Repository navigation
v2.12.0
Security
- Fixes GHSA-qmx6-47vm-3vf7 (high): a binary the classifier did not recognise could carry an elevated command through as
safe.
Minor Changes
-
#232
adc0980Thanks @tufantunc! - A command handed to a binary this classifier does not recognise could carry an elevated command through assafe— the one class that runs onrun-commandwith no approval prompt, whatever the role or approval policy. That gap is now closed: an operand of an unrecognised binary that nothing more specific has already read is classified as a command in its own right, so an elevation it carries is found and the command classifiesprivilegedlike any other.This does mean a command that used to run silently can now prompt for approval or be refused outright under a profile that does not grant
privileged. The one case worth knowing about ahead of time: classification looks at the first word of an operand, sogit commit -m "sudo fix the thing"now classifiesprivilegedand needs approval, wheregit commit -m "fix the sudo thing"still classifies as it always did. If arun-commandyou relied on starts asking for approval, check whether a commit message, comment, or similar free-text argument happens to start withsudo,doas,pkexec, orsu.The interpreter table also gains
osascript,lua,Rscript,bun,tclsh,deno eval, andpwsh/powershell, so a program handed to one of them now classifies the same way a program handed topython3 -cornode -ealready did.pwsh -EncodedCommand's base64 payload is decoded so what it carries is classified rather than merely counted as opaque.tclshcarries no-centry: a differential fuzz run against this branch found thattclsh -c 'exec systemctl stop nginx'had been classifyingdestructiveon the strength of a-cflag realtclshdoes not have — it takes a script file or reads one from stdin, the same as every other interpreter in the table without an inline-program flag. That invocation now classifiessafe, correctly:tclshis still a recognised, unreadable interpreter, soecho … | tclsh(the genuine carrier, a program on stdin) still classifiesdestructive.One gap this does not close, so you know where the edge is: an interpreter's own
value-taking option can still sit between it and its program flag —
bash -o pipefail -c 'shutdown -h now',python3 -W ignore -c '…'— and that payload
reaches the unconditional denylist scan only for the canonicalsh -c '…'spelling. Such a
command still classifiesdestructive, so it is refused for any role that does not hold
that class and prompts for one that does; what it does not get is the never-allowed
treatment. This is unchanged from previous releases.Reported by @MartOcd1709.
-
#232
adc0980Thanks @tufantunc! -sort --compress-program=<path>no longer classifiesread-only.GNU sort runs that program for every temporary file it spills, so a reader becomes a launcher.
sortis on the read-only allowlist, so the whole command classifiedread-only— the one class areadOnlyprofile permits — and a viewer could run an arbitrary program throughread-commandwhile running that same program directly was refused.It now classifies
destructive, throughDISQUALIFYING_ARGS, the table that already heldfind's-execfamily for the same reason. Ordinary sorting is unaffected:sort -u,sort -k2 -n,sort --reverseand a filename that merely contains the word all stayread-only.The first version of this fix closed the four exact spellings it was written against (
-o,--outputand--compress-program, joined and separate) and left GNU sort's own option grammar open around them. Two escapes, both closed now:- A short-option cluster is scanned left to right, and GNU sort lets any of its own argument-less short flags sit ahead of
-owithout consuming it —sort -mo out inwritesoutexactly assort -o out indoes.-m(merge) was the one argument-less flag missing from that set. getopt_longresolves a--word by unambiguous-prefix matching, not exact spelling:--o,--ou,--out,--outpand--outpuall mean--output, and--cothrough--compress-prograall mean--compress-program.--calone is excluded on purpose — it names both--checkand--compress-program, so realsortrefuses to run rather than guess.
Every short flag and every long-option prefix is derived from
sort --helpand measured against the real binary.sort -tofile,sort -t: -k2,2n,sort -ko/-So/-Toandsort --c=…are unaffected: each hands its value to a flag other than-o, or (for the ambiguous--c) never runs at all. - A short-option cluster is scanned left to right, and GNU sort lets any of its own argument-less short flags sit ahead of