CONTAINER.md
All files · Open raw file
5287 bytes · SHA-256: f8b9f86ec1aebebb53033e5f715ecb443c482a7131ae0d9d2088aeaecc3d72c9
# IcyZip E2EE review lab
The public image packages this repository with Node.js and practical inspection tools. Its default command runs the complete standalone protocol suite and deterministic synthetic mutation fuzzing without network access. A passing run establishes only that those published checks passed for that image and input set. It does not prove that the protocol, browser delivery path, proprietary relay or hosted service has no weakness.
## Run the published image
```sh
docker pull docker.io/icyzip/e2ee-review:0.4.0
docker run --rm --network=none --read-only --cap-drop=ALL \
--security-opt=no-new-privileges --memory=768m --pids-limit=128 \
--tmpfs /tmp:rw,nosuid,nodev,size=128m \
docker.io/icyzip/e2ee-review:0.4.0
```
The release record at [icyzip.com/open-source](https://icyzip.com/open-source) gives the immutable multi-platform digest after publication. Prefer that digest when reproducing a result. Docker and Podman accept the same image reference and security options.
The default run:
- reports the source, module, Node and OpenSSL identities;
- validates the embedded SPDX inventory and required license paths;
- runs the minimal exchange, complete cryptographic and receive-controller tests, security regressions, provenance checks and container contracts;
- runs 256 seeded iterations that alter authenticated public-key messages, text ciphertext and metadata, encrypted file frames, signed offers and pairing-link fragments;
- proves legitimate text and file traffic continues after each rejected mutation.
All inputs are synthetic. The image opens no listening port and the default command needs no network.
## Repeat or extend a case
Run a named seed and iteration count:
```sh
docker run --rm --network=none docker.io/icyzip/e2ee-review:0.4.0 \
node tools/fuzz.mjs --seed 4294967295 --iterations 10000
```
Open a shell with a writable copy of the public source if you want to add a small reproduction:
```sh
mkdir icyzip-e2ee-work
docker run --rm --network=none \
--mount type=bind,src="$PWD/icyzip-e2ee-work",dst=/work \
docker.io/icyzip/e2ee-review:0.4.0 \
sh -lc 'cp -R /opt/icyzip-e2ee/. /work/'
```
Edit only the copied synthetic tests, then mount the directory at `/work` and run Node from there. Do not use real users' content, keys or active pairing links. [TESTING.md](TESTING.md) explains how to keep a reproduction small and how to test forward progress after rejection.
Useful commands already available in the image include `node`, `npm`, `git`, `openssl`, `python3`, `jq`, `rg`, `file`, `od` and `strace`. For example:
```sh
docker run --rm --network=none docker.io/icyzip/e2ee-review:0.4.0 npm run coverage
docker run --rm --network=none docker.io/icyzip/e2ee-review:0.4.0 node tools/inspect.mjs
docker run --rm --network=none docker.io/icyzip/e2ee-review:0.4.0 \
strace -f -e trace=network node tools/lab.mjs
```
`strace` reports attempted network system calls; the container's `--network=none` boundary remains the enforcement mechanism.
## Inspect inventory and licenses
The image carries four generated files under `/opt/icyzip-inventory/`:
- `SBOM.spdx.json`: SPDX 2.3 inventory for installed Debian packages, Node and discoverable bundled Node/npm components, plus all public review files;
- `LICENSES.json`: paths to retained package copyright/license material;
- `sources.json`: SHA-256 and byte length of every copied review file;
- `build.json`: exact base, Debian snapshot, architecture and source identity.
The inventory records package metadata; it is not a vulnerability or license-compliance verdict. Debian copyright files remain under `/usr/share/doc/*/copyright`, common license texts under `/usr/share/common-licenses`, the official Node distribution license under `/usr/local`, and this package's Apache-2.0 license at `/opt/icyzip-e2ee/LICENSE`. The inspector lists bundled packages for which the upstream distribution supplies a license identifier but no separate license file under `licenseMetadataGaps`; it never silently substitutes another package's license.
Export the inventories without enabling the network:
```sh
docker run --rm --network=none docker.io/icyzip/e2ee-review:0.4.0 \
node -e 'process.stdout.write(require("fs").readFileSync("/opt/icyzip-inventory/SBOM.spdx.json"))' \
> SBOM.spdx.json
```
## Rebuild from public source
The recipe pins the official Node 24.21.0 Trixie slim multi-platform manifest, uses a dated Debian snapshot and verifies the complete npm 12.1.0 distribution against its recorded SHA-512 before installation with scripts disabled. `.dockerignore` denies everything first, and each allowed public file is copied explicitly. Build from this repository directory, never from a parent application checkout:
```sh
git clone https://icyzip.com/open-source/icyzip-e2ee.git
cd icyzip-e2ee
docker build --pull=false -t icyzip-e2ee-review:local .
docker run --rm --network=none --read-only --cap-drop=ALL \
--security-opt=no-new-privileges --tmpfs /tmp:rw,nosuid,nodev,size=128m \
icyzip-e2ee-review:local
```
The proprietary IcyZip relay and application server are outside the repository, build context and image. See [THREAT-MODEL.md](THREAT-MODEL.md) for the security boundary and [SECURITY.md](SECURITY.md) for private reports.