Vouch request: install.sh hardening and sandbox PATH fix #4167
Sunil56224972
started this conversation in
Vouch Request
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Hi maintainers,
I have been reviewing the OpenShell codebase and found a few hardening improvements I would like to contribute:
install.sh uses --allow-unsigned-rpm with zypper - This flag disables GPG signature verification during package installation. Removing it lets zypper enforce its default signature checks, which is safer for users installing on SUSE/openSUSE.
install.sh chmod 0755 on mktemp directories - After creating a temp directory with mktemp -d (which defaults to 0700), the script immediately widens permissions to 0755. This is unnecessary and weakens the default security posture. Removing the chmod keeps the secure default.
Local sandbox inherits supervisor PATH - The local boundary executor does not set an explicit PATH for sandbox child processes. Setting a fixed, safe PATH value prevents leaking host-specific tool directories into the sandbox environment.
I also identified some environment-ordering concerns in the sandbox executor, but those are more security-sensitive so I will report them through the proper NVIDIA PSIRT channel separately.
I have the fixes and regression tests ready to submit once vouched. Happy to discuss any of these in more detail.
Thanks!
All reactions