Skip to content

fix(device): report the configured macOS hostname, not kern.hostname - #229

Open
swarit-stepsecurity wants to merge 3 commits into
step-security:mainfrom
swarit-stepsecurity:swarit/fix/wt/macos-hostname
Open

swarit-stepsecurity wants to merge 3 commits into
step-security:mainfrom
swarit-stepsecurity:swarit/fix/wt/macos-hostname

Conversation

@swarit-stepsecurity

@swarit-stepsecurity swarit-stepsecurity commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

What does this PR do?

macOS devices were flip-flopping between their real name and ip-…ec2.internal. We reported os.Hostname(), which on macOS is kern.hostname; with no HostName set, macOS rewrites it from DHCP or reverse DNS on every network change, so a VPN resolving through AWS renamed the Mac on some scans. The backend stores whatever the latest scan sends, so the device list followed it.

On macOS the agent now reports HostName when an admin has set one, else LocalHostName. Both are read from /Library/Preferences/SystemConfiguration/preferences.plist (the file scutil reads, parsed with the existing howett.net/plist dependency), with scutil --get as the fallback since that layout isn't a documented contract, and os.Hostname() last. Windows and Linux are unchanged. Devices are keyed by serial (RegisteredDevicesv1 is customer_id + device_id), so existing Macs rename once without duplicating; nothing in agent-api keys, matches or notifies on hostname.

Type of change

  • Bug fix
  • Enhancement
  • Documentation

Testing

  • No secrets or credentials included
  • Lint passes: make lint
  • Tests pass: make test, plus make smoke and linux/darwin/windows cross-compiles

With no HostName set, macOS rewrites kern.hostname from DHCP or reverse
DNS on every network change, so a Mac on a VPN resolving through AWS
reported ip-…ec2.internal on some scans and its real name on others.
Prefer scutil HostName, then LocalHostName, then os.Hostname.

Signed-off-by: Swarit Pandey <swarit@stepsecurity.io>
Read HostName and LocalHostName from preferences.plist, the file scutil
itself reads, so the common case spawns no subprocess. The layout is
not a documented contract, so scutil stays as the fallback.

Signed-off-by: Swarit Pandey <swarit@stepsecurity.io>
@swarit-stepsecurity

Copy link
Copy Markdown
Member Author

@ashishkurmi can you please add copilot review to this PR? Thanks.

This basically reads hostname from HostName instead of LocalHostName (which is more friendly and doesn't change depending on system's network connection. This issue was reported and bought up by @karthik-stepsecurity

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant