Root escalation: --persistent ownership check misses symlinks and writable parent dirs #1
Labels
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
carvers/silta#1
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
install_daemon(src/setup.rs:373, andsafe_to_run_as_rootat src/setup.rs:346) checks only the binary file's uid/mode, not the path used to reach it. A root-owned binary reached via a user-owned symlink, or sitting in a user-writable directory, passes the check, and the LaunchDaemon plist then records the swappable path. The config is canonicalized but its parent directory's writability is likewise unchecked.Failure scenario: user runs
sudo ~/bin/silta setup --persistentwhere~/bin/siltais a symlink to root-owned/usr/local/bin/silta(or the binary is root-owned 755 inside a user-writable directory).fs::metadatafollows the link, the check passes, and the plist stores the user-controlled path. The user later replaces the symlink target or renames a new file into place (directory write suffices, no root needed), and arbitrary code runs as root at the next boot -- exactly the escalation the check exists to prevent.Fix direction: resolve the real path (canonicalize the binary), and verify every path component up to root is root-owned and not group/world-writable, for both binary and config.
Source: high-effort code review, CONFIRMED. Area: setup.