Imported OpenVPN configs can carry script directives into root execution #197
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found while researching #82. Removing the custom-scripts feature closes the GUI channel, but imported OpenVPN configs are a second path to the same place: the root service runs openvpn on whatever config an import produced, and a config can carry
script-security 2itself plus any ofup/down/route-up/route-pre-down/ipchange/client-connect. OpenVPN honors config-filescript-securityunless a later command-line option overrides it, so those directives execute as root on connect.aqomui's own script use is narrow and known: the bypass appends
script-security 2+route-up bypass_up.shwhen building its config (tunnel.py), and hop connections pass--script-security 2+--up/--down hop.shon the command line. Nothing aqomui needs lives in an imported config.WireGuard is already covered: wireguard.py deliberately avoids wg-quick and rejects extension keys, so
PostUp/PreDownin an imported wg config never execute. This issue is OpenVPN-only.Precedent: NetworkManager deliberately ignores
PostUp/PreDownwhen importing wg-quick configs — an import channel granting root exec is treated as a bug, and the sanctioned path is a privilege-symmetric one (dispatcher scripts). Same reasoning as #82.Possible shapes (picking one is part of the work):
script-securityfrom imported configs, logging what was dropped. aqomui appends its own directives after this point, so an allowlist isn't even needed.--script-securityafter--configat the level that connection type needs, so a config-file directive can't raise it. Neutralizes rather than removes — and the CLI-overrides-config ordering must be verified against the openvpn versions target distros ship.Sanitize-on-import matches the NM precedent best and keeps the config a user sees on disk equal to what runs.