06-27)
⬜ MOCHAbin — bootloader propre (adresses réservées + extlinux)
Workaround actif :
/boot/boot.scrcompilé forçant le kernel à0x0a000000. Fix durable requis.
- Option A — Corriger l'image : patcher
extlinux.confgénéré par le CI pour utiliser0x0a000000(kernel) et0x10000000(initrd) au lieu de0x02080000(adresse réservée factory U-Boot 2020.10 → reset immédiat). Boot.scr deviendrait redondant. - Option B — Enhanced Tow-Boot (#748) : bloqué par le ciseau U-Boot (voir ci-dessous) ; déverrouille wget/HTTP natif dans U-Boot, supprime le besoin de TFTP pour les futures installs.
- Valider que le fix d'adresse tient sur les deux MOCHAbin (gk2 + c3box).
⬜ #748 — wget dans U-Boot pour MOCHAbin (bloquant documenté)
Bloquant dur (ciseau) confirmé 2026-06-27. Branche
feature/748-enhanced-tow-boot-http-netboot-serial-fl: spec + plan + Kconfig +build-uboot-overlay.sh --tow-boot+ CI.github/workflows/build-tow-boot.ymlen place. Problème : board mochabin UNIQUEMENT dans fork Tow-Boot U-Boot 2022.07 (pas dewget) ;wget/TCP UNIQUEMENT dans stock U-Boot ≥2023.07 (pas de board mochabin/DTS).
- Voie 1 : backporter le stack TCP +
wgetde U-Boot ≥2023.07 dans le fork Tow-Boot 2022.07 (mochabin board natif). Diff TCP =net/wget.c+ dépendancesCONFIG_NET_WGET. - Voie 2 : porter le board mochabin (DTS Armada 7040 + PHY + eMMC) vers U-Boot mainline ≥2023.07 (sans Tow-Boot). Plus long mais durable.
- Choisir une voie, débloquer #748.
⬜ Packager le flow netboot + install signé (rig temporaire → procédure reproductible)
Actuellement rig manuel sur gk2 :
lan1=192.168.77.1/24, dnsmasq DHCP, nft, nginx:8099.
- Scripter la publication de l'image signée dans le root HTTP netboot (wget + sha256 + sig).
- Documenter / packager la config dnsmasq + nft + nginx pour un segment
lan1dédié. - Intégrer dans
scripts/deploy-netboot.shou équivalent.
⬜ Teardown rig netboot temporaire gk2
Le rig (lan1 bridge, dnsmasq, nft iif lan1 accept, nginx extra listen) reste actif jusqu'à ce que c3box soit autonome en prod.
- Retirer la règle nft
iif lan1 accept(risque : tout le segment lan1 est accepté sans filtrage). - Désactiver / retirer dnsmasq test sur lan1.
- Retirer le extra listen
192.168.77.1:8099du vhost nginx netboot (ou couper le vhost si plus nécessaire). - Vérifier que c3box auto-boot sans rig (boot.scr en place → OK).
✅ Clos 2026-06-22 — DPI exfil + report Netrunner + sbxmitm
- ✅ #687 DPI exfil pipeline — flowcap + Go collector + dashboard + cumulatif 7j,
packagé
secubox-dpi 1.1.2(inclut #692/#693/#695/#705). - ✅ #707 report kbin = fiche Netrunner HTML+PDF (#699/#701/#703/#709/#711/#714/#716).
- ✅ #689 sbxmitm cert 365d · #697 stream >8MiB (Gmail) · #688 splice rejeté.
DPI Phase 3
- Enrichissement ASN (GeoLite2-ASN) pour l'egress sans SNI — #719 mergé, live
(
secubox-dpi 1.1.3, maxminddb-golang vendored). - Historique + timeline par device — #721 mergé, live (
secubox-dpi 1.1.4, buckets quotidienshistory.json14j +/api/v1/dpi/history+ panneau Timeline dashboard). NB : JSON daily buckets (pas SQLite — pas de driver CGO dans le binaire statique ; SQL riche reportable si besoin). - Démon nDPId — évalué puis ÉCARTÉ (#722/#723 revertés). Raison perf : ndpiReader tourne en fenêtres bornées (Nice 15, ~1% CPU, libère le cœur entre les passes) ; nDPId = démon permanent + nDPIsrvd → CPU/RAM continue sur une board déjà saturée (load ~4.6/4 cœurs). Gain (JSON riche, pas de respawn) < risque. Décision : on garde ndpiReader comme producteur du pipeline exfil. (Le build CI QEMU a aussi échoué au 1er essai → chemin fragile en plus.)
⬜ Cosmétique report PDF (non bloquant)
- Glyphes drapeaux régionaux → lettres (police embarquée). Option : drapeaux PNG.
- Chiffres espacés dans certaines cellules (fallback police).
⬜ APK on-device #685/#686 — NON-ROOT ONLY (plan verrouillé, à faire)
Décision 2026-06-22 : cible non-root uniquement ; chemin root abandonné. Plan détaillé : commentaire #685.
- VpnService in-app (
com.wireguard.android:tunnel/ GoBackend wireguard-go) — l'APK EST le client WG, plus de Play Store, détection tunnel in-app fiable. - CA en DER (fix « nom de cert vide » du KeyChain intent) +
network-security-configpour que la WebView in-app fasse confiance au CA ca-wg. - Retirer RootShell/RootOnboard/BootReceiver ; manifest VpnService + consent VPN.
- Limite Android : pas de CA système sans root → MITM système impossible ; surface « safe browsing » = WebView in-app. À documenter.
- Build via CI
build-android-apk+ test sur appareil (gros build, itératif).
🎯 Backlog priorisé — revue 2026-06-24 (64 issues ouvertes)
Index d'autorité du triage. Les sections « Phase X » plus bas sont historiques : plusieurs portent « ✅ COMPLETE » alors que l'issue est restée ouverte (livré mais jamais fermé) → marquées [vérifier→fermer] ci-dessous.
🔴 T0 — Régressions & bugs sécurité (petits, débloquants, CSPN priv-sep)
- #494 secubox-core ExecStart écrase tmpfiles.d
/run/secubox(worktree actif) - #468
/etc/secuboxparent 0750 casse la traversée non-secubox (régression récurrente) - #471 secubox-mesh postinst écrase perms
/run/secubox(régression) - #421 sockets
/run/secuboxcachés en mount-ns privé (RuntimeDirectory) - #447 kiosk : mot de passe admin semé par le CI (users.json shippe un hash) ← fuite
- #91 haproxyctl régénère haproxy.cfg avec
waf_inspectorinexistant (intégrité WAF) - #65 nginx : routes API manquantes dans webui.conf
- #53 Wazuh uvicorn 100% CPU spin
- #121 metablog ingest : dirs en
secubox:secubox
🟠 T1 — Plan d'enforcement sécurité (mission CSPN ; détection→action)
- #498 Phase 7 — WAF active enforcement (mitm→CrowdSec→nft drop) (worktree actif)
- ✅ #519 Phase 13 — enforcement plane FERMÉ 2026-06-22 (livré + réparé :
blacklist-sync avortait sur NXDOMAIN + timeout unit → fix
|| true+ TimeoutStartSec 600 ; vérifié live, default-off). Inclut 13.B #522. - #455 secubox-egress — détection egress + corrélation RDS multi-signaux
- #500 Phase 8 — Utiq operator-grade tracking (detect/alert/bypass)
- #514 Phase 12 — plateforme anti-human-detection (parent ; sous-tracks fermés)
- ✅ #515 Phase 12.A CDN cache detection — FERMÉ (live,
social_host_meta.cdn_vendor) - ✅ #516 Phase 12.B anti-bot detection — FERMÉ (live via #564/#565,
social_antibot) - #525 Phase 14 — plan de déception (idée future, parké)
- ⬜ Suivi #519 perf (non bloquant) : DNS-guard ne résout que les 2000 premiers domaines/cycle (5523 en base) → couverture partielle ; résolution séquentielle lourde sur board saturé. Option : résolution parallèle bornée + rotation du cap.
🟡 T2 — UX / Hub / conscommateurs report (worktrees actifs + polish)
- #615 security-posture dans la sidebar Hub (worktree actif)
- #655 webext content-script banner CSP-immune (worktree actif)
- #485 toolbox SOC scoring (worktree actif)
- #513 ToolBox WebUI : sous-onglets + retrait UI /admin redondante
- #69 diagramme flux trafic responsive
- #67 cache history-aware glances/netdata
- #68 health checks + dépendances services au démarrage
🟢 T3 — Backlog feature (valeur, non bloquant)
- #685 APK 'corrupt' — CI signe avec clé éphémère (plan APK verrouillé)
- #686 android-toolbox flux non-root cassé (plan APK verrouillé)
- #429 nextcloud dashboard : API stubs au lieu de la vraie instance (bug)
- #430 nextcloud — fédération OCM (doc/outillage)
- #472 nextcloud — Gondwana Desktop (canvas + widgets)
- #592 secubox-webmail-hub (Gmail OAuth2 + Gandi + OVH)
- #66 auth Google OAuth
- #70 Health Banner System (preplanned)
- #71 CDN proxy injection (preplanned)
- #393 source-home des scripts health prober
🔵 T4 — Hardware-gated (dépend de pièces ; piste parallèle ; pas de spare EP06)
- Modem/PCIe : #254 modules kernel LTE · #255 pins mPCIe modem · #460 DTS cp0_pcie2 · #467 U-Boot comphy5 SerDes · #462 pivot HW AR9271/MT
- Mesh/BLE : #449 WiFi 802.11s · #452 BT mesh · #453 QR multi-canaux · #454 sourcing BLE 5.x
- GSM : #347 sentinelle-gsm
- Smart-Strip : #33 module HMI · #42 sous-repo · #379 packaging
- Eye-remote : #41 sous-repo · #79 buildroot · #127 variante square · #138 radar_concentric · #155 collision link-rename (bug) · #158 multi-gadget L3 · #478 métriques live Round Eye
- VILLAGE3B : #480 dossier presse · #497 poster grand public
⚪ T5 — Images / OS variants (basse urgence)
- #446 Full Traveller OS multi-mode/arch · #125 build-live-usb +virtualbox · #422 vm-x64 cascade
⚫ T6 — Docs / housekeeping
- #81 headers SPDX CMSD-1.0 partout · #243 clarifier scope secubox-zkp-auth (question)
- #474 ToolBoX (epic parent — garder comme tracker)
🔥 P0 — Immediate (in flight)
kbin Tor endpoint — anonymized quick-switch surfing (#683)
Capstone du couteau suisse cyber : l'anonymat de la sortie. Spec :
docs/superpowers/specs/2026-06-19-kbin-tor-anonymized-surfing-design.md. Invariants : inspection préservée, fail-closed, opt-in (défaut OFF), no DNS leak, CSPN audit.
- Transport — Option A dialer SOCKS5 upstream (cœur Go #662, préféré) vs Option B nft mark → Tor TransPort (fallback pré-#662).
- Profil Tor egress — réutiliser
secubox-exposure(bootstrap/NEWNYM), egress-only. - API toolbox —
POST /admin/tor/{on,off}(WG-hash scoped) +GET /tor/state+POST /tor/newnym+ état SQLite per-client (TTL 24h). - UI kbin — toggle 🧅 + badge état + flag pays de sortie + bouton « nouvelle identité ».
- Leak-guard nft + DNS-over-Tor (test exit IP + resolver ≠ Unbound).
tls_spliceOFF en mode Tor (#649) — sinon les flux asset fuient l'IP réelle.- CSPN — audit-log chaque bascule ; soak DARK (flag présent, UI cachée) avant flip.
ToolBox clients (clients/)
- #531 Android scaffold + CI — Gradle/Compose one-tap onboarding,
debug APK via
build-android-apk.yml. CI green. - #536 serve APK from toolbox —
GET /wg/toolbox.apk+ onboard button +secubox-toolbox-fetch-apkhelper. - #538 Android root-mode silent (PR #539) — system CA install + native kernel WireGuard + auto R3 verify, gated behind explicit root tap.
- #532 browser extension (
clients/webext-toolbox/) — MV3 Firefox.xpi/Chromium; live tracker badge + popup mini Round-Eye graph over/social/*;GET /wg/toolbox.xpi+ fetch helper +build-webext.yml. - #532 release — tag
webext-v0.1.1published the.xpi(downloadable, verified 200).make_latest:false+ tag-pinned URL so it doesn't steal "Latest" from the Android APK release. - release signing — Android keystore + AMO
.xpisigning secrets in CI for stable published fingerprints (currently unsigned sideload). - #532 follow-ups — optional
GET /social/live/{token}SSE (replace the client-side poll) ; Poke/Emancipate per-site control once #525 (deception) ships ; Chromium PNG icon rasterisation for the Web Store.
Phase 13 — Protection enforcement plane (#519) — ✅ COMPLETE
- 13.A spine (#521,
2.6.8, v2.13.17) — nft blacklist set + forward-drop chain + sync (CrowdSec + threat-intel). + override_dh_strip drift fix. - 13.B DNS-guard (#522,
2.6.9, v2.13.17) — résout domaines blocklistés → IPs ; détection DoH/DoT (block opt-in). - 13.C attribution (#524,
2.6.10, v2.13.18) — per-device blocked-attempts- quarantine + endpoints + tile.
- 13.D feedback (#527,
2.6.11, v2.13.19) — escalation evaluator (detections→nft/cscli/quarantine), audit-log, default OFF. - 13.x opt-in tuning — activer
SECUBOX_ESCALATE_*/SECUBOX_DOH_BLOCKselon politique opérateur quand voulu. - threatfox feed = 0 — investiguer l'ingestion domain vide (impacte 13.B resolved_domains).
Phase 14 — Plan de déception (#525, idée future)
- Pseudo-réponses proxy au lieu de blocage IP (indistinguable, pollue le profil) + neutralisation des scripts CDN préchargés. R3 consenti, réutilise la détection Phase 11/12. Pour plus tard.
Phase 11 — Social mapping per device (#502) — ✅ COMPLETE (v2.13.15)
- 11.A backend (#505,
2.6.0) — correlation engine + SQLite + API. - 11.B frontend (#507,
2.6.1) — d3 graph + i18n + favicon proxy + wipe. - 11.C evidence + PDF (#508,
2.6.3) — consent-probe + bilingue FR/EN PDF. - Toolbox WebUI tabs (#513,
2.6.2) — 5-tab nav, kbin /admin/ supprimé. - Mergé via PR #517 → master, tag
v2.13.15. - 11.D opérateur (futur, optionnel) — vue HTML
/admin/social/dédiée (le tab Cartographie sociale dans /toolbox/ couvre déjà l'agrégat).
Phase 12 — Anti-human-detection platform (#514)
- 12.A CDN (#515,
2.6.4) — detect_cdn + Round-Eye central-hotspot graph + by_cdn. Mergé. - 12.B anti-bot (#516,
2.6.5/2.6.6) — detect_antibot (détection seule) + ring levels visibles + Carto/Reset opérateur. Mergé. - 12.C opérateur-grade / state-adjacent (#518,
2.6.7, v2.13.16) — detect_operator_grade (telco MSISDN/x-acr + consortium Utiq/TrustPid + data-broker LiveRamp/BlueKai/Palantir-class). Top-severity lens + PDF. - 12.B bypass — résolution de challenge (gated derrière doctrine lawful-use + design review ; R3 opt-in uniquement).
- 12.D noise counter-measures — cookie-noising / header-strip / decoy-traffic (gated derrière doctrine ; R3 opt-in, interférence active).
Système — bugs gk2 (2026-06-10) — ✅ résolus
- CrowdSec firewall — restart bouncer → tables nft recréées.
- WAF /var/log/secubox traversal — fix source #511/#512 (mergé).
- WAF /stats perf (#509/#510,
secubox-waf 1.2.2) — double-buffer cache. - PeerTube + PhotoPrism — LXC redémarrés.
- Round Eye gadget — USB CDC-Ethernet TX queue wedged (NETDEV WATCHDOG, probe -110). Recovery gk2 épuisée. Fix physique : power-cycle Pi Zero / re-seat câble OTG. Reprendre côté gk2 au prochain boot propre.
Phase 10 — Banner injection perf (#501) — ✅ shipped 2026-06-09
- Banner perf quick wins (
secubox-toolbox2.5.1, commitce059d0f) — LRU_host_signals(2048), drop body tracker scan, 2 MB body cap, trim dead tile. Deployed live sur gk2, iPhone confirme "better... perfect work". - Postinst regression fix (
secubox-toolbox2.5.2, commit15f48d9d) — auto-deploy fanout drop-in enzz-, try-restart sur upgrade. Push origin, code-only (pas encore déployé). - Build + deploy 2.5.2 sur gk2 — postinst-only, attendre fenêtre de maintenance (ne pas perturber session iPhone stable).
- Ouvrir PR #501 sur instruction utilisateur (branche poussée :
perf/501-banner-injection-quickwins). - Phase 10 future — refactor banner JS-driven async (élimine buffer-read pour tous corps, pas seulement < 2 MB).
Phase 9 — mitm-wg multi-worker fanout (#501) — ✅ shipped 2026-06-08
- 4-worker template + numgen DNAT fanout (
secubox-toolbox2.5.0, merged89380a12). Live numbers gk2 : CPU 68/44/50/54 % au lieu d'un single ~90 %. - Phase 9.1 future : real filelock pour
/var/lib/secubox/toolbox/mitm-bypass-dynamic.conf(race 4-worker tolérable via launcher'ssort -u, mais propre serait mieux).
Phase 8 — Anti-tracking opérateur (Utiq) — issue #500
Plan complet documenté en issue. À implémenter :
- Quick Win (1 j) — addon
utiq_defense.pyR0 (log) + R1 (block), tile banner "🎯 Utiq detecté", tableau brut/admin/utiq-events, schéma SQLite. - Phase 2 (1 sem) — R2 (mask
utiqLoader.js→ mtid=null) + R3 (pseudo-avatar viaavatar.py). - Phase 3 (doctrine) — section CSPN sur la forge d'identifiant R3, consentement explicite par client, banner UX étoffé.
- Tests E2E — 5 sites éditeurs européens (lemonde.fr, lefigaro.fr, marmiton.org, tf1.fr, 20minutes.fr) avec attendus par niveau.
Phase 7.E follow-ups (de 2026-06-08, ref #498)
secubox-aggregator0.2.1 build + dpkg upgrade live sur gk2 (ProtectSystem=full + /etc/secubox dans ReadWritePaths). Le live drop-in40-etc-secubox-rw.confest en place tant que le paquet n'est pas upgrade.- Rebuild + déploiement
secubox-users1.4.2 (postinst chowne aussi auth.toml). - Investigation : pourquoi
systemd-timesyncdresteNTPSynchronized: nosur gk2 même avec NTP servers configurés et UDP 123 outbound fonctionnel. Peut-être un IPv6-only resolve qui échoue silencieusement.
Phase 9 ✅ shipped 2026-06-08 — voir bloc P0 ci-dessus
Approche initialement envisagée (dispatcher custom, LXC privilégiée
shared-netfilter) — résolue plus simplement via nft numgen inc mod 4
- conntrack flow-pinning + systemd template
@.service. #502 D redesign capture la suite (captive → LXC TPROXY-inside).
Phase 6 R3 WireGuard ✅ MAJOR RELEASE shipped 2026-06-05 (ref #496)
- #496 Phase 6 R3 portable WG tunnel + mitm + multi-OS install — branch
feature/496-phase-6-wireguard-mitm-autocert-mode-r3(30 commits, 2918 lines, 26 files). Live on gk2 + wiki + landing public kbin.gk2.secubox.in. - mitm WAF leak fix (Connection: close upstream) — FDs 1513→3, scur 812→87.
Live + backported
packages/secubox-mitmproxy/addons/secubox_waf.py. - Kbin filter-control READ-ONLY + admin.gk2 toolbox webui editable card.
- iPhone + Android E2E confirm : reinstall NEW CA
(SHA1
D5:E4:3A...), test banner sur HTTPS, validate "Mon rapport" link → kbin/?mh= ouverture rapport perso. - Merge branche feature/496-... → master + push.
- PR #495 (Phase 5 LXC) + PR #496 (Phase 6 WG) à ouvrir après E2E confirmé.
Phase 6 follow-ups
- threat_counts dict cleanup périodique dans secubox_waf.py (mineur leak)
- WAF leak fix : backporter aussi
packages/secubox-waf/mitmproxy/secubox_waf.py(le 2e fichier mitmproxy addon en sync, currently 756 lines vs 930 dans secubox-mitmproxy) - Investigate mitm-wg CPU > 30% au repos (idle keep-alives ?)
🛡 Phase 7 — WAF active enforcement (issue #498 filée 2026-06-05)
- #498 Phase 7.A SHIPPED 2026-06-05 same-day : bridge mitm WAF →
CrowdSec
/v1/alerts(machine JWT auth) → nft drop via existing bouncer. Live verified : login 200, alert 201, cscli decision, nft entry, ~12s round-trip. Merged3eb5378e. - #498 Phase 7.A.2 SHIPPED 2026-06-05 : backport secubox-waf, postinst
auto-setup,
/api/v1/mitmproxy/waf/enforcementendpoint,threats.htmldashboard with 6 KPI + bans/threats tables auto-refresh. Mergea35ab5c5.- Tune
BAN_THRESHOLDper category (XSS=2, SQLi=1, scanner=5) — open
- Tune
- #498 Phase 7.B SHIPPED 2026-06-05 : nft rate-limit pre-mitm
(
secubox_waf_ratelimittable, drop > 30/s SYN with 5-min self-healing TTL),secubox-waf-ratelimit.serviceboot persist, honeypot nginx routes for /wp-admin /.env /.git/config /phpmyadmin /actuator + custom log_formatsecubox_honeypot→/var/log/nginx/honeypot.log. Mergea35ab5c5. - #498 Phase 7.C long-term : eBPF/XDP kernel filter + ModSecurity remplacement mitm WAF + federation CrowdSec Hub/OTX/Spamhaus.
- Roadmap doc :
.claude/PHASE-7-WAF-ROADMAP.md✅
Release pipeline ✅ v2.13.4 APT GREEN + v2.13.12 rpi400 kiosk SALON-READY
- v2.13.4 APT publish vert (chaîne #425 + #427/PR #428 + #431/PR #432).
- v2.13.10 rpi400 image build SUCCESS (chaîne #436 — PRs #437/#438/#439/#440/#441).
- v2.13.11 mass-mask non-essential services (#442 / PR #443) — Pi 400 boote enfin sur multi-user → graphical → kiosk.
- v2.13.12 cursor visible sur kiosk (#444 / PR #445) — salon-ready.
- Boot test Pi 400 : SD v2.13.10 + live patches (mass-mask + admin password seed) boote, kiosk Chromium affiche, login admin/secubox OK.
🎪 Salon demo readiness — issues filées 2026-06-02
- #447 admin password seed côté CI :
users.jsonship avec password seedé (Option A : seed admin/secubox at build + droprunnervm3jyl0stray ; Option B : implémenter/setupflow first-login). Recommandation : A maintenant, B follow-up. - #448 LAN IP visible sur la kiosk login UI : backend
GET /api/v1/system/identity+ frontend display IP/hostname/version au bas du form. - #446 Full Traveller OS (multi-mode / multi-boot / multi-arch / shared data) — vision opérateur 2026-06-02, big architectural feature, post-salon.
Issues ouvertes filées 2026-05-31 (post-v2.13.4)
Espressobin / live-amd64 / mochabin builds (à traiter séparément)
build-live-usb x64 amd64failure préexistante depuis v2.13.x — bloque la publication GH Release sur tous les tags.build-mochabin-live-usbfailure préexistante.build-image espressobin-v7/-ultrafailure préexistante.
Ces 4 jobs sont distincts du chain kiosk #436. À investiguer un par un.
Issues ouvertes filées 2026-05-31 (post-v2.13.4)
-
PR #429 à OUVRIR : branche
feature/429-secubox-nextcloud-dashboard-api-renvoiepushée (commitb715c0e4), fix déployé live sur gk2 mais pas encore mergé en master. Dashboard NC retourne enfin les vraies données (overwrite.cli.url, occ users, du/df dans container). -
#430 Fédération Nextcloud OCM entre deux SecuBox : documenter le workflow
occ federation:trusted-servers:add, ajouter une page UI dans le dashboard NC (Settings → Federation) + endpoints API GET/POST/DELETE/api/v1/nextcloud/federation/trusted-servers, test d'intégration avec une seconde LXC NC factice. -
#433
build-rpi-usb.sh --kiosksilently fails — closed by PR #435 (fail-loud + assertion). Subsequent #436 chain made the assertion pass. -
#434 kiosk login lockdown après N attempts (CSPN hardening) : frontend kiosk login switch vers template
<lockdown />après N fails (default N=1), backend rate-limit 429 + endpoint admin unlock, TOML config/etc/secubox/kiosk.toml [lockdown], audit log immuable sur lockdown. Unlock paths : reboot / USB key / timed. -
cloud.gk2.secubox.in pas dans aucun vhost nginx — tombe sur default_server
_qui sertwrong-domain.html. Fix 1-ligne : ajoutercloud.gk2.secubox.inà la ligneserver_name nc.gk2.secubox.in nextcloud.gk2.secubox.in;de/etc/nginx/sites-available/nextcloud.conf(sur gk2 ET danspackages/secubox-nextcloud/nginx/source-side).
Issues encore ouvertes de 2026-05-30
-
#421 sockets
/run/secubox/*.sockcachés (cause des 502 sur/api/v1/cookies+/api/v1/certs+ des 500 sur tous les vhosts gated Authelia, dont lyrion). Cause racine identifiée : collision entre tmpfs mount dédié à/run/secubox(créé par secubox-runtime/tmpfiles) etRuntimeDirectory=secuboxdans plusieurs units (qui crée un namespace privé). Fix : choisir UNE seule mécanique de création et l'appliquer partout, reboot-tested. Puis revert le contournement live sur lyrion (/etc/nginx/sites-available/lyrion.conf.bak.sso-removed.*) pour réactiverauth_request /__sbx_auth_verify. -
#422 image
vm-x64cascade[FAILED]en VirtualBox (otg-gadget, networkd-wait-online, mitmproxy, crowdsec, net-fallback, openclaw en restart loop ; sshd accepte TCP mais pas de bannière). Fix : ajouter au profil de buildvm-x64unsystemctl maskdes services exclusivement hardware-appliance (secubox-otg-gadget, etc.). Maskersystemd-networkd-wait-onlinesur le profil VM ou passer en--any. Re-tester la VMSecuBox-amd64(gardée powered off sur le dev box) une fois fixé. Tag v2.13.3.
Espressobin image builds (pré-existant)
- espressobin-v7 + espressobin-ultra :
build-imagefailure dans toutes les Releases v2.13.x. Pas dans la chaîne packaging — distinct. À investiguer séparément (board/espressobin-* config, kernel, etc.).
Session 2026-05-27 evening follow-ups (peertube + photoprism + WAF)
-
Peertube install — DONE 2026-05-28. LIVE at https://peertube.gk2.secubox.in/, upload confirmed. Native-in-LXC (Node 22 + pnpm). See HISTORY 2026-05-28. Did NOT need Docker fallback — native install worked once Node bumped 20→22 + ownership fixed + production.yaml patched.
-
[~] Peertube SOURCE backport — DONE 2026-05-28, pushed on
feature/388-rework-secubox-peertube-align-with-secub(commit5e52598c). Native-LXC rework + dashboard correction + yt-dlp URL import. #390 is superseded (its vhost folded in with the port corrected to LXC :9000; user to close #390). PeerTube native HTTP import (yt-dlp) ALSO enabled on the live gk2 instance — "Import with URL" now available in the PeerTube UI. Pending: rebuild+deploy thesecubox-peertube.deb to gk2 so the dashboard Import tab + corrected status go live (currently only the upstream PeerTube UI import is live). No PR opened yet (awaiting user go-ahead). -
(historical) Peertube SOURCE backport notes — two issues/worktrees:
- #388 (
feature/388-rework-secubox-peertube-align-with-secub): package describes a Docker/Podman API-managed model; live deploy went native-in-LXC (Node 22 + pnpm + systemdpeertube.serviceinside the container). Reconcile: either (a) ship the native install recipe as a packagedinstall-peertube.sh+ document the LXC pattern, or (b) rewrite to actually drive Docker/Podman. Decide with operator — affects what the package ships + how it reproduces. Live install script lives at/data/lxc/peertube/rootfs/root/{install-peertube.sh,peertube-finish.sh,install-node22.sh,peertube-config.py}. - #390 ✅ DONE 2026-05-29 — already backported (folded into the #388
merge). The full public vhost lives in source at
packages/secubox-peertube/conf/peertube.nginx.conf(listen :9080,proxy_pass http://10.100.0.120:9000, 8G upload, 7d timeouts, WS, ACME) and is byte-identical to the live/etc/nginx/sites-available/ peertube.conf(diff clean, ignoring comments).debian/rulesships it tosites-available/andpostinstsymlinks it intosites-enabled/. Thefeature/390-…branch is superseded — operator can close #390.
- #388 (
-
NC bruteforce protection — WON'T re-enable (operator decision 2026-05-29). The WAF (CIDR-aware LAN whitelist, commit
0bf67891) is the brute-force layer; NC's built-in counter stays OFF. See memoryproject_nc_bruteforce_disabled. -
PhotoPrism admin password — DONE 2026-05-29 via
secubox-user-sync seed(#410): the seed ranphotoprism users mod -pon admin, so the password is the operator's chosen one.PHOTOPRISM_ADMIN_PASSWORDis first-init-only in PhotoPrism, so the stalesecubox-CHANGE-MEenv in the unit does NOT revert it — purely cosmetic. Optional tidy: drop that plaintext default from the unit + source install-lxc.sh. -
PhotoPrism auto-index + NC photo wiring — DONE LIVE 2026-05-28. Root cause: NC↔PhotoPrism were never connected —
/data/shared/photos(PhotoPrism originals) was bind-mounted to NCdata/Photos(a path NC doesn't serve), so it stayed empty while phone sync landed indata/<user>/files/. Fix applied live:- NC LXC bind re-pointed
/data/shared/photos → media/photos(outside data dir);files_externalapp enabled; Local external mount "PhotoLibrary" (mount id 2, all users) →/media/photos, withfilesystem_check_changes=1. - PhotoPrism:
photoprism-index.timer(every 15 min, OnBootSec=5min) runspodman exec photoprism photoprism index— PhotoPrism's built-in auto-index only fires for its own UI uploads, NOT external/NC-synced files, hence the timer. - Verified round-trip: host file → NC PhotoLibrary → PhotoPrism originals.
- Operator action: point the phone NC client's auto-upload to the PhotoLibrary folder.
- NC LXC bind re-pointed
-
SOURCE backport of the PhotoPrism↔NC integration (DRIFT) — both
secubox-photoprismandsecubox-nextcloudare still dashboard-only packages (no install-lxc.sh; the live LXC+podman installs were ad-hoc, same pre-#388 state PeerTube was in). Capturing this integration in source needs the SAME native-LXC rework as #388 for both packages (install-lxc.sh with: NC media/photos bind + files_external PhotoLibrary mount; photoprism-index.timer + podman run with originals=/data/shared/photos + PHOTOPRISM_AUTO_INDEX). Sizeable — file as its own issue(s) before doing. -
LXC template bootstrap fixes (capture lessons-learned):
- DNS: fresh download-template LXCs ship a
systemd-resolved stub with no nameservers. Workaround: overwrite
/etc/resolv.confwithnameserver 1.1.1.1 / 8.8.8.8. Should bake into the LXC template or a one-shot first-boot script. - Template choice:
lxc-create -t download -- -d debianusescommon.conf + userns.conf + apparmor=generatedby default, which breaks postgres-15 postinst + podman CNI. Usedebian.common.conf(matrix template). Document in wiki. - Bind-mount UID ownership: bind-mounted dirs default to host
root, LXC root (UID 100000 outside) can't chown across. Recipe:
chown -R 100000:100000 /data/<svc>/on host BEFORE first container start. Document.
- DNS: fresh download-template LXCs ship a
systemd-resolved stub with no nameservers. Workaround: overwrite
-
mitmproxy + WAF live-config drift: host's
/srv/mitmproxy/haproxy-routes.jsonandsecubox_waf.pyare NOT bind-mounted into the mitmproxy LXC. Each has its own copy → source-side edits don't propagate. Fix: addlxc.mount.entry = /srv/mitmproxy srv/mitmproxy none bind,create=dirto/data/lxc/mitmproxy/configso edits flow either way. Beware: the LXC currently hasmitmproxy:mitmproxyownership; host owns by root. Need to align UIDs first. -
IP-forward + lan0-masquerade backport to
secubox-system-tuning: live fix on gk2 used99-secubox-zz-lxc-forward.conf(alphabetical win) + manualnft add rule inet nat postrouting oif lan0 masquerade. Backport both as part of the tuning package so other boards inherit it on apt install. Bump secubox-system-tuning to 1.1.0. -
CrowdSec public-IP allowlist: operator's home/cellular IP not in
secubox-trustedallowlist (would need them to runcurl ifconfig.me). Without it they may hit external bf scenarios. Add when known.
Session 2026-05-27 follow-ups (consolidation pass)
-
secubox-daemonarm64 cross-build + deploy so the c3box binary-package rename (#378, in master at4cd5f343) lands on gk2 and other arm64 boards. Either: (a) on a Marvell-arm64 host:cd daemon && make build-arm64, renamesecuboxd-arm64→secuboxd(etc.) indaemon/build/, thencd packages/secubox-daemon && dpkg-buildpackage -us -uc -b; (b) patchpackages/secubox-daemon/debian/rulesto detect target arch and use the-arm64-suffixed binaries when cross-building from amd64 (cleaner, lets the dev box build everything). Non-acute: secubox-daemon not currently installed on gk2. -
secubox-ndpid 1.0.1blocked from gk2 by missingndpid | ndpi-readerapt source. Options: (a) add an apt source that providesndpidfor bookworm/arm64; (b) packagendpidourselves underpackages/ndpid/; (c) relaxsecubox-ndpidDepends:→Recommends:and add a runtime check that surfaces "ndpid daemon unavailable" in the dashboard instead of refusing to install. Recommend (c) for shortest path — operators who want the fingerprinting dashboard install ndpid themselves. -
Mail transitional postinsts (#380) should rm orphan nginx snippets on upgrade. On gk2 today, dpkg's
.listforsecubox-mail-lxc 2.2.1,secubox-webmail 2.2.0,secubox- webmail-lxc 2.2.0claimed to own/etc/nginx/secubox.d/ {mail-lxc,webmail,webmail-lxc}.confbut the new (empty) .debs don't ship them — leftovers from a pre-2.2 install that dpkg didn't auto-clean. Patch each transitional postinst to add:rm -f /etc/nginx/secubox.d/<name>.conf systemctl reload nginx 2>/dev/null || true(Mirror the mmpm pattern from #381's transitional postinst.) Bump versions, rebuild, mass-redeploy. Without this fix, other boards upgrading from <2.2 will inherit the same orphan files.
