Installed the .deb on the live server. The daemon did not start, and everything below is what that one command surfaced. 1. MemoryDenyWriteExecute=yes stopped the service dead. yara-x compiles rules to WebAssembly and JITs them, so it needs pages that go writable then executable. With W^X enforced the daemon aborts at startup: "unable to make memory executable". The unit had passed systemd-analyze verify, which checks syntax and cannot know this. Now off, with the reasoning in the unit rather than in a commit nobody will read: a hardening directive that stops the service is worse than the exposure it prevents, because the machine ends up with no antivirus at all. What compensates is spelled out beside it. 2. Hound detected itself. The goodware gate reported /usr/bin/houndd as Linux.Coinminer.XMRig and Linux.Rootkit.Preload. Correctly: the built-in pack matches on "stratum+tcp://", "xmrig", "RTLD_NEXT" and "ld.so.preload", and the pack was embedded verbatim, so the daemon's own binary contained all of them. Not cosmetic. With the execution gate armed, Hound would have refused to execute itself or quarantined its own binary — a scanner that eats its own daemon the moment protection is switched on. The pack is now XOR-masked at build time (build.rs) and unmasked at startup. Not a secret — the rules are open source — the only job is keeping the literal bytes out of the executable. Two regression tests: the embedded blob carries no plaintext rule strings, and a built daemon binary in target/ carries none either. 3. The postinst copied the built-in pack into /var/lib/hound/rules, where the daemon compiled it a second time and logged a duplicate declaration on every start. That directory is for ADDITIONAL packs; the built-ins live in the binary. Removed from deb, rpm and AUR. 4. The daemon and the CLI disagreed about the socket. systemd gives the service /run/hound; the CLI looked in $XDG_RUNTIME_DIR and reported the daemon unreachable — technically true, entirely unhelpful. default_socket_path() now prefers /run/hound when it exists, the unit states HOUNDD_SOCK explicitly, and a permission error on the socket says "try: sudo hound" instead of "Permission denied". Also: Recommends: clamav-daemon was wrong and apt duly installed clamd, which took 970 MB of RSS on the live server. clamd is an optional arm's-length engine, so it is a Suggests. I stopped and disabled the copy my install pulled in. Verified on the server after fixing: service active, status reports the engine and the gate, EICAR caught, rootkit scan clean, and the goodware gate passes across 3,955 system binaries including the now-installed houndd. The gate remains OFF. Turning it on for the host that serves Caddy is a separate decision. 295 tests pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
19 lines
350 B
Text
19 lines
350 B
Text
post_install() {
|
|
cat <<'MSG'
|
|
|
|
Hound is installed and scanning on demand.
|
|
|
|
hound status what the daemon sees
|
|
hound scan ~/Downloads scan a directory
|
|
|
|
Real-time execution blocking is OFF until you turn it on:
|
|
|
|
sudo systemctl enable --now houndd
|
|
sudo hound settings set exec_gate true
|
|
|
|
MSG
|
|
}
|
|
|
|
post_upgrade() {
|
|
post_install
|
|
}
|