security: pgrep -fl finds its own search when hunting argv credentials
Re-measured for fleetd #190. pgrep -fl reported 12 environment names in argv where ps reported 5, and 0 credential-shaped. Every extra name came from the search command itself.
@@ -194,6 +194,37 @@ the token scope — is bypassed the moment that happens, because none of them to
|
||||
gap in the host, not in `fleetd`'s own code, and it is recorded here rather than left undocumented,
|
||||
because a security page that hides its own limits is worse than one with none.
|
||||
|
||||
### Checking for it: `pgrep -fl` finds your own search
|
||||
|
||||
Re-measured on the Mac, 2026-09-10. The check itself has a trap, and it produces false positives
|
||||
that look exactly like real findings.
|
||||
|
||||
`pgrep -fl <pattern>` prints the full command line of every matching process — **including the
|
||||
process running your search**. A hunt for credential-shaped names matches the grep pattern in your
|
||||
own `argv`, so the names you are looking for appear in the output whether or not any process is
|
||||
leaking them. Read against a ticket that lists the names, it reads as confirmation.
|
||||
|
||||
The two commands disagreed by a factor of two here: `pgrep -fl claude` reported 12 environment
|
||||
names in `argv`, `ps -axwwo args=` across every process on the host reported 5, and the number of
|
||||
credential-shaped names was **0** by `ps`. The `ps` number is the right one. Every extra name came
|
||||
from the search command and from a shell command whose text quoted the ticket.
|
||||
|
||||
Check with `ps`, one process at a time, and extract names only:
|
||||
|
||||
```bash
|
||||
# every process: how many credential-shaped names are in argv?
|
||||
ps -axwwo pid=,args= | grep -oE '[A-Z][A-Z0-9_]{2,}=' | sort -u | grep -E 'TOKEN|KEY|SECRET|PASSWORD'
|
||||
|
||||
# one process, names only
|
||||
ps -wwo args= -p <pid> | grep -oE '[A-Z][A-Z0-9_]{2,}=' | sed 's/=$//' | sort -u
|
||||
```
|
||||
|
||||
`grep -o` on a pattern that ends at `=` cannot emit the value, so both forms are safe by
|
||||
construction. Never use `pgrep -fl` for this, and never print a value.
|
||||
|
||||
**When two counts disagree, suspect the two commands before the machine.** `ps` and `pgrep` do not
|
||||
search the same set: one omits the searcher, the other includes it.
|
||||
|
||||
---
|
||||
|
||||
This page does not cover herdr's own process isolation, the LavinMQ broker's per-vhost isolation
|
||||
|
||||
Reference in New Issue
Block a user