Skip to content

Audit follow-ups: DNS --server, Store badge, Settings MCP layout, shared text cleaning, macOS file limit - #565

Open
fstubner wants to merge 8 commits into
mainfrom
fix/audit-followups
Open

fstubner wants to merge 8 commits into
mainfrom
fix/audit-followups

Conversation

@fstubner

@fstubner fstubner commented Oct 8, 2026

Copy link
Copy Markdown
Owner

The leftovers from the audit that touched several branches, plus what you asked for since.

What changes for users

  • DNS lookups can ask a server you name. netscli dns --server <ip>, /dns ... --server <ip> in the TUI, a Server field in the desktop DNS tool, and a server parameter on MCP dns_lookup.
    • It replaces the removed fallback with a server you choose.
    • The MCP server holds it to the same target policy as a scan.
    • The desktop backend refuses a non-IP value before it looks anything up.
    • resolver_source says server for these answers.
    • Checked: netscli dns netscli.com --record MX --server 1.1.1.1 --csv answers with server.
  • The Microsoft Store listing is linked with Microsoft's own badge. It sits in the install section's Windows desktop list, and in the README and install guide.
    • The badge files are Microsoft's official SVGs, unmodified and served from this site.
    • The light badge shows on the dark theme and the dark badge on the light theme. Checked in both themes.
  • The MCP section in desktop Settings looks like the rest of Settings.
    • It uses the same label-and-note rows with text buttons: Command-Line Tool with Install Options, Install Command with Copy, and Agent Config with Copy Config.
    • The JSON sits under "Show config".
    • Install Options now opens through the app's allow-listed opener.
  • Reverse-DNS names and desktop CSV exports clean bidi and zero-width characters, using the same set as the CLI (is_unsafe_for_display). testdata/csv-escape.json gains four cases that both exports must pass.
  • Scans raise the soft open-file limit on macOS and Linux to min(10240, hard limit) before fanning out. macOS's default of 256 equals the default concurrency.
  • Docs:

Checked

  • cargo fmt --all --check.
  • cargo clippy -D warnings on netscli-core, netscli, netscli-mcp and netscli-gui.
  • cargo test: netscli 125, netscli-mcp 51, core DNS tests, and the guard against a built-in public resolver.
  • Desktop app: lint, 296 unit tests, build.
  • Site: astro check, build, check:css.
  • The Store badge and the Settings layout were checked in the browser.
  • CI only: the Unix open-file-limit test, because this machine can't build the Linux target's C dependencies.

It was a heading, a wrapped paragraph and a boxed code block with an icon
button, which read as a different dialog dropped into this one. It now uses
the ordinary rows and text buttons: Command-Line Tool (with Install Options),
Install Command (with Copy), and when netscli is found, Agent Config with
Copy Config and the JSON one click away under Show config. The link now opens
through the allow-listed opener instead of an anchor the webview can't follow.
… CSV too

reverse.rs rejected only control characters, and the desktop app's CSV
escaping defused only those, while the CLI now treats bidi overrides and
zero-width characters as unsafe as well (is_unsafe_for_display). Both use
that set now, and testdata/csv-escape.json holds the CLI and the desktop app
to four new cases.
…ll scripts and MCP bundles now check

The verify command accepted release.yml's signature from any ref. It now
names main (and release tags, for releases before 0.3.1), as install.sh
does. SECURITY.md said the install scripts check no signature and the MCP
bundles have none, both true until the release-pipeline change. The
packaging checklist told you to publish the release by hand, which the
new flow does itself.
Default concurrency is 256 and macOS's default soft RLIMIT_NOFILE is 256,
so a full-concurrency scan could hit EMFILE and report the failed connects
as filtered. PortScanner, UdpScanner and PingScanner now raise the soft
limit once per process to min(10240, hard limit). The Unix test runs in CI;
this machine cannot build the Linux target's C dependencies.
The desktop app is live in the Store (product XPFG556RR6B76Z). The install
section's Windows desktop list gets a Microsoft Store row with the official
badge, unmodified and served from this site so the browser does not call
Microsoft: the light badge on the dark theme and the dark one on the light
theme. README and the install guide link the listing too.
The fallback removal left no way to send a lookup anywhere but the system's
DNS servers, which on some home routers refuse MX and TXT. A named server is
the honest replacement: netscli dns --server <ip>, /dns ... --server <ip>,
a Server field in the desktop DNS tool, and a server parameter on the MCP
dns_lookup tool, which holds it to the same target policy as a scan. The
desktop backend parses it before the operation starts, so a typo is an
error rather than a lookup that silently goes to the system's servers.
resolver_source reads "server" for these answers.

The guard against a built-in public resolver now bans hickory's presets
everywhere and public resolvers' addresses outside test files, instead of
any ResolverConfig, which a user-named server needs.
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Site preview: https://pr-565.netscli-site-preview.pages.dev

Built from e5ef422 with NETSCLI_PREVIEW=1 — noindex, and analytics disabled so it does not report into netscli.com's numbers.

Production is unaffected: netscli.com is served from GitHub Pages via pages.yml, which deploys from main.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant