Repository navigation
Keep update/runtime/diagnostics out of world-writable /tmp - #12109
Chessing234 wants to merge 15 commits into
Conversation
|
Take a look at #11401 which relocates $TMPDIR into ~/.local/tmp while maintaining tmp cleanup semantics. |
5e166a4 to
1ed103b
Compare
A pre-created /tmp/omarchy-update.log symlink let another local user redirect script(1) into the victim's files. Stage the log under XDG_RUNTIME_DIR (or a 0700 cache under \$HOME).
XDG_RUNTIME_DIR falling back to /tmp let another local user race the lock path. Use ~/.local/state/omarchy instead and chmod the directory.
Falling back to /tmp/omarchy-reminders left reminder bodies world-readable on multi-user hosts. Prefer XDG_RUNTIME_DIR, else ~/.local/state, and chmod the directory 0700.
Clipboard mode wrote wl-paste into a world-readable mktemp under /tmp and left it forever. Stage under XDG_RUNTIME_DIR (else ~/.local/state), chmod 0600, wait for LocalSend, then remove the temp file.
|
rebased onto tip; dropped the stay-awake and sudo-probe commits tip already covers |
26d0fbf to
17515d8
Compare
|
Reviewed at 17515d8 against Overlap with other pull requests. Most of this diff already has a competing fix. #7995 covers Scope. The three issues it closes are about two fallbacks: the DDC cache (#11596) and the capture-region markers (#11597). #11595 was already fixed on Defects in the new fallbacks. Each of these only matters when
Next step. This waits on the maintainer to choose between this and #7995, #8429 and #12957. A version limited to the DDC cache and capture markers, with a fallback that checks ownership the way stay-awake does, would be straightforward to review on its own. |
|
Closing after maintainer review. We are not accepting this as a security vulnerability that warrants these changes for Omarchy's intended single-user desktop setup. The cross-account disclosure scenario requires an additional untrusted local account, or a separately compromised service account, plus a run of the relevant command. The report has not demonstrated a sensitive credential disclosure or a consequential exploit in the default setup. Root can already read this information, and malicious programs running as the desktop user can still read it after a move to a private file or directory. Hostname, hardware details, and package inventory alone do not establish a security vulnerability. The default systemd protections ( The default Private staging and explicit cleanup can be reasonable housekeeping, but we do not consider the demonstrated behavior a security priority for the default Omarchy threat model. We are declining this family of security-motivated changes on that basis. References: systemd default protections, kernel documentation, default tmpfs mount. This PR also bundles capture markers, DDC caches, inhibitor state, and locks. Those are distinct consumers with distinct failure modes; they do not gain a demonstrated security impact from the diagnostics argument. Closing this combined proposal. This decision does not close #11595, #11596, or #11597 or claim that every runtime-state concern is equivalent to readable diagnostic logs. Omabot on behalf of DHH |
Summary
XDG_RUNTIME_DIRor a private 0700 owner-checked state dir instead of predictable/tmppaths ([Security] omarchy-update-stay-awake stages inhibit state under predictable /tmp/omarchy-$UID #11595, [Security] omarchy-brightness-display-ddc caches bus numbers under world-writable /tmp #11596, [Security] omarchy-capture-region marker files fall back into world-writable /tmp #11597).Fixes #11595
Fixes #11596
Fixes #11597
Test plan
bash test/shell.d/capture-region-marker-path-test.shbash test/shell.d/brightness-display-ddc-cache-path-test.shbash test/shell.d/update-stay-awake-path-test.shbash test/shell.d/update-log-path-test.sh