diff --git a/16-Security-and-Trust-Boundary.md b/16-Security-and-Trust-Boundary.md index e48eef8..dc399d8 100644 --- a/16-Security-and-Trust-Boundary.md +++ b/16-Security-and-Trust-Boundary.md @@ -194,6 +194,37 @@ the token scope — is bypassed the moment that happens, because none of them to gap in the host, not in `fleetd`'s own code, and it is recorded here rather than left undocumented, because a security page that hides its own limits is worse than one with none. +### Checking for it: `pgrep -fl` finds your own search + +Re-measured on the Mac, 2026-09-10. The check itself has a trap, and it produces false positives +that look exactly like real findings. + +`pgrep -fl ` prints the full command line of every matching process — **including the +process running your search**. A hunt for credential-shaped names matches the grep pattern in your +own `argv`, so the names you are looking for appear in the output whether or not any process is +leaking them. Read against a ticket that lists the names, it reads as confirmation. + +The two commands disagreed by a factor of two here: `pgrep -fl claude` reported 12 environment +names in `argv`, `ps -axwwo args=` across every process on the host reported 5, and the number of +credential-shaped names was **0** by `ps`. The `ps` number is the right one. Every extra name came +from the search command and from a shell command whose text quoted the ticket. + +Check with `ps`, one process at a time, and extract names only: + +```bash +# every process: how many credential-shaped names are in argv? +ps -axwwo pid=,args= | grep -oE '[A-Z][A-Z0-9_]{2,}=' | sort -u | grep -E 'TOKEN|KEY|SECRET|PASSWORD' + +# one process, names only +ps -wwo args= -p | grep -oE '[A-Z][A-Z0-9_]{2,}=' | sed 's/=$//' | sort -u +``` + +`grep -o` on a pattern that ends at `=` cannot emit the value, so both forms are safe by +construction. Never use `pgrep -fl` for this, and never print a value. + +**When two counts disagree, suspect the two commands before the machine.** `ps` and `pgrep` do not +search the same set: one omits the searcher, the other includes it. + --- This page does not cover herdr's own process isolation, the LavinMQ broker's per-vhost isolation