Session 2026-05-26 follow-ups
-
Finir Preserve fix sur 2 services restants :
secubox-torrentetsecubox-voip(les seuls avecRuntimeDirectory=mais sansRuntimeDirectoryPreserve=yesaprès le mass-redeploy). Rebuild +dpkg -ices deux .debs seulement. ~2 min. -
Auditer tous les
postinstqui fontsystemctl enablesans tolérer les units masked. Pattern à reproduire (depuis le fix wazuh63284497) :if [ "$(systemctl is-enabled secubox-X.service 2>/dev/null)" != "masked" ]; then systemctl enable secubox-X.service systemctl start secubox-X.service || true fiSinon le prochain mass-redeploy se ramasse les mêmes
half-configuredsur toute box qui a masked un service par choix opérateur. Audit viagrep -L 'is-enabled.*masked' packages/*/debian/postinst | xargs grep -l 'systemctl enable'. -
secubox-system-restartorchestrateur (issue à créer) : remplacer ledpkg -i pkg1.deb pkg2.deb ... pkgN.debbrutal par un workflow ordonné qui :- Bloque les writers dashboard (mode read-only sur /data)
sync+umount /data(ou snapshot lvm)- Stop ordonné des services (dependency-graph aware)
- Replay
dpkg -isur le lot - Remount /data + bring up dans l'ordre
secubox.target→secubox-core→ modules - Unblock writers Évite le cascade de 100 systemd restarts en parallèle + le fsck forcé sur /data au reboot. Pas urgent mais nécessaire avant la prochaine mass-deploy.
-
scripts/build-packages.shdiscovery dynamique : la listePACKAGES=()est hardcodée (30 entrées) alors qu'on a 100+ paquets danspackages/*/debian/. Remplacer parmapfile -t PACKAGES < <(find packages -maxdepth 2 -type d -name debian | sed 's|/debian||;s|^packages/||' | sort). Le--filtercontinuera de fonctionner. -
v2.11.1 patch — commit + PR + tag the 4 install-lxc.sh fixes once validated on board gk2:
lxc-create -t download(bookworm unprivileged)ensure_masqueradefor 10.100.0.0/24gpg --dearmoron grafana apt key- unlink
/etc/resolv.confsymlink + write vialxc-attach
-
Validate end-to-end
grafanactl install,yacyctl install,rustdeskctl installon the board (LXC green, daemon running, web UI reachable through nginx)
🟡 P1 — Next release (v2.12.0 target)
- v1.1.0 verb implementations for the three new ctl tools (currently stub
exit 2for the noun-specific verbs):grafanactl dashboard list/add/remove/export+datasource list/add/remove/test+alert list/mute/unmute+user list/add/remove/passwd+api-key list/create/revoke. Backend = Grafana HTTP API on10.100.0.70:3000, auth = admin password from/etc/secubox/secrets/grafana-admin.yacyctl peer list/add/remove/status+index status/build/clear/optimize+query test/count+blacklist list/add/remove+crawler list/start/stop/schedule.rustdeskctl peer list/add/remove+relay status/restart/log+key show/rotate+session list/kill.
- Add the 3 new modules to
docs/MODULES.mdcatalog - Add the 3 new grammar rows to
docs/grammar.mdcanonical table (OPS MONITORING / SEARCH / REMOTE-ACCESS) - Update
.claude/MIGRATION-MAP.mdwith grafana / yacy / rustdesk
🟣 P2 — Sensor stack (WALL/MIND alignment)
- #236
secubox-rbs-sensor— Quectel EP06-E modem-based rogue-base-station sensor (WALL). Spec:docs/superpowers/specs/2026-05-20-secubox-wall-ep06.md. Prerequisites flagged: needswall_rbs_sensor.py/Observer(Protocol)/CellObservation/NeighbourObservation/ OODA verdict engine scaffolded as part of the same package (none exist yet in repo). - #237
secubox-sentinelle-gsm— RTL-SDR + gr-gsm passive RX-only sensor for false-BTS detection (MIND, feeds WALL/OPAD). Spec:docs/superpowers/specs/2026-05-20-secubox-sentinelle-gsm.md. Privacy-by-design: HMAC-truncated identifiers in PROD, LAB mode with consent banner + audit. Hard limits: RX only, no decryption, no tracking primitive. - Decide build order:
rbs-sensorframework first (Observer Protocol + CellObservation as part ofsecubox-coreor its own package?), thensentinelle-gsmplugs as second backend.
✅ PHASE 1 — Bootstrap HW + OS (S01–S03) — TERMINÉ
- P1-01 Images Debian bookworm arm64 + amd64
- P1-02 build-image.sh (debootstrap multi-arch)
- P1-03 firstboot.sh (JWT, SSH, hostname, nftables)
- P1-04 netplan templates par board
- P1-05 create-vbox-vm.sh (VirtualBox VM)
- P1-06 Kernel 6.6 LTS cross-compile (optionnel)
✅ PHASE 2 — API Gateway + secubox-core + secubox-hub (S04–S07) — TERMINÉ
- P2-01 Implémenter
common/secubox_core/(lib Python partagée)auth.py: JWT HS256, require_jwt dependency, login endpointconfig.py: charger /etc/secubox/secubox.conf (TOML), get_board_info()logger.py: logging structuré JSON vers journaldsystem.py: board_info(), uptime(), service_status(), disk_usage()
- P2-02 Écrire
common/nginx/secubox.conf- Serve
/usr/share/secubox/www/pour les statics - Proxy
/api/v1/<module>/→unix:/run/secubox/<module>.sock - TLS autosigné firstboot + Let's Encrypt optionnel
- Serve
- P2-03 Paquet
secubox-corecompletdebian/control,debian/rules,debian/postinst- Installe secubox_core dans
/usr/lib/python3/dist-packages/ - Crée
/etc/secubox/,/run/secubox/,/var/lib/secubox/
- P2-04 Paquet
secubox-hub(référence de pattern)- Porter
luci-app-secubox: dashboard central, module launcher api/main.py: endpoints status, modules, alerts, monitoring, settingsdebian/complet + unit systemdsecubox-hub.service
- Porter
- P2-05 Script
scripts/rewrite-xhr.py- Remplace
rpc.declare({object:'luci.X',method:'Y'})→fetch('/api/v1/X/Y') - Mode dry-run + mode patch in-place
- Remplace
✅ PHASE 3 — Modules (S07–S12) — TERMINÉ (33 modules)
All 33 modules ported and running:
- P3-01
secubox-crowdsec— 54 endpoints - P3-02
secubox-netdata— 16 endpoints - P3-03
secubox-wireguard— 28+ endpoints - P3-04
secubox-vhost— vhosts, SSL, certs - P3-05
secubox-mediaflow— streams, alerts - P3-06
secubox-dpi— 40+ endpoints netifyd - P3-07
secubox-qos— 60+ endpoints HTB - P3-08
secubox-auth— 20+ endpoints - P3-09
secubox-cdn— 25+ endpoints - P3-10
secubox-system— 35+ endpoints - P3-11
secubox-netmodes— 25+ endpoints + templates - P3-12
secubox-nac— 25+ endpoints - P3-13
secubox-haproxy— stats, backends, WAF - P3-14
secubox-droplet— upload, publish - P3-15
secubox-streamlit— apps, deploy - P3-16
secubox-streamforge— apps, templates - P3-17
secubox-metablogizer— sites, tor - P3-18
secubox-dns— zones, BIND - P3-19
secubox-mail— Postfix/Dovecot + DKIM + SpamAssassin + Postgrey + ClamAV - P3-20
secubox-users— unified identity - P3-21
secubox-webmail— Roundcube - P3-22
secubox-waf— 300+ rules, CrowdSec - P3-23
secubox-gitea— Git server LXC - P3-24
secubox-nextcloud— File sync LXC - P3-25
secubox-c3box— Services portal - P3-26
secubox-publish— Unified publishing
✅ PHASE 4 — APT Repo + Packaging (S13–S14) — TERMINÉ
- P4-01 APT repo signé GPG (apt.secubox.in)
- P4-02 reprepro config + publish workflow
- P4-03 Métapaquets (secubox-full, secubox-lite)
- P4-04 Local cache build system (apt-cacher-ng)
- P4-05 Deployment scripts (export-secrets.sh, local-publish.sh, install.sh)
✅ PHASE 5 — CSPN Hardening (S15–S18) — TERMINÉ
- P5-01 AppArmor profiles pour chaque service
- Base profile: /etc/apparmor.d/local/secubox-base
- Hub, Mail, WireGuard, CrowdSec specific profiles
- Generic profile for simple services
- Install script: scripts/install-apparmor.sh
- P5-02 Kernel config hardening — secubox-hardening module
- Sysctl hardening (ASLR, kptr_restrict, dmesg_restrict)
- Network hardening (SYN cookies, rp_filter, no redirects)
- Module blacklist (uncommon protocols, filesystems)
- hardeningctl CLI + FastAPI + web dashboard
- P5-03 Rootfs read-only : overlayfs + A/B partition eMMC
- P5-04 Secrets : firstboot génère dans /run/secubox/keys (tmpfs)
- JWT secret generated at firstboot
- Stored in /run/secubox/ (tmpfs)
- P5-05 auditd rules for SecuBox services
- Config changes, JWT access, firewall rules
- Authentication, privilege escalation
- Install script: scripts/install-audit.sh
- P5-06 nftables DEFAULT DROP policy + règles minimales
- inet secubox_filter with DROP policy
- Only SSH, HTTP/HTTPS, WireGuard open
- P5-07 Cible de sécurité ANSSI (rédiger draft CC EAL2)
✅ PHASE 6 — CI/CD Image Factory (S19–S21)
- P6-01
build-packages.yml: dpkg-buildpackage cross arm64 + reprepro- Dynamic matrix from packages directory
- Dual architecture (arm64 + amd64)
- Auto-publish on tag v*
- build-all.sh for local development
- P6-02
build-image.yml: matrix 5 boards + SHA256SUMS signés- MOCHAbin, ESPRESSObin v7, ESPRESSObin Ultra, vm-x64, vm-arm64
- Compressed with gzip and xz
- GPG signed checksums
- P6-03 Release pipeline : tag v* → GitHub Release + APT repo update
- Auto-publish packages to apt.secubox.in
- Auto-create GitHub Release with images
- Installation instructions in release notes
✅ PHASE 7 — Documentation (S22–S24) — TERMINÉ
- P7-01 Comprehensive API Reference (EN, FR, ZH)
- 48 modules documented with ~1000+ endpoints
- Organized by category (Core, Security, Network, Services, Apps, Intel)
- Code examples for common operations
- WebSocket documentation
- Error handling and rate limiting
- P7-02 Multilingual module documentation
- wiki/MODULES-EN.md, MODULES-FR.md, MODULES-DE.md, MODULES-ZH.md
- 48 modules with screenshots and descriptions
- P7-03 Installation guides (EN, FR, ZH)
- P7-04 Live USB guide with persistence
✅ COMPLÉTÉ
- Phase 1: Hardware bootstrap — Images arm64 + amd64, VirtualBox VM
- Phase 2: Infrastructure — secubox_core, nginx proxy, rewrite-xhr.py
- Phase 3: Modules — All 48 modules ported (~1000+ API endpoints)
- Phase 4: APT Repo — reprepro, GPG, metapackages, local cache
- Phase 5: CSPN Hardening — AppArmor, sysctl, auditd, nftables (mostly complete)
- Phase 6: CI/CD — build-packages.yml, build-image.yml, release.yml
- Phase 7: Documentation — API Reference (EN/FR/ZH), Module docs, Installation guides
Current status:
- 52 packages total (48 modules + metapackages)
- Mail server: DKIM + SpamAssassin + Postgrey + ClamAV
- WAF: 300+ rules with CrowdSec integration
- Hardening: Kernel sysctl + module blacklist
- Documentation: Comprehensive API docs in 3 languages
✅ PHASE 8 — Applications (21 modules) — COMPLETE
High-value user-facing services:
- P8-01
secubox-ollama— LLM inference, Ollama API proxy ✅ - P8-02
secubox-jellyfin— Media server LXC ✅ - P8-03
secubox-homeassistant— IoT hub LXC ✅ - P8-04
secubox-zigbee— Zigbee2MQTT gateway ✅ - P8-05
secubox-photoprism— Photo management ✅ - P8-06
secubox-matrix— Synapse chat server LXC ✅ - P8-07
secubox-jitsi— Video conferencing LXC ✅ - P8-08
secubox-gotosocial— Fediverse server ✅ - P8-09
secubox-peertube— Video platform LXC ✅ - P8-10
secubox-hexo— Static blog generator ✅ - P8-11
secubox-magicmirror— Smart display ✅ - P8-12
secubox-lyrion— Music server ✅ - P8-13
secubox-webradio— Internet radio ✅ - P8-14
secubox-voip— VoIP/PBX LXC ✅ - P8-15
secubox-jabber— XMPP server ✅ - P8-16
secubox-simplex— Secure messaging ✅ - P8-17
secubox-torrent— BitTorrent client ✅ - P8-18
secubox-newsbin— Usenet client ✅ - P8-19
secubox-domoticz— Home automation ✅ - P8-20
secubox-localai— Alternative LLM backend ✅ - P8-21
secubox-mmpm— MagicMirror package manager ✅
✅ PHASE 9 — System Tools (22 modules) — COMPLETE
Infrastructure utilities:
- P9-01
secubox-vault— Config backup/restore ✅ - P9-02
secubox-cloner— System imaging ✅ - P9-03
secubox-vm— QEMU/KVM virtualization ✅ - P9-04
secubox-glances— System monitor ✅ - P9-05
secubox-rtty— Remote terminal ✅ - P9-06
secubox-nettweak— Network tuning ✅ - P9-07
secubox-routes— Routing table view ✅ - P9-08
secubox-ksm— Kernel same-page merging ✅ - P9-09
secubox-reporter— System reports ✅ - P9-10
secubox-metabolizer— Log processor ✅ - P9-11
secubox-metacatalog— Service catalog ✅ - P9-12
secubox-saas-relay— SaaS proxy ✅ - P9-13
secubox-rezapp— App deployment ✅ - P9-14
secubox-turn— TURN/STUN server ✅ - P9-15
secubox-smtp-relay— Mail relay ✅ - P9-16
secubox-mqtt— MQTT broker ✅ - P9-17
secubox-cyberfeed— Threat feed aggregator ✅ - P9-18
secubox-avatar— Identity management ✅ - P9-19
secubox-admin— Admin dashboard ✅ - P9-20
secubox-mirror— Mirror/CDN ✅ - P9-21
secubox-netdiag— Network diagnostics ✅ - P9-22
secubox-picobrew— Homebrew controller ✅
✅ PHASE 10 — Security Extensions (10 modules) — COMPLETE
Advanced security features:
- P10-01
secubox-wazuh— SIEM integration ✅ - P10-02
secubox-ai-insights— ML threat detection ✅ - P10-03
secubox-ipblock— IP blocklist manager ✅ - P10-04
secubox-interceptor— Traffic interception ✅ - P10-05
secubox-cookies— Cookie analysis ✅ - P10-06
secubox-mac-guard— MAC address control ✅ - P10-07
secubox-dns-provider— DNS API (OVH, Gandi) ✅ - P10-08
secubox-threats— Threat dashboard ✅ - P10-09
secubox-openclaw— OSINT tool ✅ - P10-10
secubox-netifyd— DPI daemon ✅
🔄 PHASE 11 — Live USB Enhancements (v1.7.0)
Remote UI / HyperPixel 2.1 Round
- P11-R01 USB OTG composite gadget (ECM + ACM)
- P11-R02 TransportManager with OTG/WiFi failover
- P11-R03 install_zerow.sh with safe device check
- P11-R04 Fix vc4-kms-v3d conflict with HyperPixel
- P11-R05 Bookworm userconf file for pi:raspberry
- P11-R06 usb0-up.sh bypass NetworkManager
- P11-R07 Test HyperPixel display on real hardware ✅ v1.10.0
- P11-R17 USB OTG network fix — Use usb1 (ECM) for Linux hosts ✅ v2.1.1
- Fixed: dtoverlay=hyperpixel2r (not hyperpixel4)
- Fixed: hyperpixel2r-init uses pigpio instead of RPi.GPIO (lgpio issues on Bookworm)
- Fixed: Service dependencies (requires pigpiod)
- P11-R08 Display verified working after reboot ✅
- P11-R09 Framebuffer dashboard for Pi Zero W ✅ v1.11.0
- Pi Zero W (ARMv6) lacks NEON SIMD required by Chromium
- Created Python PIL-based framebuffer dashboard (fb_dashboard.py)
- Renders directly to /dev/fb0 without X11
- 6 circular module rings with animated metrics
- Auto-starts via secubox-fb-dashboard.service
Eye Remote Full Integration (v2.0.0) — Issue #31
- P11-R10 secubox-eye-agent — Multi-SecuBox connection manager
- Device token auto-authentication
- Metrics bridge (Unix socket to dashboard)
- WebSocket command handler
- Touch gestures for control
- P11-R11 secubox-eye-remote module — SecuBox side
- FastAPI endpoints for device management
- Device registry + token manager
- Pairing flow with QR generation
- WebSocket bidirectional commands
- Serial console bridge (xterm.js)
- P11-R12 WebUI management dashboard
- Device status, screenshot, reboot, OTA
- Configuration panel
- Pairing QR display
- Serial terminal (xterm.js)
- P11-R13 Touchless pairing
- QR code URL to SecuBox
- SSH auto-provisioning
- Device token generation
- P11-R14 Eye Remote as controller
- Service restart via touch
- OTG mode switching
- Emergency lockdown (3-finger tap)
- P11-R15 secubox-eye-gateway tool
- Emulator mode (fake metrics)
- Gateway mode (proxy to real SecuBox)
- Fleet mode (multi-SecuBox aggregation)
- Metrics profiles (idle/normal/busy/stressed)
- P11-R16 OTA updates + screenshot capture
Kiosk Mode
- P11-01 Display SecuBox version in kiosk mode header/footer
- P11-02 Show current authentication mode (ZKP/standard) in kiosk UI
- P11-03 Add boot mode indicator (kiosk/console/bridge) on splash
Authentication Feedback
- P11-04 Visual feedback for auth mode in portal login page
- P11-05 Auth mode toggle in system settings
- P11-06 ZKP status indicator in dashboard
Boot Experience
- P11-07 Plymouth theme with version number
- P11-08 GRUB menu version display
- P11-09 Boot mode selection with descriptions
🔄 PHASE 12 — Meta-Script Generator (v2.0.0)
SecuBox Appliance Factory — Profile-based, modular image generation with version tracking
Architecture Core
- P12-01 Profile hierarchy system ("gigogne" nested inheritance)
- base/ → tier-lite/ → tier-standard/ → tier-pro/
- Profile YAML with
inherits:directive - Component capability matrix (memory, CPU, storage requirements)
- Automatic profile selection based on detected hardware
- P12-02 Board-specific tweaks registry
- boards//tweaks.yaml — hardware-specific optimizations
- DTS/DTB overrides per board
- Kernel module blacklist/whitelist per board
- Performance profiles (idle, normal, busy, stressed)
- P12-03 Component versioning system
- component-version.yaml per package
- Semantic versioning with SecuBox patch suffix (e.g., 1.7.7-sb3)
- Compatibility matrix (min memory, requires, conflicts)
- Tag system for feature categorization
Generator CLI
- P12-04
secubox-gen— Manifest generatorsecubox-gen --profile tier-lite --board espressobin-v7 \ --enable crowdsec,wireguard --tweak low-memory \ --output manifest.yaml- Interactive mode with hardware detection
- Profile auto-selection based on target specs
- Dependency resolution and conflict detection
- P12-05
secubox-build— Image builder from manifest- Reproducible builds from manifest.yaml
- Incremental builds (delta from base image)
- Multi-stage build with checkpoints
- Build cache for faster iteration
- P12-06
secubox-fetch— GitHub release downloader- Download pre-built images for tested boards
- GPG signature verification
- SHA256 checksum validation
- Automatic version matching
Appliance README Generator
- P12-07 Auto-generated appliance documentation
- Hardware profile summary
- Component version table with status
- Applied tweaks and optimizations
- Support contact and issue reporting
- P12-08 Machine-readable manifest for bug reports
- JSON export for automated support
- Hardware capability snapshot
- Service status at generation time
- Version fingerprint hash
Portable Application
- P12-09 Electron/Tauri desktop app for image generation
- Cross-platform (Linux, macOS, Windows)
- GitHub OAuth for release access
- Visual board/profile selector
- Progress tracking with logs
- P12-10 Web-based generator (optional)
- Static site hosted on GitHub Pages
- Manifest builder with live preview
- Download link generator
- QR code for mobile access
Version Tracking & Participation
- P12-11 Component version registry API
- FastAPI service for version queries
- Compatibility checks via API
- Update notifications
- Usage statistics (opt-in)
- P12-12 Participative development workflow
- Issue templates with device fingerprint
- Feature request with profile context
- Automated testing matrix based on device reports
- Community board support voting
Profile Definitions
# profiles/tier-lite/profile.yaml
name: tier-lite
inherits: base
description: Constrained devices (≤1GB RAM, ≤2 cores)
constraints:
max_memory: 1G
max_cores: 2
max_storage: 8G
components:
exclude:
- secubox-ollama # Too heavy
- secubox-jellyfin # Needs GPU
optimize:
- secubox-crowdsec: --no-hub-download
- secubox-nginx: --worker-processes 1
tweaks:
kernel:
vm.swappiness: 10
vm.dirty_ratio: 20
systemd:
DefaultMemoryAccounting: yes
DefaultTasksMax: 100
Board-Specific Tweaks
# boards/espressobin-v7/tweaks.yaml
board: espressobin-v7
soc: Marvell Armada 3720
profile: tier-lite
capabilities:
ram: 1GB
cores: 2
storage: eMMC 8GB
network:
- wan: eth0
- lan: lan0, lan1
usb: 1x USB 3.0, 1x USB 2.0
tweaks:
kernel_modules:
blacklist: [bluetooth, btusb] # No BT hardware
device_tree:
overlay: espressobin-v7-secubox.dtbo
network:
default_mode: router
wan_interface: eth0
Reference: See REMAINING-PACKAGES.md for detailed inventory with complexity classification