Skip to content

use private runtime dir for IPC socket and cava config - #1039

Merged
MalpenZibo merged 1 commit into
MalpenZibo:mainfrom
romanstingler:fix/cava-config-private-dir
Oct 9, 2026
Merged

MalpenZibo merged 1 commit into
MalpenZibo:mainfrom
romanstingler:fix/cava-config-private-dir

Conversation

@romanstingler

Copy link
Copy Markdown
Collaborator

The visualizer config was written to a fixed, shared, predictable path:
$TMPDIR/ashell_cava.cfg. Any local user could pre-create it (the
visualizer then dies with a write error), collide with another user's
file, or, where fs.protected_symlinks/fs.protected_regular are off,
replace it with a symlink or pre-planted file.

This reuses the private-directory machinery from the IPC socket fix
(#1034), extracted into a shared helper:

  • xdg::private_dir(create): $XDG_RUNTIME_DIR when it validates,
    else $TMPDIR/ashell-<uid>, created with mode 0700 and always
    checked to be a real directory owned by the effective user with mode
    0700 (no symlink, no squatting). The fallback warning now fires
    once per process, since the cava subscription restarts on every
    pause/play and menu toggle.
  • ipc::socket_path() delegates to the helper; behavior and error
    messages are unchanged.
  • The cava config is written to ashell_cava.cfg inside that
    directory. Truncate-write is kept: the subscription restarts
    in-process, so create_new would fail with AlreadyExists.

After this, the remaining attacks all require write access to a 0700
directory owned by the victim.

@github-actions github-actions Bot added the bug Something isn't working label Oct 8, 2026

@MalpenZibo MalpenZibo left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

@MalpenZibo
MalpenZibo merged commit 8b88a95 into MalpenZibo:main Oct 9, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants