feat(FN-5375): enforce manifest-gated cloudflared checksum installation

Added manifest-gated checksum verification for cloudflared remote access tunnels: a pinned manifest validator (Step 1) and enforcement logic (Step 2) wired into the settings memory routes, with aligned tests and documentation covering fail-closed install behavior and pending-manifest guidance.

Fusion-Task-Id: FN-5375
This commit is contained in:
Fusion (runfusion.ai)
2026-05-20 18:42:00 -07:00
committed by gsxdsm
parent e814ba9508
commit dbccdb1275
5 changed files with 307 additions and 13 deletions

View File

@@ -70,7 +70,7 @@ Cloudflare **Quick Tunnel** startup gates (`quickTunnel = true`):
No Cloudflare account, tunnel token, named tunnel, or pre-created ingress URL is required.
Dashboard note: in Settings → Remote Access, selecting Cloudflare now performs a proactive `cloudflared` CLI detection check and shows a one-click **Install cloudflared** action (with manual command fallback) if the binary is missing.
Dashboard note: in Settings → Remote Access, selecting Cloudflare performs a proactive `cloudflared` CLI detection check and shows a one-click **Install cloudflared** action (with manual command fallback) if the binary is missing. The direct-download path is pinned-manifest gated: until maintainers flip the shipped manifest from `upstream-pending-verification` to a verified tagged release with per-asset `.sha256` sidecars, auto-download fails closed and the UI surfaces package-manager/manual fallback commands.
Runtime command used by engine: