Skip to content

harden socket privacy with private directory validation - #1034

Merged
MalpenZibo merged 1 commit into
MalpenZibo:mainfrom
romanstingler:fix/ipc-socket-private-dir
Oct 8, 2026
Merged

MalpenZibo merged 1 commit into
MalpenZibo:mainfrom
romanstingler:fix/ipc-socket-private-dir

Conversation

@romanstingler

Copy link
Copy Markdown
Collaborator

The IPC socket used to drop back to $TMPDIR/ashell-<uid>.sock with no peer auth, so another local user could squat or spoof it (a planted fake server could even push escape sequences into the victim's ashell msg output).

This change mirrors tmux: under an unusable XDG_RUNTIME_DIR, the socket goes in $TMPDIR/ashell-<uid>/ashell.sock, in a 0700 directory the server creates and both sides refuse unless it's a real (non-symlink) dir owned by the effective uid with mode 0700. On top of that (defense in depth), the accept loop rejects any peer whose peer_cred().uid() isn't us and writes back error permission denied. We warn! when the fallback is taken.

@github-actions github-actions Bot added the bug Something isn't working label Oct 7, 2026

@MalpenZibo MalpenZibo left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@MalpenZibo
MalpenZibo merged commit 5ece340 into MalpenZibo:main Oct 8, 2026
5 checks passed
@romanstingler
romanstingler deleted the fix/ipc-socket-private-dir branch October 8, 2026 11:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants