HyperCore v6.9.3 — Security Audit Remediation
HyperCore v6.9.3 — Security Audit Remediation
Full source audit (daemon, installer, build pipeline, WebUI) with 22 findings remediated.
Breaking
- Install contract:
customize.shnow requireschecksums.txtin the ZIP and verifies the entire extracted payload before any payload file is sourced or executed. Always package viabuild.sh, which now generates the manifest and fails if any expected file is missing.
Security
- Charging thermal ladder restored (
src/charger.c): the ladder was disabled incb6a602, leavingTEMP_OVERRIDE_ENTER/TEMP_EMERGENCY/TEMP_OVERRIDE_CLEARas dead constants whileREADMEstill claimed charging thermal protection existed. The selected mode is now a ceiling that temperature may only lower — one rung down at 45 °C (Violent → Fast → Balanced → Safe), hard floor to Safe Mode at 50 °C, restored only after 180 s continuously ≤41 °C. Dead band between 41–45 °C freezes position to prevent flapping. OEM and Bypass are exempt. - IPC socket authorised (
src/ipc.c):/dev/hypercore.sockaccepted any UID, so any app on the device could set charge modes, force Bypass, or trigger a global page-cache purge as root. Clients are now vetted withSO_PEERCRED(uid 0 for WebUI bridges andhypercore-bugreport, uid 2000 for adb shell) and untrusted peers are closed before the daemon reads from them, which also removes a main-loop stall vector. - Integrity manifest covers executables (
build.sh,customize.sh): the manifest previously listed 7 non-executable files while ignoring every binary and every root-executed script — includingcustomize.shitself. Now 13 files, coveringcustomize.sh,uninstall.sh,scripts/stock_baseline.sh,hypermoon_d,hypermoon.dexandhypercore-bugreport. Two-pass build: hash payload → embed table → relink → appendlibhypercore.so, which cannot embed its own hash. Verified by test: tampering with the daemon or the installer is now detected; previously both passed silently. - No cross-module tampering (
service.sh): removed a loop that chmod'd anyservice.d/post-fs-data.dentry matchingthermal|tweak|encore|ktweakto 0644, silently disabling third-party modules, recording no original mode, and never restored on uninstall. - Logs moved off
/sdcard(src/include/common.hpp,src/log.c): telemetry is written to/data/adb/hypercore/hypercore.loginstead of a world-readable path. - Root-shell injection hardening (
webui/src/helpers/shell.js):am start -dnow receives a single-quoted argument and onlyhttp(s)URLs.
Correctness
hypermoon_daemon→hypermoon_d: at 16 characters the name exceeded the kernel's 15-charactercommlimit, sopkill -xandpidofcould never match it. One daemon leaked per HUD toggle and it survived uninstall entirely, still globbing sysfs and forkingapp_processevery 30 s.build.shnow fails the build if a daemon binary name exceeds 15 characters.- Single-instance lock implemented (
src/main.c):struct hw_nodes.lock_filewas declared and never used, so nothing prevented two daemons fighting over the same sysfs nodes. Now an advisoryflock(LOCK_EX|LOCK_NB)taken afterdaemon(). - Gaming thermal bypass tier-gated (
src/thermal.c):sconfig=10, FPSGOthrm_enable=0and the GPU devfreq cooler reset ran at every tier, fightingmi_thermaldeven at 75 °C. Now Tier 0 only; from Tier 1 up the daemon defers to the vendor thermal stack. - Tier 2 ceilings corrected (
src/thermal.c): documented as 1.5/1.4 GHz but implemented as 1.8/1.8 GHz. Now matches the documented intent. popenno longer in the hot loop (src/gamelist.c): with an empty gamelist and no matching games,pm list packageswas spawningapp_processup to twice a second forever. Auto-detection is now capped at once per hour; thedumpsys windowfallback went 3 s → 10 s and is skipped when the screen is off or asleep.- Overlay watchdog (
src/hud/hypermoon_daemon.c): the dex fallback resolved to/data/adb/hypercore/bin/, a directory that never existed. Now checks real install paths, then/proc/self/exe, then disables itself with one warning instead of forking a shell every 30 s forever. - IPC read loop (
src/ipc.c): a singleread()truncated split commands, soSET_PROFILE:GAMsilently fell through toInteractive. Now loops to newline underSO_RCVTIMEO. - GPU governor detection (
src/hud/hypermoon_daemon.c): a pattern matching zero paths exited the loop on a stale buffer and never set the governor. Also fixed aglob()reuse withoutglobfree()and ausleep()call with a >1 s user-controlled interval. - HyperMoon "restart" (
webui/src/stores/hypermoon.js): now actually kills the processes instead of re-running a liveness check against the still-running daemon. - Exec timeout (
webui/src/helpers/shell.js): rejects instead of resolving'', so a stuck root call is no longer indistinguishable from an empty result. - SIGTERM grace (
service.sh,uninstall.sh): waits up to 10 s / 5 s forrestore_baseline_nodes()to rewrite ~60 sysfs nodes before escalating to SIGKILL.
Docs
- Corrected the "4-Tier thermal mitigation (Tier 0–3)" claim in
READMEanddocs/DOCUMENTATION.txt— there are three tiers; the fourth was removed incb6a602and the docs were never updated. Same for theGET_PROFILEandADD_GAMEIPC commands, which do not exist, and the documented socket path. - Documented the security model: two-layer integrity,
SO_PEERCREDtrust list, single-instance lock, log location.
Housekeeping
- Untracked
webui/node_modules(1263 files already listed in.gitignorebut committed before it existed). Repository.gitshrinks from 64 MB to 17 MB.