docs(audit): post-uninstall anomaly entry, classified mundane with escalation criteria
This commit is contained in:
@@ -178,6 +178,30 @@ for keeping those gates.
|
|||||||
protocols where supported, ASCII otherwise.
|
protocols where supported, ASCII otherwise.
|
||||||
- All work committed and pushed to `git.neuralplatform.ai/neuron-technologies/neuron`.
|
- All work committed and pushed to `git.neuralplatform.ai/neuron-technologies/neuron`.
|
||||||
|
|
||||||
|
## Part 4b: Post-uninstall anomaly (2026-08-21)
|
||||||
|
|
||||||
|
**Event:** After `brew uninstall opencode`, terminal output showed ripgrep
|
||||||
|
being uninstalled. Operator read this as possible executable tampering
|
||||||
|
("something is replacing the executable").
|
||||||
|
|
||||||
|
**Investigation:**
|
||||||
|
- `opencode` is a homebrew-core formula (`Formula/o/opencode.rb`,
|
||||||
|
1.18.15) with declared required dependencies: **node, ripgrep**.
|
||||||
|
- Homebrew auto-removes orphaned auto-installed dependencies on uninstall;
|
||||||
|
our `tail -2` captured only the ripgrep removal lines, creating the
|
||||||
|
appearance that ripgrep was removed *instead of* opencode.
|
||||||
|
- Both were actually removed: `/opt/homebrew/bin/opencode` and Cellar entry
|
||||||
|
confirmed deleted; ripgrep reinstalled cleanly afterwards.
|
||||||
|
- No code in Neuron invokes `brew uninstall` anywhere.
|
||||||
|
|
||||||
|
**Classification: MUNDANE — dependency autoremove**, presentation artifact of
|
||||||
|
truncated output. Recorded at operator's request given the day's other
|
||||||
|
findings. Would upgrade to suspicious only if: opencode binaries reappear
|
||||||
|
without an install action, checksums change between builds without rebuilds,
|
||||||
|
or network egress to Anomaly endpoints is observed from Neuron processes.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Part 5: Open discussion points
|
## Part 5: Open discussion points
|
||||||
|
|
||||||
1. The workspace/sync runtime (`control-plane/workspace.ts`, ~966 lines) still
|
1. The workspace/sync runtime (`control-plane/workspace.ts`, ~966 lines) still
|
||||||
|
|||||||
Reference in New Issue
Block a user