fix(security): write server.env 0600 in a 0700 data dir and repair older installs (GHSA-mh4f-3xj9-4gc4) - #14994
Merged
Conversation
…der installs (GHSA-mh4f-3xj9-4gc4) server.env holds the generated JWT_SECRET, STORAGE_ENCRYPTION_KEY and API_KEY_SECRET. scripts/build/bootstrap-env.mjs (npm run dev/start, the Docker image) and electron/main.js wrote it and created the data dir without an explicit mode, so under the usual umask 022 they came out 0644 / 0755 — readable by other local accounts (macOS staff group, Debian 0755 homes, the Docker ./data bind mount). bootstrapEnv() only rewrites the file when a secret is missing, so an existing 0644 file stayed 0644. Both writers now create the dir 0700 and the file 0600 (plus chmod, since mode only applies on create), and repair an existing server.env / the dir's "other" bits on every start. Same contract as bin/cli/privateDataDir.mjs from GHSA-2pg2-xm9r-8544; chmod stays best-effort (Windows, foreign-owned dirs). The package-root .env written by sync-env.mjs is left as is: since #11436 it no longer receives generated secrets, and forcing 0600 on a root-owned global install would stop the user's CLI from reading it. Tests fail on the old code (bootstrap: 0755/0644; electron source guard). Reported-by: peterbussch
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes GHSA-mh4f-3xj9-4gc4 (reported by @peterbussch). Follow-up to GHSA-2pg2-xm9r-8544 (#14712).
Problem
server.envholds the generatedJWT_SECRET,STORAGE_ENCRYPTION_KEYandAPI_KEY_SECRET. Two writers created the file and the data directory without an explicit mode:scripts/build/bootstrap-env.mjs, used bynpm run dev/npm startand the Docker image;electron/main.js, the desktop app.Under the usual umask 022 that gives 0644 / 0755, readable by other local accounts: the
staffgroup on macOS, Debian's 0755 homes, and the Docker./databind mount.bootstrapEnv()only rewrites the file when a secret is missing, so a file an earlier version left 0644 stays that way.Fix
server.env0600. They alsochmodafter the write, becausemodeonly applies when a file is created.server.envto 0600 and drop the data dir's "other" bits. This is the same contract asbin/cli/privateDataDir.mjsfrom fix(security): create the data dir 0700 and .env 0600, and repair existing installs (GHSA-2pg2-xm9r-8544) #14712.chmodstays best-effort: it is a no-op on Windows, and a foreign-owned bind mount must not stop the server.The package-root
.envwritten byscripts/dev/sync-env.mjsis left as is. Since #11436 it no longer receives generated secrets, and forcing 0600 on a global install owned by root (sudo npm i -g) would stop the user's CLI from reading it.Validation
tests/unit/bootstrap-env-private-modes.test.ts, 3 cases under umask 022:tests/unit/electron-server-env-private-modes.test.ts: a source guard forelectron/main.js, which exports nothing. It has positive anchors, and 3 of its 4 cases fail on the old file.bootstrap-env,bootstrap-env-sqlite-classifier,electron-main,cli-electron-to-cli-migration-server-env-7302.Operators on macOS, Debian or the Docker bind mount should rotate
JWT_SECRET,API_KEY_SECRETand the storage key if other local accounts could read the old file. Rotating the storage key needs a migration of the encrypted credentials.