Skip to content

[Security] Stage menu IPC files out of world-writable /tmp - #10506

Closed
Chessing234 wants to merge 1 commit into
omacom:quattrofrom
Chessing234:security/menu-ipc-runtime
Closed

Chessing234 wants to merge 1 commit into
omacom:quattrofrom
Chessing234:security/menu-ipc-runtime

Conversation

@Chessing234

@Chessing234 Chessing234 commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • omarchy-menu-select, omarchy-menu-input, and omarchy-menu-images used bare mktemp for selection/done files
  • Typed input (including secrets) and picker results landed in world-writable /tmp; after rm of the done file, another user can recreate that name
  • Stage those files under $XDG_RUNTIME_DIR (or a 0700 /tmp/omarchy-$UID fallback)

Test plan

  • bash test/shell.d/menu-ipc-path-test.sh
  • Run omarchy menu input and confirm the IPC files are not created under /tmp/tmp.*

@Chessing234

Copy link
Copy Markdown
Contributor Author

@dhh @ryanrhughes ready for review

@csfh

csfh commented Sep 13, 2026

Copy link
Copy Markdown
Member

Real issue — keep this open. Closing it in favor of the other /tmp PRs would leave the menu IPC hole open; nothing else relocates omarchy-menu-select / -input / -images.

Please harden the fallback before we merge, though. ${XDG_RUNTIME_DIR:-/tmp/omarchy-$UID} + mkdir -m 700 -p does not fix an existing attacker-owned /tmp/omarchy-$UID (mkdir -p won't chmod/chown what's already there). Match the stronger pattern in #11600 / #9084: prefer a real non-symlink XDG_RUNTIME_DIR, otherwise a private state/cache dir under $HOME — not a predictable path in world-writable /tmp.

Also worth covering in tests: the unset-XDG_RUNTIME_DIR fallback, and a live stub run for omarchy-menu-images (not only the static grep).

@csfh csfh added the verified Omarchy Triage has verified that this issue is ready for final review label Sep 13, 2026
@Chessing234

Copy link
Copy Markdown
Contributor Author

folded into #12066 for a single review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

verified Omarchy Triage has verified that this issue is ready for final review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants