Skip to content

Keep update log, lock, reminders, and clipboard shares out of shared /tmp - #12077

Closed
Chessing234 wants to merge 6 commits into
omacom:quattrofrom
Chessing234:fix/tmp-staging-hardening
Closed

Chessing234 wants to merge 6 commits into
omacom:quattrofrom
Chessing234:fix/tmp-staging-hardening

Conversation

@Chessing234

Copy link
Copy Markdown
Contributor

Summary

  • Keep the update transcript under a private runtime/cache path and refuse planted symlinks.
  • Keep the update lock out of world-writable /tmp.
  • Keep reminder message files under a uid-scoped runtime/state dir.
  • Stage clipboard LocalSend shares privately, chmod them, and clean them up.

Combines #9084, #9854, #9852, and #9862 into one reviewable PR.

Test plan

  • Cherry-picks apply cleanly on tip
  • bash test/shell.d/update-log-path-test.sh
  • Update lock uses ~/.local/state/omarchy (or equivalent) instead of shared /tmp
  • Reminder bodies are not world-readable under /tmp
  • Clipboard share temp files land under runtime/state, mode 0600, and are removed after LocalSend

A pre-created /tmp/omarchy-update.log symlink let another local user
redirect script(1) into the victim's files. Stage the log under
XDG_RUNTIME_DIR (or a 0700 cache under \$HOME).
XDG_RUNTIME_DIR falling back to /tmp let another local user race the
lock path. Use ~/.local/state/omarchy instead and chmod the directory.
Falling back to /tmp/omarchy-reminders left reminder bodies world-readable
on multi-user hosts. Prefer XDG_RUNTIME_DIR, else ~/.local/state, and
chmod the directory 0700.
Clipboard mode wrote wl-paste into a world-readable mktemp under /tmp
and left it forever. Stage under XDG_RUNTIME_DIR (else ~/.local/state),
chmod 0600, wait for LocalSend, then remove the temp file.
@Chessing234

Copy link
Copy Markdown
Contributor Author

folding into #12109 with the other /tmp path hardening

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant