security: pgrep -fl finds its own search when hunting argv credentials

Re-measured for fleetd #190. pgrep -fl reported 12 environment names in
argv where ps reported 5, and 0 credential-shaped. Every extra name came
from the search command itself.
Dai Ha
2026-09-10 07:10:49 +07:00
parent 180652edca
commit 967add3a07
+31
@@ -194,6 +194,37 @@ the token scope — is bypassed the moment that happens, because none of them to
gap in the host, not in `fleetd`'s own code, and it is recorded here rather than left undocumented,
because a security page that hides its own limits is worse than one with none.
### Checking for it: `pgrep -fl` finds your own search
Re-measured on the Mac, 2026-09-10. The check itself has a trap, and it produces false positives
that look exactly like real findings.
`pgrep -fl <pattern>` prints the full command line of every matching process — **including the
process running your search**. A hunt for credential-shaped names matches the grep pattern in your
own `argv`, so the names you are looking for appear in the output whether or not any process is
leaking them. Read against a ticket that lists the names, it reads as confirmation.
The two commands disagreed by a factor of two here: `pgrep -fl claude` reported 12 environment
names in `argv`, `ps -axwwo args=` across every process on the host reported 5, and the number of
credential-shaped names was **0** by `ps`. The `ps` number is the right one. Every extra name came
from the search command and from a shell command whose text quoted the ticket.
Check with `ps`, one process at a time, and extract names only:
```bash
# every process: how many credential-shaped names are in argv?
ps -axwwo pid=,args= | grep -oE '[A-Z][A-Z0-9_]{2,}=' | sort -u | grep -E 'TOKEN|KEY|SECRET|PASSWORD'
# one process, names only
ps -wwo args= -p <pid> | grep -oE '[A-Z][A-Z0-9_]{2,}=' | sed 's/=$//' | sort -u
```
`grep -o` on a pattern that ends at `=` cannot emit the value, so both forms are safe by
construction. Never use `pgrep -fl` for this, and never print a value.
**When two counts disagree, suspect the two commands before the machine.** `ps` and `pgrep` do not
search the same set: one omits the searcher, the other includes it.
---
This page does not cover herdr's own process isolation, the LavinMQ broker's per-vhost isolation