Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1231123 > unrolled thread

Bug#977877: console-setup: setupcon --setup-dir ... generates temporary file name inside etc/console-setup directory

Started byAnton Zinoviev <anton@lml.bas.bg>
First post2025-01-31 12:40 +0100
Last post2025-02-06 17:00 +0100
Articles 2 — 1 participant

Back to article view | Back to linux.debian.bugs.dist

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#977877: console-setup: setupcon --setup-dir ... generates temporary file name  inside etc/console-setup directory Anton Zinoviev <anton@lml.bas.bg> - 2025-01-31 12:40 +0100
    Bug#977877: console-setup: setupcon --setup-dir ... generates temporary file name  inside etc/console-setup directory Anton Zinoviev <anton@lml.bas.bg> - 2025-02-06 17:00 +0100

#1231123 — Bug#977877: console-setup: setupcon --setup-dir ... generates temporary file name inside etc/console-setup directory

FromAnton Zinoviev <anton@lml.bas.bg>
Date2025-01-31 12:40 +0100
SubjectBug#977877: console-setup: setupcon --setup-dir ... generates temporary file name inside etc/console-setup directory
Message-ID<KaXxn-di5H-7@gated-at.bofh.it>
On Fri, Jan 31, 2025 at 09:03:26AM +0000, Adithya.Balakumar@toshiba-tsip.com wrote:
> >
> > This temporary file name changes across builds which causes 
> > reproducibility issues.

All file names in /tmp have to be unpredictable or else this leads to 
serious security problems.

> I am attaching a patch that attempts to fix the issue mentioned here. 
> The attached patch attempts to solve this with a consistent suffix 
> appended to the temporary filename.

There are at least two problems in this patch.

First, what if something has already created a file /tmp/tmpkbd.kbdfile 
or /tmp/tmpkbd.kbd_linux or /tmp/tmpkbd.setupdir? Setupcon will fail. 
Anything can make such a file.  This can be a previous failed for some 
reason run of setupcon, an user testing a new version of setupcon, a 
user who intentionaly does a DOS attack.

Second, after you touch the temp file, it is imperative that you test 
that the touched file is owned by the user executing the script and that 
it is not a symlink.  Otherwise, this can easily lead to the so called 
symlink attack.

These are two problems that I can see.  But even if these problems are 
fixed, I would still feel uneasy about the patch.  In the area of 
security the people never say "the program runs ok in most environments, 
so it is ok to release it".  In the area of security the people don't 
care whether the program runs ok or not.  They care that the program is 
safe even in the worst possible UNTHINKABLE environment.

The bottomline is that using "touch" to create a file in /run (with some 
appropriate checks) is probably safe.  If this fails, you can probably 
try to create a file in in the home directory of the user running the 
script (although this would be unmannerly behaviour).  However, if you 
have to create a file in /tmp, then this file has to be created using 
"mktemp".

Anton Zinoviev

[toc] | [next] | [standalone]


#1232008

FromAnton Zinoviev <anton@lml.bas.bg>
Date2025-02-06 17:00 +0100
Message-ID<Kdcsh-eRHg-7@gated-at.bofh.it>
In reply to#1231123
On Thu, Feb 06, 2025 at 10:38:43AM +0000, Adithya.Balakumar@toshiba-tsip.com wrote:
> 
> I may have overlooked a simpler solution to the reproducibility problem I 
> mentioned. I was wondering if we could copy the temporary file to 
> /etc/console-setup with a constant name (in [1]).

The problem is the creation of files with predictable names in a world-writable 
directory like /tmp.

> This does not tweak anything related to the temp file creation itself (either in 
> /tmp or /run) but just rename the file when being copied to /etc/console-setup.

Since /etc/console-setup is not world-writable, I think this should be ok.

Anton Zinoviev

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web